My Honest Apps — Legal

Privacy Policy: Lumecard

Effective September 1, 2026  ·  Applies to the Lumecard iOS app

The short version

Lumecard has no server and no account system. Your cards, and everything about how you use them, stay on your device. Nothing is collected by us, because there's nothing here to collect it with. The sections below explain exactly what exists, where it lives, and the few cases where something leaves your device only because you chose to send it.

01Who this applies to

This policy covers the Lumecard iOS app, built and published by Bob Joziasse under the My Honest Apps name. Lumecard is a card-storage app: it stores loyalty, gift, membership, and similar cards on your device so you can display them at checkout.

Lumecard has no company behind it, no data-processing team, and no server infrastructure of any kind. Where this policy says "we," it means one developer, not an organization with departments or vendors handling your information.

02What data exists, and where it lives

Everything below is stored locally, on your device, using Apple's standard on-device storage. None of it is transmitted anywhere by default.

DataWhat it isWhere it lives
Card data Card name, category, barcode/QR/NFC payload, colors, subtitle On-device only, unless you turn on iCloud Backup (§3)
Custom fields Expiry dates, balances, membership numbers, PINs, notes you add to a card On-device only, unless you turn on iCloud Backup (§3)
Location data Where a card is typically used, only if you enable Location Reminders On-device only. Never included in iCloud Backup, even if that's turned on.
Usage patterns When you open which cards, used to suggest a Primary card On-device only. Never included in iCloud Backup, even if that's turned on.
Diagnostic log Technical event types and error messages, never card content — see the in-app Diagnostics screen for the full, current contents On-device only, unless you choose to attach it to a support email (§3)

Ask Your Wallet, Lumecard's natural-language search feature, and Smart Add, its card-recognition feature, both run on Apple's on-device AI (Apple's Foundation Models framework). Neither sends anything, including your questions, your cards, or any photo you take, off your device — not to us, and not to Apple.

03The only ways anything ever leaves your device

There are exactly four, and every one of them requires you to take a specific, deliberate action first. None happen automatically or by default.

iCloud Backup

Off by default. If you turn it on, your card data (not location data, not usage patterns, not the diagnostic log) is mirrored to your own private iCloud account, using Apple's CloudKit framework. This goes directly from your device to your iCloud, using Apple's own encryption and infrastructure. We have no server in this path and cannot see this data. It's governed by Apple's own privacy policy, not ours.

Local Encrypted Backup

An export you trigger yourself, encrypted with a password only you know, saved to a file you choose where to put (Files, AirDrop, your own storage). We never see this file or its contents. Losing the password means the backup can't be recovered — we hold no copy of it.

Report a Problem

If you use this feature, it opens your own Mail app with a message addressed to us, optionally including the diagnostic log described in §2. Nothing sends until you personally tap Send in your own Mail app. If you don't use this feature, nothing about a problem you encounter is ever reported to us automatically.

App Store purchases

Lumecard offers optional in-app tips, processed entirely through Apple's App Store using StoreKit. Apple handles the transaction and your payment details directly — we never receive or see your payment information. Apple may provide us with basic, aggregated sales figures (how many of each tip tier sold), never information tied to who purchased them.

04Third parties

None. Lumecard includes no analytics SDK, no crash-reporting SDK, no advertising SDK, and no third-party tracking of any kind. Crash reports, if any occur, are handled entirely through Apple's own built-in App Store Connect and Xcode Organizer tools — the same system-level crash reporting every iOS app can opt into, not something Lumecard adds.

05Children's privacy

Lumecard does not knowingly collect information from anyone, of any age, because it does not collect information at all — everything described in §2 stays on the device it's created on. Lumecard is rated 4+ and contains no content unsuitable for any age.

06Your choices and control

Because Lumecard has no account system and no server, there's no "request my data" or "delete my account" process to describe here in the way a typical privacy policy would — the data was never anywhere but your own device to begin with.

07Changes to this policy

If this policy changes, the effective date at the top of this page will change with it. Meaningful changes (anything that would actually alter what's described in §2 or §3) will also be reflected in the app's own Promise screen, not just here.

08Contact

Questions about this policy, or about Lumecard specifically: lumecard@myhonestapps.com