Privacy Policy
CardMax is a credit card wallet and manager for iPhone and iPad. It is built so that your cards, statements and spending stay on your device. There is no account to create, nothing to sign in to, and none of your card data is ever uploaded to a server we control. We do not run one.
What stays on your device
- Card details. Card nickname, bank name, cardholder name, card network, the last few digits of the card number (so the card can be recognised at a glance), expiry, currency, bill day, due day, credit limit, annual fee, perks, category and colour are stored in the app's private database on your device.
- Card numbers, CVVs and security codes. These are encrypted with AES-256-GCM before they are written to storage. The key is generated on your device and kept in the iOS Keychain with a device-only setting, so it is never synced or included in a backup.
- Your app PIN. Stored only as a salted SHA-256 digest in the Keychain. The PIN itself is never stored.
- Statements and spending. Statements you import, the transactions read from them, payments you record, milestones and the charts built from them all live in the same on-device database.
- Statement files. PDFs, CSV files and photos you import are read on the device, using Apple's PDFKit and Vision text recognition. The file is not uploaded anywhere. Only the figures you choose to save are kept.
- Saved statement PDF passwords. Only if you tick the box to save one. It is encrypted in the same way as card numbers and kept in the Keychain for that card, and it is removed when you delete the card or choose Forget Saved PDF Password.
- Settings. Theme, reminder preferences and the name on your wallet are stored locally.
Device backups
Like any app's data, the CardMax database can be part of a backup you make with iCloud Backup or a computer. That backup is controlled by Apple and by you, not by us. Card numbers, CVVs, security codes and saved PDF passwords inside it stay encrypted with a key that is never backed up, so they cannot be read from a backup, including on a new device.
Permissions the app asks for
- Face ID or Touch ID. Optional. Used to unlock the app and reveal card details. Apple handles the biometric match. The app only learns whether it succeeded and never receives your face or fingerprint data.
- Notifications. Used for bill day, payment due and annual fee reminders. These are local notifications scheduled on your device, not push messages sent from a server.
- Reminders. Optional, only if you turn on Sync to Apple Reminders. The app creates a CardMax list containing the card name, the bank name and the statement or payment date. Apple's Reminders app may sync that list through your own iCloud account, according to your Reminders settings.
- Photos and files. The app uses the system photo and file pickers, so it only ever sees the single photo or file you pick. It has no access to the rest of your library.
- Motion. The card stack tilts gently with your device. Motion readings are used live for that effect and are never stored or sent.
What leaves your device
Two services receive limited data, and neither of them receives your cards, statements, spending or PIN.
- Apple. Subscriptions are purchased and billed through your Apple Account. We never see your payment details. Apple's privacy policy governs that transaction.
- RevenueCat. Used to confirm whether your CardMax Pro subscription is active. It receives a randomly generated anonymous identifier, your App Store purchase and renewal history, and basic technical information such as app version, iOS version, device model, country and the IP address of the request. It does not receive your name, email address or any card data. See RevenueCat's privacy policy.
- Apple Ads attribution. If you installed CardMax after tapping an Apple Ads advert, Apple's AdServices framework gives the app an attribution token, which is passed to RevenueCat so it can look up which campaign, ad group and keyword led to the install. This uses Apple's own privacy-preserving attribution. It does not use the Advertising Identifier, does not track you across apps, and does not include any card data.
If you choose Send Feedback in Settings, your Mail app opens a message to us with your app version, build, subscription plan, device model, iOS version and language filled in. Nothing is sent unless you press Send, and you can edit or remove any of it first. We use what you send only to reply to you and fix problems.
What we do not do
- We do not sell your data, and we do not share it with data brokers.
- There are no ads and no advertising SDKs in the app.
- There is no analytics SDK, and we do not track you across other companies' apps or websites. The app does not use the Advertising Identifier.
- The app does not connect to your bank, read your bank login, or make payments.
- We do not ask for your name, email, phone number or contacts.
Children
CardMax is not directed at children under 13 and we do not knowingly collect personal information from them.
Your control
You can remove every card, statement and spend at any time with Delete Everything in the app's Settings. Face ID, notification and Reminders permissions can be withdrawn in the iOS Settings app. Deleting the app removes its database from your device. Reminders already written to Apple Reminders stay there until you delete them, because that list belongs to you.
Because we do not hold your card data, there is nothing for us to export or erase on our side. RevenueCat holds only the anonymous subscription record described above. To ask about it, write to us at the address below.
Changes
If this policy changes in a way that matters, the date at the top of this page changes with it, and the app update that causes the change will say so in its release notes.
Contact
Questions about privacy go to patidar.pranshu21@gmail.com, or through the support page.