BizCard Privacy Policy

Last updated: 2026-05-03

This Privacy Policy describes how BizCard ("we", "the app") handles your information when you use our Android application (package name: com.yseol.bizcard).

1. Information We Process

1.1 Stored locally on your device only

The following data is processed on-device and stored in a local SQLite database. It does not leave your device unless you explicitly enable an optional feature.

1.2 OAuth credentials (only if you enable Google Sync)

If you tap "Connect Google" in Settings, the app obtains an OAuth access/refresh token from Google with the scopes: contacts, userinfo.email, userinfo.profile. Tokens are stored in your device's Android EncryptedSharedPreferences via expo-secure-store and are never transmitted to our servers.

1.3 Subscription identifier

For Pro subscription management, a randomly generated UUID ("App User ID") is created on first launch, stored on device, and shared with RevenueCat (our subscription provider). This UUID does not contain any personal information.

1.4 Diagnostic data

When the app crashes or encounters errors, a report containing the error message, stack trace, app version, OS version, and device model is sent to Sentry (our error monitoring provider). Personal contact data, email addresses, phone numbers, and OAuth tokens are automatically redacted before transmission.

2. How We Use Information

DataPurpose
Business cards stored locallyProvide the core feature of saving and searching contacts
Camera imagesRun on-device OCR (ML Kit) to extract contact fields
Google OAuth tokensSync contacts to/from your Google account when sync is enabled
App User IDIdentify your subscription with RevenueCat
Diagnostic dataDetect and fix bugs and crashes

3. Third Parties

We share data with the following third parties only as described below:

We do not sell or share your data with advertisers. We do not use third-party analytics SDKs.

4. Permissions

PermissionWhy we need it
CameraCapture business card images for scanning
Read Contacts(Optional) Read your Google contacts during sync
Write Contacts(Optional) Export scanned cards to your device's contact list

You can revoke any permission at any time in your device's system settings.

5. Data Retention

6. Your Rights

You may at any time:

If you are in the EEA, UK, or California, you have additional rights under GDPR / UK GDPR / CCPA, including the right to access, correct, or delete your personal data, and to lodge a complaint with a supervisory authority.

7. Children

The app is not directed to children under 13. We do not knowingly collect data from children under 13.

8. Security

Local data is stored in app-private storage. OAuth tokens are stored in the OS-provided secure keystore. Network traffic uses HTTPS exclusively.

9. Changes

We may update this Privacy Policy from time to time. The "Last updated" date above reflects the most recent change. Continued use of the app after a change constitutes acceptance.

10. Contact

For questions about this Privacy Policy or our data practices, contact:

Email: support@naholosoft.com