Privacy Policy

Last updated: 30 July 2026

This Privacy Policy explains the nature, scope, and purpose of the processing of personal data when using the mobile app My Cards (the "App"). My Cards lets you digitally store and manage your own cards and codes (for example loyalty, membership, or barcode/QR cards).

In short: we do not collect any of your data. My Cards has no user accounts and no backend. Your cards are stored solely on your own device, we operate no server that could receive them, and we have no way to access them. The only data leaving your device is the diagnostic telemetry of Google's on-device barcode scanning library, described in Section 4.


1. Controller

The controller responsible for data processing within the meaning of the General Data Protection Regulation (GDPR) is:

NVP Software LLC
2111 Coronet Blvd
Belmont, CA 94002
United States of America (USA)

Email: anton@nvpsoftware.com

Further mandatory information (including authorized representative and phone) can be found in the Legal Notice.

2. No Account, No Server

The App has no registration and no sign-in. It does not create a user account, does not generate a user identifier, and does not ask you for an email address, a phone number or a password. We operate no backend for the App: it makes no API calls and transmits nothing to us.

3. Your Cards

The cards you save — the code itself, its format, and the name, colour, icon, notes and validity dates you assign — are written to a database file inside the App's private storage on your device. They are not transmitted anywhere and we have no access to them.

Because they are part of the App's storage, your cards are included in the backup your phone makes of itself (iCloud or encrypted local backup on iOS, Auto Backup or device-to-device transfer on Android). That backup is a matter between you, your device and its manufacturer; we are not involved and receive no copy.

You can additionally export your cards to a file yourself. That file is written to your device and handed to the system share sheet, where you decide what happens to it. You can erase everything at any time under "Settings → Delete all cards"; there is nothing left elsewhere to delete.

4. Barcode Scanning (Google ML Kit)

To read codes, the App uses Google ML Kit Barcode Scanning. The recognition itself runs entirely on your device: camera frames and any photo you pick from your library are analysed locally and are never uploaded, neither to us nor to Google.

The ML Kit library does, however, report diagnostic and usage data to Google on its own account. According to Google's documentation, this covers the device model and operating system version, the App's bundle ID and version, an identifier generated per installation that is not intended to identify you or your device, performance metrics such as latency, the API configuration, event types and error codes. The content of your cards, the codes you scan and the images you select are not part of this and are never passed to Google.

Purpose: providing on-device code recognition. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a functioning scanner). Google's handling of this data is described in its Privacy Policy.

5. Websites and Emails You Open Yourself

Opening the Privacy Policy or the Legal Notice from within the App loads this page from our web host, which — like any web server — processes the technically necessary connection data, in particular your IP address and the request time. The feedback screen composes an email and hands it to your own mail app; the App sends nothing itself, and you see the message before you send it. If you do send it, we receive its contents together with the App version and operating system version that were appended to it.

6. Disclosure of Data

We receive no data about you, so there is nothing for us to pass on. We do not sell personal data. The only third party involved is Google, as the provider of the on-device scanning library described in Section 4.

7. Retention Period

We store no personal data about you and therefore retain none. Your cards remain on your device until you delete them.

8. Your Rights

Under the GDPR, you have the right to:

To exercise your rights, simply send a message to anton@nvpsoftware.com. Please note that we hold no data about you: we cannot identify you, and there is no account or stored record for us to disclose, correct or erase. Your cards are under your sole control on your own device.

9. Users in Switzerland

Switzerland is not part of the EU, so the GDPR does not apply there. Users in Switzerland are covered by the revised Swiss Federal Act on Data Protection (revFADP / revDSG), which has applied since 1 September 2023. Everything described above applies equally under it: the App creates no account, collects no personal data and transmits nothing to us.

Under the revFADP you have, in particular, the right to information about data processed about you (Art. 25) and the right to have data corrected or erased (Art. 32). Here too there is nothing for us to disclose or delete, because no record about you exists. You may lodge a complaint with the Federal Data Protection and Information Commissioner (FDPIC).

The diagnostic telemetry of the barcode library described in Section 4 is sent to Google under Google's own privacy terms; this is independent of your location.

10. Children

The App is not directed at children. We do not collect personal data at all and therefore collect none from children either.

11. Changes to This Privacy Policy

We may update this Privacy Policy to reflect changes in the law or in the App's features. The current version is available in the App or at this address.

12. Contact

If you have any questions about data protection, you can reach us at: anton@nvpsoftware.com