Privacy Policy
This Privacy Policy describes how the QWallet iOS application handles information. It is based on the app’s verified behavior and configuration.
Who we are
QWallet is a mobile app for storing loyalty and membership cards, barcodes, and related reminders on your device, with optional Apple Wallet and subscription features.
Data controller: Ruslan Tsitser
Privacy contact: support@tsitser.com
Information you provide
You may enter or generate:
- card names and optional field labels;
- barcode / QR values and barcode formats;
- visual preferences such as theme and icon;
- folders, favorites, expiry dates, and reminder settings;
- an optional setting to hide the plain-text card value on an Apple Wallet pass.
You can also import barcodes from the camera or photos, import a local database backup file, and export your local database or log files from the device.
Information stored on your device
Card and folder data are stored locally in an on-device SQLite database. App preferences and cached configuration values are stored with on-device preferences storage.
Local notifications may store reminder metadata needed to notify you about card expiry. Notification content uses the card name and does not include barcode or membership numbers.
On-device Apple features may use card names, expiry dates, and deep links (for example Spotlight, Siri shortcuts, and widgets). Those surfaces are configured so barcode or membership numbers are not exposed there.
Permissions
QWallet may request the following device permissions when needed:
- Camera — to capture a barcode or QR code.
- Photo Library — to import a barcode or QR code from an image.
- Location (When In Use) — only if you choose to attach your current location when creating an Apple Wallet pass, so the pass can become relevant nearby.
- Notifications — for optional card expiry reminders.
- Siri — so Siri can open a card, help add a card, or surface expiring cards. Card names and expiry dates may be used for this; barcodes and membership numbers are not used for Siri content.
Information sent from the device
Most card data stays on your device. The app sends data off-device in these verified cases:
- Apple Wallet pass creation. When you add a card to Apple Wallet, the app calls a Firebase Cloud Function with an Apphud user ID and the card fields needed to sign the pass (such as id, name, value, format, colors, optional icon/field label, and the hide-value setting). If you opt in, the request may also include your current latitude and longitude for pass relevance.
- Anonymous Firebase Authentication. The app signs in anonymously so authenticated backend calls can be made without an email/password account.
- Subscriptions (Apphud). Purchase, restore, and premium-access checks are handled through Apphud and Apple’s In-App Purchase system. Apphud provides a user identifier used by the app for subscription and Wallet pass flows.
- Crash diagnostics (Firebase Crashlytics). The app records crash and error information to help diagnose failures.
- Remote configuration (Firebase Remote Config). The app fetches remote configuration values used for feature/config behavior.
The project includes the Firebase Analytics package together with Firebase Core. Explicit Analytics event logging was not found in the application code; any collection would be limited to Firebase’s default SDK behavior under Google’s policies.
On-device processing
Barcode recognition from camera or photo import is performed on-device with Google ML Kit barcode scanning.
Third-party services
- Apple (In-App Purchase, Apple Wallet, system APIs)
- Firebase / Google (Authentication, Cloud Functions, Crashlytics, Remote Config; Analytics package present)
- Apphud (subscriptions and related user identifiers)
- Google ML Kit (on-device barcode scanning)
Those providers process information according to their own terms and privacy policies.
Retention, deletion, and your controls
- Local cards and preferences remain on your device until you delete them in the app, replace them by importing a backup, or remove the app.
- You can export or import a local database backup and share local log files from the device.
- You can revoke permissions in iOS Settings. Location is used for Wallet pass creation only when you choose that option.
- Subscription management and cancellation are handled through your Apple ID / App Store subscription settings.
- To request deletion of server-side records related to Wallet pass creation, anonymous Firebase authentication, Crashlytics, Remote Config, or Apphud, contact support@tsitser.com.
Children
QWallet is not directed to children, and the app does not knowingly collect personal information from children for account registration. Card contents are whatever you choose to store locally.
Changes
If this policy changes, the updated version will be posted on this page with a revised “Last updated” date.
Contact
Questions about privacy: support@tsitser.com or see the Support page.