Last updated: 29 July 2026
MyGiftCards has no accounts, no servers of its own, and no analytics. Your gift cards are stored on your phone and are not uploaded anywhere. Uninstalling the app deletes them.
Everything you enter — card type, name, balance, expiry, purchase history, and optionally a payment card number, CVV and gift-card link — is written to a database inside the app's private storage on your device. None of it is transmitted to the developer or to anyone else. There is no account to create and nothing to sign in to.
Card numbers, CVVs and card expiry dates are encrypted with a key held in the Android Keystore. Where your phone has a screen lock, that key is bound to it, so the values cannot be decrypted without a fresh fingerprint, face or PIN check — the operating system enforces this, not the app. Keystore keys cannot be exported from the device.
| Where | Why | What is sent |
|---|---|---|
naveh92.github.io(GitHub Pages) |
To download the lists of shops that accept each kind of gift card, roughly weekly. | Nothing about you. These are ordinary anonymous requests for public files. As with any website, the host receives your IP address and can log it; see GitHub's privacy statement. |
| The gift-card issuer's own website (for example buyme.co.il) |
Only if you choose to save a gift-card link on a card. The app then checks that page periodically to see whether the balance is lower than your purchase log accounts for, and tells you if a purchase looks unrecorded. | The link you saved, to the issuer that issued it. Nothing is sent to the developer. Leave the gift-card link field empty and this never happens. |
That is the complete list. The app contains no advertising, no analytics, no crash reporting, no tracking, and no third-party SDKs that collect data.
You can export an encrypted backup file. It is encrypted with a passphrase that only you know, using AES-256-GCM with a key derived by PBKDF2. The file is written wherever you choose to save it, and the developer never receives a copy. If you forget the passphrase, the file cannot be recovered — not by you, and not by anyone else.
| Permission | What it is for |
|---|---|
| Internet / network state | Downloading the shop lists described above. |
| Biometrics | Confirming it is you before revealing a saved card number. |
| Notifications | A single alert, when a card holds less than your purchase log accounts for. The app only asks for this once you have saved a card with a gift-card link, since that is the only case where the alert can occur. Declining costs you nothing else. |
MyGiftCards is a general-purpose utility and is not directed at children. It collects no personal information from anyone, of any age.
Uninstall the app, or clear its storage from Android's app settings. Because nothing is held on a server, that is the end of it — there is no copy elsewhere for anyone to delete, and no request you need to send. Any backup file you exported yourself is yours to delete.
If this policy changes, the revised version will be published at this address with a new date at the top.
Questions about this policy: navehohana@gmail.com
עודכן לאחרונה: 29 ביולי 2026
באפליקציה אין חשבונות, אין שרתים משלה ואין אנליטיקס. הכרטיסים שלך נשמרים במכשיר שלך ואינם נשלחים לשום מקום. הסרת האפליקציה מוחקת אותם.
כל מה שאתם מזינים — סוג הכרטיס, שם, יתרה, תוקף, היסטוריית רכישות, ובאופן אופציונלי גם מספר כרטיס אשראי, CVV וקישור לכרטיס המתנה — נשמר במסד נתונים באחסון הפרטי של האפליקציה במכשיר. שום פרט מזה אינו נשלח למפתח או לגורם אחר. אין חשבון ליצור ואין להתחבר לשום דבר.
מספרי כרטיס, CVV ותאריכי תוקף מוצפנים באמצעות מפתח שנשמר ב־Android Keystore. במכשיר שבו מוגדרת נעילת מסך, המפתח קשור אליה, ולכן לא ניתן לפענח את הערכים ללא אימות טביעת אצבע, פנים או קוד — מערכת ההפעלה אוכפת זאת, לא האפליקציה.
האפליקציה פונה ל־naveh92.github.io כדי להוריד את רשימות החנויות המכבדות כל
סוג כרטיס, בערך פעם בשבוע. אלו בקשות אנונימיות רגילות לקבצים ציבוריים, ולא נשלח בהן שום
מידע עליכם.
בנוסף, רק אם בחרתם לשמור קישור לכרטיס מתנה, האפליקציה תבדוק מדי פעם את העמוד של המנפיק (למשל buyme.co.il) כדי לזהות רכישה שלא נרשמה ביומן. אם תשאירו את שדה הקישור ריק, פנייה כזו לא מתבצעת כלל.
זו הרשימה המלאה. אין באפליקציה פרסומות, אנליטיקס, דיווח קריסות או מעקב.
ניתן לייצא קובץ גיבוי מוצפן בסיסמה שרק אתם יודעים, בהצפנת AES-256-GCM. הקובץ נשמר במקום שתבחרו והמפתח אינו מקבל עותק. אם תשכחו את הסיסמה, לא ניתן לשחזר את הקובץ.
הסירו את האפליקציה או נקו את האחסון שלה בהגדרות המכשיר. מכיוון ששום דבר אינו נשמר בשרת, בכך הסתיים העניין — אין עותק אחר שצריך למחוק.
שאלות בנוגע למדיניות זו: navehohana@gmail.com