Zero-Knowledge • 100% Offline Vault

Legal & Transparency

Official Privacy Policy and Terms of Service governing the Card Saver mobile application on the Google Play Store.

📅 Effective Date: August 8, 2026
🛡️ Architecture: Air-Gapped & Encrypted at Rest
⚖️ Compliance: Google Play 2026 User Data Policy
🚫

Zero Internet

No network permissions

🔒

AES-256-GCM

Military-grade encryption

📸

On-Device AI

Local ML Kit OCR only

👆

Biometric Keystore

Hardware-backed unlock

01 Commitment to Zero-Knowledge Privacy

Your privacy is our highest priority. Card Saver ("we", "our", or "the application") was built from inception with an uncompromising zero-knowledge, 100% offline security architecture.

Unlike traditional cloud wallets, password managers, or fintech applications, Card Saver operates entirely on your physical Android device. We do not operate remote servers, we do not require account creation, and we have zero access to your confidential vault or payment cards.

✓ Air-Gapped Network Isolation

Card Saver strictly omits the android.permission.INTERNET permission from its Android Manifest. The application physically lacks the OS-level capability to transmit data over Wi-Fi, cellular, or Bluetooth networks.

02 Google Play Data Safety & Collection Disclosure

In accordance with the Google Play Developer User Data Policy, below is the comprehensive disclosure of how user data is handled:

Data Category Collected? Shared? Processing & Storage Mechanism
Financial Data (Card Numbers, CVV, Expiry) NO NO Local AES-256-GCM Encrypted at rest in SQLite database.
Camera & Photos (Optical Card Scanner) NO NO In-Memory RAM Processed locally via Google ML Kit. Zero frames saved to disk or network.
Biometric Data (Fingerprint / Face Unlock) NO NO Android Keystore Managed strictly by Android OS Hardware Security Module.
Personal Info (Name, Email, Phone) NO NO Card Saver requires zero user accounts or registration.
Location & GPS Coordinates NO NO Zero location permissions declared.
App Telemetry & Crash Analytics NO NO Zero analytics trackers, telemetry, or advertising SDKs.

03 Camera Usage & On-Device ML Kit OCR

Card Saver utilizes the device camera solely to provide the **Camera-Assisted Card Entry** and **Manual OCR Reader** features.

  • 100% Local Inference: Optical Character Recognition (OCR) is performed entirely on your device using bundled Google ML Kit text recognition binaries.
  • Ephemeral Frame Pipeline: Camera preview frames are analyzed in temporary volatile RAM and immediately discarded. Unencrypted card photos are never written to public storage.
  • Optional Encrypted Card Photos: If you choose to attach card snapshots, the images are encrypted on-the-fly using AES-256-GCM and stored as isolated .cardimg binary blobs accessible only when your vault is unlocked.

04 Biometric Authentication & Android Keystore

Card Saver uses the native Android BiometricPrompt and AndroidKeyStore to wrap and unwrap your vault master encryption keys:

  • No Raw Biometrics Access: The application never has access to your fingerprint images or facial geometry. Biometric authentication is evaluated entirely by the Android secure enclave.
  • Biometric Invalidation: In compliance with strict security standards, enrolling a new fingerprint or biometric credential on your device automatically invalidates the Keystore key binding, requiring vault re-authentication.

05 Privacy Hardening & System Defenses

To protect your sensitive financial credentials from rogue applications or malicious background processes, Card Saver implements multi-layered OS-level protections:

  • Screen Capture Protection (FLAG_SECURE): The application window blocks screenshots, screen recording, and task switcher previews across all vault screens.
  • Sensitive Clipboard Masking (Android 13+): When copying a card number or CVV, the payload is tagged with EXTRA_IS_SENSITIVE to suppress clipboard overlay previews.
  • 30-Second Clipboard Auto-Clear: Copied card data is automatically erased from the system clipboard after 30 seconds to prevent unauthorized background access.
  • Disabled Auto-Backup: The Android Manifest specifies android:allowBackup="false", preventing unencrypted cloud syncing via Google Drive or ADB extraction.

06 Encrypted Backups & Storage Access Framework

Card Saver allows users to create portable, encrypted .csbackup containers:

  • Argon2id Key Derivation: Backups are protected by a user-defined backup password derived using memory-hard Argon2id (64 MB memory cost, 3 iterations) combined with AES-256-GCM authenticated encryption.
  • 50-Byte Authenticated Additional Data (AAD): Tamper-evident headers bind backup versioning, salt, nonce, and entity counts into the AEAD authentication tag.
  • Storage Access Framework (SAF): Backup export and import utilize Android’s native document picker (ACTION_CREATE_DOCUMENT and ACTION_OPEN_DOCUMENT), eliminating the need for broad storage permissions (READ_EXTERNAL_STORAGE / WRITE_EXTERNAL_STORAGE).

07 Data Retention & Permanent Deletion

You retain total sovereignty over your data at all times:

  • Individual Deletion: Deleting a card immediately destroys its encrypted SQLite database record and associated encrypted image assets.
  • Emergency Reset / Uninstall: Performing an emergency vault reset, clearing app storage via Android Settings, or uninstalling the application permanently and irrecoverably erases all encrypted database files and Android Keystore master keys.

⚠️ Irrecoverable Data Notice

Because Card Saver employs zero-knowledge cryptography without backdoor recovery mechanisms, if you lose your device PIN, biometric access, and have not created an encrypted .csbackup file, your vault cannot be recovered by the developers.

08 Children's Privacy (COPPA Compliance)

Card Saver is intended for use by adults managing personal financial credentials (ages 18 and older). We do not knowingly collect, store, or solicit information from children under the age of 13.

09 Contact & Policy Updates

We may update this Privacy Policy periodically to reflect emerging security standards or Google Play requirements. All modifications will be published directly to this page with an updated effective date.

If you have questions regarding this Privacy Policy or the security architecture of Card Saver, please email us at intellignt.phool@protonmail.com

01 Agreement to Terms

By downloading, installing, accessing, or using the Card Saver application ("the App"), you agree to be bound by these Terms & Conditions ("Terms"). If you do not agree to these Terms, do not install or use the App.

02 License & Permitted Use

Subject to your compliance with these Terms, you are granted a limited, personal, non-exclusive, non-transferable, revocable license to use the App solely for personal, non-commercial security and financial card organization purposes on your Android device.

You agree NOT to:

  • Modify, reverse-engineer, decompile, or disassemble any binary code of the App, except to the extent permitted by applicable open-source licenses.
  • Attempt to bypass security barriers, cryptographic controls, or memory isolation mechanisms.
  • Use the App for any unlawful purpose, fraud, or infringement of third-party financial rights.

03 Zero-Knowledge Architecture & User Responsibility

You acknowledge and understand that Card Saver is a self-sovereign, zero-knowledge offline application:

🔑 User Key Custody Responsibility

You maintain exclusive custody of your device PIN, biometric credentials, and .csbackup passwords. The developer maintains zero master recovery keys, backdoors, or escrow systems. Loss of your authentication credentials will result in permanent loss of access to your vault data.

04 Financial & Payment Disclaimer

Card Saver is NOT a bank, payment processor, money transmitter, or financial advisor.

  • The App is strictly a secure encrypted digital vault and organizational tool for storing your card metadata and images.
  • The App does not initiate credit card charges, authorize merchant transactions, or verify live card balances.
  • You remain solely responsible for safeguarding your physical credit, debit, and prepaid cards in the real world.

05 Disclaimer of Warranties ("AS IS")

TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, CARD SAVER IS PROVIDED ON AN "AS IS" AND "AS AVAILABLE" BASIS WITHOUT WARRANTIES OF ANY KIND, WHETHER EXPRESS, IMPLIED, STATUTORY, OR OTHERWISE, INCLUDING BUT NOT LIMITED TO WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, AND NON-INFRINGEMENT.

While Card Saver uses industry-standard AES-256-GCM encryption and Android Keystore hardware protection, we do not warrant that the application will be 100% bug-free, uninterrupted, or immune to emerging hardware-level side-channel attacks on compromised or rooted devices.

06 Limitation of Liability

UNDER NO CIRCUMSTANCES SHALL THE DEVELOPERS, AUTHORS, OR CONTRIBUTORS OF CARD SAVER BE LIABLE FOR ANY INDIRECT, INCIDENTAL, CONSEQUENTIAL, SPECIAL, PUNITIVE, OR EXEMPLARY DAMAGES, INCLUDING BUT NOT LIMITED TO LOSS OF DATA, LOSS OF PROFITS, UNAUTHORIZED DEVICE ACCESS, HARDWARE CORRUPTION, OR FINANCIAL LOSS RESULTING FROM THE USE OR INABILITY TO USE THE APPLICATION OR ENCRYPTED BACKUP FILES.

07 Intellectual Property Rights

All rights, title, and interest in and to the Card Saver application—including user interfaces, graphic assets, brand elements, and codebase—are the intellectual property of the developer and are protected by international copyright and trademark laws.

08 Modifications to Terms

We reserve the right to modify these Terms at any time. Any changes will become effective immediately upon publishing the updated Terms to this page. Your continued use of Card Saver following any modifications constitutes acceptance of the updated Terms.

09 Governing Law & Severability

These Terms shall be governed by and construed in accordance with the laws of your jurisdiction without regard to conflict of law principles. If any provision of these Terms is found to be invalid or unenforceable, the remaining provisions shall remain in full force and effect.