Privacy Policy
Last updated 27 August 2026
This Privacy Policy explains what information MeishiIQ ("the app", "we") handles, and how. The app is designed privacy first: your contacts, card images and notes belong to you, live on your device, and are never sent to servers operated by us. We operate no accounts, no analytics, and no tracking. This policy is prepared with reference to the Singapore Personal Data Protection Act 2012 (PDPA); equivalent rights elsewhere (such as under the GDPR or CCPA) are respected in the same way, because the app's design gives you direct control of all your data.
1. What information the app handles
- Contacts and their fields — extracted from cards you scan, or typed by you, stored on your device with their provenance (the card evidence each value came from).
- Card images and photos — stored on your device beside the database.
- Notes, voice notes, follow-ups, groups and events — entered by you, stored on your device. Voice notes are transcribed on the device.
- Your own card (My Card) — entered by you, stored on your device, shared only when you present the QR code or send the vCard.
- API keys — stored in the device Keychain, never in the app's files.
The app collects no account, location, advertising identifier, or usage analytics from you. There is no account to create.
2. How your information is processed
On this device: card capture, text recognition, parsing, duplicate detection and search all run locally and work without any network connection.
AI features you invoke (optional, off until you add a key): nothing leaves the device for AI until you enter your own API key for the provider you choose — Anthropic, OpenRouter or OpenAI. From then on, what is sent depends on which feature you use, always under your own key and that provider's terms:
- Card verification and online research send the text extracted from a card, never the photo. These are the features the "AI card verification" switch controls.
- Ask MeishiIQ answers over your whole database, so it sends a summary line for every contact: name, role, company, email and phone numbers, website, LinkedIn, city and country, group names, the start of your most recent note about them, and the titles of their ScribeIQ meetings.
- A pre-meeting brief sends everything on record for that one person: their card fields, the full text of your recent notes about them, open follow-ups, and the summaries of their ScribeIQ meetings.
Research requests additionally use the provider's web search. The "AI card verification" switch does not gate the chat or the brief — those send data only when you personally open them and ask. Remove the API key to stop all of it; the app remains fully usable without AI.
3. When information is shared
Only at your instruction:
- AI providers — as described above, when you use AI features.
- iCloud sync (optional) — when enabled, your data is stored in your private iCloud database, accessible only to your Apple ID. Apple acts as the storage provider under its own terms.
- Saving to iPhone Contacts — "Save new contacts to iPhone Contacts" in Settings is ON by default, so a scan that finishes cleanly is written into your iPhone address book without a further tap; that is the moment iOS asks you for Contacts permission. Your address book is read only to check whether that person is already in it, so nobody is added twice; nothing is imported from it. Decline the permission, or turn the switch off, and scans stay inside MeishiIQ until you save each one yourself.
- Exports and archives — spreadsheets, vCards, PDFs and full archive folders go only to the destinations you choose, when you choose.
We never sell or rent personal information, never use your data to train AI models, and the app never contacts the people whose cards you scan. Enrichment facts are stored with their public source and marked unverified.
4. International transfers
The app itself transfers nothing across borders. Where you use AI features, your chosen provider may process the text in other countries under its own safeguards; consult that provider's policy. iCloud data residency is managed by Apple.
5. Retention and deletion
Everything is retained on your device until you delete it. Deleting a contact removes its fields, cards, images, notes and reminders from the device (and from your private iCloud, where sync is enabled). Deleting all data in Settings is protected by your deletion passcode. Uninstalling the app removes all local data. An archive you exported is the deliberate exception: it lives wherever you saved it and survives uninstalling the app, which is the point of an archive. It remains yours to keep or delete.
6. Security
Your data is stored within the app's protected sandbox and covered by your device's encryption. API keys are held in the Keychain. Network calls to AI providers use HTTPS. No method of transmission is entirely secure; choose AI providers you trust.
7. Your rights
Because your data never leaves your control, you exercise your rights (access, correction, deletion, portability, and withdrawal of consent under the PDPA or equivalent laws) directly in the app: view and edit everything, export anything, delete anything. There is no third party holding your data on our behalf to petition.
8. The people on the cards
A business card is personal data about someone else. You are responsible for obtaining cards lawfully and honouring the expectations of the people who hand you theirs, including applicable data-protection law (such as the PDPA or GDPR) when you store, export or share their details.
9. Children
MeishiIQ is intended for users aged 18 and above.
10. Changes to this policy
Material changes to this policy will be reflected here and in the app with an updated date at the top of this document.
11. Contact
Questions about this policy: angweeseng@hotmail.com