Hidden Camera Scan Detector Privacy Policy
Effective Date: May 28, 2026
Last Updated: May 28, 2026
This Privacy Policy explains how AtaForge ("we," "us," or "our") collects, uses, and protects information when you use the Hidden Camera Scan Detector mobile application ("the App"). By using the App, you agree to the practices described in this Policy.
Account information. When you sign in with Apple or Google, we receive your email address and, where you allow it, your name. Apple's Hide My Email relay addresses are accepted and never linked back to your real address.
Support correspondence. If you contact us, we keep the messages and your email address to respond.
Device identifiers. A randomly generated installation ID used to identify your device for push notifications and subscription state.
Push notification tokens. Provided by Apple Push Notification service (APNs) and Firebase Cloud Messaging (FCM). Used solely to deliver alerts you opted in to.
Subscription state. Provided by RevenueCat after purchases on the App Store or Google Play.
Basic technical data. App version, operating system version, and locale, used to provide compatible functionality.
The following scanning data is generated locally and is not transmitted to our servers:
Wi-Fi network scan results (SSIDs, MAC addresses of nearby devices)
Bluetooth and Bluetooth Low Energy (BLE) scan results
Electromagnetic field (EMF) sensor readings
Infrared camera detection results
Audio frequency analysis output
Network traffic inspection results
Scan history, reports, and notes you create
This local data is stored in an encrypted database using SQLCipher (AES-256) and is deleted when you uninstall the App.
We do not access your contacts, photos, calendar, or location history.
We do not record or upload audio or video.
We do not sell or share your personal information for advertising.
We use the information described above to:
Provide and operate the App and your account.
Process subscription purchases and verify entitlements via RevenueCat.
Send transactional emails (welcome message, password reset, account deletion confirmation, billing issue alerts).
Send the push notifications you opted in to.
Provide customer support.
Detect and prevent abuse, fraud, and security incidents.
Comply with legal obligations.
We use analytics (PostHog) only when you opt in via the in-app consent banner. Analytics events are scrubbed of personal identifiers (email addresses, JWTs, UUIDs) before they leave your device.
Where the GDPR applies, we rely on:
Performance of a contract — to provide the App and process your subscription.
Legitimate interests — to keep the service secure and to improve it.
Consent — for optional analytics and marketing emails.
Legal obligation — to comply with tax, accounting, and law-enforcement requirements.
We share information only with the following processors, each bound by contract to use it only as we instruct:
Apple Inc. — App Store distribution, Sign in with Apple, push delivery (APNs).
Google LLC — Google Play distribution, Google Sign-In, push delivery (FCM).
RevenueCat, Inc. — subscription verification and webhook events.
PostHog — product analytics (only when you opt in).
Railway — backend hosting (United States / EU regions).
Yandex — outbound email delivery.
We do not sell or rent your personal information. We may disclose information when required by valid legal process or to protect the rights, safety, or property of users, the public, or AtaForge.
Some of our processors are located in the United States. Where the GDPR applies, we rely on the European Commission's Standard Contractual Clauses for these transfers. By using the App you acknowledge that your information may be processed in countries other than your own.
Account data is retained while your account is active.
Push tokens are deleted from our servers immediately when you uninstall the App or sign out.
Email logs are kept for 30 days for deliverability troubleshooting, then deleted.
Local scan data is kept on your device until you delete it or uninstall the App.
When you request account deletion, we mark your account as "pending deletion" and finally erase it after 30 days. During that period you may sign in to cancel the request.
Depending on where you live you may have the right to:
Access the personal information we hold about you.
Correct inaccurate information.
Delete your information ("right to be forgotten").
Restrict or object to certain processing.
Receive a portable copy of your data.
Withdraw consent for optional processing.
Lodge a complaint with a supervisory authority.
To exercise these rights, email ataforge@gmail.com from the address associated with your account. We respond within 30 days.
Hidden Camera Scan Detector is rated 4+ but is intended for adults performing security inspections. We do not knowingly collect personal information from children under 13 (or the equivalent minimum age in your country). If you believe a child has provided us information, contact us and we will delete it.
We protect your information using:
TLS encryption for all data in transit.
AES-256 encryption (SQLCipher) for local data on your device.
Certificate pinning between the App and our backend.
Short-lived JWT access tokens with refresh-token rotation.
A 3-session-per-user cap to limit credential reuse.
No method of electronic storage or transmission is 100% secure. If we become aware of a breach affecting your information, we will notify you and the relevant authorities as required by applicable law.
We may update this Policy from time to time. We will post the new effective date at the top and, if changes are material, notify you in the App or by email at least 30 days before they take effect.
AtaForge
Email: ataforge@gmail.com
For California residents: Information about our practices under the California Consumer Privacy Act ("CCPA") is provided above. We do not sell personal information.
For EEA / UK residents: Where required, our EU representative is AtaForge, contactable at ataforge@gmail.com.