QuanCard
中

QuanCard Server · Self-hosted

Your cards,
synced on your own server.

Run the sync service and the web vault on a server you control. iPhone and browser stay in sync, end-to-end encrypted, while the server stores only ciphertext it cannot read. Open source, auditable, yours.

QuanCard web vault: cards grouped by region with sidebar navigation

Sync across devices

iPhone and the web share one revision protocol, so a change on either side appears on the other.

Fully self-hosted

One Docker Compose file with automatic HTTPS. You choose the domain, the backups and when to upgrade.

Zero-knowledge security

Encryption happens in the browser and on the iPhone. The server never sees a card number, a key or your password.

Scan once. Both sides are ready.

Create a one-time QR code in the browser and scan it with your iPhone. The key goes from the browser to the phone and never passes through the server.

  • One-time pairing code

    The code expires after 10 minutes and works once. You confirm your password before it appears.

  • Confirmed on both sides

    The moment the phone connects, the browser confirms it. Both screens play the same linked animation and show the first sync.

  • Always current

    The web refreshes when you return to the tab, and every 60 seconds while it is open. The iPhone syncs on its own schedule.

Pairing complete: iPhone connected, synced, all set

The server stores everything. It can read none of it.

QuanCard uses an end-to-end encrypted key hierarchy. Even if the server, its database or a backup falls into the wrong hands, card details stay ciphertext.

  1. 01Your passwordUsed only in the browser
  2. 02Argon2id · 64 MiBDerives an authentication key and an encryption key
  3. 03Account keyWrapped by your password
  4. 04Vault keyRandom 256-bit, wrapped by the account key
  5. 05AES-256-GCMEach item sealed as an immutable revision

The server sees

  • Account names and sign-in times
  • How many revisions, their sizes and times
  • The names of paired devices

The server never sees

  • Card numbers, expiry, security codes, account numbers
  • Notes, tags and card photos
  • Your password or any decryption key

An honest boundary: a compromised server could serve modified web code, a limit shared by every browser-based encrypted app. Run the server yourself and keep it updated; on hosts you do not trust, prefer the iPhone app. Read the threat model

Conflict centre: field differences for two items with choices

When edits collide, you decide.

Two devices changed the same card while offline? QuanCard never lets a device clock pick a winner. Identical copies are folded automatically; real differences go to the conflict centre, compared field by field.

  • Every differing field is marked; secrets only show "differs"
  • Choose per item, or in bulk: most recent edit, one copy of each sample, or keep all as copies
  • Every bulk action lists exactly what it will do first

A real desktop app.

The web vault is not a lite version. It shares card colours and sample data with the iPhone, with interactions built for keyboards and large screens.

⌘K command palette

Find cards and accounts, or run an action.

Sidebar and sheets

Browse by region and favourites; details and edits open in a side sheet.

Masked by default

Card numbers show the last four digits; full details need your password again.

Family members

The owner invites; each member has a separate account and a separately encrypted vault.

Two-step and audit

TOTP with recovery codes, rate limits and lockout, an append-only activity log.

Open and extensible

AGPL-3.0 open source; protocol specs and test vectors under Apache-2.0.

The web vault in a phone browser

Three commands. Your own sync service.

You need a Linux host with Docker, a domain pointing to it, and ports 80 and 443 open. One vCPU and 512 MB of memory are enough for a household.

Then open your domain, create the owner account, and pair your iPhone with a scan.

Read the install guide
  1. # Get the sourcegit clone https://github.com/zoolapp/quancard-server.git && cd quancard-server
  2. # Write the configuration and a one-time setup token./scripts/init-env.sh vault.example.com
  3. # Start it, with automatic HTTPS certificatesdocker compose up -d --wait

About self-hosting

Does it cost anything?

The server and web vault are open source under AGPL-3.0, free to use, modify and deploy. You pay only for your own server.

How is it different from iCloud sync?

iCloud follows your Apple account and needs no upkeep. Self-hosting keeps the data on a server you control and adds the web vault and family accounts. Use one at a time; disconnect before switching, and your local collection stays.

What if I forget my password?

It cannot be reset: the server never knows your password, which is the price of zero knowledge. A paired iPhone still keeps its local copy. Use a long passphrase and turn on two-step verification.

What happens if the server is compromised?

The database and backups hold only ciphertext and verifiers, so a leak reveals no card details. An attacker could alter the web code to capture passwords typed later, so keep the system and image updated, and prefer the iPhone app on hosts you do not trust.

Can I use only the web, without an iPhone?

Yes. The web vault supports adding, editing and deleting, card photos and routing details, and can be installed as a desktop app (PWA).

What stage is it at?

A development preview without an independent security audit. Self-hosted sync on iPhone opens with the App Store release. You are responsible for deployment and maintenance.

Ready to deploy?

The install guide covers quick deployment, reverse proxies, configuration, pairing, backups and upgrades.

Screenshots use the built-in sample data (public test numbers that cannot pay). Card artwork and trademarks belong to their owners.

QuanCard. Coming to iPhone.

Join the app waitlist for early-bird pricing at launch.

The waitlist is open

We’ll email you when the app launches. Already joined? Keep your confirmation email; no need to join again.

By continuing, you agree to emails about your app reservation and launch. Privacy note