片刻 (Pianke) runs entirely on your device and has no internet access. It does not collect, transmit, or upload any of your data — there are no accounts, no servers, and no cloud. — 本 App 完全在你的裝置上運作、沒有網路權限,不收集、不傳輸、不上傳你的任何資料;沒有帳號、沒有伺服器、沒有雲端。
English
Who this is from
片刻 (Pianke) is a business-card scanner and contact organizer. It works fully offline. We (the developer) operate no servers and receive none of your information — so this policy is mostly a description of what stays on your device and what only ever leaves it when you deliberately send it somewhere.
What the app stores (on your device only)
The corrected photo of each scanned card (the original capture is discarded).
The recognized text and parsed fields: name, company, title, phone numbers, email, address, website, and your notes.
Any tags you add and an optional follow-up reminder time you set for a card.
Your own “My Card” details and the optional avatar image you pick for it.
Your settings (default country for phone formatting, theme, whether app lock is on).
All of this lives in the app's private storage on your device. It is never sent to us or any third party. The shipped app declares no internet permission — verified in the app's final merged manifest — so it is technically unable to make a network connection or upload anything.
Scanning: camera, text recognition & QR
Camera — image capture is performed by Google Play Services' on-device document scanner; the image is returned to the app and stored only on your device. The app does not run a camera in the background and does not access your photo library except for an image you explicitly pick (to scan, or to use as your “My Card” avatar).
Text recognition (OCR) — uses Google's ML Kit on-device recognizer, processing the image locally on your phone. The image and text are not sent off the device.
QR / barcode — if a card carries a contact QR code, it is decoded on-device (ZXing, a pure offline library) to help pre-fill the fields. No network is used.
Sharing & exporting (all user-initiated)
Information leaves the app only when you choose to send it out — never automatically:
Export a card as a standard .vcf (vCard) or .csv file through the Android share sheet to a destination app you pick.
Save a card into your phone's Contacts app — the app opens the system Contacts screen pre-filled and you confirm the save (no contacts permission is used).
Export a card's image as a PDF or JPEG to a location you choose.
Display a card (including your “My Card”) as a QR code for someone to scan — your private notes and tags are deliberately excluded.
Once information is handed to another app, or saved to a location you selected, we do not control what happens to it next.
Backup & restore (local, and only when you ask)
You can export a backup of your cards and import it later. A backup is created only when you tap Export, and is handed to a destination you choose (e.g. Files, a messaging app, your own cloud drive). We never receive it.
You can protect a backup with a password: it is encrypted on-device with AES-256-GCM using a key derived from your password (PBKDF2, high iteration count). We cannot read or recover a password-protected backup — keep your password safe.
Automatic system/cloud backup is disabled (allowBackup=false), so your card data is not silently copied to cloud backup without your action.
Follow-up reminders
If you set a follow-up reminder on a card, the app schedules a local notification on your device for that time and re-schedules pending reminders after a reboot. This is entirely on-device; nothing is sent over a network.
App lock
You can optionally require your device biometric (fingerprint/face) or screen lock to open the app. This is handled by Android's system prompt — the app never sees or stores your biometric data. While app lock is on, the app also hides its contents from the app switcher and screenshots.
Permissions the app uses
Permission
Why
POST_NOTIFICATIONS
Show the local follow-up reminder you set. No network.
RECEIVE_BOOT_COMPLETED
Re-arm your pending reminders after the phone restarts (alarms are cleared on reboot).
USE_BIOMETRIC, USE_FINGERPRINT
Optional app lock, via Android's system prompt. The app never receives your biometric data.
INTERNET, ACCESS_NETWORK_STATE
Removed. These were pulled in transitively by a Google library; we explicitly strip them so the shipped app cannot use the network.
Data retention & deletion
Delete an individual scanned card at any time.
Settings → Clear local data deletes your saved scanned cards and their images, plus any plaintext files the app left in its cache. Your separate “My Card” profile is not affected by this.
Uninstalling the app removes all of its data from your device, including your “My Card” and its avatar.
We retain nothing, because we never receive anything.
Analytics, ads, tracking & Data safety
The app contains no analytics, no advertising, and no tracking SDKs, and requests no advertising identifier. Consistent with this, our Google Play Data safety declaration is: no data collected and no data shared. Backups and exports you create are data you move yourself; they are not collected by us.
Children
The app is a general productivity tool and is not directed at children.
Changes & contact
If data practices change, this page and the “Last updated” date will be updated. Questions about this policy: piankecard@gmail.com (片刻 Pianke).