Privacy
Privacy Policy
CardConnect helps you capture professional contacts and prepare follow-ups. This policy explains what data is involved and the controls available to you.
Effective 25 August 2026
1. Who we are
CardConnect is provided by Manual 2 AI Private Limited (“Manual2AI”, “we”, “us”, or “our”). This policy applies to the CardConnect Android app, iOS app, web app, and related services.
Questions or privacy requests can be sent to info@manual2ai.com.
2. Data CardConnect handles
- Account and profile data: name, email address, phone number, company, designation, authentication provider, and account identifiers.
- Contact and relationship data: business-card images, names, professional contact details, companies, roles, websites, addresses, event details, tags, meeting context, notes, follow-up drafts, follow-up status, and OCR field confidence.
- Files you choose to add: brochures, documents, photos, or other attachments used with a follow-up.
- Voice context:microphone audio used while you dictate notes and the resulting transcript. The native app first uses the device's speech recognition service. When you are signed in and online, CardConnect may send the bounded recording through its protected API for Google Gemini to clean up the transcript. The web app may also send a recording for transcription after you choose to record it.
- Purchase information: product, entitlement, and transaction identifiers needed to verify a subscription. Google Play handles Android billing, Apple handles iOS billing, and Razorpay handles web billing. Those providers handle full payment-card details; CardConnect does not receive them.
- Operational service data: authentication and security events, request timestamps and status, sync outcomes, notification subscription details, and limited server error logs when an online feature is used. The native iOS app has no advertising, cross-app tracking, or third-party crash-reporting SDK. Its bundled Google Sign-In SDK declares linked, non-tracking service data: other data types for app functionality and analytics; coarse location for app functionality; user identifiers for app functionality and analytics; and device identifiers and other usage data for analytics. Native camera focus, sharpness, and lighting checks remain on the device. OCR field confidence may sync with an approved contact. Local queue state and interface actions remain on the device unless you choose to include them in a support request; they are not sent as CardConnect analytics.
CardConnect also stores essential session and preference information on your device or in browser storage. We do not use third-party advertising cookies.
If you choose Google Sign-In, Google may provide your name, email address, profile picture, and Google account identifier. The Google Sign-In SDK may also process phone numbers and the linked, non-tracking operational and analytics-purpose data described above. Supabase processes and stores the identity information with your authentication and CardConnect profile records. We use it to create, authenticate, secure, and show your account; personalize follow-up drafts you request; and prefill customer details if you start a web subscription checkout. A requested draft may send your name to Google Gemini, and web checkout may send your name and email address to Razorpay as described in section 5. Google Sign-In does not give CardConnect access to your Gmail, Google Drive, Google Contacts, or Google Calendar.
3. Device permissions
CardConnect asks for a permission only when a related feature needs it. You can change permissions in system settings.
- Camera lets you capture a card, badge, or QR code. Android's system photo picker can provide an image you select without giving CardConnect broad access to your photo library.
- Microphone and Speech Recognition let you dictate meeting context.
- When you tap Save to Apple Contacts, CardConnect directly creates or updates that person. It reads back only the linked record and fields needed to update it and verify that the save succeeded; it does not browse or upload unrelated address-book entries. A person photo stays only in CardConnect unless you explicitly include it in this save, after which Apple Contacts may sync it according to your system account settings.
- When you tap Add follow-up to Calendar, CardConnect directly creates the requested event using write-only access where the system supports it; CardConnect does not read or upload your calendar.
- Notifications are used for follow-up reminders you enable.
4. How we use data
- Authenticate you and keep your account secure.
- Extract business-card details, organize contacts and events, sync approved data, and keep offline work queued until connectivity returns.
- Produce an immediate on-device extraction or transcript in the native app. Native card photos and recognized card text stay on the device. When you request it, Google Gemini may clean up a recording or personalize a draft using bounded contact context. The web scanner may send a selected card image through the protected API for extraction.
- Prepare messages, reminders, exports, contact cards, and other actions you request. A draft is not treated as sent.
- Verify purchases and provide subscription features.
- Operate, troubleshoot, protect, and improve CardConnect, including measuring scan reliability and preventing misuse.
- Comply with law and enforce our terms.
5. Processing and sharing
We use service providers only as needed to operate CardConnect. These may include Supabase for authentication, databases, and storage; Vercel for web hosting and APIs; Apple and Google for sign-in and platform services; Google Gemini for web card extraction, requested transcription, or requested message assistance; Resend for a web email you direct CardConnect to send; and payment providers for subscription processing.
When you choose WhatsApp, email, phone, calendar, Contacts, or a share action, the relevant app or platform receives the information needed to perform that action under its own privacy terms. We may also disclose data when required by law, to protect users or the service, or as part of a business transaction subject to appropriate safeguards.
We do not sell personal data, use it for cross-app tracking, or share it for third-party targeted advertising.
6. Your responsibility for contact data
Business cards and meeting notes can contain information about other people. You are responsible for collecting, storing, and contacting those people lawfully, respecting their choices, and avoiding spam or unwanted communications.
7. Storage, retention, and deletion
The native app can keep captures, contacts, events, and queue state on the device so capture can continue offline. Confirmed data may sync to your CardConnect account. We retain account data while your account is active and as reasonably needed to provide the service, resolve disputes, prevent abuse, and meet legal obligations.
You can export your data and request permanent account deletion from More → Privacy & account in the Android or iOS app. Instructions are also available on our account-deletion page. Account deletion removes the account, associated application records, and files in CardConnect's user-scoped storage. Limited copies can remain temporarily in encrypted backups or security logs until normal retention cycles expire. We may retain a minimal provider transaction identifier and final subscription state when needed to prevent repeat charges, replayed purchases, fraud, or to meet legal obligations; this record does not contain card details or restore deleted contact data. Before account deletion completes, CardConnect cancels a linked Razorpay web subscription so it cannot charge again. Apple does not permit CardConnect to cancel an App Store subscription for you, so that subscription remains managed in your Apple Account settings. A Google Play subscription similarly remains managed in Google Play.
8. Security and international processing
We use access controls, encryption in transit, restricted service credentials, and other reasonable safeguards. No system can guarantee absolute security. Our providers may process data in countries other than yours, using contractual and technical safeguards appropriate to the service.
9. Your choices and rights
Depending on your location, you may have rights to access, correct, export, delete, restrict, or object to processing of personal data. Many of these controls are available in the app. You may also contact us at info@manual2ai.com. We may need to verify your identity before completing a request.
10. Children
CardConnect is a professional networking service and is not directed to children under 13 or the minimum age required by local law. If you believe a child provided personal data, contact us so we can review and remove it.
11. Changes to this policy
We may update this policy as CardConnect or applicable law changes. We will post the revised policy here, update its effective date, and provide additional notice in the app when a material change requires it.