Meishitto is built around the principle that your business card data belongs to you. This page describes, factually and precisely, what information the app actually collects and stores — and what it does not.
1. By default, we do not store scanned card content on our servers
Scanned card images, extracted text, and contact fields are stored on your own device. When you use the optional AI refinement step (the third tier of our OCR pipeline), the image and text are sent to our backend transiently for processing and are not retained after the result is returned to your device.
That transfer happens only after the app has named the recipient (a third-party AI model provider) and the purpose, and you have tapped "Agree and use AI". If you decline, the image never leaves your device, and on-device scanning, saving and exporting remain free and unlimited. You can withdraw the consent at any time in Settings.
The one exception is your own digital card (My Card): only the fields you explicitly mark as public, and only while card-update notifications are switched on. Those public fields are stored so that people who scanned your QR code and subscribed can fetch your latest details. Anyone who has not subscribed cannot fetch them. Turning notifications off, or deleting your account, removes them from our servers.
The other exception is "cloud sync", and the "AI connection" that runs on top of it. Only if you switch one of them on in Settings and agree after reading the notice, a copy of your card library (card text) is stored on our servers (switching on the AI connection switches on cloud sync too). Its sole purpose is to let the AI assistant you chose (such as Claude) read that copy through a dedicated URL. The AI cannot write to the copy or to your cards directly — corrections, tags and deletions arrive in the app as proposals, and you decide whether to apply them (unless you switch on automatic application in Settings). Nobody without that URL can access it, and we never use this copy for AI training, advertising or analytics. Tapping "Disconnect", turning cloud sync off, or deleting your account, deletes the server copy immediately. Both switches are off by default — unless you turn one of them on, your card library is never stored on our servers.
A published My Card also gets a stable share link (of the form meishitto.smartrich.ai/c/…). If you set a logo image, that logo is served publicly from the same link (this is the logo you chose yourself, never a photo of a scanned card). Anyone who has that link can view the public fields without signing in — the link contains a 10-character random string that cannot be guessed, but we cannot stop a recipient from forwarding it. Withdrawing the card invalidates the link immediately. Fields you kept private never appear on that page.
2. Information stored on our servers
Our backend (Cloudflare Workers + D1 database) stores only the following minimal data.
- Account identifier: an internal ID derived from your Google or Apple sign-in (e.g. "google:xxxxx"). We do not store your email address on our servers.
- Subscription status: your plan tier (Free/Plus/Pro), expiry, and a purchase reference ID from the App Store / Google Play, used for fraud prevention and restore-purchase support.
- Your My Card public fields and display name — only while card-update notifications are on. Visible to your subscribers and to anyone holding your share link; removable by you at any time.
- Only while AI connection is on: a copy of your card library (card text) and a hash of the access token. Deleted immediately when you disconnect or delete your account.
- Scan-quality feedback (only if you tap 👍 or 👎): anonymous signals only — which tier produced the result (on-device or AI), the recognition score, and how many fields were extracted. Tapping 👍 or 👎 by itself never sends any card content (names, companies, phone numbers).
- Samples for improving recognition (only if you also tap “Send this photo to help us improve”, which appears after 👎): we store that one photo plus what was read from it (the recognised text and extracted fields). We do not record who sent it — no account or device identifier is stored alongside it, so it cannot be linked back to you. Samples are used only to improve recognition accuracy and are deleted automatically after 30 days. Nothing is sent unless you tap it.
- AI-refinement usage counters for the current billing period (a number only — no card content).
- If you allow push notifications: your device push token (the delivery identifier issued by Apple/Google) and your notification on/off preferences. We do not compose notification text on the server — the wording is assembled on your device, so neither the message content nor your display language is stored by us. Business Chain is the one exception: the notification is pointless unless it carries the question your friend actually typed, so that one sentence does travel through the delivery path (see “About Business Chain” below).
- The list of people whose card updates you subscribed to: which accounts you subscribed to by scanning their QR code (their account identifier only — no card content). You can unsubscribe individually, and deleting your account removes these in both directions.
- A one-way cryptographic hash (SHA-256) of card data, used solely to prevent importing duplicate cards across your devices. The original card content cannot be recovered from this hash.
- If you sign in with Google and grant Drive backup access: an encrypted OAuth refresh token limited to the `drive.file` scope, which only lets the app access files it created itself.The same permission is also used to read those files back when you change devices or reinstall (only files this app created).
- If you sign in with Apple: your card images are stored in your own iCloud (the CloudKit private database). They live in your account, not ours — we cannot read them. When you switch devices, signing in with the same Apple ID reads them back.
- Usage statistics (anonymous, aggregate only): we send event names and counts only, along with plan, language, OS and app version. No user ID, no device ID and no card content are ever included. You can turn this off in Settings at any time (when off, nothing is sent).
- Aggregate usage/analytics events (e.g. feature usage counts) sent to Cloudflare Analytics Engine. These are not linked to individual card content.
About your device contacts
By default the app only writes to your contacts — it does not read them.
Only if you turn on "Two-way sync with device contacts" in Settings do we ask for read access. While it is on, the app (1) merges into a contact you already have when the email address or phone number matches, so the same person is not saved twice, and (2) removes the contact it created when you delete that card in the app.
Nothing we read is sent to our servers — the matching happens entirely on your device. You can turn this off at any time.
About the thank-you message draft (only when you use it)
When you use “Draft a thank-you message” on a card, that card’s name, company and job title — together with any note you choose to add — are sent to an AI provider so the text can be written. This is a separate transfer from the one used to re-read a card.
Only those three fields and your own note are sent. Phone numbers, email addresses, postal addresses and your private memos are not. The draft that comes back is not stored on our servers. The feature draws on the same monthly AI allowance as re-reading.
Nothing happens unless you use the feature. What you get is a draft: the app never sends it for you — you read it, and you decide whether to send it at all.
About widgets and the lock screen
If you place a widget on your home screen or lock screen, it shows the QR code for your own card. It shows only the fields you marked as public, and never anything from your card folder.
On the lock screen, that QR can be scanned without unlocking the phone. That is the point of the feature — handing your card over instantly — but it also means that anyone who can pick up your phone can take your public fields. If you would rather they could not, remove the widget from the lock screen or reduce which fields you publish.
The image the widget displays is stored in a shared area on your device and is never sent to our servers. Deleting your card deletes that image as well.
About the Apple Wallet pass (only if you add one)
“Add to Wallet” builds a pass containing only your published fields and stores it in your Wallet. Building it requires a signature, so those fields pass through our servers — but we do not keep them afterwards.
The pass carries no update endpoint. We therefore never reach your device through it and never learn whether or how it is used. Delete the pass from the Wallet app — the Meishitto app cannot remove it for you.
About Business Chain (only if you turn it on)
Business Chain forwards a question to you when a friend who has your card is looking for someone. It is off by default and only runs once you turn it on.
- What we store: a hash (HMAC-SHA256) computed from the contact details on your own published card (email address / phone number), plus your account identifier. We do not store the email address or phone number itself, and the original value cannot be recovered from the hash.
- We do not read anyone’s card library: we never read a card library to work out who knows you. Matching happens only against the hash you registered for yourself. We do not know who knows people in which industries.
- The question travels through the delivery path: the question your friend typed to their AI assistant (up to 120 characters) arrives on your device as the notification itself. This is the only feature where the content of a notification leaves your device. The question is not stored in our database and expires after seven days. It never contains card content.
- What the other person learns: only if you tap “I can help” does your display name reach them. If you tap “Skip”, or do nothing at all, they learn nothing — they are never shown who was asked, or how many people were.
- How to stop: turn it off in Settings at any time. The registered hash is deleted and no further questions reach you. Turning off cloud sync also turns this off.
3. Information we do not access
We never access or read the following.
- Any file in your Google Drive that this app did not create itself — the `drive.file` scope makes this technically impossible.
- Photos on your device other than the ones the app itself saved there.
4. Third-party services
The following third-party services are currently integrated into the app and on this website (we do not list SDKs that are not yet installed).
- Google Sign-In / Sign in with Apple (authentication)
- Google Drive API (`drive.file` scope), used only if you opt into Drive backup
- Apple iCloud / CloudKit (where card images go if you sign in with Apple — stored in your own iCloud, not readable by us)
- AI providers for text recognition and text generation (Gemini / GPT-family models) — card images and text are sent transiently for the refinement step; if you use the thank-you draft, that card’s name, company and job title are sent as well
- Cloudflare (hosting and infrastructure)
- Cloudflare Web Analytics — on the website only (meishitto.smartrich.ai), never inside the app. It counts page views without cookies and without any identifier tied to you, and it never sees your card data.
- Cloudflare R2 (storage — only for encrypted backups and for recognition samples you chose to send us)
- Firebase Cloud Messaging (FCM) / Apple Push Notification service (APNs) for delivering notifications. Notification text is assembled on your device and does not travel this path — Business Chain is the single exception, where the question itself does
- Apple Wallet (only if you use “Add to Wallet”; the pass is stored in the Wallet on your own device)
5. Deleting your data
Deleting your account from in-app Settings immediately removes your subscription status, usage counters, and duplicate-detection hash from our servers. On-device data is removed when you uninstall the app.
One exception: your encrypted backup is kept for 30 days. If you lose your phone, it is the only way back. Signing in again with the same Google account within those 30 days cancels the scheduled deletion; after 30 days it is deleted automatically and permanently. Everything else — the server-side copy of your card library (used for AI linking), subscription status, published MyCard fields — is deleted immediately.
Any contacts, Drive files, or photos the app wrote on your behalf belong to your own Google/Apple account — manage or delete them directly through Google/Apple, independent of this app.
6. Children’s privacy
Meishitto is a business-card management tool intended for professional use and is not directed at children.
7. Changes to this policy
We may update this policy from time to time. Material changes will be reflected by updating the date shown at the top of this page.
8. Requesting disclosure, correction, or deletion
You may ask us to notify you of the purpose of use of, disclose, correct, add to, delete, suspend the use of, erase, or stop the third-party provision of the personal data we hold about you. Contact us at the address below; we will respond to the extent we can verify that the request comes from you.
Note that the content of the cards you scan is not stored on our servers unless you switched on cloud sync or the AI connection — in which case turning either off, or deleting your account, removes the server copy immediately. (A sample you chose to donate is the other exception; it carries no account or device identifier and therefore cannot be traced back to you.) Beyond that there is nothing for us to disclose or delete. Data on your device can be deleted from within the app.
9. Operator and contact point
Operator: Crealize LLC
Address: 1-4-51-601 Nishiazabu, Minato-ku, Tokyo 106-0031, Japan
Representative: CHEN YI
Privacy enquiries, complaints, and disclosure requests: support@smartrich.ai