Effective date: July 24, 2026 Last updated: July 30, 2026
Summary
Brightcard is a privacy-first, on-device wallet for loyalty cards, tickets, vouchers, holdings, and business cards. We do not collect, transmit, sell, or share your personal data. Brightcard has no accounts, no servers, no analytics, no advertising, and no third-party trackers. Everything you add stays on your device — and leaves it only when *you* explicitly share it or open it in another app (for example, getting directions or sharing a card).
Who we are
Brightcard ("the app") is published by Fioritmo B.V. ("we", "us"); "Brightcard" is a trademark of Fioritmo B.V. We operate from the Netherlands; company details and our registered address are available at https://fioritmo.com. You can reach us at support@brightcard.io.
This policy covers the Brightcard iOS app. The website at brightcard.io (the web version and app-link fallback) is a separate surface; if it collects anything (e.g. standard web-server logs), that is described in the website's own notice.
What data Brightcard handles, and where it lives
You create content in the app: loyalty/membership cards (name, code, barcode/QR/NFC value, colors, notes, optional photo and saved locations), tickets for events and journeys (name, code, the date and time it happens, venue, seat, and any additional codes for other passengers or seats), vouchers (name, code, expiry, face value), holdings accounts and their balance history — including expense reports, where each entry can carry an amount, merchant, category, note, an optional budget, and an attached receipt photo or PDF — and business cards (contact details, optional logo), which you can organise into personas so you keep separate work, freelance and social identities and share the right one at each venue.
All of this is stored only in the app's local database on your device. We have no ability to see it, and it is never uploaded to us. It leaves your device only for the specific item you choose to share or open in another app — see "Maps, directions & links to other apps" below.
What we collect: nothing
- No account and no sign-up. Brightcard has no username, password, email login, or user profile.
- No servers — and no server-side pass creation. The app makes no network requests to us; there is no Brightcard backend. This is also why Brightcard renders your barcodes and QR codes on your device instead of generating signed
.pkpasspasses: creating a.pkpassrequires a pass-signing server, so many wallet apps quietly send your card details off to their servers to produce one — something most of them never spell out. Brightcard never does. (You can still *import* a.pkpassyou already have; it's unpacked entirely on-device — see "Importing passes" below.) - No analytics or telemetry. We do not measure usage, crashes, or behavior.
- No advertising and no tracking. We do not use the advertising identifier (IDFA) and do not track you across apps or websites.
- No third-party SDKs that collect data.
Authentication (passkey)
Access is protected by an on-device passkey using your device's Secure Enclave and Face ID / Touch ID / passcode. The private key never leaves the Secure Enclave, is never transmitted, and is not known to us. There is no password to store or recover.
Device permissions and how each is used
Brightcard asks for a permission only at the moment a feature needs it. Data from these stays on your device and is never sent to us.
- Camera — to scan a barcode/QR code, take a photo to use as a card background, or photograph a receipt for an expense report. Images are processed on-device.
- Photos — you may choose an existing photo for a card background, a card image to detect a code from, or a receipt for an expense, via the system photo picker. The app only receives the photo you pick.
- NFC — to read data from a physical NFC tag so you can save it as a card.
- Location (While Using / Always) — optional. Used to suggest saved cards near you and, if you enable it, to remind you about a saved card when you arrive at one of its locations. Location is evaluated on your device and is never collected by us. (If you tap Directions for a saved location, the destination is handed to your chosen maps app — see "Maps, directions & links to other apps" below.) "Always" access is only needed for arrival reminders when the app is in the background, and you can decline or revoke it at any time in iOS Settings.
- Contacts — when you tap "Add to Contacts," the app opens the system contact card so you can save a business card to your Contacts. Brightcard writes only the contact you choose to save and does not read or upload your contacts.
- Face ID / biometrics — to unlock the app and to reveal protected values.
- Notifications — local reminders only (ticket event times, voucher expiry, location arrivals). Scheduled on-device; no push server is involved.
On-device intelligence (receipt scanning & code detection)
Some features analyze an image you provide — reading the text on a receipt to suggest an amount, merchant, category and date for an expense, or detecting a barcode/QR code in a photo so you can create a card from it. All of this runs entirely on your device using Apple's on-device Vision framework. No image, receipt, or extracted text is uploaded, sent to us, or processed by any server or third party. The suggestions are yours to accept or edit, and the analysis happens locally each time. Automatic receipt scanning is a Brightcard Pro feature and can be switched off any time in Settings; you can always attach a receipt and enter the details by hand.
Home Screen widgets
Brightcard Pro can show a Home Screen widget: a Flagged widget listing items you individually marked "Show in Widget," and a Nearby widget showing loyalty cards close to one of their saved locations. Both are off by default — the Flagged widget shows only items you explicitly opt in, one by one.
To draw a widget, the app writes a small snapshot into a shared App Group container on your device that the widget can read. That snapshot never contains a card's scannable code or a rendered barcode/QR image — only display details (name, colour, an icon, a masked hint, and for Nearby the place label and distance). Tapping a widget opens Brightcard, where the actual code is shown behind your passkey — so the code never lives outside the lock. The snapshot stays on your device; nothing about it is sent to us or any server. The Nearby widget's distances are computed from location evaluated on your device (see the Location permission above).
Apple Watch
If you have a paired Apple Watch, Brightcard Pro can show your loyalty cards, tickets and vouchers on the Watch so you can scan them from your wrist. This is off by default and doubly opt-in: you must turn on Watch sync in Settings and mark each individual item "Show on Apple Watch." Only the items you explicitly opt in are ever sent.
The data travels directly from your iPhone to your paired Watch over Apple's WatchConnectivity link — never through a Brightcard server or any network. The iPhone renders each card's code to an image and sends it, along with the card's name and value, to the Watch, which caches it locally so it works out of Bluetooth range. NFC cards are not sent as a scannable code. Nothing about this reaches us, and turning off Watch sync (or letting Pro lapse) clears the cards from the Watch.
Importing passes (.pkpass)
Brightcard Pro can import an Apple Wallet .pkpass file (for example a loyalty card or pass you received) into your wallet. The file is read and unpacked entirely on your device to create a card; nothing about the pass is sent to us or any server.
iCloud Keychain (encryption key sync)
If you use encrypted backups, the encryption key is stored in your iCloud Keychain so your own Apple devices can open your backups. iCloud Keychain is operated by Apple and protected by Apple's end-to-end encryption; it is governed by Apple's Privacy Policy. We never receive this key. Your wallet contents are not synced by us; only the key rides iCloud Keychain, and only if iCloud Keychain is enabled on your device.
Backups you create
You can export an encrypted backup file. It is encrypted so that only your key can open it, and rejects import on a device that does not hold your key. You choose where the file goes (AirDrop, Files, Mail, etc.); once you share it, its handling is governed by wherever you send it. We are not involved and cannot access it.
Secure Transfers (sharing items with another person)
Brightcard lets you send a card, group, or your whole wallet to another person — for example a family member on a different Apple Account — as an encrypted Secure Transfer. This is a file-based, end-to-end encrypted feature, and no Brightcard server or network is ever involved.
Here is exactly how it works and what it means for your data:
- The item(s) are encrypted on your device before they leave the app. Brightcard serializes what you chose (card details, tickets and their additional codes, holdings balances, business-card contact fields, vouchers, saved locations, etc.), encrypts it with AES-256-GCM, and writes a single encrypted
.bcsharefile. The encryption key is derived from a short transfer code (e.g.K7QP-4M9X) that the app shows only to you. - The transfer code is never inside the file. You share the code with the recipient separately and out-of-band (say it aloud, text it in another app). The file alone cannot be opened; the recipient must type the code to decrypt it. If the code is wrong, decryption fails.
- You choose how the file travels. The encrypted file is handed to the standard iOS share sheet, so you can send it over AirDrop, Messages, Mail, or any file/cloud provider you pick. Whatever channel you choose then handles the file under its own terms — but because the file is encrypted and the code travels separately, that channel cannot read the contents.
- We are never involved and cannot access it. There is no Brightcard account, server, or backend in this flow. We do not receive, route, store, or log the transferred data or the code.
Because confidentiality depends on the code, keep the transfer code separate from the file and share it only with the intended recipient. Anyone who obtains both the file and its code can open the transferred items.
Maps, directions & links to other apps
Some actions you take hand a single piece of information to another app or service that you choose. In each case it's initiated by you, only the item involved is sent, and it never passes through a Brightcard server (there isn't one). We don't receive or log any of it.
- Directions: tapping *Directions* for a saved location opens Apple Maps or Google Maps and shares that destination with the provider you pick so it can route you. That provider then handles it under its own privacy policy (Apple, Google). Brightcard shows a one-time notice before the first time this happens, and it never happens automatically.
- Business card links: tapping a phone number, email, website, or *Add to Contacts* opens the relevant system app with the detail you tapped.
- Sharing: sharing a card, QR code, vCard, an encrypted backup, or an encrypted Secure Transfer sends only what you chose to wherever you send it. (Secure Transfers are additionally end-to-end encrypted with a separate code — see "Secure Transfers" above.)
Purchases (Brightcard Pro)
Brightcard Pro is sold as a single one-time in-app purchase (no subscription) processed entirely by Apple through the App Store. Payment and billing are handled by Apple under Apple's terms and privacy policy; we do not receive your name, payment method, or card details. Your Pro status is determined on your device from your App Store purchase history — nothing about your purchases is sent to us.
Data retention and deletion
Your data lives on your device for as long as you keep it. Delete individual items, or delete the app, to remove it. Because we hold nothing, there is no server-side copy for us to delete. (There is no account, so no account to delete — this satisfies App Store account-deletion requirements by design.)
Security
Your content is protected by iOS app data protection and your device passcode/biometrics. The app is gated by a Secure Enclave passkey, and both backups and Secure Transfers are encrypted with AES-256-GCM (a Secure Transfer's key is derived from a transfer code you share separately from the file). No system is perfectly secure, but nothing leaves your device unless you explicitly export or share it.
Children
Brightcard is not directed at children and does not knowingly collect any data from anyone, including children.
Your rights (GDPR, CCPA/CPRA, and similar)
Because we do not collect or process your personal data, most data-subject requests (access, deletion, portability, opt-out of sale/sharing) have nothing for us to act on — you already hold and control all of your data on your device. We do not sell or share personal information. If you have a question, contact support@brightcard.io.
Changes to this policy
If we change this policy, we will update the date above and post the new version at this URL. Material changes will be reflected in an app update where appropriate.
Contact
Fioritmo B.V. — support@brightcard.io