AgentMClose
VintSnaptitraCitedSitePriceSiblinyLanyardTariffShieldPopSnap

Privacy policy

Agent M LLC · Lanyard · Last updated 10 September 2026 · Version 0.26

01 Who we are

Lanyard is made by Agent M LLC (“we”, “us”). Questions about this policy, or about the app: hello@agentm.co.uk.

02 Whose data this is really about

Most privacy policies describe data collected about you, the user. Lanyard is unusual, and being straight about it matters more than sounding tidy.

When you scan a badge or a business card at a trade show, the name, email address, phone number, job title and employer that Lanyard reads belong to the person you just met — not to you, and not to us. That person never opened this app and never saw this page.

In the language of the UK GDPR and EU GDPR: you, or the organisation exhibiting, are the data controller for the leads you capture. Agent M LLC acts only as a processor, and only for what you switch on: with backup off and the AI features off, which is how a new install arrives, we receive nothing at all.

Practically, that means it is your responsibility to have a lawful basis for capturing someone’s details, and to tell them what you will do with them — under Article 14, at your first communication with them. Lanyard helps by recording, on every capture, which event it belonged to and what consent basis applied at the time, frozen at the moment of capture so it can be evidenced months later.

03 What Lanyard handles

DataWhere it comes fromWhy
Name, email, phone, job title, employerThe badge barcode, or text you scanTo create the lead record
Badge or card photographYour camera, at the moment of captureEvidence of what was scanned, and a fallback if parsing was imperfect
Voice notes, and their transcriptsYour microphone, only while you hold the record button. Transcription runs on the phoneTo record what was actually discussed
Event name, country, consent basisEntered by you when you set up an eventCorrect phone formatting, and a defensible consent record
Your ideal-customer profileTyped by you in SettingsTo score leads, on the device. One sentence derived from it — what you sell, and to which industries — is included in an AI request, if you have switched those on (section 05)

Lanyard does not read your location, your contacts, your calendar, your messages, your photo library, or any advertising identifier. It has no access to any of them.

04 Where it is stored, and what leaves the device

Everything above is stored on your device: leads in an encrypted database, photographs and audio in the app’s private storage. Other apps cannot read them.

The app contains no analytics, no crash reporting, no advertising SDK and no tracker of any kind. Nothing about how you use Lanyard is reported to us.

So that a problem can still be diagnosed, the app keeps a short list of its own most recent errors on your phone: the time, which part of the app failed, and a shortened technical message with anything resembling an email address or phone number removed. It contains no lead. It goes nowhere unless you choose Settings → Support, which opens a draft in your own mail app with that list in it — you can read it, edit it, and decide whether to send it.

Lead data leaves your phone in exactly two circumstances, and you switch both of them on yourself. Backup, which needs an account and a paid plan; and the AI briefings and drafts described in section 05, which are off until you turn them on. With neither switched on — the state of a new install — nothing you capture is transmitted anywhere at all.

Five things use the network. Only the first two can carry anything about a lead:

  • Backup, if you switch it on. With an account, a booth and a paid plan, leads and note text are copied to our Firestore project so they survive a lost phone and reach your colleagues. Badge photographs and voice recordings are not included — there is no code path that uploads either — and Settings → Privacy tells you which state your phone is in.
  • AI briefings and follow-up drafts, if you switch them on. Off by default. Section 05 sets out exactly what is sent, what is not, and where it goes.
  • The transcription model. If you choose to download it, the app fetches a language model file (about 75 MB) from Hugging Face. That is a plain file download; no data of yours is sent. Turning a voice note into text then runs entirely on your phone, always, with no account and no network — and the audio recording itself never leaves the handset under any setting.
  • Purchases. If a paid plan is offered in your version and you buy one, the purchase is handled by Apple or Google, and their receipt is validated through RevenueCat, our billing provider. They receive an anonymous customer identifier and the purchase itself. They do not receive your leads. We never see your card details.
  • Links you tap. “Find on LinkedIn” opens a search in your own browser, signed in as you. We store no profile and call no data vendor.

If a future version transmits something this page does not describe, this page will be updated before that version ships, and the store listings will change at the same time.

05 The AI features, and what they send

Lanyard can write two things for you: a short briefing about the company and the job title on a badge, and a draft follow-up email based on the voice note you recorded. Both are generated by Google’s Gemini, reached through Firebase AI Logic.

They are off until you turn them on. A new install has them off. An update from an earlier version has them off. Buying a paid plan does not turn them on. They are switched on in Settings → AI, deliberately, after reading the same list you are reading now — and switched off again in the same place, with one tap, taking effect on the very next request.

While they are on, and only when you ask for a briefing or a draft, this is what is sent to Google:

SentNever sent
The company name on the badge, and its website domainAny question about the person. A briefing is asked about a company and a job title; the name is not part of that request and cannot be added to it
The job title printed on the badgeAny badge or business-card photograph
The text of the note you recorded, when you ask for a draftAny audio recording
The lead’s first name — for a follow-up draft only, so the email can open “Hi Sarah,”. Never for a briefingAny email address, phone number or badge ID
One sentence describing what you sell, from your ideal-customer profileAny surname of a lead
Your own name, if you have set one in Settings — for a follow-up draft only, so the email can close with itAnything else about you or your account
The name of the event, as you typed it — for a follow-up draft only, so the email can say where you metWhere or when the badge was scanned

Nothing is sent in the background. Every request follows a button you pressed, on one lead at a time. Nothing is generated while the app is closed, and opening the queue sends nothing.

The feature needs a paid (Blaze) Firebase project, and that is a privacy decision rather than a capacity one. On Google’s free tier the Gemini terms permit Google to use submitted content to improve its products, and permit human reviewers to read it. Those are not terms anyone may accept on behalf of a person whose badge was scanned at a stand, so the feature is not offered there. On the paid tier, Google’s terms say prompts and responses are not used to improve their products.

A briefing is a summary of what the app already holds about a company plus a generalisation about a job title. It is not research about a person, and Lanyard refuses to produce one when the company name is all it has — because a model given only a name writes a confident paragraph about a firm it has never heard of. What is generated is stored on your phone and is never backed up.

The first name in a draft is a greeting, not a question. It is included so the email you are about to send opens the way you would open it yourself. The model is never asked anything about that person, and a draft that comes back containing an email address or a phone number has it stripped out before it is stored — a model must never be the source of a contact detail.

06 What we never do

  • Sell or rent personal data.
  • Share data with advertisers or data brokers.
  • Track you across other apps or websites. Lanyard requests no tracking permission and uses no advertising identifier.
  • Send marketing email to the people you scan.
  • Send anything in bulk on your behalf.
  • Send anything to a model without your having switched that on first.
  • Ask an AI model to invent a fact about a named person, or to invent an email address or a phone number. A briefing names no individual, and a generated draft is stripped of any contact detail the model produced before it is stored.
  • Upload a photograph or an audio recording. Neither leaves your phone under any setting.

07 Keeping and deleting

Data stays on your device until you remove it. Discard a lead and it stops appearing anywhere in the app; a short recoverable window exists so an accidental tap at a busy stand is not permanent. Deleting the app removes the database, the badge images and the voice notes with it.

With backup off, we hold no copy: we cannot delete your leads for you and we cannot recover them if you delete them. With backup on, the copy in your workspace goes when you delete your account — covered on its own page. Briefings and drafts are held only on the phone that generated them and are never backed up, so deleting the app removes them.

08 Rights of the people you scan

Anyone whose details you capture may have the right to ask for a copy of what you hold, to correct it, or to have it erased. Those requests go to you, as the controller. Lanyard is built so you can honour such a request: every lead is visible, editable and deletable in the app, and exportable to CSV, and deleting one removes it from your backed-up copy as well.

09 Children

Lanyard is a business tool for trade-show exhibitors. It is not directed at children and is not designed for or marketed to anyone under 16.

10 Changes to this policy

If this policy changes materially — in particular if a future version transmits something this page does not describe, or turns something on that this page says is off — the date at the top will change and the store listings will be updated at the same time.

11 Contact

Agent M LLC · hello@agentm.co.uk

Kept with the app’s source code and published here unchanged, apart from the contact address.

How AgentM handles data across all its products