Last Updated: July 28, 2026
This page informs you of my policies regarding the collection, use, and disclosure of personal data when you use Secure Card Wallet and the choices you have associated with that data.
As an independent developer, I am committed to protecting your privacy. Secure Card Wallet is a personal wallet and document storage app. It is designed to store your sensitive data locally on your device. I do not store your card details, identity document details, passwords, or biometric data anywhere, because the app has no servers.
1. Information Collection and Use
A. Local Data Storage (Sensitive Information)
The app stores text only. No photographs, scans, screenshots or images of your documents or cards are ever saved by the app. When you scan a card or document with the camera, the image is used in memory purely to read the text from it, and is discarded immediately — it is not written to your device's storage, not saved to your gallery, and not transmitted anywhere. Only the resulting text fields are kept, and those are encrypted.
The core function of this app is to securely store the contents of your wallet. Depending on which categories you choose to enable, the text data you enter or scan may include:
- Card Details: Card numbers, CVVs, expiry dates, cardholder names and any notes you add.
- Identity Document Details: Passport numbers, national ID numbers, driving licence numbers, names, dates of birth, issuing country and any other fields you choose to enter.
- Travel Booking Details: PNRs and booking references, passenger names, itineraries, seat and gate information, and hotel booking details.
- Event Ticket Details: Ticket numbers, barcode values, venue, seat and event date information.
- Loyalty and Gift Card Data: Membership and card numbers, PINs, balances and barcode or QR values.
- Vehicle Details: Registration details and document expiry dates (RC, PUC, insurance, fitness certificate).
- Insurance Details: Policy numbers, insurer details, beneficiary names and emergency contacts.
- Custom Fields: Any additional user-created fields, labels and values you add to an item.
The following applies to all of the data listed above, without exception:
- Stored Only on Your Device: It is encrypted with AES-256 and written only to your device's internal, app-private storage.
- Never Transmitted: It is never transmitted to me, to any server, or to any third party. There is no cloud sync and no automatic backup.
- No Account Required: The app requires no account, no email address, no phone number and no sign-up in order to use it.
- No Developer Access: I have no technical ability to access, recover or view any of your stored data. There is no server to hold it and no key that I possess.
- Unrecoverable Without Your Backup: If you delete the app, reset your device, or lose your device, this data is permanently unrecoverable unless you have created your own backup file. Android's automatic cloud backup is deliberately disabled for this app, because a restored copy could not be decrypted on a new device.
B. Permissions and Device Features
The app declares only the permissions listed below, each for the stated purpose:
- Camera: Used for OCR scanning of cards and documents, so details can be filled in without typing. Frames are processed on your device, in memory, solely to extract text. No image is saved to your gallery, stored by the app, or transmitted anywhere, and the app has no ability to access photos already on your device.
- NFC (Near Field Communication): Used to read contactless cards you tap against your device. The data is read on-device only and is never transmitted.
- Biometrics: Used to lock and unlock the app. Authentication is performed by the Android system; the app only receives a "success" or "fail" result and never receives or stores your fingerprint or face data. Note that Android may also accept your device screen-lock credential (PIN, pattern or password) as an alternative to biometrics, exactly as it does for other apps.
- Notifications: Used only for expiry reminders, which are generated locally on your device. These reminders are opt-in and can be enabled or disabled per category in Settings. No notification content leaves your device.
- Vibration: Used for haptic feedback within the app interface.
- Google Play Billing: Used to offer optional in-app purchases and subscriptions through Google Play.
- Internet: The wallet itself works fully offline and your wallet data is never sent over the network. Internet access is used only to validate subscription purchases (see Section 2) and to allow Google Play Services to download the on-device OCR text-recognition model the first time it is needed.
The app does not request storage, location, contacts, microphone or phone permissions.
C. In-App Purchases (Google Play Billing)
If you choose to make an in-app purchase, the transaction is processed securely by Google Play. I do not process, collect, or store your payment information on my end. Your transaction is subject to the Google Privacy Policy.
2. Subscription Analytics (RevenueCat)
Subscriptions in the app are managed using RevenueCat, a third-party subscription infrastructure provider. This is the only third party the app communicates with, and I want to state plainly what is and is not shared.
- What is shared: An anonymous, randomly generated device identifier, and subscription purchase and entitlement events (for example: a purchase, renewal, expiry or restore). This is used to determine whether your device has an active subscription and for subscription analytics.
- What is never shared: No wallet contents. No card numbers, identity document details, travel or event data, loyalty, gift card, vehicle or insurance data, custom fields, or any other personal information you store in the app is ever shared with RevenueCat or with anyone else.
- No identity linkage: The identifier is not linked to your name, email address or any account, because the app does not have accounts.
RevenueCat's handling of this data is governed by their own policy: RevenueCat Privacy Policy.
3. Log Data & Analytics
Apart from the subscription events described in Section 2, I do not collect error logs, crash reports, advertising identifiers, or usage analytics. There is no advertising SDK and no tracking SDK in the app. Your use of the wallet itself is not measured, recorded, or reported anywhere.
4. Backup and Restore
The app includes a feature to back up and restore your data. Backups cover every category you have enabled.
- Encrypted Backup: When you create a backup, the file is encrypted with a password you provide.
- Entirely Under Your Control: Backups are created only when you ask for one, and the resulting file stays wherever you choose to put it. It is never uploaded to me or to any service by the app.
- User Responsibility: You are responsible for keeping this backup file and its password safe. Since I do not have access to your data or password, I cannot recover your data if you lose your password.
5. Security
I value your trust in using this app, thus I am striving to use commercially acceptable means of protecting your data. The app uses industry-standard AES-256 encryption to protect your database, with the encryption key held in the Android Keystore. However, remember that no method of transmission over the internet, or method of electronic storage is 100% secure and reliable, and I cannot guarantee its absolute security.
6. Children's Privacy
These Services do not address anyone under the age of 13, and the app is not directed at children. I do not knowingly collect personally identifiable information from children under 13. Because the app has no servers and no account system, I do not receive any user-submitted information at all. If you believe a child has provided personal information within the app on your device, you can remove it by deleting the relevant items or uninstalling the app, and you may contact me at the address below with any concerns.
7. Changes to This Privacy Policy
I may update this Privacy Policy from time to time. Thus, you are advised to review this page periodically for any changes. I will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date above.
8. Contact Me
If you have any questions or suggestions about this Privacy Policy, do not hesitate to contact me.
By email: appverse.wallet@gmail.com