Privacy Policy
Effective August 24, 2026
WalletApp stores payment card information for your reference. Card data stays on devices and services you control; the developer does not operate a card-data backend.
Who is responsible
WalletApp is provided by Andrei Gaivoronskii, an independent developer. Privacy questions and deletion requests can be sent to andrei@gaivoronskii.com.
Data stored on your devices
Card fields, presentation settings, card order, favorite status, reminders, and app preferences are stored locally. Sensitive fields such as card numbers, CVC, PIN, login details, passwords, and security questions are encrypted before local storage.
Deleting the app removes its local data, subject to device backups and synchronized copies managed by Apple or Google.
Optional iCloud sync
On Apple devices, you can enable iCloud sync to synchronize card data through your personal iCloud account. Sensitive card fields remain encrypted. The developer does not receive your iCloud credentials or synchronized card data.
Optional Google Drive sync
If you connect Google Drive, WalletApp stores an end-to-end encrypted vault in the private application-data folder of the Google account you choose. This supports synchronization between WalletApp on iPhone and Android.
- Sync is optional and starts only after you choose a Google account and grant access.
- WalletApp requests the
drive.appdatascope, which allows access only to hidden app data created for WalletApp, not your other Drive files. - The vault is encrypted on your device before upload. Google and the developer do not have the vault key and cannot read its card data.
- A recovery code is required to decrypt the vault on another device. WalletApp and Google cannot recover a lost recovery code.
- The vault includes card fields, card order, favorite status, presentation settings, and available or custom bank icons. Custom card background images remain local to the device.
- Disconnecting revokes app access and stops synchronization. Existing hidden app data may remain in your Google account until you remove it through your Google account settings.
Google account authorization
When you connect Google Drive, Google Sign-In authenticates the account and returns authorization credentials to the app. WalletApp displays and stores the selected account email locally so it can restore the connection. The developer does not receive the credentials or account email through a server.
Google Sign-In and Google Play services may process account, contact, approximate location, device identifier, and usage information for authentication, security, fraud prevention, app functionality, and service diagnostics under Google's privacy policy. WalletApp does not use this information for advertising or tracking.
Bank and card identification
Payment-system detection primarily runs locally. For unresolved cards, WalletApp may send only the first six digits of the card number to HandyAPI to identify an issuer. A bank domain may be sent to Google's favicon service to retrieve a bank icon. Full card numbers, CVC, PIN, passwords, and other card fields are not sent to these lookup services.
Companion devices and widgets
Apple Watch, Wear OS, widgets, and system shortcuts receive the card data needed for the feature you configure. Apple or Google may relay wearable transfers through their protected device services when a direct connection is unavailable. Local wearable copies use platform-provided storage protection.
Permissions
- Camera: used only when you scan a physical card. Text recognition runs on-device, and scan frames are not stored or uploaded.
- Photos or images: used only when you choose a custom card background or bank icon, or share an image. Custom bank icons are included in Google Drive sync; custom background images are not.
- Biometrics: Face ID, Touch ID, and Android biometric checks are handled by the operating system. WalletApp cannot access biometric templates.
- Notifications: used for card-expiry reminders you configure.
Analytics, advertising, and tracking
WalletApp contains no advertising SDK and does not use developer-operated analytics or cross-app tracking. Apple and Google may provide aggregated store, reliability, or service information and may process technical data when their platform services are used.
Support messages
If you contact support, we receive your email address and the information you include. It is used only to answer the request, provide support, or process a deletion request and is retained only as long as reasonably necessary for those purposes or legal obligations.
Security
WalletApp uses platform key stores, authenticated encryption, HTTPS, and limited service permissions. No storage or transmission method is completely secure. You are responsible for protecting device access, backups, and the Google Drive recovery code.
Retention and deletion
- Delete a card in WalletApp to remove it locally and propagate a deletion through enabled sync services.
- Disable iCloud or Google Drive sync to stop future synchronization.
- Remove hidden WalletApp app data from your Google account settings to delete the Drive copy.
- Contact us to request deletion of support correspondence. We cannot access or delete card vaults stored in your personal iCloud or Google account.
Children
WalletApp is a general-purpose finance utility and is not directed to children. We do not knowingly collect personal information from children.
Changes
We may update this policy when WalletApp, platform requirements, or connected services change. The effective date above identifies the latest version.