Privacy Policy
Wallet Libre · effective August 10, 2026
Wallet Libre turns a card you already carry into an Apple Wallet pass. There is no account to create, no advertising, and no third-party analytics or SDKs in the app. The short version: your cards live on your iPhone, and the only thing the server does is sign a pass and forget it.
What stays on your device
Your card library — names, numbers, colors, photos, and the pass files themselves — is stored on your iPhone. It is not uploaded anywhere for safekeeping, backup, or sync, and we have no way to read it.
What is sent to the signing server, and for how long
Apple requires a pass to be cryptographically signed by a registered developer certificate, which cannot ship inside an app. So when you add a card, its details — the card name, number, colors, and any branch locations you chose — are sent over HTTPS to our signing server, which builds the pass, signs it, returns it, and deletes its working copy before the response is sent. Card data is never written to a database and never written to the logs. What the logs do hold is request status lines, and a note of the shape of each pass built — which kind of barcode, how many characters it holds, how many locations are on it, how big the finished pass was — so we can see what real cards look like and keep the barcode legible at a counter. No values of any kind: never the number itself, never the card’s name, never a color, never a place. There is one further exception, the issuer-name lookup described below, which records the name of the institution and nothing else. Nothing in any of it says who asked.
The optional AI fill
If you tap “Fill the rest in for me”, the photo of your card and the text read from it are sent to our server, which forwards them to Anthropic’s API for a single reading that suggests a title, colors, and the issuer’s branches. We do not keep the photo. Anthropic processes it as our API provider under its commercial terms and does not use it to train models. This is the one step that hands your card image to another company, it is why the app declares “Photos” in its App Store privacy label, and it never happens unless you ask for it — every field can be typed in by hand instead.
The same step looks for the issuer’s logo. Our server visits the issuer’s own website, collects the candidate images, and sends the pictures themselves back to your phone. Your phone does not visit the issuer’s site, or any other site, to fetch them — so no one outside this app learns your address from a logo.
Looking up an issuer’s locations
When the app looks for the places a card is used, it asks Apple Maps on your device and, at the same time, asks our server whether it recognises the institution’s name. That request contains the name — “San José Public Library” — and nothing else: not your position, not your card, not an identifier for you or your phone. The server answers from a copy of the U.S. Institute of Museum and Library Services’ public library directory that ships inside it, so it makes no outside call and consults nothing about you.
It does keep a running note in its logs of which institution names are asked for and whether it recognised them, so we can see which issuers the directory is missing and add them. Those notes are counts of names, not of people: nothing in them says who asked, from where, or how often. Choosing which of the places found go on your pass happens entirely on your phone.
Camera, photos, and location
- Camera is used only while you are scanning a card, to read its barcode and take the picture you see in the editor.
- Photo library access happens only when you pick an existing picture of a card.
- Location, if you allow it, is used to look up the issuer’s nearest branches so the pass can offer itself on your lock screen there. The search runs through Apple Maps and against the directory described above. Your position is not sent to our server in either case — when the directory returns more than one institution of the same name, your phone picks the nearest one itself. Branch coordinates you choose become part of the pass, so they are included in the signing request above.
Abuse prevention
To stop the signing endpoint being used by anything other than this app, each device proves itself with Apple’s App Attest. The server keeps a salted hash of the attested device key in memory to count requests against a rate limit. It is not linked to you, not stored on disk, and it disappears whenever the server restarts.
What we do not do
- No tracking, no advertising identifiers, no cross-app profiling.
- No analytics or crash-reporting SDKs.
- No selling or sharing. The server keeps two things: the log of which issuer names were looked up, and hourly counts of how many requests of each kind it answered and how many failed. Neither is about you, and neither is for sale.
Children
Wallet Libre is not directed at children and collects nothing that would identify anyone of any age.
Your choices
Deleting a card in the app removes it from your device; deleting the pass in Apple Wallet removes it there. Uninstalling the app removes everything it stored. There is no server-side copy of your cards for us to delete on request — but if you have a question, ask.
Changes
If this policy changes in a way that affects what leaves your device, the effective date above changes with it.