# CardScoop Privacy Policy
**Effective date:** 10 July 2026
**Last updated:** 10 July 2026
CardScoop is provided by **Digibump** (“Digibump,” “we,” “us,” or “our”). This Privacy Policy explains how information is handled when you use the CardScoop iOS application (the “App”).
CardScoop is designed to be privacy-first and local-first. The App processes the information you enter or import on your device. Digibump does not receive, collect, store, sell, or use that information on its servers because the App does not currently operate a user-account system, analytics service, advertising service, or remote application backend.
## 1. Information Processed on Your Device
To provide its features, CardScoop may process and store the following information locally on your iPhone:
– Card issuer, product, network, nickname, and the last four digits of a card number;
– Credit limit, statement and due dates, annual fee, renewal date, outstanding balance, minimum amount due, reward balance, and annual spending;
– Milestones, fee-waiver progress, lounge benefits, reward or benefit expiry dates, and spending caps;
– Transactions, merchants, amounts, dates, categories, payment channels, refunds, payments, fees, interest, EMI entries, and reward information;
– Credit-card statement information extracted from PDF files that you explicitly select through the system file picker;
– Preferences such as whether the optional Face ID app lock is enabled; and
– Local notification schedules for bill reminders.
This information is used only to provide App features such as card recommendations, bill reminders, utilization insights, statement review, reward estimates, reward comparisons, repayment estimates, and local export.
## 2. Information CardScoop Does Not Request
CardScoop is not designed to request, collect, or store:
– Complete credit-card numbers;
– CVV or security codes;
– Card PINs;
– One-time passwords (OTPs);
– Internet-banking or payment credentials;
– SMS inbox content;
– Credit-bureau reports;
– Contacts, precise location, photos, microphone recordings, or camera data; or
– Face ID biometric templates or facial images.
Face ID authentication is handled by iOS. CardScoop receives only the authentication result and does not receive or access your biometric data.
## 3. PDF Statements and Files
PDF statements are accessed only after you select a file through Apple’s system file picker. Supported statement text is processed on-device. CardScoop does not upload statements to Digibump or to an artificial-intelligence service.
The source PDF is not intentionally copied into CardScoop’s permanent storage. Extracted transaction and statement details may remain in the App’s protected local data store until you delete them.
Password-protected or unsupported PDF files are handled locally and are not uploaded. CardScoop does not retain PDF passwords.
## 4. Data Collection by Digibump
Digibump does **not** collect or receive personal data, financial data, usage data, diagnostics, device identifiers, or statement content from the current version of CardScoop.
The App contains no third-party advertising SDK, behavioural advertising, tracking technology, or third-party analytics SDK. CardScoop does not track you across apps or websites.
If CardScoop’s data practices change in a future version, this Privacy Policy and the App Store privacy disclosures will be updated before the new practices are introduced, and consent will be requested where required.
## 5. Storage and Security
CardScoop stores its working data inside the App’s iOS sandbox. Local records and exports created by the App use iOS file-protection features. The Face ID lock preference is stored using Apple’s Keychain with device-only protection.
The App also hides sensitive financial values when it enters the background. These safeguards reduce risk, but no device or storage method can be guaranteed to be completely secure. You are responsible for maintaining the security of your iPhone, device passcode, backups, and any files you export.
## 6. Notifications and Permissions
CardScoop requests notification permission only if you choose to enable bill reminders. Bill reminders are scheduled locally on your device. CardScoop does not use remote push notifications or collect a push-notification token.
You can revoke notification permission at any time in iOS Settings. You can disable the optional Face ID lock inside CardScoop.
## 7. Sharing and Sale of Data
Digibump does not sell, rent, license, or share CardScoop data with advertisers, data brokers, analytics providers, financial institutions, or other third parties because the data is not transmitted to or collected by Digibump.
If you choose to export or share a JSON file, you select the destination using Apple’s share sheet. Copies sent to another app, person, cloud provider, or service are governed by that recipient’s privacy and security practices.
CardScoop may display links to an issuer’s website. Opening an external link leaves CardScoop, and the external website’s privacy policy and terms will apply. Digibump does not control those websites.
## 8. Retention, Export, Correction, and Deletion
Local CardScoop data remains on your device until you change or delete it.
You can:
– Review and correct card or transaction details within the App;
– Export your locally stored CardScoop data in JSON format;
– Stop future bill reminders by recording a payment or changing notification permission;
– Disable the optional Face ID lock; and
– Use **Delete all my data** in the App to remove cards, transactions, statements, preferences, and CardScoop reminder schedules.
Deleting all data also removes the CardScoop Keychain preference created by the App. Deleting the App removes its sandboxed data, subject to how iOS manages device backups and Keychain items. Copies you previously exported or shared must be deleted from their destination separately.
Because Digibump does not receive or maintain a server-side copy of your App data, Digibump cannot access, recover, correct, or delete that local data on your behalf.
## 9. Children
CardScoop is intended for adults who manage their own credit cards. It is not directed to children or anyone under 18 years of age. Digibump does not knowingly collect personal data from children through the App.
## 10. Financial and Educational Notice
CardScoop is a read-only educational tool. It does not issue credit, process payments, move money, access credit-bureau information, or provide financial, legal, tax, or investment advice.
Reward calculations, repayment estimates, product terms, and other insights may be incomplete or differ from an issuer’s records. Sample card data must be verified directly with the relevant issuer.
## 11. Your Privacy Choices and Rights
All primary privacy controls are available within the App because CardScoop data remains local. Depending on the law where you live, you may also have rights concerning personal data processed by a business.
For questions, complaints, or requests relating to this Privacy Policy, contact Digibump using the details below. If a request concerns information stored only on your device, we will explain how to use the App’s local controls.
## 12. Changes to This Privacy Policy
We may update this Privacy Policy to reflect changes to CardScoop, legal requirements, or privacy practices. The revised policy will show a new “Last updated” date. Material changes will be communicated through the App or our website where appropriate.
## 13. Contact Digibump
**Business name:** Digibump
**Email:** [digibump.in@gmail.com](mailto:digibump.in@gmail.com)
**Website:** [https://digibump.in](https://digibump.in)
For App Store submission, publish this policy on a publicly accessible page on `digibump.in` and use that live page as CardScoop’s Privacy Policy URL in App Store Connect.