FeaturesPrivacyPricing
Get Brightcard
Privacy

Privacy Policy

Effective July 24, 2026Last updated August 27, 2026
On this page
  1. Summary
  2. Who we are
  3. What data Brightcard handles, and where it lives
  4. What we collect: nothing
  5. Authentication (passkey)
  6. Device permissions and how each is used
  7. On-device intelligence (receipt scanning, business-card scanning & code detection)
  8. Dictating a note
  9. The vault (notes, and the secrets in them)
  10. Payment cards (credit cards)
  11. Identity documents
  12. Home Screen widgets
  13. Apple Watch
  14. Importing passes (.pkpass)
  15. iCloud Keychain (encryption key sync)
  16. Collections (asking other people for details, and answering)
  17. Shared expenses
  18. Backups you create
  19. Secure Transfers (sharing items with another person)
  20. Maps, directions & links to other apps
  21. Purchases (Brightcard Pro)
  22. Data retention and deletion
  23. Security
  24. Children
  25. Your rights (GDPR, CCPA/CPRA, and similar)
  26. Changes to this policy
  27. Contact

Effective date: July 24, 2026 Last updated: August 27, 2026

Summary

Brightcard is a privacy-first, on-device wallet for loyalty and payment cards, tickets, vouchers, holdings, and business cards. We do not collect, transmit, sell, or share your personal data. Brightcard has no accounts, no servers, no analytics, no advertising, and no third-party trackers. Everything you add stays on your device, and leaves it only when *you* explicitly share it or open it in another app (for example, getting directions or sharing a card).

Who we are

Brightcard ("the app") is published by Fioritmo B.V. ("we", "us"); "Brightcard" is a trademark of Fioritmo B.V. We operate from the Netherlands; company details and our registered address are available at https://fioritmo.com. You can reach us at support@brightcard.io.

This policy covers the Brightcard iOS app. The website at brightcard.io (the web version and app-link fallback) is a separate surface; if it collects anything (e.g. standard web-server logs), that is described in the website's own notice.

What data Brightcard handles, and where it lives

You create content in the app: notes kept in notebooks, each with a title, free text, and any number of fields you name yourself, where a field can be marked secret so its value stays hidden until you ask for it (a password, a licence key, a door code) loyalty/membership cards (name, code, barcode/QR/NFC value, colors, notes, optional photo, saved locations, and any key/value details you add, a customer number, a branch, a PIN, where a detail can be marked secret so it stays hidden until you ask), credit and other payment cards (holder name, card number, expiry month and year, the security code, CVC/CVV, if you choose to add one, and the same key/value details, secret ones included), identity documents (a passport, identity card, driving licence, residence permit or other document, which document it is, the name printed on it, its number, its expiry date, details such as nationality, date and place of birth or issuing authority, and photographs of the front and back if you add them), tickets for events and journeys (name, code, the date and time it happens, venue, seat, and any additional codes for other passengers or seats), vouchers (name, code, expiry, face value), holdings accounts and their balance history, including expense reports, where each entry can carry an amount, merchant, category, note, an optional budget, an attached receipt photo or PDF, and a shared expense: the people a bill was split with (a name, copied from a contact you picked or typed by hand, and whether they have settled up), the itemised lines it was split from, and any amount assigned to a person outright, and business cards (contact details, optional logo), which you can organise into personas so you keep separate work, freelance and social identities and share the right one at each venue.

All of this is stored only in the app's local database on your device. We have no ability to see it, and it is never uploaded to us. It leaves your device only for the specific item you choose to share or open in another app, see "Maps, directions & links to other apps" below.

What we collect: nothing

  • No account and no sign-up.: Brightcard has no username, password, email login, or user profile.
  • No servers, and no server-side pass creation.: The app makes no network requests to us; there is no Brightcard backend. This is also why Brightcard renders your barcodes and QR codes on your device instead of generating signed .pkpass passes: creating a .pkpass requires a pass-signing server, so many wallet apps quietly send your card details off to their servers to produce one, something most of them never spell out. Brightcard never does. (You can still *import* a .pkpass you already have; it's unpacked entirely on-device, see "Importing passes" below.)
  • No analytics or telemetry.: We do not measure usage, crashes, or behavior.
  • No advertising and no tracking.: We do not use the advertising identifier (IDFA) and do not track you across apps or websites.
  • No third-party SDKs that collect data.

Authentication (passkey)

Access is protected by an on-device passkey using your device's Secure Enclave and Face ID / Touch ID / passcode. The private key never leaves the Secure Enclave, is never transmitted, and is not known to us. There is no password to store or recover.

Device permissions and how each is used

Brightcard asks for a permission only at the moment a feature needs it. Data from these stays on your device and is never sent to us.

  • Camera: to scan a barcode/QR code, take a photo to use as a card background, photograph a receipt for an expense report, photograph a paper business card so its details can be read into a new contact, photograph a credit card so its number and dates can be read in, or photograph an identity document. It is also used to read a document's machine-readable zone live: the camera runs, each frame is examined on the spot for the two or three lines of capitals, and when the numbers are found they fill in the fields. Those frames are never saved, see "Identity documents" below. Images are processed on-device.
  • Photos: you may choose an existing photo for a card background, a card image to detect a code from, a receipt for an expense, or a photo of a business card to read, via the system photo picker. The app only receives the photo you pick.
  • NFC: to read data from a physical NFC tag so you can save it as a card, if you choose to read the chip in your own passport or identity card, and if you choose to read a contactless payment card in order to save its number and expiry. Every chip exchange is read-only: nothing is written to the document or the card, nothing authorises a payment, and nothing leaves the phone. See "Identity documents" and "Payment cards" below.
  • Location (While Using / Always): optional. Used to suggest saved cards near you and, if you enable it, to remind you about a saved card when you arrive at one of its locations. Location is evaluated on your device and is never collected by us. (If you tap Directions for a saved location, the destination is handed to your chosen maps app, see "Maps, directions & links to other apps" below.) "Always" access is only needed for arrival reminders when the app is in the background, and you can decline or revoke it at any time in iOS Settings. When it is granted, Brightcard also notices when you *leave* a saved location, not to notify you, but so the Nearby widget stops showing a card you have walked away from. That evaluation happens on your device like the rest.
  • Contacts: when you tap "Add to Contacts," the app opens the system contact card so you can save a business card to your Contacts. Brightcard writes only the contact you choose to save and does not read or upload your contacts.
  • Microphone: optional, and only while you are dictating a note. The audio is turned into text on your device and is not recorded, kept, or sent anywhere, see "Dictating a note" below.
  • Face ID / biometrics: to unlock the app and to reveal protected values.
  • Notifications: local reminders only (ticket event times, voucher expiry, location arrivals). Scheduled on-device; no push server is involved.

On-device intelligence (receipt scanning, business-card scanning & code detection)

Some features analyze an image you provide:

  • Receipts: reading the text on a receipt photo or PDF to suggest an amount, merchant, category and date for an expense.
  • Business cards: photographing (or picking, or pasting) a paper business card so its text can be read into a new contact: name, company, job title, phone, email, website, address, and anything left over as a note. The photo is used only for that reading and is not saved to the card or kept by the app only the text you keep is stored, and only in fields you had left empty. While the form is open you can preview the photo, with the parts that were read marked on it, so you can check the result against the card; that preview is held in memory and goes when you close the form. Because a photo of paper is never a certain thing, every field is a suggestion for you to check and correct.
  • Codes: detecting a barcode/QR code in a photo so you can create a card from it.
  • Payment cards: reading the printing on a photo of a credit card to fill in the number and, where the card shows them, the expiry, holder name and security code. As with a business card, the photo is used only for that reading and is not saved to the card.
  • Identity documents: reading the two or three lines of block capitals along the bottom of a passport or ID card (the *machine-readable zone*) to fill in the name, document number, nationality, date of birth, sex and expiry, and detecting the printed portrait so it can be cropped out and kept as the document's thumbnail. A North American driving licence has no such zone, so the PDF417 barcode on its back is read instead, the same fields, plus the issuing state and the address printed on the licence. The photograph you took is saved to the card, because it is the scan you asked for; nothing about it is uploaded.
  • The live zone scan: when the app needs the three numbers that unlock a document's chip, it can read them straight from the camera rather than asking you to type them. The camera runs, each frame is examined on your device, and the numbers appear on screen as they are read. No frame is stored, and no photograph is produced: what survives is the three values, and only until you use or discard them. This exists because typing a document number by hand is error-prone, not so that anything extra can be captured.

All of this runs entirely on your device using Apple's on-device Vision framework. No image, receipt, business card, payment card, or extracted text is uploaded, sent to us, or processed by any server or third party. The suggestions are yours to accept or edit, and the analysis happens locally each time.

Dictating a note

You can speak a note instead of typing it. Brightcard uses Apple's on-device speech recognition (the SpeechAnalyzer framework in iOS 26), which transcribes locally, on your device:

  • Your voice is never sent anywhere.: The audio is transcribed as you speak and then discarded, no recording is saved, by us or on your device. Only the text that lands in the note is stored, and you can edit or delete it like anything you typed.
  • The language model is a download; your speech is not.: The first time you dictate in a language, iOS fetches that language's recognition model from Apple. That is the only network activity involved, it carries nothing about you, and after it completes dictation works with no connection at all.
  • We don't use the older server-based recognition.: Apple's speech API can send audio to Apple's servers; Brightcard deliberately uses the on-device framework instead, so there is no configuration in which your voice leaves the device.
  • Not every language can be transcribed locally on every device.: When yours can't, the Dictate button is simply absent; Brightcard will not fall back to a server to make the feature work.
  • The microphone is only live while you are dictating, and it is released the moment you stop or leave the note. iOS shows its own indicator while any app is listening.

Receipt scanning and business-card scanning are Brightcard Pro features, and each can be switched off any time in Settings; you can always attach a receipt or type a contact in by hand.

The vault (notes, and the secrets in them)

Brightcard Pro includes a vault: notes, filed in notebooks, each holding text and fields you name yourself. A field can be marked secret, which is what lets a password sit beside the account it belongs to.

What that means concretely:

  • A secret is stored the same way everything else sensitive is: sealed in the app's local database on your device and reachable only behind your passkey. It is not sent anywhere, and there is no Brightcard account or server that could hold it.
  • Secret values are masked in the app: until you tap to reveal them, one field at a time. That mask is about the person next to you, not about us: we never see either state.
  • A secret is sealed, not merely hidden behind the lock.: The value is encrypted where it sits (AES-GCM), under a key held in the device keychain that can be read only on this device and only while it is unlocked. Card numbers, PINs, note bodies, document scans and receipts are sealed the same way. We never hold the key; there is nowhere for it to be. See Security below for what that does and does not protect against.
  • Notes can carry saved places: like a card can, so arriving somewhere can remind you about one. Evaluated on your device; see the Location permission above.
  • Notes can carry attachments: photos taken with the camera, images from your library or clipboard, and files (PDFs or images) picked from Files. They are stored in the app's local database like everything else, are never uploaded, and nothing is read out of them: an attachment is kept, not analysed. Photos are downscaled and re-encoded at the image quality you choose in Settings, to keep the space they take reasonable.
  • Backups and Secure Transfers include notes, secrets and all: attachments included. Both are encrypted (AES-256-GCM), and a transfer's code travels separately from the file, see those sections below.
  • Searching a note looks inside it, including its secret values, because the search runs entirely on your device behind your passkey and a password you cannot find is a password you cannot use.

Payment cards (credit cards)

A card you add as a credit card is stored exactly like everything else sensitive: in the app's local database on your device, with the number itself sealed under a key that needs you present, reachable only behind your passkey. It is never uploaded, and there is nobody to upload it to: Brightcard has no servers.

Some specifics, because this is the most sensitive thing the app can hold:

  • It is a record, not a payment method.: Brightcard cannot pay for anything. It does not talk to your bank, a card network, or a payment processor; it is not a wallet in the Apple Pay sense, and adding a card here neither registers nor activates it anywhere. It is the equivalent of writing the card down somewhere only you can read.
  • Masked by default, and revealing needs your face or passcode.: A payment card's number starts hidden, showing only the last four digits. Uncovering the number, the security code, or a detail you marked secret, or copying the number, each asks for Face ID / Touch ID / your device passcode first, one at a time. Everything re-hides when you leave the card or put the app away, so a number uncovered a minute ago is not still on screen when the phone is picked up again. (On a device with no biometrics or passcode set up, or with the app lock turned off, there is no credential to check against and the reveal proceeds, the alternative would be locking you out of your own card.) Copying asks because the clipboard is readable by whatever app you open next.
  • Never on a glanceable surface.: Payment cards are excluded from the Apple Watch and from Home Screen widgets, not merely switched off by default, but excluded, because a number or a security code that can be read over your shoulder defeats the point of masking it.
  • Reading a card from a photo happens on your device.: If you photograph (or pick, or paste) a card, Apple's on-device Vision framework reads the printing and the app fills in what it finds: the number, and the expiry, holder and security code where the card shows them and your fields are still empty. The photo is used only for that reading and is not saved to the card. The number is checked against the card's own checksum, so a misread is discarded rather than saved.
  • Reading a card's chip over NFC does the same job, and cannot do more.: Instead of photographing a contactless card you can hold it against the phone and let the app read its chip. What the chip hands over is what is printed on the front: the number, the expiry, and which scheme issued it. The exchange is read-only and authorises nothing: there is no payment, no bank is contacted, and no network is involved at any point. The security code cannot be read this way, by us or by anyone. A card's chip does not carry the CVC/CVV printed on the back in any readable form, so the one field a card thief actually needs is not obtainable here even by mistake.
  • You decide whether to store a security code at all.: The field is optional and empty unless you fill it. Industry guidance for *merchants* is not to retain security codes; that guidance is about businesses storing other people's cards on servers, which is a different situation from your own card on your own locked device, but if you would rather not keep it, leave the field blank and nothing is stored.
  • Backups and transfers include it.: A payment card travels in an encrypted backup and in a Secure Transfer like any other item (see those sections below). A backup file is only as protected as where you put it.

Identity documents

An identity document a passport, an identity card, a driving licence, a residence permit, is held the same way a payment card is, and for the same reason: it is the sort of record that would matter if it left the device, so it does not.

  • It is a record, not a credential.: Brightcard cannot present a document to anyone, prove your identity to a service, or act as an official ID. It is the equivalent of keeping a photocopy in a locked drawer, including for a family member's document, which is yours to keep in the same sense the paper copy is.
  • Masked by default, and revealing needs your face or passcode.: The document number starts hidden. Uncovering it, or copying it, asks for Face ID / Touch ID / your device passcode first, and everything re-hides when you leave the card or put the app away.
  • Never on a glanceable surface.: Identity documents are excluded from the Apple Watch and from Home Screen widgets, not merely defaulted off: a passport number readable over your shoulder is exactly what masking is meant to prevent.
  • Reading the zone with the camera keeps nothing.: The quickest way to fill in a document's details, and the three numbers its chip needs, is to point the camera at the machine-readable zone and let the app read it as you hold it. That runs frame by frame on your device and stores no image at all: no photograph is taken, none is written to the card, and only the values you can see on screen are kept. Photographing the document is a separate, deliberate act, described next.
  • The photographs stay on the device.: A front or back photo you add is downscaled and stored in the app's local database (sealed under the same key as a secret, in external file storage), and is not uploaded or sent anywhere. It *is* analysed, on your device only, if you let the app read it: Apple's Vision framework looks for the machine-readable zone and the printed portrait, and what it finds fills in the fields and becomes the thumbnail.
  • Reading the chip is optional, local, and read-only.: Most passports and ID cards contain a chip holding the issuer's own copy of the printed details and the portrait. If you choose to, Brightcard can read it over NFC: you hold the phone against the document, and the app talks to the chip directly using the access protocols in the ICAO 9303 standard (PACE, or the older BAC). Three things about how that works are worth stating plainly: - The chip only answers to the document.: The key is derived from the document number, date of birth and expiry date printed on it, or the card access number on the front. Brightcard cannot read a chip it is not holding the document for, and neither can anyone else. - Nothing is written, and nothing is sent.: The exchange is read-only: the app cannot alter a document's chip. What it reads, the data groups holding the machine-readable zone and the portrait, is decrypted on your device and saved to the card you are adding. No part of it, and no part of the exchange, reaches us or anyone else. There is no network involved at any point. - It is not a verification.: Brightcard does not check the chip's signature against a country's certificate authority, and does not claim a document is genuine. What you get is what the chip said.
  • Linking a document to a ticket keeps both on the device.: You can mark which passport or ID a trip is booked on, per booking and per passenger, so Brightcard can warn you when a document expires before, or too soon after, the date on the ticket. The link is a reference between two things already on your phone: no document details are copied onto the ticket, and no check is made against any authority, airline or service.
  • Backups and transfers include it.: An identity document travels in a backup, an export and a Secure Transfer like any other item, photographs included, because a restore that handed back the record without the scan would have lost the part you took the trouble to photograph. A backup file is only as protected as where you put it.

Home Screen widgets

Brightcard Pro can show a Home Screen widget: a Flagged widget listing items you individually marked "Show in Widget," and a Nearby widget showing loyalty cards close to one of their saved locations. Both are off by default the Flagged widget shows only items you explicitly opt in, one by one.

To draw a widget, the app writes a small snapshot into a shared App Group container on your device that the widget can read. That snapshot never contains a card's scannable code or a rendered barcode/QR image only display details (name, colour, an icon, a masked hint, and for Nearby the place label and distance). Tapping a widget opens Brightcard, where the actual code is shown behind your passkey so the code never lives outside the lock. A widget that holds more items than it can show can be paged through with its own buttons; which page it is on is remembered on your device alongside the snapshot. The snapshot stays on your device; nothing about it is sent to us or any server. The Nearby widget's distances are computed from location evaluated on your device (see the Location permission above).

Apple Watch

If you have a paired Apple Watch, Brightcard Pro can show your loyalty cards, tickets and vouchers on the Watch so you can scan them from your wrist. This is off by default and doubly opt-in: you must turn on Watch sync in Settings and mark each individual item "Show on Apple Watch." Only the items you explicitly opt in are ever sent.

The data travels directly from your iPhone to your paired Watch over Apple's WatchConnectivity link, never through a Brightcard server or any network. The iPhone renders each card's code to an image and sends it, along with the card's name and value, to the Watch, which caches it locally so it works out of Bluetooth range. NFC cards are not sent as a scannable code, and payment cards are never sent to the Watch at all. Nothing about this reaches us, and turning off Watch sync (or letting Pro lapse) clears the cards from the Watch.

Importing passes (.pkpass)

Brightcard Pro can import an Apple Wallet .pkpass file (for example a loyalty card, event ticket or boarding pass you received) into your wallet. The file is read and unpacked entirely on your device, and you choose whether it becomes a card or a ticket, the pass's own type picks the default. Nothing about the pass is sent to us or any server.

iCloud Keychain (encryption key sync)

If you use encrypted backups, the encryption key is stored in your iCloud Keychain so your own Apple devices can open your backups. iCloud Keychain is operated by Apple and protected by Apple's end-to-end encryption; it is governed by Apple's Privacy Policy. We never receive this key. Your wallet contents are not synced by us; only the key rides iCloud Keychain, and only if iCloud Keychain is enabled on your device.

Collections (asking other people for details, and answering)

Collections lets you ask other people for details you need, and lets other people ask you. It is the one feature where somebody else's data can end up on your device, so what follows is exact.

There is still no server and no account. A request and a reply are files you pass by whatever means you already use, mail, a messaging app, AirDrop, and Brightcard is not a party to that delivery. Nothing is routed through us, and we never see a request, a reply, or the fact that either happened.

Being asked

  • Only somebody you have already approved can ask you.: A requester is identified by their signing key, not by a name in a text field, so impersonating an organiser requires their key rather than their letterhead. A request from anyone you have not saved and approved does not open. Revoking a requester stops them asking you again.
  • You choose what goes back, field by field.: The app states in its own words what you are about to hand over, never the organiser's, and nothing is sent until you send it.
  • A reply is sealed to the organiser and nobody else.: What you send is encrypted to the organiser's key, so the mail server it crosses, and any phone it is forwarded through, carry ciphertext they cannot read. It is separately signed so the organiser can tell who it came from.
  • You can withdraw it.: A withdrawal notice makes the organiser's app destroy the key to your answer, which renders it unreadable wherever that ciphertext exists, including in their backups. What no app can reach is a copy they have already exported or printed, and Brightcard says so rather than implying otherwise.

Doing the asking

  • Answers are encrypted at rest, individually.: Each submission is sealed under its own key. The app never holds a decrypted pile of other people's documents: an export is assembled only when you ask for one, and handed straight out.
  • A retention promise is kept, not just displayed.: If you set a date by which answers will be destroyed, the request states it and the app carries it out on that date, shredding each answer by destroying its key. What remains is the manifest: who was asked, who answered, and that the purge happened.
  • What you gather is yours to look after.: Other people's details on your device are your responsibility, including whatever law applies to holding them. Brightcard gives you the retention and shredding tools; it cannot see whether you use them.

Shared expenses

An expense in a holdings report can record that a bill was split with other people: who was there, what each line cost, who had it, and who has since settled up. This is the only part of Brightcard that is *about* other people rather than about you, so it is worth being exact about what that means.

  • The people are names you hold, not accounts anyone signs into.: A participant is a name and nothing more. When you pick one from the business cards you keep inside Brightcard (your iPhone's own Contacts database is neither read nor searched for this), the name is copied rather than linked, so a bill settled last year still says who was at it after you rename or delete that contact. Nobody is contacted, invited, notified, or looked up. The other people in a split do not need the app, are never told they are in it, and no request goes anywhere.
  • The arithmetic is shown, not asserted.: A split keeps the lines it was worked out from and derives the totals from them, so a person being asked for money can check the sum rather than take a figure on trust. Where the shares and the amount actually spent disagree, the app states the difference rather than absorbing it.
  • It stays on your device like everything else.: A split is stored in the app's local database with the expense it belongs to, and travels in an encrypted backup or a Secure Transfer exactly as any other item does. It is never uploaded, and there is nobody to upload it to.

Handing a split to somebody

Two routes take a split off the device, and both are things you do deliberately, item by item:

  • As a PDF.: An expense report can be rendered as a page, with the split, the arithmetic, the merchant, the date and the receipts, so it can go to somebody who does not have the app. Because a page that has been sent is somebody else's copy forever, the export asks first which expenses to include, and separately whether the page should say who has settled up. A report holds things that are nobody else's business, and the export is where that stops being recoverable. The file goes wherever you send it; once shared, its handling is governed by that destination, and we are not involved.
  • As a reply to a collection request.: Where somebody has asked you for expenses through Collections, you can answer from the report you already keep instead of typing figures again. Every line starts unticked, and only the lines you choose, plus the receipts belonging to them, are included. Everything you do not tick never leaves the device. The reply itself travels under the Collections rules described above, sealed to the organiser and withdrawable.

Backups you create

You can export an encrypted backup file. It contains everything the wallet holds, items, groups, balance and expense history, vault notes and their secrets, and the files you attached: card photos, contact logos, expense receipts and note attachments. A backup that gave you back less than you had would not be a backup, which is why it carries the images too and why a photo-heavy wallet produces a file measured in megabytes. It is encrypted so that only your key can open it, and rejects import on a device that does not hold your key. You choose where the file goes (AirDrop, Files, Mail, etc.); once you share it, its handling is governed by wherever you send it. We are not involved and cannot access it.

Secure Transfers (sharing items with another person)

Brightcard lets you send a card, group, or your whole wallet to another person, for example a family member on a different Apple Account, as an encrypted Secure Transfer. This is a file-based, end-to-end encrypted feature, and no Brightcard server or network is ever involved.

Here is exactly how it works and what it means for your data:

  • The item(s) are encrypted on your device before they leave the app.: Brightcard serializes what you chose (card details, tickets and their additional codes, holdings balances, business-card contact fields, vouchers, saved locations, etc.), encrypts it with AES-256-GCM, and writes a single encrypted .bcshare file. The encryption key is derived from a short transfer code (e.g. K7QP-4M9X) that the app shows only to you.
  • The transfer code is never inside the file.: You share the code with the recipient separately and out-of-band (say it aloud, text it in another app). The file alone cannot be opened; the recipient must type the code to decrypt it. If the code is wrong, decryption fails.
  • You choose how the file travels.: The encrypted file is handed to the standard iOS share sheet, so you can send it over AirDrop, Messages, Mail, or any file/cloud provider you pick. Whatever channel you choose then handles the file under its own terms, but because the file is encrypted and the code travels separately, that channel cannot read the contents.
  • We are never involved and cannot access it.: There is no Brightcard account, server, or backend in this flow. We do not receive, route, store, or log the transferred data or the code.

Because confidentiality depends on the code, keep the transfer code separate from the file and share it only with the intended recipient. Anyone who obtains both the file and its code can open the transferred items.

Maps, directions & links to other apps

Some actions you take hand a single piece of information to another app or service that you choose. In each case it's initiated by you, only the item involved is sent, and it never passes through a Brightcard server (there isn't one). We don't receive or log any of it.

  • Directions:: tapping *Directions* for a saved location opens Apple Maps or Google Maps and shares that destination with the provider you pick so it can route you. That provider then handles it under its own privacy policy (Apple, Google). Brightcard shows a one-time notice before the first time this happens, and it never happens automatically.
  • Business card links:: tapping a phone number, email, website, or *Add to Contacts* opens the relevant system app with the detail you tapped.
  • Sharing:: sharing a card, QR code, vCard, an encrypted backup, or an encrypted Secure Transfer sends only what you chose to wherever you send it. (Secure Transfers are additionally end-to-end encrypted with a separate code, see "Secure Transfers" above.)

Purchases (Brightcard Pro)

Brightcard Pro is sold as a single one-time in-app purchase (no subscription) processed entirely by Apple through the App Store. Payment and billing are handled by Apple under Apple's terms and privacy policy; we do not receive your name, payment method, or card details. Your Pro status is determined on your device from your App Store purchase history, nothing about your purchases is sent to us.

Data retention and deletion

Your data lives on your device for as long as you keep it. Delete individual items, or delete the app, to remove it. Because we hold nothing, there is no server-side copy for us to delete. (There is no account, so no account to delete, this satisfies App Store account-deletion requirements by design.)

Security

Your content is protected by iOS app data protection and your device passcode/biometrics. The app is gated by a Secure Enclave passkey, and both backups and Secure Transfers are encrypted with AES-256-GCM (a Secure Transfer's key is derived from a transfer code you share separately from the file). No system is perfectly secure, but nothing leaves your device unless you explicitly export or share it.

The sensitive fields are sealed individually, not merely gated. A lock and encryption are different promises, and it is worth being exact about which one you are getting. A passkey gate decides what the app *draws*: it stops a person holding your phone, but it does not stop code. iOS unlocks an app's container at first unlock and leaves it unlocked, so anything that can read that container, malware with a sandbox escape, a jailbreak, a backup pulled through a trusted computer, could read whatever sat inside it as ordinary text.

So the things worth stealing are not stored as text. Card numbers, security codes, PINs, the values you mark secret, note bodies, document scans and receipts are each encrypted with AES-GCM, and the key is held in the device keychain marked so that it can be read only on this device, and only while it is unlocked. It is not in any backup and does not travel to another phone. Plaintext exists only after you have actually authenticated.

Two limits, stated plainly. This protects your data at rest; it is not a defence against a device that is already compromised while you are using it, and no app can honestly claim otherwise. And names, colours, dates and grouping stay readable, because a list has to draw before anything is revealed. Brightcard does not attempt to detect or block jailbroken devices. Such checks are easily defeated and would imply a guarantee we cannot keep. The design assumes the container can be read, and makes sure that is not enough.

Children

Brightcard is not directed at children and does not knowingly collect any data from anyone, including children.

Your rights (GDPR, CCPA/CPRA, and similar)

Because we do not collect or process your personal data, most data-subject requests (access, deletion, portability, opt-out of sale/sharing) have nothing for us to act on, you already hold and control all of your data on your device. We do not sell or share personal information. If you have a question, contact support@brightcard.io.

Changes to this policy

If we change this policy, we will update the date above and post the new version at this URL. Material changes will be reflected in an app update where appropriate.

Contact

Fioritmo B.V. - support@brightcard.io

← Back to BrightcardTerms of UsePrivacy PolicyAge SuitabilitySupportsupport@brightcard.io

© 2026 Fioritmo B.V. “Brightcard” is a trademark of Fioritmo B.V. iPhone, Apple Watch, Apple Wallet and Face ID are trademarks of Apple Inc., used for descriptive purposes only.