Cards2 — Privacy Policy / プライバシーポリシー
English
Effective date: 2026-07-20
This Privacy Policy describes how the mobile application Cards2 ("the App," "we," "our") handles information when you use it. The App is developed and published by mosless.
1. Summary
Cards2 stores card information (such as photos, names, memos, tags, and barcodes) on your device only. We do not run a backend service that stores user accounts or card data, and we do not use advertising tracking or third-party trackers. To improve reliability, we may review Apple-provided crash and performance information, and we may use feedback or diagnostic information that you choose to submit. Anything synced off your device goes to your own iCloud account by Apple, not to us. The only routine network requests the App makes that reach servers we control are when you browse the optional skin (background image) gallery — those requests fetch publicly hosted images and carry only standard HTTP metadata such as your IP address — and, only if you explicitly use the feature, when you create or update an Apple Wallet pass (see Section 3).
With your permission, the App accesses the following on your device. The content listed below is not transmitted to us as part of normal App use, except when you explicitly use a feature described in Section 3 (such as Apple Wallet passes or feedback).
- Camera and Photo Library — to let you capture or pick images of cards. Images are stored locally in the App's sandbox.
- Local Notifications — to remind you of card expiration dates you set. Notifications are scheduled by iOS and remain on your device.
- Spotlight Index — when enabled in Settings, the App registers your card titles with iOS Spotlight so you can search them from the system search field. This index never leaves your device.
- iCloud Drive (your account) — when you create a backup or enable Auto Backup, backup files are saved to your personal iCloud Drive folder. We have no access to your iCloud account.
3. Optional Network Connections We Initiate
- Skin gallery (Customize screen) — when you open the skin gallery, the App fetches the list of available background images and their previews from the skin catalog content delivery network we host. These requests are anonymous: they contain only your device's IP address as part of standard HTTP traffic. No card data, no account information, and no usage analytics are sent. We do not analyze or share these access logs.
- Apple Wallet passes (optional) — Apple Wallet passes must be cryptographically signed with an Apple-issued pass certificate, which cannot be done on the device. For this reason — and this is the one feature of the App that requires sending card data off your device — if you choose to add a card to Apple Wallet (or update such a pass), the App sends the minimum data required to create the pass — the card name, the barcode value and format (or a barcode image rendered from them), the pass colors, the pass images your device composes for the pass (such as the card's logo or thumbnail and the strip image), any card details you choose to show on the pass (such as the expiration date, category, the date you added the card, or your own custom label and value), and an internal pass identifier — over an encrypted connection to a pass-signing service we operate on Cloudflare Workers. This service processes the data in memory solely to produce the signed pass and returns it to your device; it does not store your card content. Its operational logs use a strict allowlist (a request identifier, the route, the HTTP status, a coarse size range, the duration, and the attestation result) and never contain your card names, barcode values, images, or identifiers; Cloudflare retains standard platform request logs (such as IP address and timestamp) only briefly for operations, and we do not use them for profiling. The only records the service keeps are an abuse-prevention entry per device: a pseudonymized device-attestation key (Apple App Attest), stored as a keyed hash rather than the raw device key, together with issuance counters. These are retained only as long as needed to prevent abuse, a key can be disabled (revoked) if misused, and the short-lived verification challenges and rate-limit records expire within minutes and are deleted automatically by a scheduled cleanup. The finished pass is stored in Apple Wallet on your device and managed by Apple. When you first use this feature, the App asks you to confirm this transfer inside the App, and nothing is sent unless you explicitly use it.
- Feedback and diagnostics (Settings → Feedback or similar support flows) — if you choose to submit feedback, report a problem, or attach diagnostic information, we receive the information you provide and any diagnostics you choose to send. The feedback link opens our support form in your browser, hosted at cards2.app on infrastructure we operate. The App attaches basic diagnostic metadata to the form link (App version, iOS version, device model) to help us investigate. Support submissions and email replies are processed by the related services we use to operate support, only for App quality and support purposes.
4. Quality Improvement and Crash Reports
We may use the following information to investigate bugs, crashes, performance problems, compatibility issues, and support requests:
- Apple-provided crash, performance, and diagnostic information from App Store Connect, TestFlight, Xcode Organizer, or MetricKit.
- Feedback text, screenshots, and diagnostic attachments that you voluntarily submit.
- Diagnostic metadata such as App version, iOS version, device model, language, basic settings state, recent App screen/action breadcrumbs, crash diagnostics, performance diagnostics, and non-content error logs.
Diagnostic attachments are designed to exclude card photos, card names, memos, tags, barcodes, backup files, passcodes, payment details, and App database files. If you type sensitive card information into a free-text feedback field or include it in a screenshot, we will receive what you submit, so please avoid including sensitive card details unless you intentionally want us to review them for support.
We may use related services and tools to organize feedback and prepare responses efficiently. We do not use feedback or diagnostics for advertising tracking, cross-app tracking, data broker sharing, or profiling unrelated to App quality and support.
5. Purchases and Subscriptions
In-app purchases (Pro plans and one-time purchase) are processed by Apple via StoreKit. We never see your payment details. We only receive the verified entitlement status from Apple to unlock Pro features on your device.
To honour customers who purchased earlier paid versions of Cards2, the App also asks Apple, on this device only, whether the same Apple ID previously purchased Cards2 — specifically the build version that originally bought the App (AppTransaction.originalAppVersion). This signal is read locally to decide whether to grant a legacy lifetime Pro entitlement. It never leaves the device, and we do not store or transmit your purchase history.
- We do not run a backend that stores your card photos, names, memos, tags, barcodes, backup files, passcodes, or App database files. (The optional Apple Wallet signing service described in Section 3 processes a card's name, barcode, image, and the details you choose to show on the pass transiently in memory and does not store them.)
- We do not use advertising SDKs or track you across other companies' apps or websites for advertising or data broker purposes.
- We do not sell your data, share it with data brokers, or process it for advertising profiling. Voluntary feedback and diagnostics may be processed by the related services we use for forms, support, and diagnostics, only for App quality and support purposes.
- We do not contact you, email you, or send push notifications from a server. All notifications are scheduled locally on your device.
- Where applicable (EU/UK/California), you have the right to access, correct, or delete the limited information you voluntarily submit (feedback, diagnostics) by contacting us at the address in Section 11. Because card content stays on your device, you can exercise erasure for that content directly via the in-App "Delete All Data" action described in Section 7.
7. Data Retention and Deletion
All card data is stored locally on your device.
- To delete a single card, edit it and tap "remove" in the App.
- To delete everything, open Settings → Data Management → Delete All Data. This permanently removes every card, tag, custom skin, and image file from the App.
- Uninstalling the App from your device also removes all local data.
- iCloud backup files you have created remain in your own iCloud Drive until you delete them.
- Feedback and diagnostic submissions are retained only for as long as reasonably needed to provide support, investigate issues, improve App quality, and maintain release history.
- Apple Wallet passes you added are stored in Apple Wallet and are removed when you delete them from Wallet. The abuse-prevention records held by the signing service (a pseudonymized device key and issuance counters) are kept only as long as needed to prevent abuse and can be revoked; the short-lived verification and rate-limit records are purged automatically.
8. Security
Card data is stored locally in the App's iOS sandbox. Data you choose to back up remains in your own iCloud Drive account, which we cannot access.
9. Children's Privacy
The App is not directed at children under 13 and does not knowingly collect any information from children. Aside from the optional features described in Section 3 (Apple Wallet passes and feedback), all data handling is local to the user's device regardless of the user's age.
10. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be reflected by updating the "Effective date" above. Continued use of the App after a change constitutes acceptance of the updated policy.
If you have questions about this Privacy Policy, please contact:
moslesson@gmail.com
日本語
施行日: 2026-07-20
本プライバシーポリシーは、モバイルアプリ「カード類2 (Cards2)」(以下「本アプリ」) が情報をどのように扱うかを説明するものです。本アプリは mosless が開発・提供しています。
1. 概要
本アプリは、カードの情報 (写真、名称、メモ、タグ、バーコード等) をお使いの端末内にのみ保存します。当方はユーザーアカウントやカードデータを保管するバックエンドを運用しておらず、広告目的のトラッキングや第三者トラッカーも使用しません。品質改善のため、Apple から提供されるクラッシュ情報・パフォーマンス情報、およびお客様が任意で送信したフィードバックや診断情報を利用する場合があります。お使いの端末から外部に同期されるデータは、Apple によってお客様自身の iCloud アカウントに送信されるもので、当方には届きません。当方が運用するサーバーへの通常のネットワーク要求は、お客様が任意で「スキン (背景画像) ギャラリー」を閲覧する際に画像を取得する場合に限られ、その際送信されるのは IP アドレス等の標準的な HTTP メタデータのみです。これに加え、お客様が明示的に Apple Wallet 機能を使用した場合に限り、パスの作成・更新のための送信が発生します (第3章参照)。
2. 本アプリが端末上でアクセスする情報
お客様の許可のもと、本アプリは端末上で以下にアクセスします。以下の内容は、通常のアプリ利用において当方へ送信されることはありません (お客様が明示的に利用した場合の Apple Wallet パス発行・フィードバック送信を除きます。第3章参照)。
- カメラおよび写真ライブラリ — カード画像の撮影・選択のために使用します。画像は本アプリのサンドボックス内に保存されます。
- ローカル通知 — お客様が設定したカードの有効期限を通知するために使用します。通知は iOS によってスケジュールされ、端末内に留まります。
- Spotlight インデックス — 設定で有効にした場合、システム検索からカードを検索できるよう、カード名を iOS の Spotlight に登録します。このインデックスが端末外に出ることはありません。
- iCloud Drive (お客様のアカウント) — バックアップを作成、または自動バックアップを有効にした場合、バックアップファイルがお客様の iCloud Drive フォルダに保存されます。当方はお客様の iCloud アカウントにアクセスできません。
3. 当方が発生させる任意のネットワーク接続
- スキンギャラリー (カスタマイズ画面) — スキンギャラリーを開いた際、本アプリは当方が運用しているスキンカタログ用コンテンツ配信ネットワークから、利用可能な背景画像のリストとプレビューを取得します。これらの要求は匿名で、標準的な HTTP の一部としてお客様の端末の IP アドレスのみが送信されます。カードのデータ・アカウント情報・利用分析等は一切送信されません。当方は、これらのアクセスログを分析・第三者提供することはありません。
- Apple Wallet パス発行 (任意) — Apple Wallet のパスは Apple 発行のパス証明書による暗号署名が必須であり、この署名は端末内では行えません。そのため — これは本アプリで唯一、カードのデータが端末外へ送信される機能です — お客様がカードを Apple Wallet に追加 (またはそのパスを更新) することを選択した場合に限り、本アプリはパス生成に必要な最小限のデータ (カード名、バーコードの値と形式またはそこから描画したバーコード画像、パスの配色、端末上で合成したパス用画像 (カードのロゴやサムネイル、帯 (strip) 画像など)、パスに表示するためにお客様が選んだカードの項目 (有効期限・カテゴリ・登録日、またはお客様が入力した任意の見出しと内容など)、パスの内部識別子) を、当方が Cloudflare Workers 上で運用する署名サービスへ暗号化通信で送信します。このサービスは受け取ったデータを署名済みパスの生成のためだけにメモリ上で処理して端末へ返却し、カードの内容を保存しません。運用ログは厳格な許可リスト方式 (リクエスト識別子・ルート・HTTP ステータス・粗いサイズ区分・処理時間・端末認証の結果) で、カード名・バーコードの値・画像・識別子を記録しません。Cloudflare 側の標準的なリクエストログ (IP アドレスやタイムスタンプ等) は運用のため短期間のみ保持され、プロファイリングには使用しません。サービス側に保持されるのは、不正利用防止のための端末ごとの記録のみです。すなわち、疑似化された端末認証鍵 (Apple App Attest。生の端末鍵ではなく鍵付きハッシュとして保存) と発行回数の記録です。これらは不正利用防止に必要な期間に限って保持し、不正があれば鍵を無効化 (失効) でき、短命な検証チャレンジやレート制限の記録は数分で期限切れとなり、定期的な掃除処理で自動削除されます。生成されたパスはお使いの端末の Apple Wallet に保存され、以後 Apple の管理下に置かれます。初回利用時には、アプリ内でこの送信について確認をお願いしており、明示的に使用しない限り、これらの送信は一切行われません。
- フィードバックおよび診断情報 (設定 → フィードバック、または同様のサポート機能) — お客様がフィードバック、不具合報告、診断情報の添付を任意で送信した場合、当方はお客様が入力した内容および送信を選択した診断情報を受け取ります。フィードバックリンクは、当方が運用する cards2.app 上のサポートフォームをブラウザで開きます。調査のため、アプリはフォームリンクに基本的な診断メタデータ (アプリバージョン、iOS バージョン、端末モデル) を付与します。フォームの送信内容およびサポートメールへの返信は、サポート運用のために当方が利用する関連サービスによって、アプリ品質改善およびサポート目的に限って処理されます。
4. 品質改善・クラッシュ報告
当方は、不具合、クラッシュ、パフォーマンス問題、互換性問題、サポート依頼を調査するため、以下の情報を利用する場合があります。
- App Store Connect、TestFlight、Xcode Organizer、MetricKit 等を通じて Apple から提供されるクラッシュ情報、パフォーマンス情報、診断情報
- お客様が任意で送信したフィードバック本文、スクリーンショット、診断添付情報
- アプリバージョン、iOS バージョン、端末モデル、言語、基本的な設定状態、直近のアプリ画面・操作履歴、クラッシュ診断、パフォーマンス診断、カード内容を含まないエラーログ等の診断メタデータ
診断添付情報には、カード画像、カード名、メモ、タグ、バーコード、バックアップファイル、パスコード、決済情報、アプリのデータベースファイルが含まれないよう設計します。ただし、お客様が自由入力欄やスクリーンショットに機微なカード情報を含めた場合、当方はお客様が送信した内容を受け取ります。サポート目的で意図的に必要な場合を除き、機微なカード情報は入力しないでください。
当方は、フィードバックの整理や返信の作成を効率化するため、関連サービス・ツールを利用する場合があります。フィードバックや診断情報を、広告目的のトラッキング、他社アプリ・ウェブサイトを横断したトラッキング、データブローカーへの共有、またはアプリ品質改善・サポートと無関係なプロファイリングには使用しません。
5. 購入およびサブスクリプション
アプリ内課金 (Pro プランおよび買い切りアンロック) は、Apple の StoreKit を介して処理されます。当方がお客様の決済情報を見ることはありません。当方が Apple から受け取るのは、端末上で Pro 機能を解放するための検証済み権利情報のみです。
旧版 Cards2 を購入いただいたお客様への移行措置として、本アプリは「同一の Apple ID で過去に Cards2 を購入したか」を Apple に対して端末内でのみ問い合わせます (具体的には AppTransaction.originalAppVersion を参照します)。これは旧購入者へ Lifetime Pro 権利を付与するか否かを判定する目的でローカル参照されるのみで、購入履歴を当方が保存・送信することはありません。
6. 当方が収集しない情報
- お客様のカード画像、カード名、メモ、タグ、バーコード、バックアップファイル、パスコード、アプリのデータベースファイルを保管するバックエンドを当方は運用していません。(第3章の Apple Wallet 署名サービスは、カード名・バーコード・カードの画像・パスに表示する項目をメモリ上で一時的に処理するのみで保存しません。)
- 広告 SDK を使用せず、広告またはデータブローカー目的で他社のアプリやウェブサイトを横断してお客様をトラッキングしません。
- お客様のデータを販売・データブローカーへの提供・広告プロファイリングへの利用は行いません。任意で送信されたフィードバックや診断情報は、フォーム・サポート・診断のために当方が利用する関連サービスによって、アプリ品質改善およびサポート目的に限って処理される場合があります。
- サーバーからのご連絡、メール送信、プッシュ通知の送信は行いません。すべての通知はお使いの端末上でローカルにスケジュールされます。
- お住まいの地域 (EU・英国・カリフォルニア州等) に該当する場合、お客様が任意で送信された情報 (フィードバック、診断情報) について、アクセス・訂正・削除の権利を行使いただけます。第 11 項のお問い合わせ先までご連絡ください。カードデータは端末内にのみ保存されるため、その削除はアプリ内「全データを削除」機能で直接行えます (第 7 項参照)。
7. データの保持および削除
カードのデータはすべて端末内にローカル保存されます。
- 個別のカードを削除するには、編集画面で「削除」をタップしてください。
- すべてのデータを削除するには、設定 → データ管理 → 全データを削除 をご利用ください。すべてのカード・タグ・カスタムスキン・画像ファイルが本アプリから完全に削除されます。
- 本アプリを端末から削除すると、ローカルデータもすべて削除されます。
- お客様が作成した iCloud バックアップファイルは、お客様自身が削除するまでお客様の iCloud Drive に残ります。
- フィードバックおよび診断情報の送信内容は、サポート対応、不具合調査、品質改善、リリース履歴の維持に合理的に必要な期間に限って保持します。
- Apple Wallet に追加したパスは Apple Wallet に保存され、Wallet から削除すると取り除かれます。署名サービスが保持する不正利用防止用の記録 (疑似化された端末鍵と発行回数) は不正利用防止に必要な期間のみ保持し、失効させることができます。短命な検証・レート制限の記録は自動的に削除されます。
8. セキュリティ
カードデータは、本アプリの iOS サンドボックス内にローカル保存されます。お客様がバックアップを選択したデータは、お客様自身の iCloud Drive アカウント内に保存され、当方はアクセスできません。
9. 子どものプライバシー
本アプリは 13 歳未満の子どもを対象としておらず、子どもから情報を意図的に収集することはありません。第3章に記載した任意機能 (Apple Wallet パス発行・フィードバック) を除き、すべてのデータ処理はユーザーの年齢に関わらずユーザー端末内で完結します。
10. ポリシーの変更
本プライバシーポリシーは随時更新されることがあります。重要な変更があった場合は上記「施行日」を更新します。変更後も本アプリのご利用を継続される場合、更新後のポリシーに同意いただいたものとみなします。
11. お問い合わせ
本プライバシーポリシーについてご質問がある場合は、以下までご連絡ください:
moslesson@gmail.com