Card Studio hosts digital business cards. That means we hold contact details — names, job titles, phone numbers, email addresses and sometimes photographs — for the people who carry our cards. This page explains what we keep, why, and how to get it changed or removed.
Last updated 10 August 2026
Who we are
Card Studio is a service of Quo Vadis AI. For questions about anything here, write to john@qvadisai.com.
What we collect
From cardholders
The information you choose to put on your card: name, honorific, job title, organisation, email address, phone number, website, LinkedIn profile and an optional note. Optionally a headshot and a company mark. Your email address is also how you sign in.
All of it is intended to be public — it is printed on a card you hand to people, and it appears on your card’s web page and in the contact file anyone can download from it. Please do not put anything on a card that you would not want a stranger to have.
From visitors to a card
Nothing. We set no analytics or advertising cookies, we do not track who views a card, and we do not build profiles of visitors. Our hosting provider keeps short-lived server logs that include IP addresses, which is ordinary infrastructure logging and is not used to identify anyone.
Sign-in
When you sign in we store a session cookie. It is strictly necessary to keep you signed in and is not used for tracking, which is why this site shows no cookie banner. We briefly record a count of sign-in requests per email address and per IP address, so that nobody can use our system to flood an inbox with links.
Why we hold it
To provide the service you asked for: rendering your card, generating your contact file, and letting you sign in to keep it current. We do not sell personal information. We do not share it with advertisers. We have no interest in it beyond making your card work.
Who else processes it
We use a small number of providers to run the service. Each one only receives what it needs, and all are based in or process data in the United States.
- Vercel — hosting and file storage (your headshot and mark). Also serves the pages themselves.
- Neon — the database holding your card’s details.
- Resend — sends your sign-in emails. Receives your email address only.
- Sentry — tells us when something breaks, so we can fix it rather than wait for you to notice. It receives error reports: what failed and where in our code. Email addresses and phone numbers are stripped out of those reports before they are sent, and we have turned off the setting that would otherwise attach your IP address.
Sentry is not loaded on your public card at all — only on the pages you sign in to. If an error happens while you are editing, it also records a replay of that session so we can see what went wrong. Every piece of text and every form field in that replay is masked: we see which buttons you pressed and where you got stuck, not what you typed.
How long we keep it
For as long as your card exists, which is the point of the product: the address on a printed card has to keep working for years.
There is something you should understand about that. A card’s web address is permanent by design and cannot be deleted or reassigned — otherwise every card already in someone’s wallet would become a dead link. What we can do is take the card out of service and erase the personal information behind it, leaving the address resolving to a short notice and nothing else.
Your choices
- Change anything — sign in and edit your details, or ask us and we will do it.
- Take your card offline — ask us. The address keeps working and shows a brief notice.
- Have your information erased — ask us. We will remove your details, your headshot and your mark, and close your sign-in account. As above, the address itself remains but will hold nothing about you.
- Get a copy — ask us and we will send you everything we hold about you.
Write to john@qvadisai.com for any of these. We aim to respond within 30 days.
Security
Connections are encrypted in transit. Sign-in is by emailed link rather than a password, so there is no password of yours for us to lose. Access to your card is checked on our servers on every request, and one cardholder cannot reach another’s card. Sign-in links expire after ten minutes and work once.
No system is perfect. If you believe something is wrong, please tell us at john@qvadisai.com and we will take it seriously.
Children
This is a service for working professionals. It is not directed at children and we do not knowingly hold information about them.
Changes
If we change this policy we will update the date above. If a change materially affects how we handle your information, we will email cardholders rather than rely on you noticing.
← Card Studioby Quo Vadis AI · Privacy