Privacy
Last updated 10 October 2026
We follow Malaysia's Personal Data Protection Act 2010 (PDPA). This page says, in plain words, what we keep and why.
What we store
- Your account: name, personal email, and a scrambled (hashed) password.
- Your cards: the details, photo and logo you add.
- Your contacts: details you scan, type in, or receive when someone shares back, plus your notes and tags.
- Card activity: counts of views, saves and shares, so you can see how your card is doing.
What we don't keep
- Photos of cards you scan. We send the image to our own reading engine, keep the text, and discard the image. Once Google Drive is connected, the photo goes to your own Drive instead.
- Hidden details. A card only ever sends the details on that card; your private number never reaches someone who has your Business or Event card.
Where it lives
On servers in Malaysia, run by IP ServerOne. Card reading runs on our own server, not on a third-party AI service.
Who sees it
- People you share a card with see that card.
- On Pro, your team admin sees team cards and work contacts, never your Personal or Close friends cards.
- Payments are handled by Stripe; we never see your card number.
Your choices
Export your contacts anytime from Settings. Delete your account from Settings and we remove your data. To ask about your data, use the feature request box in Settings.