Effective: July 16, 2026
Sparkline briefly processes the UID/IDm of a supported NFC card at read time, for chemistry readings, re-identifying a card, card management, and history. It never issues commands to read stored value, transit or use history, payment data, names, hotel key data, or any other data held on the card.
The UID/IDm is immediately converted to an HMAC-SHA256 using a device-only Keychain key. The raw UID/IDm is never stored, displayed, or transmitted. A QR code or barcode image and its decoded value are likewise only processed transiently; only the identifier derived with the device-only key is stored.
Card names, issuers, categories, status, storage locations, deadlines, notes, and travel sets that you enter, along with reading history, registration date, check count, and appearance style, are stored on your device. Card-face images are never stored.
This app uses no account, advertising, third-party analytics SDK, or tracking SDK. The only thing the developer receives is anonymous usage counts, used to improve the app. They go only to the developer's own server (collect.appline.app, on Cloudflare) and are never sold or provided to third parties.
What is counted, all as totals (aggregates) only: how many times the app is opened, a card is newly registered, a pair / solo / Bump reading is produced, a visual code scan is used, and the history or collection screen is opened.
What is sent (only this): a fixed, predefined event name plus the app version number. Nothing else.
What is never sent: no UID/IDm, stored hash, card name, issuer, memo, storage location, travel set, reading text, or QR/barcode string — and no name, email, device identifier (IDFA/IDFV), advertising ID, or location.
No individual can be identified or tracked: the app assigns no persistent identifier to a device or user (no device ID, no session ID). All that is stored is "how many times, in total, something happened" — there is no key to join these counts on, which makes it structurally impossible to identify a user, follow the same person over time, or build a profile. Your IP address is not logged, stored, or used.
Because these counts are not linked to anyone's identity, they do not constitute tracking under App Tracking Transparency (ATT), and the app does not request ATT permission. In Apple's App Privacy the app declares Usage Data > Product Interaction, used for Analytics, not linked to the user, and not used for tracking.
During a Bump, two nearby iPhones communicate over Bluetooth and the local network with encryption required. They exchange fresh random nonces, a protocol version, a coarse card persona, on-device AI availability, mutual confirmation state, a single-session token, and the finished fictional reading text.
Never sent to the peer: the raw UID/IDm, the stored hash, card names, notes, or management data. Nothing is sent to a developer server or any internet service.
On eligible devices, Apple Foundation Models generates the secret genre, the fictional Bump chemistry text, and the solo Today's Card reading on device. Card names, notes, issuers, storage locations, UID/IDm, stored hashes, and raw QR/barcode values are not provided to the model. A bundled on-device fallback is used when generation is unavailable.
Sharing happens only when you open the iOS share sheet; the shared image contains card names, the reading, and the date. Notifications are scheduled on device only if you enable deadline reminders, and their text never includes card or venue names. Stored data uses complete iOS file protection, and app contents are hidden in the app switcher.
Information stays on your device until you delete it. Cards can be deleted individually, and the in-app Privacy & Legal screen deletes cards, travel sets, Bump history, solo history, mission state, and notifications together. Deleting the app removes the data in its container.
This app is rated 4+. Because the developer collects no personal information at all, no personal information is collected from children under 13 either.
Credit/debit cards, identity documents, My Number cards, driver's licenses, passports, and ISO 7816 cards are unsupported. Do not read another person's card or code without that owner's clear permission. Do not enter room numbers, PINs, card numbers, names, or unlock codes into card names or notes.
FeliCa is a registered trademark of Sony Corporation and MIFARE of NXP B.V. This app is not endorsed or sponsored by any card issuer, Sony, NXP, Apple, or the NFC Forum.
This policy may change. Significant changes will be announced on this page.
For questions or bug reports, please contact us here.
© 2026 Sparkline