false for schemes that must never be handed to the system from untrusted card content: local/script payloads (file, javascript, data) and intent (arbitrary component targeting). Deep links and web/mail/tel/sms pass through — same policy as the iOS cell.