Privacy Policy
Effective 15 August 2026
The short version
Your gift card numbers, PINs, and barcodes are stored in encrypted storage on your phone. We never receive them in a form we can read. While you are signed in, the app keeps a sealed copy of your vault on your account so reinstalling the app can restore it. We cannot open that copy.
What we hold is an account: an email address, the records needed to sign you in, non-secret card details (such as last four digits, retailer, and balance), and that sealed snapshot.
This policy covers both the Wallyo website and the Wallyo app on iOS and Android. The website and the app are quite different, so we have kept them separate below.
1. Who we are
Wallyo is operated by Pivot Innovation, LLC, United States.
For any question, request, or complaint about privacy, email hello@wallyo.io. We answer privacy requests at that address, and it is the fastest way to reach a person.
2. Visiting wallyo.io
We set no cookies on this website. There is no analytics, no advertising tag, and no tracking pixel. Nothing follows you after you leave, and there is nothing here for a consent banner to ask you about.
Every asset on this site is served from this site. Fonts, images, and the logo are all hosted here, so loading a page makes no request to any third party at all.
Our servers keep standard request logs: your IP address, browser type, the page requested, and the time of the request. These exist to serve the page and to guard against attacks. Where we use infrastructure providers to host or deliver the site, they receive the same information as part of doing so.
We do not use these logs to build a profile of you, and we do not combine them with anything else.
3. The app: what never leaves your device in readable form
The following is written to your phone's hardware-backed secure storage, the keychain on iOS and the Keystore on Android. We have no ability to read it:
- Gift card and prepaid card numbers
- PINs and security codes
- Barcode and QR payloads, whether scanned or generated
- Photographs you take of the front or back of a card
- Any notes you add to a card
- Text read from a card by on-device scanning
These are the things that can spend your money or identify you beyond the card. A barcode payload is on that list for the same reason a card number is: it is what a register accepts, so anyone holding it could spend the balance.
If you are signed in, a sealed copy of this material may also be stored on your account, encrypted on the phone first. We cannot decrypt it. That snapshot is how reinstalling the app restores a usable vault. It is not a plaintext upload of the items above.
Scanning happens entirely on your phone, using the text recognition built into your device's operating system. No photograph, and no text extracted from one, is sent to us or to anyone else in readable form.
3a. What is saved to your account
If you are signed in, the app keeps a copy of each card's details, not its credentials, so your cards survive losing or replacing your phone. For each card we store:
- A random identifier for the card, generated on your device. If you copy the card to another Wallyo, both accounts keep this same identifier.
- The retailer's name, and the identifier we use for that retailer
- The last four digits of the card number, so a card can be told apart from another at the same shop. Never the rest of the number.
- Whether it is a retailer gift card or a prepaid card
- The balance, whether the balance is known at all, and the currency
- The expiry date, and the low-balance amount you asked to be warned at
- The card's colour, and the barcode format it uses
- When the card was added and last changed
- Balance history: each time the balance changed, by how much, when, and whether you entered it or the app looked it up
Taken together this describes where you hold cards, what they are worth, and when you use them. That is why it is listed here in full rather than summarised.
Sealed vault snapshot. While you are signed in, the app also uploads a copy of the vault that was encrypted on your phone (the same format as an exported .wallyo file). It includes card numbers, PINs, barcodes, photographs and notes, as ciphertext. We cannot open it. Signing in on a phone that still has the key, or entering a recovery passphrase you set, is what opens it.
What we never receive in readable form: card numbers, PINs, barcode payloads, photographs, and your notes. Those are either only on the device, or only inside the sealed snapshot.
Changes are queued on your device and sent when there is a connection, so using the app offline works normally. If you are not signed in, nothing is sent at all.
3b. Location, if you turn it on
Nearby store alerts are off until you turn location on. The app first explains why, then the system asks for permission. If you decline, nearby alerts stay off.
If you allow it, the app uses your location on the device to notice when you are at a physical store for a retailer you already have a gift card for, and shows a local notification on your phone. Card numbers, PINs, balances, and barcodes are not sent anywhere as part of this.
To find store pins, the app may send your approximate location and the retailer name to a map search service (currently Photon / OpenStreetMap, operated by Komoot). That is the only location-related information that leaves the phone. You can turn nearby store alerts off in Settings at any time; that stops the geofences immediately.
3c. Copying or moving a card to another Wallyo
You can copy or move a saved card to another person who has Wallyo, in person. The number and PIN go to their phone, encrypted to a key that exists only on that phone for that session. They do not go through us, email, iMessage, or the system share sheet.
On copy, we store that both accounts hold the same card id, and the details we already store for sync (retailer, last four, balance, expiry) — not the number or PIN. Both of you can spend the remaining balance; this is not a split.
On move, your account is removed as a holder after you confirm. Do not use this to send a card to someone who is not with you.
4. The app: what we collect
Your account
To create an account we collect:
- Your email address, and a password that is stored only in hashed form, so we never store or see the password itself; or
- A sign-in service provided by your device platform, such as Sign in with Apple or Sign in with Google. In that case the platform may give us a private relay address rather than your real one, and we never receive your password for that account.
Sign-in records
Each time you sign in, our sign-in system records the IP address, the date and time, and basic device and app version information.
We use these only to operate sign-in and to detect abuse, such as repeated failed attempts against an account.
What we do not collect
- No advertising or analytics software is built into the app
- No crash-reporting or telemetry service is connected to it
- We do not read your device's advertising identifier
- We do not register a push notification token. Reminders about balances, expiry dates, and nearby stores are scheduled locally on your phone, and what they say never reaches us
- We do not access your contacts or calendar. Photo library access is limited to the specific images you choose to capture or attach. Location is used only if you turn on nearby store alerts, as described in section 3b
5. Who else is involved
Account sign-in is operated under our control and on our instructions. Your email address, your hashed password, and your sign-in records are used only to sign you in and to detect abuse. They are not sold, not shared with advertisers, and not used for anyone else's purposes. They cannot reach the items in section 3 in readable form.
Your account and the card details in section 3a are held in a database operated by Supabase, Inc. on our behalf. Supabase processes this information only on our instructions and is not permitted to use it for its own purposes. Access is restricted so that each account can read and write only its own rows.
Other parties may be involved, and only if you choose them:
| Who | What they receive | Why |
|---|---|---|
| Apple, Inc. and Google LLC | Your platform sign-in identity, if you sign in that way | Authentication only, under their own privacy policies. |
| Apple, Inc. and Google LLC | The contents of a Wallet pass, if you add a card to Wallet | Covered in detail in section 7. |
| Komoot GmbH (Photon / OpenStreetMap) | Approximate location and retailer name, if nearby store alerts are on | To resolve nearby store pins. Never a card number, PIN, or balance. |
We also use infrastructure providers to run our servers and deliver our website. They receive only what is needed to do that, they act on our instructions, and they are not permitted to use your information for their own purposes. If you would like to know which companies these are, email hello@wallyo.io and we will tell you.
That is the complete list. We do not sell your personal information. We do not share it for cross-context behavioural advertising. We have no advertising partners and no data brokers.
We will disclose information if we are legally compelled to. It is worth being precise about what that means: a valid legal order can reach your email address and your sign-in records. It cannot reach your card numbers or PINs, because we do not have them.
6. Checking balances with a retailer
When you check a card's balance, Wallyo may open the retailer's own balance page in your browser, or place a call to the number printed on the card.
At that point you are dealing with the retailer directly. The card number you type into their page goes to them, over their connection, under their privacy policy, not ours. Wallyo is not part of that exchange, and we do not receive the result unless you record it yourself in the app.
We spell this out because the distinction is easy to miss. "Your card number never leaves your phone" describes what we receive. It does not prevent you from giving the number to a retailer, which is the whole point of checking a balance.
7. Adding a card to Apple Wallet or Google Wallet
Wallyo can add a card to Apple Wallet or Google Wallet so you can reach it from your lock screen without opening the app.
This is the one place where card details deliberately leave Wallyo's protection, and we would rather be direct about it than let you discover it later. To create a pass, the card number and barcode have to be written into that pass. From that point the pass belongs to Apple or Google, under their terms and their privacy policies, not ours.
In practice:
- On iOS, passes are held in the Wallet app. If you have iCloud Backup switched on, your passes are included in that backup.
- On Android, creating a Google Wallet pass involves Google's pass service, so the contents of the pass reach Google's systems.
We receive nothing as part of this, and it changes nothing about what we store. But the promise that your card numbers stay on your phone describes Wallyo. Once you choose to put a card into Apple Wallet or Google Wallet, that card is also subject to how Apple or Google handles it.
This is your choice, card by card. If you never add a card to Wallet, none of this applies to you.
8. How long we keep things
| What | How long |
|---|---|
| Your account record | Until you delete your account |
| Sign-in records | Only as long as we need them to operate sign-in and investigate abuse |
| Website request logs | Only as long as we need them to serve the site and guard against attacks |
| Everything in section 3 | On your device, and inside the sealed snapshot while you are signed in |
| Card details in section 3a | Until you delete the card or your account, whichever comes first |
| Sealed vault snapshot | Until you delete your account, or overwrite it by signing in with an empty vault after a completed restore |
We are still settling the infrastructure behind the service, so we have not fixed the exact periods yet. We will publish specific retention periods on this page once they are set, and we will not keep anything longer than the purpose it was collected for requires.
9. Deleting your account and your data
Email hello@wallyo.io from the address on your account and we will delete the account and its sign-in history within 30 days.
Two things are worth understanding before you do:
- Deleting your account does not delete cards on other people's phones. If you copied a card into someone else's vault, they keep it; you are removed as a holder.
- Deleting your account does not delete your cards on this phone until the app removes them. They are stored on the device. To remove them, delete them in the app or uninstall it.
- Deleting your account also deletes the sealed vault snapshot. We cannot open that snapshot, and we cannot restore your cards for you afterwards. If you lose the device key, any recovery passphrase, and any
.wallyofile you exported, the numbers are gone.
Passes you have added to Apple Wallet or Google Wallet are not removed by any of this. Delete those in the Wallet app itself.
10. Your rights
California
If you live in California, you have the right to know what personal information we collect, to get a copy of it, to correct it, to delete it, and not to be treated differently for exercising any of those rights.
We do not sell your personal information, and we do not share it for cross-context behavioural advertising. There is no "Do Not Sell or Share My Personal Information" link on this site because there is nothing for it to act on. If that ever changes, we will say so here, and we will say so before it changes.
What we hold is described in section 4. In the language of the California Consumer Privacy Act, it consists of identifiers (your email address and IP address) and internet activity, meaning your sign-in records.
Other states
If you live in a state with a comparable privacy law, including Virginia, Colorado, Connecticut, Utah, Oregon, Texas, and Montana, you have similar rights to access, correct, delete, and obtain a portable copy of your information.
Making a request
Email hello@wallyo.io. We will verify that the request comes from the email address on the account before we act on it, and we will respond within the time your state's law allows, which is 45 days in most cases.
You may use an authorised agent to make a request on your behalf. We will ask for written proof that you authorised them.
11. Where we operate
Wallyo is operated from the United States, and your information is processed there.
The app is currently offered in the United States. If we make it available elsewhere, we will update this policy first.
12. Children
Wallyo is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child has created an account, email us and we will delete it.
13. Security
- Card numbers, PINs, and barcode payloads are held in your phone's hardware-backed secure storage, protected by your device passcode
- Your sign-in session is stored there too, not in ordinary app storage
- Traffic between the app and our servers is encrypted in transit
- Passwords are stored only as salted hashes. We never see, store, or log the password itself, and we cannot recover it. We can only help you set a new one
No system is perfectly secure, and we are not going to claim otherwise. What this design guarantees is narrower and more useful than a promise of perfection: a breach of our servers cannot expose your card numbers in a form anyone can read.
14. Changes to this policy
If we make a material change, particularly any change to what we collect, we will update the date at the top of this page and tell you in the app before the change takes effect. We will not quietly broaden what we collect under an unchanged policy.
15. Contact
Pivot Innovation, LLC
United States