Security
You Can Take A Card Back
A business card is the one thing you hand out with no way to recall it. That is the problem this page is about, and most of the answer is that your code points at a card you still control rather than carrying a frozen copy of your details.
What You Control
Any Card Can Be Switched Off
Revoke a card and its code stops resolving immediately, everywhere. That includes anything already printed, any tap card carrying it, and any email signature it sits in.
Somebody scanning a revoked card is told it was revoked rather than shown an error, so they know to ask for a current one instead of assuming your card is broken.
A Revoked Code Is Never Handed To Somebody Else
When a person leaves, their card goes off and stays off. The code is permanent and already out in the world, so reissuing it would mean everyone who ever scanned that card starts saving a different person.
Restoring a card brings back the same code, which is what makes an accidental revoke recoverable without breaking anything printed.
Two Factor Authentication
Turn on a six digit code from any authenticator app and a stolen password stops being enough on its own. Set it up from your account page.
Lock The App Behind Your Face Or Fingerprint
The Herald app can ask for Face ID, Touch ID, or your fingerprint every time it opens, with your phone's passcode as the fallback. Switch it on from the app's Account screen; it is off until you do.
The lock protects the app on that phone and nothing else. Scans of your card are never affected, because the person scanning you never needed your phone in the first place.
Sign Out Everywhere
Ends every session on every device in one action, including the one you are using. Worth doing after a password change, or when a laptop goes missing.
Your Cards Are Isolated At The Database
Access rules live in the database itself rather than only in application code, so a card, a scan record, or a follow-up note can only ever be read by the account that owns it.
What We Deliberately Cannot Do
We Do Not Know Who Scanned You
There is no identity attached to a scan, no cookie set on the scanner's phone, and no attempt to recognize the same person across cards or across sites.
Your log can tell you four people saved you on Tuesday. It can never tell you which four. That is a limit we chose, and we are not planning to remove it.
Location Is An Area, Not A Person
The place on a scan is worked out from the network the request came in on. It is a city at best, it is frequently wrong, and it is often missing entirely.
Nobody is prompted for location permission because nobody is being located.
A Tap Card Holds A Link, Not Your Details
Cards that write your contact into the chip are frozen the day they are made and cannot be recalled. Ours points at your card, so it stays current and can be switched off.
Deleting Means Deleting, And You Choose How Far
Removing your account removes your drafts, your captured contacts, your scan history and your login. It asks what to do with cards you already published: take them down, and their codes stop working immediately, or leave them serving, frozen at what they held that day and belonging to nobody, with their scan records visible to no one.
Contacts other people already saved stay on their phones either way, because those are copies on devices we cannot reach.
We Edit A Card Only When You Ask Us To
Herald can open and save a card only when its owner asked us to set it up for them, and only that card, never the rest of their account. Every change we make is logged, and we never know your password or sign in as you.
We Never See Your Card Number
Payments are taken by Stripe on Stripe's own checkout page. Your card number, expiry and security code are never typed into Herald and are never stored by us. What comes back is that a payment succeeded and how much it was.
What Is On Your Phone Stays On Your Phone
The app keeps your published cards on the device for its offline screen (the iPhone and Android apps and the installed web app), and draws each one as a picture for the home screen widgets. Those pictures live in the app's own private storage and are never uploaded.
Which card the widgets show is remembered on that phone alone. Two people sharing one account each get their own choice, and neither phone tells us or the other one what it picked.
A wallet pass carries your card's link rather than a copy of your details, which is what lets its code open your latest details and stop working the moment you revoke the card.
Anything Herald fetches on your behalf, your photo and your logo, is resolved and checked before the connection opens, so a card can never be used to make our servers reach somewhere private.
Found A Problem
Write to hello@heraldcards.com with what you found and how to reproduce it. We answer within one business day, we will not threaten you for reporting it in good faith, and we will tell you when it is fixed.