Privacy Policy
Who this covers
This policy applies to the Blinc mobile app for iOS and Android (the “App”). It explains what the App does and does not do with your information.
Information stored on your device
The cards you add — including the store or brand name, the card number, its barcode value and format, and which cards you mark as favourites — are saved only in the App’s private storage on your device (a local database). This information:
- never leaves your device automatically;
- is not sent to us or to any third party;
- is removed when you delete a card or uninstall the App.
You can also attach up to two photos to a card — typically its front and back, so you can keep the plastic out of your pocket. Those pictures are copied into the App’s own private storage on your device and are treated exactly like the rest of the list above: they are never uploaded, never sent to us or anyone else, and they are deleted when you delete the card or uninstall the App. Because they stay on the device, they are not included in a backup file — a backup restores your cards, not your pictures.
There is no account, no login, and no server-side copy of your wallet. The App works fully offline, and opening a card never makes a network request.
Usage statistics
To understand which parts of the App are actually used — and which store brands to support next — the App sends anonymous usage events to PostHog, an analytics provider that processes the data on our behalf on servers in the United States. This is on by default and you can switch it off at any time in Settings → Privacy → Share usage data.
When it is on, an event is sent when you:
- add a card (and whether you scanned it or typed it);
- open a card’s barcode screen (and whether you came from the home-screen widget or from inside the App);
- look at a card on that screen, including each one you swipe or page to;
- swipe or tap between cards, open a card’s photos, or turn on the high-contrast “trouble scanning?” view;
- edit, favourite, delete, or reorder a card;
- attach or remove a photo on a card (only that you did, and to which of the two slots — never the picture itself, where it came from, or anything about it);
- scan a barcode out of a screenshot (whether one was found, not the image);
- decline the camera or photo-library permission;
- change a setting (which setting, and its new value);
- send your cards to a paired watch;
- export or import a backup (for an import, only how many cards were added or skipped — never what they were);
- send feedback (that you did, and the category you picked — the message itself is covered in the next section);
- move between the App’s screens — the name of the screen only, such as
/settings, never the card it is showing; - tap a button — the button’s fixed name, such as
save_edit, and nothing you typed; - hit an action that fails (for example a card that would not save), so we can find out how often it happens;
- install, update, open, or leave the App.
The card events above carry the store or brand name shown on the card
(for example Costco), because knowing which brands people keep is how we
decide which ones to support properly. That name is whatever you typed when you
added the card — so if you rename a card to something personal, that text is
included. If you would rather it weren’t, keep card names to the store name, or turn
usage statistics off.
The App also reports its own crashes and errors to PostHog when usage statistics are on: the error’s type and message, and the list of code locations it passed through. These come from the App’s own code, so they describe what the App was doing — never your card numbers, card names, notes, or photos. Messages your device or the App writes to its debug log are not collected.
Alongside each event, the analytics software automatically includes basic technical information: a random identifier generated on your device (not linked to you, your phone’s advertising ID, or any account), the App version, your device model and manufacturer, operating system and version, screen size, language and time-zone settings, and the time of the event.
Feedback you send us
The App has a feedback form — the speech-bubble button on the home screen, or Settings → Help → Send feedback. Nothing is sent unless you write a message and tap Send, and it is not connected to the usage statistics above: turning those off does not stop you sending feedback, and sending feedback does not turn them on.
When you send a message, we receive:
- the category you chose (something’s broken, feature idea, feedback, question, or something else);
- whatever you type in the message box. That is free text and it reaches us exactly as written — please don’t paste card numbers or anything you would rather we did not hold;
- your email address, only if you fill that field in. It is optional and exists solely so we can reply. Leave it blank and we have no way to contact you;
- the App version and build you are running, your device model, its operating system and version, and your language setting — so we can reproduce what you describe.
Messages are delivered into Linear, the issue tracker we use to plan work, which processes them on our behalf. We keep a message for as long as we need it to act on what it says. No card numbers, no barcodes, no screenshots, and no analytics identifier are attached — a feedback message cannot be joined up with your usage statistics, because nothing in it identifies the device that sent it.
What is never collected
Regardless of the settings above — and whether or not you ever use the feedback form — the App never sends:
- Card numbers or barcode values. The thing that actually makes a loyalty card work never leaves your device, in any form.
- Camera images or photos. Nothing the camera sees is transmitted, and neither are the photos you attach to a card: those are saved on your device and stay there.
- Your identity. No name, phone number, contacts, or account — the App has none of these to send. The only way we ever learn an email address is if you type one into the feedback form yourself, which is optional.
- Your location. No GPS, and we have switched off the analytics provider’s IP-based location lookup, so no city, region, or country is derived from your connection.
- Advertising identifiers. There is no advertising, no ad network, and no cross-app or cross-site tracking. Your data is never used for advertising and never sold or shared with data brokers.
- Screen recordings or on-screen text. Session replay and “autocapture” are both disabled, specifically so a barcode on screen can never be recorded.
Turning usage statistics off
Open Settings → Privacy and switch off Share usage data. Nothing further is sent from that moment on — including the automatic app-open and app-update events. The choice is stored on your device and survives restarts and updates.
Because the events are anonymous and carry no identifier we can trace back to a person, we cannot look up or delete “your” past events on request — there is no way for us to tell which ones were yours. Uninstalling the App stops all collection.
If you are in the EEA or the UK
Metis AI Research Inc. is the controller for the usage statistics described above; PostHog acts as our processor. We rely on our legitimate interest in understanding how the App is used to improve it, and we keep the data to the minimum described here. You can object at any time simply by switching the setting off.
We are also the controller for anything you send through the feedback form, with Linear as our processor. There we rely on our legitimate interest in answering and acting on the messages people choose to send us; you can avoid it entirely by not using the form. If you gave an email address and want the message deleted, write to us at the address below and we can find it — unlike the usage statistics, a message you signed with an email is something we can look up. If you have questions, or wish to raise a concern, contact us at the address below.
Camera
The App uses your device camera for two purposes, both of which you start yourself: to scan a card’s barcode when you add a card, and — if you ask it to — to take a photo of a card to keep with it. A scanned camera image is processed on your device in real time to read the barcode and is never saved. A photo you deliberately take is saved to the App’s private storage on your device, and nothing the camera sees is transmitted anywhere in either case. You can also add a card by typing its number instead, and the App works fully without camera access.
Home-screen widget
If you add the Blinc widget, it displays the cards you have marked as favourites so you can open them quickly. This happens entirely on your device using the data already stored locally; nothing is sent anywhere.
Backups you create
The App lets you export a backup file of your cards. This file is created at your request and handed to whatever destination you choose (for example, saving it to your files or sharing it to another app). We do not receive, store, or have any access to your backup files. A backup contains your cards but not any photos you have attached to them — those stay on the device that took them. Anyone you share a backup with can read the cards inside it, so keep backups somewhere you trust. Importing a backup reads a file you select and adds those cards back to your device.
Sharing and selling of data
We do not sell your information, and we do not share it with data brokers, advertisers, or anyone else for their own purposes. Two third parties receive anything at all, both strictly on our instructions: PostHog, which processes the anonymous usage events described above, and Linear, which receives the feedback messages people choose to send. We may also disclose information if we are legally required to, though in practice the only thing we hold that could identify you is an email address you gave us yourself.
Children’s privacy
The App is not directed to children and we do not knowingly collect personal information from anyone, including children under 13. The usage statistics described above are anonymous and are not used to build a profile of any individual.
Your control over your data
You are always in control. Delete an individual card to remove it, or uninstall the App to remove all of its data from your device. Because there is no server copy of your cards, removing them from your device removes them completely. Usage statistics can be switched off in Settings at any time, as described above.
Changes to this policy
If the App changes in a way that affects this policy, we will update this page and revise the “Last updated” date above.
Contact
Questions about this policy or the App? Email metis.ai.research@gmail.com.