BlinkCard SDK releases published on GitHub on 25 Sep (iOS v3000.1.0, Android v3001.0.0, with Web 3001.0.0 on npm on 24 Sep) make redaction of sensitive card data the default. The card number is now redacted in both the captured image and the returned result with only the first 4 and last 4 digits visible, and the CVV is fully redacted; IBAN and cardholder name are not redacted.
Our readIssuers, lenders and payments firms that capture cards in their apps now receive masked PAN and no CVV from scans unless they change the setting, which limits how much full card data lands in their systems and logs and bears directly on PCI DSS scope.