On-device processing
Barcodes are decoded in your browser. ID data is never transmitted to our servers.
No customer database
We don't collect, store, or sell the personal data on the IDs you scan. Nothing to leak.
HTTPS everywhere
The app is served over encrypted HTTPS with automatic certificates, required for camera access, too.
Minimal dependencies
We keep third-party services to a minimum and never share ID data with any of them.
What stays on the device
Everything sensitive. The decoded ID details, the scan log, your device ID, and any device name you set live in your browser's local storage on that specific device. We have no access to them. If you clear your browser data, they're gone.
What leaves the device
Only two things, and only if you opt in. If you enable location, the GPS coordinates of a scan are sent to a mapping service to turn them into an address, never any ID data. And if you submit a form on our website (like a contact request), the details you type are sent to us so we can reply. That's it.
Your part
Because you hold the data, you also control it. Any CSV you export is yours to store securely and handle in line with the laws that apply to your business. We recommend restricting who can access exported records and only keeping them as long as you need.
Reporting a vulnerability
Found a security issue? We appreciate responsible disclosure. Email support@trycarded.app with the details and we'll respond promptly.