ID Card Wallet

Privacy Policy for ID Card Wallet

Last Updated: 2026-07-08

Introduction

Welcome to CardWallet (also known as ID Card Wallet), developed and maintained by Lazybyte Labs operated by Ikramul Hossain Mondal ("we," "us," or "our"). This Privacy Policy explains how we handle information in connection with your use of the App on both iOS and Android platforms.

We built CardWallet on a privacy-first principle: your personal documents, ID cards, bank cards, tickets, and any other sensitive data you store in this App never leave your device. We do not operate servers that collect, transmit, or retain your personal information.

Please read this policy carefully. By downloading or using the App, you agree to the practices described herein.


1. Summary: Data We Collect

We do not collect any personal data. All information you enter into this App is stored exclusively on your device and is never transmitted to us or any third party (except for payment processing, which is handled entirely by Apple or Google on our behalf).

This App falls under the "Data Not Collected" category as defined by Apple's App Privacy practices and Google Play's Data Safety requirements.


2. Information We Do NOT Collect

We want to be fully transparent about what we do not do:

  • We do not collect your name, email address, or any account credentials.
  • We do not transmit your ID cards, documents, bank card details, or ticket data to any external server.
  • We do not track your location.
  • We do not use advertising networks or sell your data to third parties.
  • We do not store or receive your biometric data (fingerprint or Face ID data).
  • We do not collect analytics or usage data about how you use the App.
  • We do not use crash reporting SDKs that transmit device information to external servers.

3. Data Stored Locally on Your Device

The App is a local-storage-only application. All data you enter or capture is stored exclusively on your device. This includes:

| Data Type | Description |
|---|---|
| ID Cards | Photos and scanned images of identity documents |
| Bank Cards | Manually entered card details (number, holder name, expiry) |
| Documents | Scanned or imported document files |
| Tickets | Event, travel, or other ticket information and barcodes |
| OCR Text | Text extracted from your documents via on-device recognition |
| App Settings | Preferences such as app lock status, theme, and notification settings |
| Launch Counter | An anonymous local counter used solely to trigger the in-app review prompt |

This data is stored using:

  • SQLCipher (sqflite_sqlcipher) — An encrypted SQLite database that secures your card and document data at rest.
  • Flutter Secure Storage — For sensitive key-value data, backed by Android Keystore / iOS Keychain.
  • SharedPreferences — For non-sensitive app preferences and settings.
  • Device File System — For storing captured images and document files, within the App's private sandbox storage directory.

No data is stored on our servers, in the cloud, or shared with third parties.


4. Permissions Requested

The App requests only the permissions necessary for its core functionality. Below is a full explanation of each permission.

📷 Camera

Why: To scan ID cards, documents, and read barcodes or QR codes on tickets.
How it's used: Images are captured and immediately saved to your device's private storage. No image is transmitted externally.

🖼️ Photo Library / Media & Files (Read & Write)

Why: To allow you to import existing images from your photo library into the App, and to save captured documents.
How it's used: Files are accessed only when you explicitly choose to import them. All saved files remain in the App's private storage directory on your device.

🔐 Face ID / Biometric Authentication

Why: To power the App Lock feature, which prevents unauthorized access to your stored data.
How it's used: The App relies entirely on your device's built-in biometric hardware and operating system (Face ID on iOS, Fingerprint on Android) through platform-native APIs. We never receive, process, or store any biometric data whatsoever. Your biometric information never leaves your device's secure enclave.

🔔 Notifications

Why: To send you local reminder notifications (e.g., document expiry reminders).
How it's used: All notifications are generated locally on your device using flutter_local_notifications. No notification content or scheduling data is sent to external servers.

🎙️ Microphone (iOS only — requested by camera framework)

Why: Requested as a system-level requirement by the camera access framework used for the document scanner.
How it's used: The App does not actively record or use audio. This permission is incidentally required by the iOS camera framework. No audio is ever recorded, captured, or transmitted.


5. Third-Party Services & SDKs

The App integrates a minimal set of third-party SDKs. All of them operate on-device, or handle only payment processing. None of them receive your personal documents, card data, or any user-generated content.

Apple In-App Purchase (StoreKit) — iOS

Used to process payments for the premium upgrade on iOS. All financial transactions are handled exclusively by Apple. We do not process, receive, or store any credit card or payment information.
→ Apple Privacy Policy

Apple In-App Review — iOS

Used to present a native in-app rating prompt after a certain number of app launches. This prompt is managed entirely by Apple and the App Store. We do not receive your rating or review text directly.
→ Apple Privacy Policy

Google Play In-App Billing — Android

Used to process payments for the premium upgrade on Android. All financial transactions are handled exclusively by Google Play. We do not process, receive, or store any credit card or payment information.
→ Google Payments Privacy Notice

Google Play In-App Review — Android

Used to present a native in-app rating prompt. This prompt is managed entirely by Google Play. We do not receive your rating or review text directly.
→ Google Privacy Policy

Google ML Kit — Text Recognition (On-Device)

Used for Optical Character Recognition (OCR) to extract text from scanned documents. All processing happens locally on your device using Google's on-device ML model. No document images or text are sent to Google's servers via this feature.
→ Google Privacy Policy


6. Data Security

We take the security of your data seriously and implement multiple layers of protection:

  • Encrypted Database: All card and document metadata is stored in a SQLCipher-encrypted database. The encryption key is managed securely on your device and never transmitted externally.
  • Secure Storage: Sensitive configuration values are stored using platform-native secure keystores (Android Keystore, iOS Keychain).
  • App Lock: The optional Biometric / PIN lock feature provides an additional access control layer before the App can be used.
  • Screenshot / Screen Recording Protection: The App uses screen_protector to prevent your sensitive data from being captured by screenshots or screen-recording apps.
  • No Cloud Backup (Android): The App is configured with android:allowBackup="false", preventing Android's automatic cloud backup from copying your sensitive data off-device.
  • No iCloud Backup (iOS): App data files are stored in the Application Support directory and are excluded from iCloud backups to protect your sensitive information.
  • No Cloud Sync: The App does not sync any data to cloud services. Your data remains solely on your device.

Note: While we implement strong on-device protections, no method of electronic storage is 100% secure. We encourage you to use the App Lock feature and keep your device's operating system up to date.


7. Data Retention and Deletion

Since all data is stored locally on your device:

  • Your data is under your full control. You can delete individual cards, documents, or tickets at any time from within the App.
  • Uninstalling the App will permanently delete all locally stored App data from your device, subject to your device's operating system behavior.
  • We have no ability to recover your data once it is deleted, as we hold no copies of it.
  • We have no remote access to any data stored within the App, and therefore cannot fulfill remote deletion requests on your behalf — your device is the only place your data exists.

8. Children's Privacy

CardWallet is not directed to children under the age of 13 (or the equivalent minimum digital age of consent in your jurisdiction). We do not knowingly collect any personally identifiable information from children. If you are a parent or guardian and believe your child has used this App and stored personal information, please contact us. We will guide you on how to remove the data directly from the device.


9. Your Privacy Rights

Depending on your country or region, you may have rights regarding your personal data, including the right to access, correct, or delete it. Because all data is stored locally on your device and we have no access to it, you exercise these rights directly through the App's interface (by editing or deleting records) or by uninstalling the App.

Users in the European Economic Area (EEA), United Kingdom, and California may have additional rights under GDPR, UK GDPR, and CCPA respectively. Since we do not collect or process any personal data on our servers, these rights are effectively exercised by you directly on your device.

For any privacy-related inquiries, please contact us at the address below.


10. International Users

CardWallet is available globally. If you use the App outside your home country, please be aware that your data does not leave your device regardless of your location. We do not transfer personal data across borders because we do not collect it.


11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in the App's features, technology, or legal requirements. When we do, we will:

  • Update the "Last Updated" date at the top of this document.
  • Post the updated Privacy Policy at the link provided in the App Store and Google Play listings.

Your continued use of the App after any changes constitutes your acceptance of the revised policy. We encourage you to review this policy periodically.


13. Apple App Store — Privacy Nutrition Label Summary

The following summarizes the App's data practices as disclosed to Apple for the App Store privacy label:

| Category | Data Collected | Linked to Identity | Used for Tracking |
|---|---|---|---|
| Contact Info | None | — | — |
| Health & Fitness | None | — | — |
| Financial Info | None | — | — |
| Location | None | — | — |
| Sensitive Info | None | — | — |
| Contacts | None | — | — |
| User Content | Stored on-device only | No | No |
| Browsing History | None | — | — |
| Identifiers | None | — | — |
| Diagnostics | None | — | — |
| Summary | Data Not Collected | — | — |

This App does not collect data from users. All user content remains exclusively on the user's device and is never transmitted to Lazybyte Labs or any third party.


This privacy policy applies to CardWallet (ID Card Wallet), version 1.1.0 and above, developed by Lazybyte Labs. This policy covers both the iOS (App Store) and Android (Google Play) releases of the App.

Contact Us

If you have any questions about this Privacy Policy, please contact the developer directly:

Ikramul Hossain Mondal

Support@lazybyte.in
Built by One, Used by Many.

© 2026 LazyByte Labs. All rights reserved.