Privacy Policy

Last updated 2 August 2026.

[[LEGAL ENTITY NAME]] (“we”) operates Business Card Scanner, a tool that reads a photograph of a business card and turns it into a contact record. This policy explains what personal data passes through the service, why, how long it is kept, and how to have it deleted.

Two different people are described here

Almost every privacy policy addresses only its users. This service is unusual, and honest about it: most of the personal data it holds does not belong to the people who signed up.

  • The user — someone who created a workspace and signs in. They agreed to these terms.
  • The scanned contact — the person whose business card was photographed. They never agreed to anything, and in most cases will not know this service exists. The section If your card was scanned below is for them, and their rights do not depend on having an account.

What we collect

From users

  • Name, email address, and a hashed password. Passwords are stored only as bcrypt hashes and are never readable by us.
  • Workspace name, address slug, and timezone.
  • If Google sign-in is used, the Google account id and email — never the Google password.
  • Usage records: how many scans were run and when, used to apply the workspace’s scan allowance.
  • If Google Sheets export is configured, the service-account credentials supplied. These are encrypted at rest with AES-256-GCM and are never returned to the browser.

From scanned business cards

  • The photograph of the card, front and back.
  • Everything printed on it: name, company, job title, phone numbers, email address, postal address, website, social handles, GST number.
  • Notes the user adds, including voice notes, which are converted to text and then discarded as audio.
  • The event or context at which the card was collected, if the user records it.

Why we collect it

  • To provide the service: reading a card and storing the resulting contact is the entire product.
  • To count scans against the workspace’s allowance.
  • To export contacts to a Google Sheet the user controls, when they configure it.
  • To prepare follow-up messages the user chooses to send from their own phone.

We do not sell personal data, share it between workspaces, use it to build a contact graph or directory, or use card contents to train machine-learning models of our own.

Who else sees it

  • OpenAI processes the card image to extract text, and voice-note audio to transcribe it. Data sent through the API is not used to train their models by default.
  • Google Sheets receives contact rows only if a user configures an export, and only into a spreadsheet that user owns.
  • Our hosting and database providers, who store the data on our behalf.

Data is stored in India. Each workspace lives in its own separate database.

How long it is kept

  • Contacts and images are kept until deleted by the workspace that scanned them.
  • Deleting a workspace erases its data permanently within 30 days, including backups.
  • A workspace inactive for 12 months is erased after notice to its registered email.
  • Voice recordings are transcribed and discarded immediately; only the resulting text is stored.
  • Usage records — scan counts and timestamps, no card contents — are retained for accounting purposes.

If your card was scanned

Someone you met may have photographed your business card and stored it here. You do not need an account, and you do not need to know which company did it.

Email [[GRIEVANCE OFFICER EMAIL]] from the address printed on the card, or tell us the phone number printed on it. We will search every workspace for records matching those details and, at your choice:

  • tell you what is held and which organisation holds it;
  • correct anything wrong;
  • delete it entirely, including the card image.

We will respond within 30 working days. We will not charge you, and we will not require you to create an account to ask. If we cannot verify that the card is yours, we will say so rather than act on a request that might not be from you.

Rights of users

Users may access, correct, export, or delete their workspace data at any time from Settings, or by writing to support@yanisa.in. Contacts can be exported to Excel at any point, so leaving does not mean losing the data.

Security

  • Each workspace is stored in a physically separate database; a request carrying one workspace's session cannot address another's records.
  • Passwords are bcrypt-hashed. Sessions are signed tokens in HTTP-only cookies.
  • Third-party credentials are encrypted at rest with AES-256-GCM.
  • Card contents are never written to application logs.

Grievance Officer

Under the Digital Personal Data Protection Act, 2023, you may contact our Grievance Officer:
[[GRIEVANCE OFFICER NAME]]
[[GRIEVANCE OFFICER EMAIL]]
[[LEGAL ENTITY NAME]], [[REGISTERED ADDRESS]]

Changes

If this policy changes materially we will email registered users before the change takes effect. The date at the top always reflects the current version.

Privacy Policy