EMV Card Analyzer
Privacy Policy
Effective date: September 15, 2026
HCEImage provides EMV Card Analyzer as a utility for EMV payment card inspection and diagnostics in authorized test environments. This policy describes local card analysis, history and diagnostic processing.
Current application scope
The Android application reads supported contactless payment applications using the device's built-in NFC reader, displays and locally saves analysis snapshots, and can export user-selected diagnostic reports. External card readers, including readers for contact cards, are not currently supported.
Data collection and sharing
EMV Card Analyzer does not automatically collect or send personal data to HCEImage or third-party services. The application has no account, advertising, analytics, crash reporting, tracking or network services. A report leaves the application only when the user explicitly saves or shares it. Support messages sent by the user are described below.
Device information and local state
The application checks whether the device has an NFC adapter and whether NFC is enabled. Card application data and raw APDU exchanges are processed locally. After a card read reaches a terminal state, its snapshot is saved automatically in an application-private Room database. The newest 100 analyses are retained by default. Settings can retain 100, 500, 1,000 or Unlimited analyses. A finite limit removes the oldest excess records; Unlimited keeps records until the user deletes them and can use increasing device storage. Users can delete individual rows or clear all history. Depending on the card, history may include account numbers, expiry dates, cardholder information or other sensitive values. An optional user note is stored with its analysis.
The selected theme, diagnostic detail preference and acknowledged development-use notice version are stored locally. Local data survives restarts and is removed when app data is cleared or the app is uninstalled. Application backup is disabled.
Reports and sharing
Reports are created only after the user chooses Save or Share in a saved analysis. Summary reports exclude the PAN and raw APDU commands and responses. Detailed reports include raw APDUs and may therefore contain sensitive card data. Save uses Android's document picker. Share uses Android's Sharesheet and grants the selected receiving application temporary read access to the generated file. The chosen destination then handles the file under its own privacy practices.
Copying and local diagnostics
Users can explicitly copy raw APDUs and decoded values to the system clipboard. The application marks clipboard content as sensitive to suppress supported system previews; other clipboard access and retention follow the operating system's behavior.
The diagnostic preference controls Android Logcat output. Errors records only failures; Sessions also records session events; APDUs additionally logs raw commands and responses, which may contain sensitive card data. APDUs is the default. Android manages these logs separately from analysis history. Users can choose a lower detail level in Settings. Sharing device logs is a user-controlled action, not an automatic upload by the application.
NFC permission
The Android NFC permission is used to read cards after the user selects Start analysis. Reader mode is released on Stop, leaving the Analyzer screen, Activity pause and completion or failure when the default analyzer behavior is enabled. Opening NFC settings is an explicit user action. The app does not perform payments or change the default payment service.
Children's privacy
EMV Card Analyzer is a specialized developer utility and is not directed to children.
Policy website hosting
This public policy page is hosted by GitHub Pages. GitHub logs visitor IP addresses for security purposes under the GitHub Privacy Statement. This website hosting is separate from the application data practices described above.
Changes to this policy
This policy may be updated when the application's functionality or data practices change. The effective date above identifies the current version.
Contact
For privacy or support questions, contact HCEImage at hceimage@gmail.com. If you email us, we receive your email address, message and any attachments you choose to send, and use them to respond to your request. Do not include real payment card data or other sensitive information in support messages.