Privacy Policy
CardLens · Last updated 31 August 2026
Card images, the details printed on them and your address book all stay on your device. The only information that leaves it is anonymous usage and crash data, and you can switch that off.
CardLens is made by SwiftyApp. This policy explains what the app does with data, and what it does not do.
Cards you scan
A business card is somebody else’s personal information, which is why none of it leaves your device. The photograph, the text read off it, and every value that ends up in a field are all handled on the iPhone in your hand. They are never uploaded, never sent to me, and never shared with anyone else.
The reading is done by the operating system’s own text and code recognition. Name, company and title are worked out by Apple Intelligence running on the device; nothing is sent away to be processed. Every value it proposes is checked against the text actually printed on the card before it is accepted.
CardLens keeps no library of its own. When you save, the contact goes into the Contacts app and nothing about the card stays behind — no image, no copy of the text, no history of what you scanned. If you abandon a card without saving it, nothing is kept at all.
Your address book
If you grant the contacts permission, CardLens reads your address book in order to answer one question: do you already have this person? The comparison happens entirely on your device. Your contacts are not uploaded, not indexed anywhere, and not sent to me.
CardLens writes to your address book only what you have agreed to. New details are ticked and ready to add; anything that would overwrite a value you already have starts switched off and shows you both versions before you decide.
You can decline the permission and still use the app. CardLens then hands the finished card to the Contacts app’s own save sheet, which means no duplicate check — because CardLens cannot see your contacts to make one — but the card still gets in. The permission can be changed at any time in iOS Settings → Privacy & Security → Contacts → CardLens.
Camera, photo library and Files
The camera is used to photograph a card and nothing else. Photo library access is optional and used only to bring in a card you already have as an image; CardLens reads the image you pick and does not browse or catalogue the rest of your library.
Importing from Files asks for no permission of its own: iOS hands CardLens only the file you chose in the picker, and CardLens reads that image and nothing else. The file stays where it was; nothing is copied into a library of the app’s own.
If you turn on the optional contact photo feature, the headshot is cropped from the card image on your device and written to that contact. It is off by default.
There is no account and no sign-in. Nothing you do in CardLens is tied to an identity I hold.
What is collected
Usage analytics — Google Firebase Analytics
CardLens records anonymous events describing how the app is used: which screens are opened, whether a card arrived by scan, from the photo library or from Files, which features are used, and the steps of the in-app purchase flow. It records nothing about the card itself — no image, no recognised text, no names, no numbers, no addresses, and nothing about who is in your address book.
Firebase gives each install an app instance ID, which is what makes two events part of the same session. It is not tied to you, because CardLens has no accounts and no sign-in for it to be tied to, and deleting the app ends it.
Crash reports — Google Firebase Crashlytics
If CardLens crashes, a report is sent on the next launch containing the crash itself, the device model and iOS version, and a short trail of what the app was doing beforehand. That trail is drawn from a fixed list of app actions; by design it cannot contain anything read off a card or anything you typed.
Switching it off
Both are optional. Turn them off in the app’s Settings and CardLens stops sending them.
Advertising
There is none. CardLens shows no ads and contains no advertising SDK. It does not ask for permission to track you, does not read Apple’s advertising identifier (IDFA), and is built against the version of Google’s analytics library that omits it entirely. Nothing it sends is used to build an advertising profile, and nothing it sends is joined with data collected by anyone else.
Purchases
The purchase that unlocks unlimited scanning is processed entirely by Apple. I receive no payment details — only whether an Apple Account is entitled to the purchase.
Why
Analytics and crash reports exist to tell me which parts of the app are used and what is broken, so that the next version is better. That is the whole of it; there is no other purpose, and the data is not used to profile anyone.
Who receives data
Google, as the provider of Firebase Analytics and Crashlytics, and Apple, as the operator of the App Store handling purchases. Nobody else. Data is not sold, and there is nothing to sell — none of it is tied to a person, and none of it comes off a card.
Where CardLens is available
CardLens is not offered in the European Economic Area or the United Kingdom. That is why the app does not present a consent prompt before collecting the data described above.
Children
CardLens is not directed at children and does not knowingly collect information from anyone under 13.
Your choices
- Analytics and crash reporting can be turned off in the app’s Settings.
- Declining the contacts permission stops CardLens reading your address book at all; the app still saves cards through the Contacts app’s own sheet.
- The contact photo feature is off unless you turn it on.
- Deleting CardLens removes the app and everything it holds. Contacts you have already saved stay in Contacts, because they belong to you and not to the app.
- To ask what is held about your install, or to have it deleted, write to info@swiftyapp.ca. Because nothing is tied to an identity, I may need the approximate dates and the device in order to find anything at all.
Changes
If this policy changes, the date at the top changes with it, and material changes are noted on this page.