← Brain Index

BRAININDEX OÜ · CARD INDEX / КАРТОТЕКА

Card Index application privacy policy

Effective 9 October 2026. Card Index / Картотека is provided by BRAININDEX OÜ (Brain Index), Estonia. Contact: hello@brain-index.com. This policy concerns the Android application, not just this promotional website. Card Index is intended for adults aged 18 and over, not children.

Your records and sources

A new installation contains no working records or automatically selected remote database. By default, companies, people, tasks, events, attachments and your personal business profile are stored on your device. You may choose your own external source; that provider or your organisation controls its storage, access and retention. Brain Index does not receive your entire working database as a hosted catalogue.

Contacts are read only after your permission and import action. File imports and incoming shares are reviewed before saving. Card Index cannot read private WhatsApp, Telegram, Viber or other messenger databases merely because those apps are installed. We do not use advertising identifiers or sell your working records.

OfferPSP is a separate product, not a Card Index service database. Its records are not included in a new installation. Access to OfferPSP or any other external database requires a source connection you choose and are authorised to use; signing into Card Index does not grant access to it.

Account and notifications

Local work does not require a BIX account. Online AI uses a BIX identity hosted with Supabase. Email/password or Google sign-in processes account identifiers, email and authentication information; Google may supply your name and profile image. Source authentication is separate. Optional push notifications use Firebase Cloud Messaging, a delivery token, installation identifier and minimal registration timestamps. Local reminders do not upload your working catalogue.

Card Index stores a daily AI request count and last-request time, not the prompt in this usage table. Usage older than 30 days is removed when that account next requests AI; otherwise it remains until account deletion. The first public release is free and does not collect payment-card information.

AI and voice messages

Recording and replay occur on the device. Audio is not sent simply by holding or releasing the microphone. Sending a voice message explicitly transmits its audio through the BIX service to Groq for transcription; the transcript and the open company name, when relevant, are then used for planning. Sending text similarly transmits that text and relevant company name. The remaining catalogue is not sent to the model. AI output is applied to the selected source on the device; writes require review and confirmation.

Online AI requires internet and service authentication; offline speech recognition is not offered. BIX application handlers do not deliberately persist request audio, prompts or transcripts in a working-record database. Platform operational logs may contain request metadata. Groq's diagnostic or abuse-investigation processing may retain inputs and outputs for up to 30 days unless its zero-data-retention setting applies; we do not claim that setting is enabled for this service. Do not send secrets or information you are not authorised to disclose. See Groq data practices.

Optional billing connection

The beta is free: purchases, purchase restoration and paid restrictions are disabled. Opening Card Index or its billing panel does not initialise RevenueCat. Selecting Check connection sends an anonymous installation identifier and SDK-required technical information (such as device and operating-system type, app and SDK versions, and network request information) and subscription metadata to RevenueCat and reads the subscription status, which may be cached. Card Index does not send RevenueCat your BIX identity, email, profile, contacts, working catalogue, files, audio or source credentials. Optional SDK diagnostics and advertising attribution identifier collection are disabled. No payment-card information is collected by Card Index. Anonymous RevenueCat records are separate from the BIX account deletion flow; contact support for provider-record deletion requests. See RevenueCat privacy.

Providers and international processing

Service providers include Supabase for account and temporary service processing, Google for optional sign-in and Firebase push, Groq for AI and transcription, RevenueCat for an optional billing status check, and Vercel for this website. Your chosen source provider receives requests you authorise for that source. Processing may occur outside your country, including in the United States. Each provider also operates its own security and operational systems: Supabase privacy, Google privacy, Vercel privacy. This policy is not a promise that no data ever leaves the device.

Retention and deletion

Local records remain until you delete them or uninstall the app. Exports contain personal and business information and remain wherever you save or share them. Disconnecting a source does not delete that provider's records. Temporary exported cache copies older than one day are cleaned on the next export, not by a guaranteed background timer. Unsaved voice drafts are temporary and are not a durable backup.

In Profile, Delete Card Index account deletes all Card Index push registrations and AI usage rows for your identity and closes service access. It does not erase local records, your own external database or a shared BIX identity used by other products. Only the account identifier and closure timestamp remain as a security revocation marker, so an old token cannot restore access. That marker is removed if the underlying BIX identity is deleted, or cleared on your explicit recreation after a fresh sign-in. Other BIX products and providers may retain their separate account data under their own policies.

You can also request account deletion, access, correction or further erasure without the app: Card Index account deletion and data requests. We verify identity before processing. A request concerning a shared BIX identity must specify whether it also covers other products, so their data is not deleted accidentally. Legally required or security-related retention will be explained in the response.

Your choices

You may refuse or revoke microphone, contact and notification permissions in Android settings, use local storage without service login, choose or disconnect a source, export your records, and stop sending AI requests. Tokens are stored using Android's protected credential facilities; exports exclude them. These controls reduce risk but are not a guarantee against all device or provider compromise. Contact the address above about privacy rights or complaints; you may also contact your applicable data-protection authority.

Кратко по-русски

Картотека — инструмент для вашей информации. Новая установка пустая; рабочие записи и визитка по умолчанию находятся на вашем устройстве либо в выбранном вами источнике. Импорт контактов и файлов требует вашего действия. Установленные мессенджеры не дают доступ к их закрытым базам.

Запись и прослушивание голоса локальные. После «Отправить» аудио, распознанный текст и при необходимости название открытой компании проходят через BIX и Groq. Весь каталог модели не отправляется. Онлайн-ИИ требует интернет и сервисный вход. У провайдера возможно диагностическое хранение до 30 дней; включённый ZDR для этого сервиса не заявляется.

Первый выпуск бесплатный: покупки и восстановление покупок отключены. RevenueCat не запускается при открытии приложения или раздела оплаты. Только «Проверить соединение» передаёт анонимный идентификатор установки и технические сведения для проверки статуса подписки; рабочие записи, контакты, голос, email и BIX-identity туда не передаются. Запрос на удаление этих отдельных записей провайдера можно направить в поддержку. OfferPSP — отдельный продукт, доступный только через выбранное и разрешённое вами подключение источника.

«Удалить аккаунт Картотеки» удаляет регистрации push и учёт использования ИИ, закрывает сервисный доступ, но не удаляет вашу рабочую базу, локальные записи или общую BIX-identity других продуктов. Остаётся минимальная отметка отзыва доступа: идентификатор и дата закрытия доступа. Для запросов вне приложения и вопросов о данных: удаление аккаунта или hello@brain-index.com. Первый публичный выпуск бесплатный, платёжные карты не собираются.

Account deletion · Card Index product website