APP01 Privacy Policy

Business Card Scanner: AI OCR Privacy Policy

This policy separates on-device processing, local training files, and improvement summaries sent externally.

Effective date: 2026-07-18Last updated: 2026-07-18English version

01Operator and scope

The operator brand and developer name are SeSeol AI. This policy applies to com.sea.cardvault and, based on the current Google Play audience, is for users aged 18 or older.

02On-device processing

Business card images, OCR input and results, and the original business card or contact data are not sent to the SeSeol AI improvement-summary server.

Google ML Kit does not send input images or recognized results to Google servers. The SDK may process device and app information, performance, API configuration, input/output sizes, events, and error codes for diagnostics and usage analytics.

03Local training files

OCR rawText and line data, user-corrected name, company, department, title, phone, email, address and notes, plus device manufacturer, model and Android version may remain on the device or in shared Downloads storage.

04Contacts permissions

Read access is used when the user imports contacts, and write access is used when the user saves a card to system contacts. Camera capture and photo selection use only the permissions needed for each feature. Imported contacts are excluded from OCR training samples.

05Improvement summaries

The first attempt occurs at app launch when 24 hours have passed after the first personal feedback and a new summary exists. Later attempts occur at app launch when 24 hours have passed since both the last automatic attempt and the last successful upload and a new summary exists. Card images, names, phone numbers, email, addresses, company, department, title, notes, OCR source text, and imported contact source data are excluded.

06Server processing and retention

Cloudflare, Inc. Workers and D1 are used for receipt, storage, deduplication and security checks. Accepted summaries are retained for up to 180 days, and audit history without original card, contact, or rejected-request content is retained for up to one year. Rejected requests do not retain original business card or contact content; only limited security and error metadata such as the rejection reason, request length, and receipt time is retained for up to 90 days. The server runs automatic deletion daily. The actual storage location and cross-border processing details will be disclosed based on Cloudflare account settings and contract documents.

07Advertising and privacy choices

In the current v1.4.66 release, the first list slot on the standard Home screen shows one native ad whenever the user is not searching or in selection mode, regardless of the number of saved cards. Saved cards begin in the second slot. After that, one native ad appears after every five cards and one at the end of the list. If the last card falls on a multiple of five, no duplicate ad appears at the same position. The first-slot ad also appears when no cards are saved. During search, list native ads are replaced by one anchored adaptive banner at the bottom of the screen. The banner remains when there are no search results and is removed when search closes. No ads appear in selection mode or during app launch or exit, card capture, OCR review or editing, contact import, saving, or sharing.

When an ad request is made, Google may process the advertising ID or other device or app identifiers, IP address, device and app information, diagnostics and performance data, and ad interactions. Depending on region and consent, ads may be personalized, non-personalized, or limited. Where required, users can review or change available choices in the app's privacy and ad settings.

08App data not used for ads

Business card images, OCR input, results and source text, names, phone numbers, email, addresses, company, department, title, notes, imported contact source data, in-app card data, and improvement summaries are not sent to Google Mobile Ads SDK as ad-targeting information.

09Firebase Analytics processing and choices

In the v1.4.64 release build, Google Analytics for Firebase collection is active by default. Automatic collection may include an app-instance ID, Firebase installation ID, approximate location derived from a masked IP address, app lifecycle events such as app launches, screen views and sessions, and app and device metadata. Data is encrypted in transit. Depending on regional consent signals, Analytics storage may be limited, and users may review or change their choices in the app's privacy and ad settings.

GA4 event data and user data are each retained for two months, with reset on new user activity disabled. This setting applies to Explorations and funnel reports, not standard aggregated reports, so it must not be described as deleting all Analytics data after two months.

10Information not recorded in Analytics

Advertising ID collection and ad-personalization signals are disabled in Analytics. No custom events, custom user properties, User-ID, or login account identifiers have been added. Business-card images; OCR input, results or source text; names, phone numbers, email addresses, addresses, company, department, job title and notes; original contact content; search queries; in-app card data; and improvement summaries are not recorded as Analytics event names, values or parameters. These Analytics settings are separate from advertising processing by Google Mobile Ads SDK.

11App error and performance diagnostics

Starting with v1.4.64, published on July 17, 2026, automatic Firebase Crashlytics and Performance Monitoring collection is used only in the production release build to identify and improve app errors and performance. Collection and automatic Performance Monitoring instrumentation are disabled in standard developer and store preview builds. The dedicated verification build uses only fixed test errors and the app01_quality_verification performance event for quality verification.

Crashlytics may process the Crashlytics installation UUID, Firebase installation ID, stack traces for crashes, abnormal terminations and ANRs, related app state, and diagnostic information about the app, operating system, device, memory, disk and process state. Automatically collected Analytics events may be attached as diagnostic breadcrumbs, but business-card content is not added. Crashlytics data is retained for 90 days, after which removal from live and backup systems begins.

Performance Monitoring may process the Firebase installation ID and session ID, country information derived from an IP address, app, device, CPU, memory and network information, and performance information for app startup, screen rendering and HTTP/S requests, including URL, response code, response size and duration. URL query parameters and request or response body contents are excluded. IP-linked events are retained for 30 days, while installation-linked and de-identified performance data are retained for 60 days, after which removal begins.

12Content not recorded in diagnostic or performance data

Business-card images; OCR input, output and source text; names, phone numbers, email addresses, addresses, companies, departments, job titles and notes; original contact data; search terms; in-app business-card data; and improvement-summary content are not recorded in Crashlytics custom logs, keys or user IDs, Performance Monitoring custom traces, metrics or attributes, or HTTP/S URL queries or bodies. No Crashlytics user ID is set, and no developer-defined custom items are added beyond the fixed dedicated-verification tests.

13Cross-border processing of quality diagnostics

Google LLC and relevant service providers may process this information for error diagnosis and performance improvement. Firebase uses Google's global infrastructure, and the app cannot select a specific storage country, so information may be processed outside the user's country. This policy does not state that information is stored or processed only in any particular country. Information is encrypted in transit. Advertising ID collection and ad-personalization signals remain disabled in Firebase Analytics.

14Google Play in-app reviews

In the v1.4.66 production release build, the app may request Google Play's standard in-app review flow after at least three successful new-card saves, at least 24 hours after the first such save, and at least 120 days after the previous request, when another new card is successfully saved. The feature is disabled in standard developer, store preview, and ads-verification builds. Google Play quota rules may prevent the review screen from appearing. The app does not determine or store whether the screen appeared or whether a rating or review was submitted.

Any star rating and optional free-text review that the user chooses to enter are processed by Google Play to leave a Play Store review. The data is encrypted in transit. A submitted review may be public on Google Play, or may be provided privately to the developer on a closed test track. Users can delete their reviews from Google Play Store or their Google Account. The successful new-card save count, first-save time, and last-request time are stored only on the device to determine request timing and are not separately sent to SeSeol AI or Google Play. Business-card images, OCR source text, names, contact details, and in-app card data are not sent as review-request data.

15Deletion and contact

On Android 10 or later, Downloads/SeSeolAICardVault/training may remain after uninstall. See the data deletion instructions. Contact seseol.app@gmail.com.