← cardwarden.app

Klarna Killed Stocard. So I Built CardWarden.

By Bruce Mok · · Part 1 of 2 · 10 min read

There was a time when nearly fifty million people kept their loyalty cards in a single app. It was called Stocard, and it did one thing brilliantly: it stored your barcodes so you could leave the plastic at home. No frills, no upsells, no financial products wedged between you and your grocery rewards. Just scan and go.

Then Klarna bought it. And everything fell apart.

This is the story of how that acquisition, a handful of frustrating personal experiences, and a password manager called Bitwarden converged into a design problem I couldn't leave alone. I wanted a card manager that could sync across a household without requiring me to hand shopping data to an advertising platform or a fintech funnel. That problem eventually became CardWarden.

The Rise and Fall of a Beloved App

Stocard was founded around 2011 by a group of University of Mannheim graduates in Germany and grew into one of the most downloaded loyalty card apps in the world. By 2021, it had amassed somewhere between 49 and 60 million users across more than 40 countries. The pitch was disarmingly simple: digitize your loyalty cards, organize them in one place, and never fumble through your wallet at checkout again. Users loved it because it stayed in its lane. It was fast, it was clean, and it didn't try to sell you anything. It even had Apple Watch support - raise your wrist, barcode scans instantly.

In July 2021, Swedish fintech giant Klarna acquired Stocard for a reported sum exceeding €110 million. On paper, it made sense - Klarna was building a "super app" for shopping, and Stocard's enormous user base was the perfect funnel. In practice, it was the beginning of the end.

At first, the changes were subtle. A Klarna logo here, a shopping suggestion there. But by October 2024, Klarna folded Stocard into its own app entirely. Users who just wanted to scan a Tesco Clubcard were now being funneled through a buy-now-pay-later platform. By March 2026, Stocard was officially shut down, with users given roughly two weeks to migrate their cards to Klarna or lose everything.

The backlash was immediate, vocal, and entirely predictable.

49 Million Users, Zero Consultation

I spent a considerable amount of time reading through app store reviews, Reddit threads, and forum posts from former Stocard users after the forced migration. The sentiment wasn't just negative - it was visceral. People felt betrayed. They had trusted an app with years of carefully organized loyalty cards, and that trust was handed off to a company whose core business is consumer lending.

Here is a sample of what actual users had to say:

"Stocard was a perfectly simple fidelity card storage. This forced change is not working well."

- App Store review

"It is clearly not designed for loyalty cards. It takes a serious back seat and is missing all the features."

- App Store review

"I didn't want to gift my data to Klarna."

- Reddit user

"They've changed their mind: they will stop the Stocard app and are pushing me into moving everything into the Klarna app - which is something I don't want because that's all about purchasing and payment."

- Online forum

The complaints clustered around a few recurring themes: the forced creation of a Klarna financial account just to access loyalty cards, the loss of Apple Watch support, the disappearance of custom card sorting and location-based suggestions, a mandatory phone number requirement, and perhaps most damningly, cards no longer working offline. Users reported the app "hanging 9 times out of 10" at checkout - the one moment when reliability matters most.

But beneath all the feature complaints was a deeper grievance about privacy. Klarna's data collection practices are, by every reasonable measure, significantly more aggressive than what Stocard had required. Users who once handed over nothing more than a barcode image were now being asked to create a financial profile. The consensus in online discussions was blunt: Klarna treated 49 million Stocard users not as a community to be served, but as leads to be funneled into a payments platform.

The Landscape After Stocard

The void left by Stocard's demise spawned a wave of alternatives, each solving a different slice of the problem. I tried most of them. Several are excellent at what they set out to do. The gap I kept hitting was narrower and more personal: household sync with encryption I could trust, without living inside someone else's advertising or payments business.

SuperCards

SuperCards is probably the closest spiritual successor to what Stocard once was. Built by members of the original Stocard team, it is simple, free, and blissfully ad-free. No tracking, no signup required, over 4,000 card templates. It does exactly what a loyalty card app should do and nothing more. I genuinely like it - it is probably my favorite among the alternatives.

SuperCards does offer a form of cloud backup - you can generate a QR code or backup link to transfer your cards to another device, which is a thoughtful touch. But it is not the kind of always-on, multi-device sync where a card added on one phone automatically appears on another. If you and your spouse both need the same Costco card, you are still managing two separate copies that will not stay in sync when one of you uses a gift card at the store.

Catima

The open-source option. Available on F-Droid, fully offline, zero data collection, no internet permission whatsoever. Privacy purists adore it, and rightfully so. But it is Android-only, has no PIN or biometric lock, no cloud backup, and again - no family sharing. If you lose your phone, you lose your cards.

Google Wallet & Apple Wallet

The native solutions exist, and for many people they are enough. Free card managers from Google and Apple cover a lot of everyday use. They also come with real limitations that power users hit quickly. Google Wallet caps you at 10 gift card additions per 30-day period and only 5 per merchant. Neither platform supports arbitrary barcode cards, and neither offers any mechanism to check gift card balances or share cards with family members. You can't even set a custom sort order.

There is also a trust tradeoff. Those wallets are free in part because they sit inside much larger businesses whose economics are not limited to a standalone card manager. For some people that is fine; for others, shopping behavior attached to advertising profiles is exactly what they were hoping to avoid.

The Common Thread

What struck me most about the post-Stocard landscape is that nearly every alternative proudly advertises that it works 100% offline, as though connecting to the internet is inherently dangerous. The messaging implies that having your data leave your device and keeping it truly secure are somehow mutually exclusive.

That is a false choice. Some apps do let you log in with the same credentials on multiple devices and sync everything across them - but I could not find a single one that offered that kind of sync while also properly supporting gift cards with balance tracking. It was always one or the other.

And I knew it was a false choice, because I had been using an app for years that proved otherwise.

• • •

The Password Manager That Changed My Mind

In 2015, LogMeIn acquired LastPass - at the time, one of the most popular password managers in the world - for roughly $110 million. A developer named Kyle Spearrin watched that acquisition unfold and saw an opportunity. As he later put it: "I looked at what they had built, and the terms of the acquisition, and said to myself that I think I could improve upon this market space significantly."

Spearrin launched Bitwarden in 2016 as a side project - a Chrome extension, a mobile app, and a web vault, all built by one person. His core thesis was that a password manager should use zero-knowledge encryption - meaning the company operating the servers literally cannot read your data even if they wanted to. Your passwords are encrypted on your device, and only you hold the key.

His timing proved prescient. In 2022, LastPass suffered a catastrophic data breach that exposed encrypted user vaults and unencrypted metadata including website URLs, putting millions of users at risk. Bitwarden, meanwhile, had grown from a solo side project to a tool used by millions of individuals and organizations including NASA. One developer, building the right thing for the right reasons, had created a genuine industry alternative.

I have been a Bitwarden user for years. My wife and I share a vault for common passwords - things like Netflix and other accounts we both use - and it is always in sync. I have even added credit cards to it, with autofill straight to online shopping cart payment screens, which is genuinely convenient. I once tried adding a few gift cards that do not require a barcode to function, like eBay gift cards, and that worked fine too. But Bitwarden cannot display a barcode for a supermarket gift card, of course - it is a password manager, not a card wallet.

Still, Bitwarden is the app that taught me a critical lesson: you can have cloud sync, multi-device access, and family sharing without sacrificing privacy or security. You just need to do the cryptography right.

That lesson sat in the back of my mind for a long time. It took a personal annoyance to bring it to the surface.

• • •

The Gift Card Problem

My wife and I are gift card stackers. Whenever a grocery chain runs a promotion - 10% off, bonus points, buy-one-get-one - we stock up on discounted gift cards. Over the course of a year, the savings add up meaningfully. It is one of those boring personal finance tricks that actually works.

The problem is managing those cards.

Our preferred grocery chain doesn't have an official app that supports gift card storage. So we used a third-party app purpose-built for that specific retailer. It was basic - scan the barcode, store it locally, and tap a button to open the retailer's balance-check website with the card number and PIN pre-filled. After battling through a CAPTCHA to prove you are human, the page would pull back the current balance and update the app.

It worked. Barely. Two problems made it genuinely painful:

Problem one: duplication. Every time I bought a new gift card, I had to scan it into my phone, and then scan it again on my wife's phone. Two devices, two scans, every single time. There was no sync, no sharing, no way to add a card once and have it appear everywhere.

Problem two: balance drift. When one of us partially used a card at checkout, the balance would update on that person's device only. The other person would still see the old balance. To fix it, you had to open the app on the other device, tap "check balance," and fight through the CAPTCHA mini-game all over again. The app did not even support manually typing in a new balance - presumably to prevent human error - which meant there was no shortcut. Every partial spend triggered a ritual of verification on two devices.

We lived with it. The savings were worth the friction. Until the day the app introduced full-screen interstitial ads.

I was standing in the checkout line, groceries on the belt, and when I opened the app to scan a gift card, a full-screen ad covered my barcode. It was one of those moments where a minor inconvenience crystallizes a long-simmering frustration into a decision. I turned to my wife and said, "I'm building our own app."

The Idea Takes Shape

The design thesis was clear from the beginning. Keep what the best loyalty card apps already do well - the simplicity of SuperCards, the barcode storage of the old Stocard, the balance-checking workflow of niche gift card apps - and apply the security model I already trusted in Bitwarden: encrypt on device, sync over the network, and keep the server unable to read the contents.

In shorthand, that is how I thought about it: Stocard's job, Bitwarden's architecture.

I have been building Android apps professionally for over 15 years and working in software for more than 20. I shipped my first app - a small utility called Credit Card Manager - over a decade ago, and it is still quietly doing its thing on the Google Play Store today. CardWarden is different mainly in motive: it is the app I wished existed for a problem I live with every week, so I built it from scratch.

There was just one catch: building it would be an enormous amount of work.

I had the idea for a few years before I wrote a line of code. Full-time startup work - building other people’s apps - plus family life (I have a wonderful little daughter; she is six now) left very little spare capacity. I was also, honestly, lazy about starting. Not because the idea felt wrong, but because I estimated that if I only worked on it as a side project at night, it would take at least three to four years to build properly. So the ambition stayed parked.

Early this year, the startup I had joined ran out of money before it ever found revenue. Suddenly I was out of work. The job market has been pretty rough, so while I looked for the next role I also started poking at Claude Code. I had seen the “non-coders shipping apps in four days” hype and was skeptical - but I reasoned that if those tools could help a beginner that much, maybe they could help someone with twenty years of software experience tear through something genuinely complex.

So I started CardWarden from the ground up. Early on I spent time designing the architecture and writing a baseline the AI agents could actually follow - constraints, patterns, where the sharp edges were. Once that scaffolding existed, the workflow stopped feeling like “using a tool” and started feeling like having a few very eager mid-to-senior developers working on several tasks at once. Throw something at them and they come back asking what’s next. Sometimes I want to tell them to chill. Sometimes they fix the bug I asked about and casually mention another one at line 247. Yes. Yes, please fix that too.

What I still review carefully myself are the core parts: anything touching security or encryption on the client or the backend. Mundane UI work I mostly leave to the mid-seniors. I only step in when there is a real performance problem worth caring about - no need to pre-optimize layout that is not hurting anyone yet. I also had them write meaningful unit tests alongside each feature, which helped confidence grow with the codebase.

I am still learning the rhythms of this way of working, and so far I am enjoying it - until I hit the five-hour limit, or worse the weekly limit. Then I rediscover the joys of mundane tasks like designing App Store screenshots.

A project I had parked for years as “three to four years of nights-only side-project time” became reachable in a fraction of that. That still feels a little surreal.

• • •

If you have made it this far, thank you for reading. Part 2 covers how CardWarden was actually built - the design decisions, day-one foundations like shared Android/iOS code and reactive UI, the security architecture, what ended up in the app, and why monetization is structured the way it is.

Continue to Part 2: How I Built CardWarden. →