Privacy Policy
Last updated 12 August 2026
The short version. The business cards you collect are encrypted on your iPhone with a key only you hold. They are not sent to Carte, and we cannot read them. If you connect a calendar, its events are read on your device and are not sent to us either. We hold an email address so you can sign in, and nothing else.
Who we are
Carte is produced by Appé Latte, in Alberta, Canada. Appé Latte is the data controller for the information described below.
If you have a question about this policy or about your data, write to hello@appe-latte.ca or call +1 825 521 6591.
What we collect, and what we do not
| Data | Where it lives | Can Carte read it? |
|---|---|---|
| Your cards and saved contacts | Encrypted on your device; optionally in your own iCloud | No |
| Account email address | Firebase Authentication | Yes |
| Subscription status | RevenueCat and Apple | Yes |
| Calendar events from a connected source | Read on your device; not stored by Carte | No |
| Access tokens for connected accounts | Your device’s Keychain | No |
| Card view counts | A random card ID and a timestamp | Yes, but it identifies no one |
How your contacts are protected
Every card and contact you store is encrypted on your device using AES-256-GCM before it is written to disk. The encryption key is generated on your device and stored in the iOS Keychain.
So that your cards are still available when you replace your phone, that key is stored as a synchronising Keychain item. This means it can travel to your other Apple devices through iCloud Keychain, which Apple protects with end-to-end encryption. Carte never receives the key, and neither does Appé Latte.
You may also set a recovery passphrase. If you do, an encrypted copy of your key is stored in your own private iCloud database, locked with that passphrase. The passphrase is never transmitted and never stored. If you forget it, we cannot reset it — that is what keeps the data private.
Backups
Backups are optional. When enabled, your wallet is encrypted on your device and then written to your own private iCloud storage. It is not stored on Carte’s servers, and it is encrypted before it leaves your phone.
When you share a card
A shared card link carries its contents in the fragment of the URL — the part after the #, which browsers do not transmit to the server. The card is rendered in the recipient’s browser. We do not receive the contents of cards you share.
If you are a Pro subscriber, a shared link may include a random identifier so we can count how many times that card was opened. That count records only the random identifier and a timestamp. It does not record who opened it, their location, or any other information.
Calendars and connected accounts
Carte can connect to a calendar so the People screen can lead with who you are seeing today, and so a meeting can remember who was in the room. Connecting is entirely optional and nothing is read until you do it.
What is read. Event times, titles, the conferencing link, and the names and addresses of the people invited. Carte does not read the body, description or notes of an event. For Google Calendar this is enforced by the request itself: Carte names the fields it wants, so the description is never transmitted at all rather than being received and ignored.
Where it goes. Nowhere. Events are fetched by your phone, matched against the cards already in your wallet on your phone, and displayed. They are not sent to Carte, are not stored on our servers, and we cannot see them.
The access tokens. When you connect an account, the token that allows Carte to read it is stored in your device’s Keychain and is scoped to the account you signed in with. It is never stored on our servers. For Slack and Notion, the one-time exchange that turns your approval into a token passes through a Carte server, because those two providers require a secret that cannot safely live inside an app; that server adds the secret, passes the provider’s answer straight back to your phone, and stores nothing.
Disconnecting. You can disconnect any source at any time in Settings → Sources. Disconnecting deletes the stored token and removes that source’s events from Carte. You can also revoke Carte’s access from the provider’s own account settings.
Carte’s use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In plain terms: calendar data is used only to provide the features described above, is never sold or transferred, is never used for advertising, and is not used to build or improve any general-purpose model.
Notifications
If you allow notifications, Carte registers with Apple’s push service so it could be reached in future. Carte does not keep the resulting device token, does not send it anywhere, and no server of ours sends push notifications today — the notifications you see are generated on your own phone. If that changes, this section changes with it.
Third parties
- Firebase Authentication (Google) — stores your email address so you can sign in. If you use Sign in with Apple, we receive only what Apple passes on.
- Apple — processes subscription payments and provides iCloud storage for your backups and Keychain sync.
- RevenueCat — records whether your subscription is active.
- Google Calendar — only if you connect it. Your phone reads your events directly from Google; nothing passes through us.
- Calendly — only if you connect it. Your phone reads your own scheduled bookings directly from Calendly.
- Slack and Notion — only if you connect them. Carte offers these connections but does not yet read anything from them; the Sources screen says so on the row itself.
Carte contains no advertising, no third-party analytics SDK, and no tracking. We do not sell or share your personal information for money or for anything else of value, and we have nothing about your contacts or your calendar to sell.
Company logos
Carte can display a company logo next to a contact. When this setting is on, the website or email domain of that contact is sent to a public icon service in order to fetch the logo. If you would rather no contact domain ever leave your device, turn this setting off in Settings; it can be disabled at any time.
Device permissions
- Calendar — only if you connect Apple Calendar, to read the times, titles and invitees of your events. Never the body of an event.
- Notifications — only if you allow them, to reach you about your own activity.
- Camera — to scan QR codes and paper business cards.
- Contacts — only to save a card you have chosen to save.
- Photos — only to save a QR code image you asked to save.
- Local network and Nearby Interaction — to exchange a card with a phone in front of you.
- NFC — to write your card to a tag, or read one.
- Face ID — to lock the app, if you enable that.
Keeping and deleting your data
Your contacts stay on your device until you delete them. Deleting your account from Settings removes your account record, your subscription link, any escrowed recovery key, and any backup Carte created — and erases the encryption key from your device, after which any remaining encrypted copy is unreadable by anyone, including us.
Calendar events are not retained at all: they are read when the app refreshes and held only in memory. Disconnecting a source deletes its access token from your Keychain, and deleting your account removes every token along with it.
Earlier versions of Carte stored contacts on our servers before the app moved to on-device encryption. Those records are deleted when the app migrates your data, and are removed on account deletion.
Your rights
Depending on where you live, you may have the right to access, correct, export or delete your personal data. Your contacts are already in your possession and can be exported from the app. For anything held by us — which is essentially your email address — write to hello@appe-latte.ca or call +1 825 521 6591, and we will respond within 30 days.
Children
Carte is not directed at children under 13, and we do not knowingly collect their personal information.
Changes
If this policy changes materially we will update the date above and note the change in the app. Continued use after a change means you accept the updated policy.