Privacy Policy
Last updated 8 October 2026
This policy explains what My Card Wallet: Secure Notes (“My Card Wallet”) collects, what it deliberately cannot collect, and what you can ask us to do about it. My Card Wallet is built so that the things you care about most, the contents of your capsules and your saved cards, are encrypted before they leave your device, and are unreadable to us by design rather than by promise.
1.Who we are
My Card Wallet: Secure Notes is operated by Highglossy FZE, a company registered in the United Arab Emirates, with its registered office at Al Shmookh Business Center, One UAQ, UAQ Free Trade Zone, Umm Al Quwain, U.A.E. (“we”, “us”). For the purposes of the UK and EU General Data Protection Regulation, we are the data controller for the personal data described here.
Questions, requests and complaints: privacy@highglossy.com.
2.The short version
- We cannot read your capsules. Their contents are encrypted on your device with a key we never receive. What we store is ciphertext and a pointer to it.
- We cannot read your saved cards. Card details are encrypted on your device and stay there. They are never uploaded to us at all.
- We do not ask for your name, email or phone number. An account is created from a cryptographic key generated on your device.
- We do not sell personal data, and we do not use it for advertising or profiling.
- We do see some things: your subscription status, the fact that a capsule exists and how large it is, and crash reports.
3.What stays on your device
- Capsule contents. Files, messages and attachments are encrypted on your device before upload. The decryption key is sealed under material we do not hold: the invite secret and, where you set them, your security answers.
- Your security questions and answers. The answers are never transmitted in any form. The questions themselves are stored encrypted under a key derived from the invite secret.
- The invite secret. When you share a capsule, the secret travels in the fragment of the link (the part after #), which browsers never send to a server. We store only a hash of it, which lets us check a secret is valid without knowing it.
- Your saved cards, photos and notes. The card wallet is encrypted on your device and written to local storage as ciphertext, with the key held in the device Keychain or Keystore. There is no card sync and no card upload.
- Card scans and price scans. Scanning a card or a price tag runs entirely on your device using the operating system's on-device text recognition. No image and no recognised text is sent anywhere.
- Your private key. The key that proves your account is yours is generated in, and never leaves, the device's secure hardware-backed store.
4.What we collect, and why
Every category we hold, why we hold it, the lawful basis and how long we keep it:
- Account identifier: a random account ID and the public half of your device key — To identify your account without knowing who you are. Basis: Contract (Art. 6(1)(b) GDPR). Kept: until you delete the account.
- Session records: a hash of your session token and its expiry — To keep you signed in and let you revoke a device. Basis: Contract (Art. 6(1)(b) GDPR). Kept: until expiry or sign-out.
- Capsule metadata: capsule ID, status, size in bytes, unlock time, timestamps — To store and deliver the capsule and enforce your storage quota. Basis: Contract (Art. 6(1)(b) GDPR). Kept: until you delete the capsule.
- Encrypted capsule payload: the ciphertext itself — To hold the capsule until its recipient opens it. Basis: Contract (Art. 6(1)(b) GDPR). Kept: until deleted or reclaimed (see below).
- Access records: that an invite was opened, by which request, whether decryption succeeded, plus a recipient public key — To run the release rules you chose and to tell you someone tried to open your capsule. Basis: Legitimate interests (Art. 6(1)(f) GDPR). Kept: 24 months.
- Audit events: the security history of a capsule — Fraud prevention, abuse investigation, and your own record of who did what. Basis: Legitimate interests (Art. 6(1)(f) GDPR). Kept: 24 months.
- Push tokens: a notification token and whether the device is iOS or Android — To alert you when someone attempts to open a capsule. Basis: Consent (Art. 6(1)(a) GDPR). Kept: until the token is revoked or goes stale.
- Subscription records: plan, status, expiry, store product ID, the store transaction identifier and the Adapty profile ID — To give you the storage you paid for and to restore it on a new device. Basis: Contract (Art. 6(1)(b) GDPR). Kept: life of the account, then 7 years where tax law requires.
- Notification history: the alerts we have sent you — So the list is complete even when a push fails to arrive. Basis: Contract (Art. 6(1)(b) GDPR). Kept: 12 months.
- Crash and error reports: stack traces, device model, OS version, app version — To find and fix the defects that would otherwise lose your data. Basis: Legitimate interests (Art. 6(1)(f) GDPR). Kept: 90 days.
Crash reports carry no IP address and no user identifier: a crash tells us what broke and on what kind of device, but not who or where you are. We do not collect an advertising identifier, we do not track you across other apps or websites, and we run no advertising SDK.
5.Who we share it with
We use a small number of processors. Each is bound by a data processing agreement and may use the data only to provide the service to us.
- Adapty — subscription management. Receives a random account identifier and purchase events so your plan can be applied and restored. Does not receive capsule data.
- Apple and Google — payment processing for in-app purchases. They take the payment; we never see your card number or billing address. Your relationship for the payment itself is with the store, under its own privacy policy.
- Google Firebase Cloud Messaging — delivery of push notifications. Receives the notification token and the notification text, which never contains capsule contents.
- Crash reporting (Sentry, hosted in the European Union) — receives stack traces, device model, OS and app version. Crash reports carry no IP address and no user identifier.
- Microsoft App Center / CodePush — over-the-air delivery of app updates. Receives app version and device platform in order to decide whether an update applies.
- Our hosting provider — runs the servers and object storage holding the encrypted payloads.
We also disclose data where we are legally compelled to: to comply with a legal obligation, to protect our rights or property, to investigate possible wrongdoing in connection with the app, or to protect the safety of users or the public.
Because of how My Card Wallet is built, what we are able to hand over under a legal demand is limited to the metadata listed above: we cannot produce the contents of a capsule, because we cannot decrypt one.
We do not sell personal data, and we do not share it for cross-context behavioural advertising.
6.How long we keep things
The section above gives the retention period for each category. Two cases deserve spelling out because they are specific to how My Card Wallet works. When a subscription lapses, your storage becomes read-only and a download-only window opens; you can still download everything during it. When it closes, capsules that were never armed for release may be deleted to reclaim the storage. Capsules that were already armed are not touched: a lapsed subscription must never be the reason a capsule fails to deliver. When you delete your account, we delete your account record and everything that references it, including capsules, encrypted payloads, access records and push tokens. Backups are purged on a rolling 30-day cycle. We retain subscription records where tax or accounting law obliges us to.
7.Where your data is processed
Our servers and object storage are located in the United Arab Emirates, while some processors listed above operate outside your country. Where personal data leaves the UK or the EEA, the transfer relies on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum or an adequacy decision, as applicable.
8.Your rights
Wherever you live, you can ask us to:
- Give you a copy of the personal data we hold about you, in a portable format.
- Correct anything inaccurate.
- Delete your data. You can do this yourself in the app; we will also do it on request.
- Restrict or object to processing we carry out on the basis of legitimate interests.
- Withdraw consent, for example for notifications by turning them off in your device settings, without affecting what we did before you withdrew it.
Write to privacy@highglossy.com. We respond within 30 days.
One honest limitation: because we identify accounts by a key on your device and hold no name or email, the only way we can authenticate a rights request is through the app itself. If you have lost the device and its key, we have no way to confirm an account is yours, and we will not act on the request. This is the direct cost of not knowing who you are, and we think it is the right trade.
If you are in the UK or the EEA, you may also complain to your data protection authority: in the UK the Information Commissioner's Office, in the EEA the supervisory authority where you live.
9.California residents
Under the CCPA as amended by the CPRA, in the last 12 months we collected the categories described above for the business purposes stated there, from you and from your device. We have not sold personal information and we have not shared it for cross-context behavioural advertising. We have no actual knowledge of selling the personal information of consumers under 16.
You have the right to know, delete, correct, and to be free from discrimination for exercising those rights. Exercise them at privacy@highglossy.com.
10.Children
My Card Wallet: Secure Notes is not directed to children and is not intended for anyone under 16. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with data, write to privacy@highglossy.com and we will delete it.
11.Security
Capsule contents are encrypted on your device using authenticated encryption, with keys derived through a memory-hard key derivation function where security answers are involved. Your account key lives in the device's hardware-backed Keychain or Keystore and is gated behind your biometric or device passcode. Data in transit is protected with TLS.
No system is perfectly secure, and we will not claim otherwise. What we can say precisely is that a breach of our servers would expose the metadata listed above; it would not expose the contents of any capsule, because the keys required are not there to be taken.
12.Changes
We will update this policy when what we do changes. The date at the top always reflects the current version. If a change materially reduces your rights or widens what we collect, we will tell you in the app before it takes effect.
13.Contact
Highglossy FZE, Al Shmookh Business Center, One UAQ, UAQ Free Trade Zone, Umm Al Quwain, U.A.E.
Support: support@highglossy.com · Privacy: privacy@highglossy.com