Privacy Policy
Last updated 19 July 2026
ZapCard is a business-card scanner and follow-up tool for people who meet a lot of contacts — at exhibitions, trade shows and in the field. This policy explains what we collect, why, and the control you have. We do not sell your data, and we do not show ads.
What we collect
- Your account — when you sign in with Google we receive your name, email address and profile picture. If you sign in with a phone number, we store that number. This identifies your account and syncs your data across your devices.
- The cards you scan — the photos you take and the contact details extracted from them (names, phone numbers, emails, addresses, company, GST/tax IDs and similar). These are your business contacts, stored so you can find and follow up with them.
- Notes & reminders you add to a contact, including voice notes. Voice notes are transcribed to text on your device using your phone's built-in speech recognition; we do not receive your audio.
- WhatsApp setup — if you connect WhatsApp follow-ups, we store the messaging key you provide (e.g. your Interakt key) so the app can send on your behalf. Messages are sent through your own messaging provider, not ours.
- Basic diagnostics — app version and device type when you send us feedback, so we can reproduce issues.
How AI processing works
Which third party receives your data. When you scan a card with “Cortex cloud” or “Auto” mode, the card photograph is sent to Google LLC and processed by the Google Gemini API, which we operate under the name Cortex. Google is our sub-processor for this and nothing else.
Exactly what is sent. Only the photograph(s) of the business card you just scanned, and — if you ask Cortex to tidy a dictated note or draft a follow-up message — the text of that note. Nothing else goes to Google: not your contact list, not your other cards, not your account details, name, email, phone number or location.
What Google does with it. The data is processed solely to return the extracted details to you. Under our paid Gemini API configuration Google does not use it to train its models, and Google is contractually bound to protections equivalent to those in this policy. See Google’s Gemini API terms and privacy policy.
Your permission, and how to withhold it. We ask before the first card is ever sent, and you can decline. If you decline, or choose “Fully offline” in Settings → Card extraction, extraction runs entirely on your device and no card image or note text leaves your phone. You can change this at any time in Settings, and English-language cards are read on-device without any network at all.
Where your data lives
Your contacts are stored on your device and, when you are signed in, synced to our cloud database (hosted on managed infrastructure) so you don't lose them if you lose your phone. Data is transmitted over encrypted connections.
Who we share it with
- Nobody, for advertising or sale. We never sell your data.
- Service providers that run the app for us — cloud hosting, the AI extraction provider (Google LLC — Gemini API), and (only if you connect it) your WhatsApp messaging provider — process data strictly to provide the service.
- Your team — if you join a team/organisation in ZapCard, your team's admin can see cards added under that team, by design.
Your choices & rights
- Delete everything. In the app, go to Settings → Your data → Delete account. This permanently removes your account, your synced cards, your uploaded images and your notes from our servers. This cannot be undone.
- Export. You can export your contacts (vCard/CSV) at any time.
- Work offline. You can use extraction modes that keep photos on your device.
- To ask a question or make a request, email aayush.shah@sheen.ai.
Children
ZapCard is a business tool and is not directed at children under 16.
Changes
We may update this policy; material changes will be reflected here with a new date above.