Kardhaus

Privacy policy

The app is the short half of this page: it sends nothing to us. What does leave the device, and where to, is named below.

Effective 2026-08-18 · Last updated 2026-09-22

Last updated 2026-09-22. This policy covers both the Kardhaus iOS app and this website. They are very different documents joined together, so they are kept separate below. The controller is the developer of Kardhaus, reachable at hello@kardhaus.com.

The iOS app

The app sends nothing to us

The app sends nothing to us: no account system, no analytics endpoint, nothing of ours for it to call. It is not that we promise not to look — there is no channel through which the app could send us your cards. Everything that does leave the device is named below: address lookups in Apple Maps; AI recognition, from version 1.1 on iOS 27; and follow-up drafts you ask for, from version 1.2 on iOS 27 — all three to Apple; and, from version 1.2 and only if that switch is on, your purchases to RevenueCat. Card data goes to Apple and to nobody else.

What the app holds. Card images, the text recognised from them, your notes, tags, and — if you allow location access — the place you were when you saved a card. All of it lives in the app’s own storage on your iPhone.

Where it syncs. If iCloud is on for Kardhaus, that store syncs through your own iCloud private database, under your Apple Account. That is a channel between your devices and Apple, not one that includes us: we are not a party to it and have no ability to read it. Switching iCloud off for Kardhaus in iOS Settings stops the sync and leaves the data on the device.

Recognition. Scanning and text recognition — reading the characters on the card — happen on your iPhone, using the OCR built into iOS. AI recognition is a second pass that sorts that text into fields such as name, company, department, branch office, title and address. Up to version 1.0.x, and on iOS 26, it runs on the device with Apple Intelligence. From version 1.1, on iOS 27 with Apple Intelligence, AI recognition sends the recognised text and the photo of that one card to Apple’s Private Cloud Compute first. Apple designed Private Cloud Compute so that the data sent is used only to fulfil that request, is not stored, and is not accessible to anyone, including Apple. If Private Cloud Compute is unavailable — no connection, a device that is not eligible, or Apple’s usage limit for Private Cloud Compute reached — Kardhaus uses Apple Intelligence on the device instead, and failing that, the built-in recognition; the card is saved either way. If the free AI recognitions are used up and Pro has not been purchased, AI recognition does not run: the built-in recognition reads the card on the iPhone, and nothing is sent to Private Cloud Compute. Version 1.1 has no in-app setting to turn Private Cloud Compute off; from version 1.1.1, the Private Cloud Compute switch in Settings › Apple Intelligence turns it off, and AI recognition then runs on the device. None of this is sent to us.

Follow-up drafts, from version 1.2. Kardhaus can draft a follow-up message to someone whose card you saved. Nothing is sent until you tap to generate a draft, and the app tells you what goes where before the first one. On iOS 27 with Apple Intelligence the draft is written by Apple’s Private Cloud Compute first; if that is unavailable or switched off, Apple Intelligence on the device writes it, and failing that, built-in templates. For one draft, Private Cloud Compute receives only: the name, title, department and company on that card; the venue name (never its street address), date, kind and note of your latest meeting with that person; up to six of the card’s tag names; your impression of the person, up to 400 characters; short excerpts of up to two earlier drafts you marked as sent; the hint you typed; and your own name, title and company. It never receives a phone number, an email address, a postal address, a tax ID, a website or a photo — any of those in text you typed is removed before sending — and your sign-off is added on the device after the draft comes back. As with recognition, Apple designed Private Cloud Compute so that this is used only for that request, is not stored, and is not accessible to anyone, including Apple. None of it is sent to us. Drafts are saved with the card, on your device and, if iCloud sync is on, in your own iCloud private database. The Private Cloud Compute switch in Settings › Apple Intelligence covers drafts too: off, they are written on the device or from templates.

Maps. When a card carries an address, Kardhaus asks Apple Maps to look that address up, automatically after a card is scanned, imported or edited, so the card can be placed on the map. Only the address text is sent, and it goes to Apple, not to us.

Permissions, and what each is actually for. Camera — photographing cards. Location, optional — recording where you were given a card. Microphone and speech recognition — speaking a note or searching by voice; the audio is turned into text on the device, never stored and never uploaded. Contacts — only written to, and only when you ask to save a card. Photos — only written to, and only when you ask to save an image. Every one of these can be refused, and the app keeps working without it.

Purchases. The purchase is Apple’s: it is handled through StoreKit, we never see your payment details, and whether Pro is unlocked is decided by Apple’s own signed transaction record on your iPhone — which is why it works offline and why Family Sharing is unaffected.

RevenueCat, from version 1.2. From version 1.2 the purchase itself can also be recorded by RevenueCat, Inc. (United States), which acts as our processor under a data processing agreement covering the GDPR, the UK GDPR and the CCPA. It is optional, and it is off by default for anyone who was already using Kardhaus: an install that finished setting up before 1.2 has it off, a fresh install has it on, and either way the switch is “Send purchase records to RevenueCat” in Settings › Privacy inside the app, taking effect at the next launch. With the switch off, the RevenueCat SDK is never started and makes no network request at all — buying and restoring run purely on StoreKit, as they did in 1.1. With it on, RevenueCat receives, per request: the purchase (the product identifier and the App Store transaction), a random anonymous identifier RevenueCat generates for the install, the app version and build, the iOS version, the device model, your first preferred languages, your App Store country, and whether the purchase was made in the sandbox. That purchase record is kept on RevenueCat’s servers, which run on Amazon Web Services in the United States.

What RevenueCat never receives: a card, a card photo, any text read from a card, your name, an email address, an account identifier — there is no account — a custom or stable user ID, the device’s identifier for vendor (the RevenueCat SDK in Kardhaus is patched so that it never reads it), an advertising identifier or IDFA, attribution data, or anything about how you use the app. We never call its login, device-identifier-collection or attribution interfaces, its diagnostics are switched off, and no third-party integration is enabled on our RevenueCat project, so the anonymous identifier reaches nobody else. If RevenueCat cannot be reached, the purchase still completes through StoreKit.

Why RevenueCat is there. Kardhaus is entered in Shipaton, RevenueCat’s hackathon, whose rules require the app to use the RevenueCat SDK to power at least one in-app purchase. That is the whole reason, and it is why there is a switch rather than a silent dependency.

SDKs. From version 1.2 the app embeds exactly one third-party SDK — RevenueCat’s, described above, which does nothing at all while that switch is off. There is no advertising, attribution, crash-reporting or usage-analytics SDK: no Firebase, no Mixpanel, no Sentry, no advertising identifier, no App Tracking Transparency prompt and no device fingerprinting. Nothing in the app measures how you use it. Up to version 1.1.x the App Store privacy label reads Data Not Collected; from version 1.2 it declares one thing, Purchases → Purchase History, used for app functionality and analytics, not linked to your identity and not used for tracking. Nothing taken off the cards themselves appears on that label in any version.

If this ever changes. Card data goes to Apple — for Apple Maps, AI recognition and, from version 1.2, follow-up drafts — and to nobody else. If that ever stops being true, this policy will name the recipient before that update ships — not after, and not in a silent update. Naming RevenueCat here, before 1.2 goes on sale, is that promise being kept rather than an exception to it: RevenueCat receives purchases, never cards.

Children. Kardhaus is a tool for working adults and is not directed at children. We ask for no personal details from anyone, of any age, and there is no account to create.

No account, and how to delete everything

There is no account. Nothing to register, no email address required, no password, no profile. That is also why there is no “delete my account” button anywhere in the app: there is no account of yours to delete, and no copy of your library on our side either.

How long the app keeps things. For as long as you keep them. There is no expiry and no retention schedule, because the data sits on your device and the decision is yours.

Deleting it. Removing the app deletes the library it holds on that iPhone. If iCloud sync was on, a copy remains in your own iCloud until you remove that too: iOS Settings → your name → iCloud → Manage Account Storage → Kardhaus → Delete Data. We can do neither of those for you, and neither can be undone afterwards.

Website analytics

Until you accept the banner, this site loads nothing from any other company. No analytics, no fonts, no embeds, no pixels. That is checkable in about ten seconds: open your browser’s network tab and reload — every request goes to kardhaus.com and nowhere else.

Google Analytics 4 — on by default, off in one tap

GA4 sets cookies, so it stays a choice you can change at any time. Outside the EEA, the UK and Switzerland it is on when you arrive, and a notice on your first visit says so and offers Turn it off in one tap. Inside the EEA, the UK and Switzerland it is the other way round: Google Consent Mode v2 starts with `analytics_storage` set to denied for those regions, and `gtag.js` is not requested from Google at all until you tap Allow. Either way `ad_storage`, `ad_user_data` and `ad_personalization` stay denied everywhere — including after you agree — so this traffic never becomes an advertising audience. A refusal is kept in your browser as `kh-consent` and honoured on every later visit.

If you do allow it, GA4 receives page views, referrer, approximate location derived from your IP (GA4 does not retain the IP itself), device and browser type, and a `waitlist_signup` event if you sign up. Google Signals and ad personalisation are disabled, so the data is not used to build advertising audiences. Your choice is stored in your browser under `kh-consent` and is never asked twice.

GA4’s Enhanced Measurement is on, which adds a handful of automatic events alongside page views: how far down a page you scrolled, clicks on links that leave this site, file downloads, and the fact that you started or submitted the wishlist form. It records that those things happened, not what you typed — the contents of the form reach us through our own endpoint, described below, and never through Google.

To change your mind, clear this site’s data in your browser settings and the banner will appear again.

There are no Google Fonts, no Google Tag Manager container, no advertising pixels and no third-party embeds on this site.

The wishlist

If you submit the wishlist form, we store the email address you type, the region you optionally select, anything you write in the optional “what would make you switch” box, the page you submitted from, your locale, the country your request came from, and a timestamp. We also store a coarse, hashed rate-limit token derived from your request so the form cannot be flooded; it is not reversible to an IP address and is discarded on a rolling basis.

The comment box is free text, so please treat it as such. It is read by a person and used to decide what gets built. Do not put anything confidential in it, and please do not put a third party’s contact details in it.

Purpose. To email you when the TestFlight build opens and when the app launches, to attach your free scan allowance to that address, and to prioritise what to build.

Legal basis. Your consent, given by submitting the form.

Retention. Until launch plus 90 days, or until you ask us to delete it — whichever is sooner. Unsubscribing deletes the record rather than flagging it.

Where it is stored, and who processes it. The form posts to kardhaus.com itself, never to a third-party form service, so no other company sees the submission as it happens. The record is written to Cloudflare D1 in our own account, and mirrored into a private Google Sheet we control so the list can be read without a database client. Google therefore processes your address and your comment as a storage provider. It does not receive your IP address or your user agent: the copy is sent from our server, not your browser.

Recipients beyond that: nobody. The list is not sold, rented, shared, or used for anything other than the two emails described above.

Your rights. Access, correction, deletion and withdrawal of consent. Email hello@kardhaus.com and it is done, with no verification hoops beyond replying from the address in question. Deletion removes the record from both the database and the Sheet.

If you asked for the Android test. The address you leave on the Android page goes onto Google Play’s tester list for Kardhaus, which means Google receives it — that is how Play sends the invitation and decides who may install the test. It is used for that and nothing else, kept until the test ends or you ask us to remove it, and taken off the list whenever you ask.

Contact

hello@kardhaus.com — privacy requests, deletion requests, accessibility problems, or anything else. It is the only address we use, and a person answers it.