Privacy

Last updated September 2026

The short version: we know what is on your card and how often it was scanned. We do not know who scanned it, and we never will.

What We Collect

Your email address and password, so you can sign in. Passwords are stored hashed by our authentication provider and are never visible to us.

Whatever you put on a card: name, title, company, phone numbers, email addresses, links, a short bio, and a photo address if you provide one.

A record of each scan of a published card. That record holds the time, the browser's user agent string, an approximate location derived from the network the request arrived on (city, region and country, any of which may be missing), and the referring page if there is one. When the code that was scanned carries a label for where it was printed or placed (a printed card, an email signature, a sign), the record holds that label too. The card's owner can see that log.

If you take the day's networking quiz, the day you took it and your score out of five, so the quiz is not offered again that day. It goes with the account when the account is deleted.

Whatever someone chooses to type into the optional "share your info back" form on a card page: their name, an email or phone number, a company, and a note. It goes to that card's owner as a contact, and when the card belongs to a team the form says, before sending, that the team will see it too. Filling it in is entirely optional and needs no account; skipping it changes nothing about saving the card.

An email address you type into one of the "tell me when this is ready" boxes, along with which thing you asked about and which page you asked from. It is used to write to you once about that thing and nothing else, it is never sold or shared, and asking us to delete it is enough. Every email of that kind carries a one-click opt-out link. Using it marks the address as opted out so nothing further is sent, and that mark is kept so the choice is honored.

What We Do Not Collect

We do not know who scanned your card. There is no identity attached to a scan, no cookie set on the scanner's device, and no attempt to match a scan to a person across sites.

The location on a scan is the area the network was in, not an address and not a device location. Nobody is asked for permission because nobody is being located: it is derived from the connection, sometimes with the help of a geolocation service that maps network addresses to areas on our behalf, and it can still be imprecise or absent. The network address itself is not kept in the scan record.

The contact file a scan produces carries one extra line in its note, saying the day it was saved and roughly where, so the person who scanned can find it again later. That line is written into the file handed to their phone and lives only on their device. It is the same approximate area described above, and nothing further about the person scanning is stored by us because of it.

This is why the dashboard can tell you that four people saved you on Tuesday and can never tell you which four. It is a deliberate limit, not a missing feature.

Scans of free test cards are not recorded at all. Testing your own card should not count as a connection.

A photo of somebody else's card taken with no signal is kept on your own phone, in that browser's storage, until you choose to read it. It is not sent to us until then, and discarding it removes it from the phone. Photos that are read are processed and not kept as images. The one exception: when a card you keep in Cards You Captured prints a photo of the person, that small cropped picture is kept privately with the contact so it can go into your phone with them, and it is deleted when you delete the contact or your account. If you share that contact with your team, your teammates can save it with the picture. Scanning a card without keeping it stores nothing, picture included.

What Is Public

Everything on a published card. Anyone with the address or the code can read it, and search engines may index the page.

Nothing in your account is public: not your email, not your scan counts, not your referral figures, not your other cards.

Paying For A Card

Publishing a card is a one time payment, taken by Stripe. Your card number, expiry and security code are typed on Stripe's own checkout page and never reach Herald: we cannot see them, and we do not store them.

What comes back to us is that a payment succeeded, how much it was, and Stripe's own reference for it, which is what lets us find your purchase if you ever write to us about it.

A team's year is the one payment that repeats. It is a yearly subscription held by Stripe, so Stripe keeps the payment method on file to charge the renewal, again without Herald ever seeing the number. What we store for it is Stripe's reference for the subscription, how many seats it bills and when it renews, which is what the team's own Billing section shows an admin.

Nothing is bought inside the iPhone or Android app. Purchases happen on the website.

If We Set Up Your Card For You

If you ask us to set up your card, the request form collects your name, email address and phone number, whether you want a call and when suits you, the details you want on the card, and a photo and logo if you send them. We use it to make your card and to contact you about it, and for nothing else.

Pictures you upload are kept in private storage that no browser can read, until they become your card's photo or logo. The people who see your request are Herald's founders, who do the setup themselves.

Your card is marked as managed by Herald, which lets our founders open and save that card in the builder. Every change we make is recorded. They cannot see your password, and they never sign in as you. You can ask us to stop managing your card at any time.

The request and its uploads are deleted 90 days after your card is delivered, or when you delete your account if that comes first. A request that is never paid for is deleted after a day. The card itself stays until you change or delete it, like any other card.

On Your Own Phone, And Nowhere Else

The Herald app keeps a copy of your published cards on the phone for its offline screen (the iPhone and Android apps and the installed web app), and draws each one as a picture for the home screen widgets. Those pictures are written into the app's own private storage on that device. They are never uploaded, and removing the app removes them.

Which of your cards the widgets show is remembered on that phone alone, deliberately: two people sharing one account each get their own choice, and neither phone tells us or the other one what it picked.

Adding a card to Apple Wallet or Google Wallet hands the pass to that wallet, which then holds your card's link and its design. What Apple or Google do with a pass in their own wallet is covered by their terms, not ours. A pass carries the link rather than a copy of your details, so removing it removes everything. If your card uses your logo, you can choose whether the pass shows the logo or your colors; the choice lives on the card and changes nothing else.

Saving your card as a picture draws it on our servers and hands the file to your phone. We keep no copy of it, and where the picture goes afterwards is between you and your phone.

If you switch on the app lock, the check is done by your phone's own Face ID, Touch ID or fingerprint reader. Herald is told only whether it passed; no face, fingerprint or passcode ever reaches us.

Notifications

If you switch on a notification when somebody saves your card, your device gives us a subscription that lets us push a message to it. We keep that subscription and nothing else about the device, and switching notifications off or removing the app ends it.

The notification never says who scanned you, because we do not know. It names the card and nothing more.

If you are on a team, we email you before its cards switch off: an admin 30 days and 7 days before the team's year ends, and 35 days and 7 days before it renews with the amount it will charge, and a member 7 days before the card the team pays for stops. If a renewal payment fails for good, admins and members are told the same day, a week before the cards switch off. A member of a team that was deleted is told 7 days before the year it paid for runs out. These go to the email address you sign in with, with a push notification as well if you have switched those on. They are notices about your account, so there is nothing to unsubscribe from.

Who Else Sees It

Our hosting and database providers process this data so the service can run. They act on our instructions and do not use it for their own purposes.

If you ask us to set up your card, Herald's founders see what you send for it, as described above.

Some features send what you hand them to an AI provider so it can be read: a look you describe for a card (the description and your company name, never your contact details), a photographed card or list you ask Herald to read, a card link or contact file you bring over, a company lookup for Fill In The Rest, and a question typed into the help chat. Each is sent to answer that one request and nothing else.

We do not sell your data, and we do not share it for advertising.

How Long We Keep It

Card content stays until you change or delete it. Scan records stay while the card exists, because they are what the counts are made of.

Free test cards are deleted one hour after they are made.

Deleting your account removes your drafts, your captured contacts, and your login, and asks what to do with your published cards: take them down with everything else, or leave them serving. A card you choose to leave up is frozen from that moment, holds only what you had already published, belongs to nobody, and its scan records stop being visible to anyone. Backups roll off within thirty days.

Your Choices

You can edit or delete any card at any time, and delete the whole account from the account page.

If you want a copy of what we hold, or you want something corrected, write to hello@heraldcards.com and we will sort it out.

Cookies

One to keep you signed in. One to remember a referral code if you arrived through somebody's link. One to remember which of Herald's own posts or places you came from, when the link you followed was one we published and named (a podcast, an event, a social post); it holds that one word, it is kept with your account if you sign up, and a link we did not publish sets nothing. One to count the free test cards made from this browser, so the free tier has a limit without needing an account. While the site is still private before launch, one more that remembers you got through the password gate.

There are no advertising or tracking cookies, none of them follow you to other sites, and there is nothing to dismiss.

Children

Herald is a tool for working adults and is not directed at children under thirteen. We do not knowingly hold their data, and we will delete it if we learn we have.

Contact

Herald is operated by The Speaking Realm, LLC in Idaho. Privacy questions and requests go to hello@heraldcards.com, and a person reads them.

Questions about anything here go to hello@heraldcards.com.