MyCard Privacy Policy
Last Updated: 3 September 2026
Scope of This Policy
This Privacy Policy applies to the MyCard iOS application. Other Cratox products have their own policy at cratox.com/privacy.
1. Introduction
CRATOS INNOVATIONS S.R.L. ("Cratox", "we", "our", "us"), based in Brașov, Romania (CIF 51792827), operates MyCard. This policy explains what the App does with your information. The short version: your business cards are built and stored on your iPhone, we run no accounts, no analytics and no advertising, and nothing leaves your phone.
2. Data the App works with
- Contacts: MyCard asks for access to Contacts only to find your own entry and copy it onto a card. The lookup runs on your phone. No contact, yours or anyone else's, is uploaded, logged or stored by us. With "Select Contacts", MyCard sees only the entries you selected. With "Pick it myself", Apple's picker hands MyCard the single contact you tap and no permission is requested. You can revoke access any time in Settings › Privacy & Security › Contacts.
- Your card: name, job title, company, phone numbers, e-mail addresses, websites, social profiles, a photo and an optional logo, as imported from Contacts or edited by you. Home addresses are never imported. Cards are stored in the App's own folder on your device and appear in the Files app under MyCard.
- Photos: if you add a logo, Apple's photo picker gives MyCard only the image you chose. It is stored with the card on your device.
- Device and usage data: none. MyCard contains no analytics, crash-reporting, advertising or attribution SDKs and collects no advertising identifier.
3. No server, no upload
MyCard has no account and no server-side copy of your card. Everything the App shows is computed on your phone: the card, its QR code and its contact file. Nothing is uploaded to Cratox. Sharing sends the contact file or QR image through the channel you pick (Messages, Mail, AirDrop), which is governed by that channel.
4. QR codes and sharing
The QR code and the contact (.vcf) file contain the card fields you chose to keep on the card. Whoever scans or receives them obtains those fields, exactly as with a paper business card. Sharing is always started by you, through the iOS share sheet.
5. How we use data
Solely to produce your card, its QR code and its contact file on your device. We do not sell, rent or trade personal data, and we do not use it for advertising or profiling.
6. Third-party services
- Apple (Contacts, Photos, App Store): governed by Apple's privacy policy.
- Vercel: hosts these web pages only. Vercel may process connection metadata (IP address, timestamps) when you open cratox.com, under its own policy. The App itself does not call Vercel.
- No other third party receives data from MyCard.
7. Data sharing
We share no personal data with anyone, except as required by law.
8. Data security
Cards are protected by your device's own security (passcode, Face ID, encryption at rest). MyCard operates no service of its own, so there is nothing of yours held outside the device.
9. Your rights (GDPR and CCPA)
Because your data lives on your device, you exercise most rights yourself: view and edit your cards in the App, delete a card, or delete the App to remove everything. Home and Lock Screen widgets and the Watch app show only what is on your phone and disappear with the App. We hold no personal data to access, export or erase on our side. If you believe otherwise, write to us and we will respond within 30 days. You may also lodge a complaint with the Romanian supervisory authority (ANSPDCP) or your local authority.
10. Children
MyCard is not directed at children under 13 (or the age of digital consent in your country) and knowingly collects no personal data from anyone.
11. Changes to this policy
If this policy changes, the new version appears here with a new date. Material changes will also be noted in the App's release notes.
12. Contact
CRATOS INNOVATIONS S.R.L., Brașov, Romania · office@cratox.ai · See also the MyCard Terms of Service.