Card Studio hosts digital business cards. That means we hold contact details — names, job titles, phone numbers, email addresses and sometimes photographs — for the people who carry our cards. This page explains what we keep, why, and how to get it changed or removed.
Last updated 24 August 2026
Who we are
Card Studio is a service of Quo Vadis AI. For questions about anything here, write to john@qvadisai.com.
What we collect
From cardholders
The information you choose to put on your card: name, honorific, job title, organisation, email address, phone number, website, LinkedIn profile and an optional note. Optionally a headshot and a company mark. Your email address is also how you sign in.
All of it is intended to be public — it is printed on a card you hand to people, and it appears on your card’s web page and in the contact file anyone can download from it. Please do not put anything on a card that you would not want a stranger to have.
From visitors to a card
We count. When a card is opened, when its contact file is saved, and when somebody arrived by scanning the code or tapping the card, we add one to a daily total for that card. The person whose card it is can see those totals; nobody else can.
No cookie, no IP address, no third party, and nothing that identifies you. To answer “how many different people” without keeping anything about them, we store a one-way hash of your address and browser, salted with a key that changes every day. Two visits by the same person on two days produce two unrelated hashes, so the trail cannot be followed — including by us. The hashes are deleted after 30 days and the day’s salt goes with them, which makes the older ones unreadable even in a backup.
We drop what is not a person: crawlers, link previews, our own uptime checks, and browser prefetches. Our hosting provider keeps short-lived server logs that include IP addresses, which is ordinary infrastructure logging we do not use to identify anyone.
Nothing on a card comes from anybody else. Its typefaces, its images and its code are all served from our own servers — no fonts from Google, no scripts from anywhere, nothing that would let a third party see who opened your card. That was not always true: until August 2026 the typefaces came from Google Fonts, which meant Google saw the network address of every visitor. We moved them.
Sign-in
When you sign in we store a session cookie. It is strictly necessary to keep you signed in, it is set by us and not by anybody else, and it is not used for tracking — which is why this site shows no cookie banner. There are no other cookies of any kind.
We record a count of sign-in requests per email address and per IP address, so nobody can use our system to flood an inbox with links. Those counters hold your address in plain form, so they are deleted within 24 hours.
From organisations
If a company holds cards with us we keep the company’s name and address, who has access and at what level, any invitation we have sent on its behalf and whether it was accepted, and any design the company has authored. An invitation holds the email address it was sent to until it is accepted, revoked or expires.
A record of who did what
Actions that matter — changing a card, changing somebody’s access, setting a plan, taking a card out of service — are written to a log that cannot be edited or deleted, by us or by anyone. That is deliberate: it is the only real check on the access described below.
Each entry records what happened, when, whether it was one of our staff, and the network address and browser of whoever did it. The detail inside an entry, including that address, is deleted after 24 months; the fact of the action is kept.
Why we hold it
To provide the service you asked for: rendering your card, generating your contact file, and letting you sign in to keep it current. We do not sell personal information. We do not share it with advertisers. We have no interest in it beyond making your card work.
Who else processes it
We use a small number of providers to run the service. Each one only receives what it needs, and all are based in or process data in the United States.
- Vercel — hosting and file storage (your headshot and mark). Also serves the pages themselves.
- Neon — the database holding your card’s details.
- Resend — sends your sign-in emails. Receives your email address only.
- Sentry — tells us when something breaks, so we can fix it rather than wait for you to notice. It receives error reports: what failed and where in our code. Email addresses and phone numbers are stripped out of those reports before they are sent, and we have turned off the setting that would otherwise attach your IP address.
Sentry is not loaded on your public card at all — only on the pages you sign in to. If an error happens while you are editing, it also records a replay of that session so we can see what went wrong. Every piece of text and every form field in that replay is masked: we see which buttons you pressed and where you got stuck, not what you typed.
How long we keep it
For as long as your card exists, which is the point of the product: the address on a printed card has to keep working for years. Everything that is not the card has a limit, and a job that runs every day enforces it:
- Sign-in and download counters — deleted within 24 hours. These are the only place we hold an email address or an IP in plain form, so they go as soon as they have done their job.
- Visitor hashes — deleted after 30 days, along with the daily salt that would be needed to read them.
- The detail inside a log entry, including the address of whoever acted — deleted after 24 months. The entry itself stays.
- Daily counts for a card — kept with the card. They are the cardholder’s own figures and identify nobody.
There is something you should understand about that. A card’s web address is permanent by design and cannot be deleted or reassigned — otherwise every card already in someone’s wallet would become a dead link. What we can do is take the card out of service and erase the personal information behind it, leaving the address resolving to a short notice and nothing else.
Your choices
- Change anything — sign in and edit your details, or ask us and we will do it.
- Take your card offline — ask us. The address keeps working and shows a brief notice.
- Have your information erased — ask us. We will remove your details, your headshot and your mark, and close your sign-in account. As above, the address itself remains but will hold nothing about you.
- Get a copy — sign in and download it. Everything we hold about you, as a file, including a note of what is not in it and why. You do not need to ask anybody, and it is not part of any paid plan: it is your data.
Write to john@qvadisai.com for any of these. We aim to respond within 30 days.
Who at our end can see it
Three people. Card Studio is a small studio and building somebody a card means being able to see it, so three of our staff can reach any customer’s data. We think the honest thing is to say so rather than imply a wall that does not exist.
What makes that safe is the log described above: every such access is recorded as staff access, and neither we nor anybody else can edit or delete those records. An organisation’s owners can read the log for their own organisation.
Security
Connections are encrypted in transit. Sign-in is by emailed link rather than a password, so there is no password of yours for us to lose. Access to your card is checked on our servers on every request, and one cardholder cannot reach another’s card. Sign-in links expire after ten minutes and work once.
No system is perfect. If you believe something is wrong, please tell us at john@qvadisai.com and we will take it seriously.
Children
This is a service for working professionals. It is not directed at children and we do not knowingly hold information about them.
Changes
If we change this policy we will update the date above. If a change materially affects how we handle your information, we will email cardholders rather than rely on you noticing.
← Card Studioby Quo Vadis AI · Privacy · Terms