名刺っと

Privacy Policy

2026-08-10

Meishitto is built around the principle that your business card data belongs to you. This page describes, factually and precisely, what information the app actually collects and stores — and what it does not.

1. By default, we do not store scanned card content on our servers

Scanned card images, extracted text, and contact fields are stored on your own device. When you use the optional AI refinement step (the third tier of our OCR pipeline), the image and text are sent to our backend transiently for processing and are not retained after the result is returned to your device.

That transfer happens only after the app has named the recipient (a third-party AI model provider) and the purpose, and you have tapped "Agree and use AI". If you decline, the image never leaves your device, and on-device scanning, saving and exporting remain free and unlimited. You can withdraw the consent at any time in Settings.

The one exception is your own digital card (My Card): only the fields you explicitly mark as public, and only while card-update notifications are switched on. Those public fields are stored so that people who scanned your QR code and subscribed can fetch your latest details. Anyone who has not subscribed cannot fetch them. Turning notifications off, or deleting your account, removes them from our servers.

The other exception is "cloud sync", and the "AI connection" that runs on top of it. Only if you switch one of them on in Settings and agree after reading the notice, a copy of your card library (card text) is stored on our servers (switching on the AI connection switches on cloud sync too). Its sole purpose is to let the AI assistant you chose (such as Claude) read that copy through a dedicated URL. The AI cannot write to the copy or to your cards directly — corrections, tags and deletions arrive in the app as proposals, and you decide whether to apply them (unless you switch on automatic application in Settings). Nobody without that URL can access it, and we never use this copy for AI training, advertising or analytics. Tapping "Disconnect", turning cloud sync off, or deleting your account, deletes the server copy immediately. Both switches are off by default — unless you turn one of them on, your card library is never stored on our servers.

A published My Card also gets a stable share link (of the form meishitto.smartrich.ai/c/…). If you set a logo image, that logo is served publicly from the same link (this is the logo you chose yourself, never a photo of a scanned card). Anyone who has that link can view the public fields without signing in — the link contains a 10-character random string that cannot be guessed, but we cannot stop a recipient from forwarding it. Withdrawing the card invalidates the link immediately. Fields you kept private never appear on that page.

2. Information stored on our servers

Our backend (Cloudflare Workers + D1 database) stores only the following minimal data.

About your device contacts

By default the app only writes to your contacts — it does not read them.

Only if you turn on "Two-way sync with device contacts" in Settings do we ask for read access. While it is on, the app (1) merges into a contact you already have when the email address or phone number matches, so the same person is not saved twice, and (2) removes the contact it created when you delete that card in the app.

Nothing we read is sent to our servers — the matching happens entirely on your device. You can turn this off at any time.

About the thank-you message draft (only when you use it)

When you use “Draft a thank-you message” on a card, that card’s name, company and job title — together with any note you choose to add — are sent to an AI provider so the text can be written. This is a separate transfer from the one used to re-read a card.

Only those three fields and your own note are sent. Phone numbers, email addresses, postal addresses and your private memos are not. The draft that comes back is not stored on our servers. The feature draws on the same monthly AI allowance as re-reading.

Nothing happens unless you use the feature. What you get is a draft: the app never sends it for you — you read it, and you decide whether to send it at all.

About widgets and the lock screen

If you place a widget on your home screen or lock screen, it shows the QR code for your own card. It shows only the fields you marked as public, and never anything from your card folder.

On the lock screen, that QR can be scanned without unlocking the phone. That is the point of the feature — handing your card over instantly — but it also means that anyone who can pick up your phone can take your public fields. If you would rather they could not, remove the widget from the lock screen or reduce which fields you publish.

The image the widget displays is stored in a shared area on your device and is never sent to our servers. Deleting your card deletes that image as well.

About the Apple Wallet pass (only if you add one)

“Add to Wallet” builds a pass containing only your published fields and stores it in your Wallet. Building it requires a signature, so those fields pass through our servers — but we do not keep them afterwards.

The pass carries no update endpoint. We therefore never reach your device through it and never learn whether or how it is used. Delete the pass from the Wallet app — the Meishitto app cannot remove it for you.

About Business Chain (only if you turn it on)

Business Chain forwards a question to you when a friend who has your card is looking for someone. It is off by default and only runs once you turn it on.

3. Information we do not access

We never access or read the following.

4. Third-party services

The following third-party services are currently integrated into the app and on this website (we do not list SDKs that are not yet installed).

5. Deleting your data

Deleting your account from in-app Settings immediately removes your subscription status, usage counters, and duplicate-detection hash from our servers. On-device data is removed when you uninstall the app.

One exception: your encrypted backup is kept for 30 days. If you lose your phone, it is the only way back. Signing in again with the same Google account within those 30 days cancels the scheduled deletion; after 30 days it is deleted automatically and permanently. Everything else — the server-side copy of your card library (used for AI linking), subscription status, published MyCard fields — is deleted immediately.

Any contacts, Drive files, or photos the app wrote on your behalf belong to your own Google/Apple account — manage or delete them directly through Google/Apple, independent of this app.

6. Children’s privacy

Meishitto is a business-card management tool intended for professional use and is not directed at children.

7. Changes to this policy

We may update this policy from time to time. Material changes will be reflected by updating the date shown at the top of this page.

8. Requesting disclosure, correction, or deletion

You may ask us to notify you of the purpose of use of, disclose, correct, add to, delete, suspend the use of, erase, or stop the third-party provision of the personal data we hold about you. Contact us at the address below; we will respond to the extent we can verify that the request comes from you.

Note that the content of the cards you scan is not stored on our servers unless you switched on cloud sync or the AI connection — in which case turning either off, or deleting your account, removes the server copy immediately. (A sample you chose to donate is the other exception; it carries no account or device identifier and therefore cannot be traced back to you.) Beyond that there is nothing for us to disclose or delete. Data on your device can be deleted from within the app.

9. Operator and contact point

Operator: Crealize LLC

Address: 1-4-51-601 Nishiazabu, Minato-ku, Tokyo 106-0031, Japan

Representative: CHEN YI

Privacy enquiries, complaints, and disclosure requests: support@smartrich.ai