01 Commitment to Zero-Knowledge Privacy
Your privacy is our highest priority. Card Saver ("we", "our", or "the application") was built from inception with an uncompromising zero-knowledge, 100% offline security architecture.
Unlike traditional cloud wallets, password managers, or fintech applications, Card Saver operates entirely on your physical Android device. We do not operate remote servers, we do not require account creation, and we have zero access to your confidential vault or payment cards.
✓ Air-Gapped Network Isolation
Card Saver strictly omits the android.permission.INTERNET permission from its
Android Manifest. The application physically lacks the OS-level capability to transmit data
over Wi-Fi, cellular, or Bluetooth networks.
02 Google Play Data Safety & Collection Disclosure
In accordance with the Google Play Developer User Data Policy, below is the comprehensive disclosure of how user data is handled:
| Data Category | Collected? | Shared? | Processing & Storage Mechanism |
|---|---|---|---|
| Financial Data (Card Numbers, CVV, Expiry) | NO | NO | Local AES-256-GCM Encrypted at rest in SQLite database. |
| Camera & Photos (Optical Card Scanner) | NO | NO | In-Memory RAM Processed locally via Google ML Kit. Zero frames saved to disk or network. |
| Biometric Data (Fingerprint / Face Unlock) | NO | NO | Android Keystore Managed strictly by Android OS Hardware Security Module. |
| Personal Info (Name, Email, Phone) | NO | NO | Card Saver requires zero user accounts or registration. |
| Location & GPS Coordinates | NO | NO | Zero location permissions declared. |
| App Telemetry & Crash Analytics | NO | NO | Zero analytics trackers, telemetry, or advertising SDKs. |
03 Camera Usage & On-Device ML Kit OCR
Card Saver utilizes the device camera solely to provide the **Camera-Assisted Card Entry** and **Manual OCR Reader** features.
- 100% Local Inference: Optical Character Recognition (OCR) is performed entirely on your device using bundled Google ML Kit text recognition binaries.
- Ephemeral Frame Pipeline: Camera preview frames are analyzed in temporary volatile RAM and immediately discarded. Unencrypted card photos are never written to public storage.
- Optional Encrypted Card Photos: If you choose to attach card snapshots, the
images are encrypted on-the-fly using AES-256-GCM and stored as isolated
.cardimgbinary blobs accessible only when your vault is unlocked.
04 Biometric Authentication & Android Keystore
Card Saver uses the native Android BiometricPrompt and AndroidKeyStore
to wrap and unwrap your vault master encryption keys:
- No Raw Biometrics Access: The application never has access to your fingerprint images or facial geometry. Biometric authentication is evaluated entirely by the Android secure enclave.
- Biometric Invalidation: In compliance with strict security standards, enrolling a new fingerprint or biometric credential on your device automatically invalidates the Keystore key binding, requiring vault re-authentication.
05 Privacy Hardening & System Defenses
To protect your sensitive financial credentials from rogue applications or malicious background processes, Card Saver implements multi-layered OS-level protections:
- Screen Capture Protection (
FLAG_SECURE): The application window blocks screenshots, screen recording, and task switcher previews across all vault screens. - Sensitive Clipboard Masking (Android 13+): When copying a card number or
CVV, the payload is tagged with
EXTRA_IS_SENSITIVEto suppress clipboard overlay previews. - 30-Second Clipboard Auto-Clear: Copied card data is automatically erased from the system clipboard after 30 seconds to prevent unauthorized background access.
- Disabled Auto-Backup: The Android Manifest specifies
android:allowBackup="false", preventing unencrypted cloud syncing via Google Drive or ADB extraction.
06 Encrypted Backups & Storage Access Framework
Card Saver allows users to create portable, encrypted .csbackup containers:
- Argon2id Key Derivation: Backups are protected by a user-defined backup password derived using memory-hard Argon2id (64 MB memory cost, 3 iterations) combined with AES-256-GCM authenticated encryption.
- 50-Byte Authenticated Additional Data (AAD): Tamper-evident headers bind backup versioning, salt, nonce, and entity counts into the AEAD authentication tag.
- Storage Access Framework (SAF): Backup export and import utilize Android’s
native document picker (
ACTION_CREATE_DOCUMENTandACTION_OPEN_DOCUMENT), eliminating the need for broad storage permissions (READ_EXTERNAL_STORAGE/WRITE_EXTERNAL_STORAGE).
07 Data Retention & Permanent Deletion
You retain total sovereignty over your data at all times:
- Individual Deletion: Deleting a card immediately destroys its encrypted SQLite database record and associated encrypted image assets.
- Emergency Reset / Uninstall: Performing an emergency vault reset, clearing app storage via Android Settings, or uninstalling the application permanently and irrecoverably erases all encrypted database files and Android Keystore master keys.
⚠️ Irrecoverable Data Notice
Because Card Saver employs zero-knowledge cryptography without backdoor recovery mechanisms,
if you lose your device PIN, biometric access, and have not created an encrypted
.csbackup file, your vault cannot be recovered by the developers.
08 Children's Privacy (COPPA Compliance)
Card Saver is intended for use by adults managing personal financial credentials (ages 18 and older). We do not knowingly collect, store, or solicit information from children under the age of 13.
09 Contact & Policy Updates
We may update this Privacy Policy periodically to reflect emerging security standards or Google Play requirements. All modifications will be published directly to this page with an updated effective date.
If you have questions regarding this Privacy Policy or the security architecture of Card Saver, please email us at intellignt.phool@protonmail.com