FONYM
Privacy Policy
Effective 4 September 2026. This is the privacy policy for Fonym ("the app") on iPhone, and for the support email address at the end of it. "We" and "us" mean the app's publisher, an independent developer named as the seller on the App Store listing. It describes what happens to data — nothing in it is an agreement, and nothing in it asks anything of you.
Summary: the cards, contacts, photos, tags and settings you keep in Fonym never reach us. The app has no account system, no server and no analytics, and sends none of your content anywhere. Two narrow things can reach us, and neither contains what you store: correspondence you choose to send us, and — only if you switched that setting on yourself — a crash report Apple may pass on. Both are described below.
What the app stores. Business cards, contacts, tags, card photos, and your settings are stored only on your device, in the app's private storage, which no other app can read. They are protected at rest by your device's own encryption, iOS Data Protection. That protection is only as strong as your device lock. Your backup password is held in the operating system's secure storage, the iOS Keychain.
Backup files. A backup file you export is encrypted with your password, using cryptography built into your device, before it leaves the app. Card photos inside it are encrypted along with everything else. One thing is not: the password hint, if you set one, is stored in the file unencrypted, because it has to be readable before the password is — so treat a hint as something anyone holding the file can read, and do not put anything private in it. We never see that password, and can recover neither it nor the file.
What leaves your device, and only when you choose it. Sharing a card through the system share sheet, showing a QR code, exporting a backup file, or letting your device's own cloud backup include the app. Tapping a phone number, email address, website or social link on a card hands it to the app that handles it — your dialler, messaging app, mail app or browser — and opening this policy from Settings hands its address to your browser in the same way. Each of these is an action you take, in an app that is not ours. We are not a party to any of them and receive nothing from them.
Third parties. We pass nothing about you to anyone, and nothing that reaches us is shared onward. The app carries no advertising, no analytics and no third-party component that collects anything from you. When you export a backup or share a card, the service you choose — for example Apple iCloud, Google Drive, Dropbox, or a messaging app — receives what you sent it and handles it under its own privacy policy, not ours. Your device's operating system may also include the app's data in its own backups if you turn that on.
Permissions. The camera is used to photograph cards and to read QR codes. Biometric unlock — your face or fingerprint — is used only to unlock the app, and only if you turn that lock on. Fonym never sees the scan: the match happens inside the operating system, which tells the app only whether it succeeded. No face or fingerprint data is sent to the app, held by it, or received by us at any point. You can withdraw either permission whenever you like, in your device's own settings under Fonym's entry; the app keeps working without them, minus the feature each one serves. Fonym never asks for access to your photo library at all: importing a photo of a card uses the system photo picker, which hands the app the one image you chose and nothing else. Reading the text on a card happens entirely on your device, using text recognition built into the operating system; card images are not uploaded anywhere.
Diagnostics. The app contains no crash reporting, no telemetry and no analytics of any kind, and sends nothing anywhere itself. Every logging call is stripped out when the app is built for release, so a released build writes nothing to your device log either. There is no analytics setting inside Fonym — nothing in the app to switch on or off, because there is nothing to switch. One channel exists outside the app, and it is under your control rather than ours: iOS can pass crash reports to developers if you have turned that on yourself, under Settings › Privacy & Security › Analytics & Improvements › Share With App Developers. It is off unless you enabled it, and it applies to every app on your phone, not to Fonym in particular. A report that reaches us that way describes the crash, your device model and your iOS version. It is a technical record of the failure — not a copy of what the app holds: your cards, contacts, photos and backups are not in it. We cannot switch it on for you, and if you leave it off no crash report ever reaches us.
What we hold. Two things, and nothing else: support correspondence you send us, covered below, and — if you turned on Share With App Developers — whatever crash reports Apple makes available to us, which sit in Apple's tools under Apple's own retention rules. Everything else we simply do not have: no usage records, no logs of your activity, and no copy of anything the app stores. Those never leave your device, so there is nothing for us to look up, hand over or lose.
Your purchase. Apple handles the payment and tells us nothing that identifies you: we never receive your name, your email address, your Apple Account or any payment details. What reaches us is sales figures Apple has already aggregated — how many copies sold, not who bought them.
Data deletion and retention. Everything the app stores lives on your device and is removed when you delete the app. We operate no server and hold no copy of it, so as far as your cards, contacts and photos go there is nothing for us to retain, access, correct, export or delete. Backup files are yours alone: you choose the service and the location where each one is kept, only you hold the password, and only you can delete it from wherever you put it. We cannot access, recover or erase a backup file, and we never receive one.
When you contact us. If you email us for support or feedback, we receive your email address and whatever you choose to put in the message. We use it only to answer you and to fix what you reported. We keep it only for as long as it is useful for dealing with what you wrote about, and delete it after that. We never add you to a mailing list, never use it for marketing, and never sell or share it. If you would like it deleted, ask at the email address below and we will delete it.
Your rights. In relation to support correspondence you can ask us for a copy, ask us to correct it, or ask us to delete it, at the email address below. In relation to everything in the app, there is nothing for us to act on, because we never receive it — you control it directly on your device.
Changes. The current version is always this page, https://fonymapp.github.io/privacy/index.html, which the app links to from Settings. If the policy changes, the updated text appears here with a new effective date.
Contact: fonym.dev@gmail.com