Privacy Policy
Last updated: July 4, 2026
cardlio is built so that your contacts stay yours. This policy describes what the app and this website do with data — which is very little, by design.
What cardlio processes on your device
Scanning, text recognition, card parsing, and organizing all run locally on your iPhone or Mac. Card images and contact details are stored on your device and in your personal iCloud (see below). We operate no servers that receive, store, or analyze your contacts.
iCloud sync
Your card library syncs between your devices through Apple's iCloud (CloudKit), in a private database tied to your Apple ID. Only you can access it; we cannot. Apple's own privacy terms govern iCloud.
Address verification
To verify and pin addresses, the app queries Apple Maps with the address text from a card. This request goes to Apple, not to us, under Apple's privacy terms.
Optional cloud AI
You may optionally add your own API key for a third-party AI provider (Anthropic Claude or Google Gemini) to improve recognition of difficult cards. If — and only if — you do, the text of the card being processed is sent to that provider under their terms. Keys are stored in your device's Keychain. Without a key, no card data ever leaves your device for AI processing.
Shared card links
When you share your own card as a link (or QR code / NFC tag), the card's data is encoded inside the link itself, in the part after the "#" that browsers do not send to web servers. Opening a card link downloads only this website's static page; the card is decoded in the recipient's browser. Nothing about your card or the recipient is transmitted to or stored by us.
Apple Wallet passes
Creating a Wallet pass sends your card's details to our pass-signing service for the duration of one request, solely to produce the signed pass file. The service stores nothing, logs nothing, and has no database. Its source code is public.
Office 365 sync
If you connect a Microsoft 365 account, cardlio can push your cards into your own Outlook contacts. This is entirely optional and off until you connect it. When you tap Sync, your card details are sent directly to Microsoft under your own account, using permissions you grant at sign-in; they are stored in your Microsoft mailbox, not on any server we operate. Sign-in uses Microsoft's standard OAuth flow, and the resulting token is kept in your device's Keychain. Disconnecting the account in Settings removes that token. We never see your Microsoft credentials or your contacts.
This website
cardlio.app uses no cookies, no analytics, and no tracking of any kind. It is a static site.
What we collect
Nothing. cardlio has no accounts, no sign-up, and no telemetry. If you email support, we see what you send us and use it only to help you.
Changes
If this policy changes, the new version will be published here with an updated date.
Contact
Questions about privacy: info@cardlio.app