Kardhaus

The cards you scan are not yours to upload

Every privacy page talks about protecting your data. This one is about the other person on the card.

Last updated 2026-08-17

The argument nobody in this category makes

When you scan a business card, the personal data being processed is not yours. It is a name, a direct line, a work email and often a mobile number belonging to someone who handed you a piece of paper at a meeting. They consented to you having it. They did not consent to a third-party company in another jurisdiction holding it, indexing it, or building a social graph out of it.

A cloud card scanner makes that decision on their behalf, silently, every time you press the shutter. A local-only app is the only architecture where scanning someone’s card does not hand their data to a company they have never heard of. This matters more under Japan’s APPI and Taiwan’s PDPA than generic privacy marketing does, and no cloud competitor can copy it without rebuilding their product.

What Kardhaus does and does not do

  • Recognition runs on your device using the OCR built into iOS. Turn on airplane mode and scan a card — it works. That is the whole product.
  • Cards are stored on your device, and synced through your own iCloud private database if you want them on your iPad too. We are not a party to that sync and cannot read it.
  • There is no account. No email required to use the app, no password, no profile, nothing to breach.
  • No analytics SDK in the app. No RevenueCat, no Firebase, no Mixpanel, no attribution SDK. The App Store privacy label reads *Data Not Collected*.
  • No ads and no ad identifiers, on any tier.

Where the recognition actually runs

Two layers, both on the phone. A deterministic pass reads the card with the OCR built into iOS and fills the fields it can prove from the text. Then a second pass — we call it Genius — reads that same text with Apple’s on-device language model to work out which line is a department and which is a job title, and to keep a Chinese name and a Latin name attached to one person.

Neither layer makes a network request. The app contains no networking code at all — no URL session, no API key, no endpoint of ours for one to point at. You do not have to take that on faith: put the phone in airplane mode and scan a card. Everything works, because there is no degraded mode to fall back to.

What we are conceding

Genius needs a device new enough to run Apple Intelligence. On an iPhone that cannot, you get the deterministic pass only — a complete, usable record with the inferred fields left blank instead of guessed. Nothing fails, and nothing is sent anywhere to make up for it. Hard cards still exist: stylised 楷體, vertical layouts, foil on gloss. Those you will finish by hand, and we would rather say so than send someone else’s contact details to a data centre to avoid admitting it.

If a future version ever needs to send a card off the device, it will be off by default, it will name the company receiving it on the same screen where you switch it on, and it will be described here before it ships. It will not arrive in a silent update.

How this compares

Account requiredCards stored on vendor serversWorks offlineAd tracking
KardhausNoNoYes, fullyNo
CamCardYesYesPartial
EightYesYesNo
myBridgeYesYesNoYes, third-party
HiHelloYesYesNo

Compiled from each app’s own App Store privacy disclosures and published documentation, August 2026. Check them yourself — they are one tap away on every App Store listing, and reading them is the fastest privacy audit available to anyone.

Common questions

If there is no account, how do I move my cards to a new phone?
iCloud. Cards sync through your own iCloud private database, so a new iPhone signed into the same Apple Account restores them. You can also export everything to vCard or CSV at any time and carry it out yourself.
If nothing reaches you, how do you count the free scans?
We do not, and we could not. Nothing about what you scan reaches us, so the allowance is counted on the device itself. That makes it defeatable by reinstalling, and we accept that — it exists to demonstrate value, not to police anyone. An allowance we could enforce would require a server that watched you use the app, which is the product we are deliberately not building.
Is the app open source?
Not currently. We are considering open-sourcing the parsing and recognition core, which is the part where a privacy claim is either true or false, while keeping the app shell closed. If that matters to you, say so on the waitlist — it is a real decision that is still open.
What do you collect on this website?
Two things, and you control the second one. Plausible analytics runs for everyone: cookieless, aggregate, EU-hosted, no personal data, nothing to opt out of. Google Analytics is optional — it sets cookies, so it is off by default and nothing from Google is even downloaded until you accept the banner. Declining is remembered and never asked again. If you join the waitlist we store the email address you type and whatever you choose to write in the optional comment box, in our own Cloudflare database and a private Google Sheet. No Google Fonts, no Tag Manager, no ad pixels, and Google advertising signals are switched off.

Not on the App Store yet

Get the first build, and 100 free scans

100 free scans, front and back included

Kardhaus is in development for iOS 18 and later. Leave your email and you get the TestFlight build when it opens, plus 100 free AI scans on the house — double-sided cards included, counted as one card, not two.

A person reads these. They go on the build list, in order of how often they come up.

One email when the build is ready, one when it launches. No newsletter, no drip sequence, never sold and never handed to an ad network. Stored in our own Cloudflare database and a private Google Sheet. Unsubscribe deletes the record. How we handle this email