Privacy notice
Personal Data Protection Act 2010 (Malaysia) · Last updated 4 September 2026
Who holds your data
Azim Faris is the data user for the purposes of the PDPA and is responsible for the personal data described here. You can reach him at azmfrs.studio@gmail.com.
What is collected
Two different kinds of personal data are involved, and it matters which is which.
Your own data. Your email address, from signing in. Anything you put on your own profile card — name, job title, company, phone, email. Your sign-in is by emailed link or Google; no password is stored.
Other people's data, from the cards you scan. Photographs of business cards you capture, the text read from them (name, title, company, phone numbers, email addresses, websites, postal addresses), anything you add yourself such as where you met someone and your own notes, and tags produced automatically about the company.
The source of that second category is you: it comes from cards handed to you, not from any purchased list or public scrape.
Why it is collected
To provide the product: to read a card so you do not have to type it, to let you find and organise your contacts, to let you share a contact or send yourself an export, and to add publicly available context about a company.
Providing this data is voluntary. You can use KNOU without a profile card, and without notes or met-at details. If you do not scan a card, there is nothing for the product to do.
Who it is shared with
These are the only parties data reaches, and each is listed because of something the product genuinely does.
- Supabase — hosts the database, files and sign-in. Data is stored in the Singapore region.
- Cloudflare — serves the application.
- OpenRouter — the AI service that reads card images and generates company summaries and follow-up drafts. Card images and card text are sent to it.
- Resend — delivers sign-in emails, and delivers contact exports to addresses you type in yourself.
- Anyone you give a share link to. A share link is unlisted but is not secret: anyone holding the link can open it until it expires or you revoke it.
Data is not sold, and is not shared with advertisers or data brokers.
What you control
- See and correct. Every field on every card is editable in the app, and your profile card is editable at any time.
- Delete. Deleting a card moves it to Trash, where you can restore it. After 30 days it is removed permanently, along with its images.
- Stop sharing. Any share link can be revoked from the Shared links screen, which also shows how many times it has been opened.
- Ask for a copy, or for erasure. Write to azmfrs.studio@gmail.com and it will be handled.
How long it is kept
Cards are kept until you delete them. A deleted card sits in Trash for 30 days and is then removed permanently. A record of contact exports you send by email is retained as an audit log, because it records that personal data left the app and to whom.
How it is protected
Each account can only read its own data; that separation is enforced by the database itself, not only by the application. Card images are stored privately and are served through links that expire after one hour. Public share pages expose only a limited set of fields and never your private notes.
Being asked, and changing your mind
The people whose cards you scan have not agreed to this notice — you have. If someone asks you to remove their details, delete their card, and it will be gone within 30 days.