Privacy Policy for PDFScanner
Effective Date: March 6, 2026
PDFScanner is designed with a local-first architecture: your documents are stored on your device by default, we do not operate document-hosting servers, and documents are transmitted only when you explicitly export, share, or enable cloud sync.
This Privacy Policy explains how PDFScanner ("we," "us," or "our") handles personal information when you use the PDFScanner iOS application (the "App").
Data Controller
PDFScanner is operated by Dilshodi Kahori. For privacy questions or requests, you can contact us through the support email listed on the PDFScanner App Store page. We handle privacy requests in accordance with applicable data protection laws.
1. Introduction
This Policy applies to your use of PDFScanner on iOS worldwide, including where laws such as the EU General Data Protection Regulation (GDPR), California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), and Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA) apply.
By using PDFScanner, you agree to the practices described in this Privacy Policy.
Our Privacy Principles
- Documents remain on your device by default.
- We minimize personal data collection wherever possible.
- We do not operate document-hosting servers for user files.
- We use trusted platform providers (such as Apple and Google infrastructure) only where needed to provide features you request.
- We aim to provide clear, specific, and up-to-date privacy disclosures.
2. Information We Collect
A. Data categories (including Apple Privacy Label categories)
1. Identifiers
- Examples: Push token identifiers (APNs token, Firebase Cloud Messaging token), app-specific identifiers generated by service providers.
- Purpose: Deliver push notifications and maintain messaging functionality.
- Shared with: Apple (APNs), Google Firebase Cloud Messaging.
2. Usage Data
- Current status: In this app version, in-app analytics events are logged locally on-device (using Apple os.Logger) and are not sent to our own servers.
- Purpose: Local diagnostics and development troubleshooting.
- Shared with: Not sent to our backend.
3. Diagnostics
- Current status: We do not use Firebase Crashlytics in this version.
- Purpose: Local debugging logs and operational troubleshooting.
- Shared with: Not sent to our backend.
4. Purchases
- Examples: Subscription product IDs, transaction verification/entitlement status.
- Purpose: Enable premium features, restore purchases, and verify subscription state.
- Shared with: Apple (StoreKit/App Store).
5. Device Information
- Examples: Device/app metadata required by Apple and Google infrastructure for push delivery and service integrity.
- Purpose: Push delivery, anti-abuse, security, and platform compatibility.
- Shared with: Apple and Google service infrastructure as applicable.
6. Advertising Data
- Current status: Google AdMob is not enabled in this app version.
- If enabled in a future release: Advertising identifiers and limited device/network metadata may be processed for ad delivery, measurement, and fraud prevention.
B. Permissions and user-provided content
Depending on features you use, we may process:
- Camera captures (for scanning documents and codes).
- Photos you explicitly select via the iOS photo picker (for Image-to-PDF workflows).
- Contact card data only when you choose "Add to Contacts" from scanned vCard content.
- Files you choose to export/share.
C. Data We Do Not Collect
We do not collect or store on our own servers:
- Your scanned document contents by default.
- Payment card numbers or card security codes.
- Biometric identifiers.
- Precise geolocation.
- Government-issued identification numbers (unless contained in your own documents you choose to process on-device).
3. How We Use Information
We use information to:
- Provide core app functions (scan, OCR, edit, export, share, compress, watermark, merge, split, protect/unlock PDFs).
- Deliver push notifications if you grant permission.
- Verify and manage subscription entitlements via Apple StoreKit.
- Support optional cloud synchronization/storage features when enabled and available.
- Maintain service reliability, security, and fraud prevention.
- Comply with legal obligations.
Legal bases (GDPR)
Where GDPR applies, we rely on:
- Contract necessity: To provide features you request.
- Consent: For permissions (e.g., notifications, camera, contacts where applicable).
- Legitimate interests: Security, abuse prevention, reliability.
- Legal obligation: Compliance with tax/accounting/regulatory requirements.
4. Permissions We Request
PDFScanner requests only permissions tied to specific user actions:
All permissions are optional, are used only when you use the related feature, and can be revoked at any time in iOS Settings.
1. Camera
- Why: Scan paper documents and capture QR/barcode content.
2. Photos access (via iOS Photos Picker)
- Why: Import selected photos into PDFs.
- Note: You select specific photos in Apple’s picker flow.
3. Push Notifications
- Why: Send product updates, account/subscription-related notices, and feature announcements.
- Control: You can disable notifications in iOS Settings at any time.
4. Contacts (only for vCard action)
- Why: Save scanned vCard contact data to your Contacts when you explicitly choose that action.
5. User Documents & Storage
Local-first document handling (critical transparency)
1. Stored locally by default
- Scanned/imported documents are stored on your device (app-local storage) by default.
- In the current app build, storage is configured local-first by default.
2. No developer document cloud
- We do not upload or store user documents on developer-operated servers as part of normal app use.
Document Privacy
- The developer cannot access, view, analyze, or store the contents of your documents on developer-operated servers.
- Document processing is performed locally on your device, and documents remain private unless you explicitly choose to export, share, or synchronize them using external services.
3. When documents may leave your device
- Documents leave your device only when you choose one of these actions:
- Export or share files (e.g., via iOS share sheet, email, messaging, third-party apps).
- Use iCloud/CloudKit synchronization features (where available and enabled).
- Use external third-party services that you select.
4. On-device processing
- Scanning, cropping, OCR text extraction, watermarking, PDF transformation, and compression are performed on-device whenever possible.
- OCR text processing occurs locally on your device whenever possible, and document text is not uploaded to external servers for OCR processing.
5. Trash handling
- Deleted files are moved to in-app Trash and may be auto-purged after a retention window (currently 30 days).
6. Third-Party Services
We use platform and infrastructure providers. Their policies also apply to their processing.
1. Apple App Store / StoreKit
- Use: In-app subscriptions and purchase restoration.
- Data: Apple processes payment, billing, and transaction data.
- We receive: Subscription/entitlement status and transaction verification results, not full card details.
2. Apple Push Notification service (APNs)
- Use: Push delivery.
- Data: Push token and notification routing metadata.
- Provider processing: Apple may process this information to deliver notifications.
3. Apple iCloud / CloudKit
- Use: Optional cloud sync/storage functionality (when enabled/available).
- Data: Document files and metadata necessary for sync in your personal iCloud account.
- Account association: Cloud-synced data is associated with your Apple ID and managed within Apple’s iCloud ecosystem.
- Provider processing: Apple manages the cloud infrastructure and processes data for iCloud/CloudKit operation.
- Developer hosting: We do not host these cloud-synced documents on developer-operated servers.
4. Google Firebase Cloud Messaging (FCM)
- Use: Push messaging infrastructure.
- Data: FCM registration token and device/app metadata required for message delivery.
- Provider processing: Google may process such data under Firebase/Google policies.
- SDK dependency note: Firebase Messaging can include supporting Google/Firebase libraries as package dependencies (for example, GoogleAppMeasurement, GoogleDataTransport, GoogleUtilities, App Check, gRPC, GTMSessionFetcher, Promises, nanopb, and leveldb) to support SDK operation, reliability, and delivery.
5. Firebase Analytics
- Current status: Not actively configured as a standalone analytics feature in this app version.
6. Firebase Crashlytics
- Current status: Not implemented in this app version.
7. Google AdMob
- Current status: Not enabled in this app version.
- Dependency note: The package dependency tree may include Google advertising-related support libraries, but AdMob ads are not currently enabled.
Third-party policy references:
- Apple Privacy Policy: https://www.apple.com/legal/privacy/
- Firebase Data Processing and Privacy: https://firebase.google.com/support/privacy
- Google Privacy Policy: https://policies.google.com/privacy
- Google AdMob Policy Center: https://support.google.com/admob/answer/6128543
7. Advertising
PDFScanner currently does not enable Google AdMob advertising.
Advertising features may be introduced in future versions of the app, and this Privacy Policy and App Store privacy disclosures will be updated if advertising practices change.
If advertising is enabled in a future release:
- Advertising identifiers may be used by Google AdMob, together with limited device/network data for ad delivery and measurement.
- Ads may be personalized or non-personalized depending on your consent choices and applicable law.
- For users in the EEA/UK/Switzerland and other required jurisdictions, consent will be requested where legally required before personalized advertising.
- You can opt out of personalized advertising through your device settings.
- We will update this Policy and App Store privacy disclosures if ad practices change.
8. No Sale of Personal Information
PDFScanner does not sell personal information. We do not trade, broker, or sell your personal information to third parties.
9. Subscriptions & Payments
Subscriptions are handled through Apple’s in-app purchase system.
1. Apple manages billing and payment information.
2. We do not receive your full payment card details.
3. We receive transaction outcomes and entitlement status required to unlock premium features.
4. Subscription management, cancellation, and refunds are governed by Apple’s billing policies and your Apple account settings.
10. Data Retention
We retain information only as long as needed for the purposes described above:
1. User documents
- Stored locally until you delete them.
- Items moved to Trash may be automatically removed after approximately 30 days.
2. Analytics/diagnostic logs
- Current version: event logs are local on-device logs, retained per system/device log behavior.
- We do not maintain a separate analytics database for these local events.
3. Crash reports
- Current version: no Firebase Crashlytics integration.
4. Support communications
- If you contact support outside the app (e.g., support email listed on the App Store page), we retain communications as needed to respond, resolve issues, and satisfy legal obligations.
5. Subscription records
- Entitlement state is processed as needed to provide premium access.
- Transaction handling and primary billing records are maintained by Apple.
11. Security
We use reasonable technical and organizational safeguards, including:
- iOS platform security controls, app sandboxing, and secure platform APIs.
- Least-privilege access to permissions (camera, notifications, contacts only when needed).
- Encrypted communication where applicable (for example, Apple/Google infrastructure channels used for push and cloud services).
- Operational safeguards to reduce unauthorized access, alteration, disclosure, or loss.
No method of transmission or storage is 100% secure, but we implement measures appropriate to the risks.
12. User Rights
Depending on your jurisdiction, you may have rights regarding personal information.
A. GDPR (EEA/UK, where applicable)
You may have rights to:
- Access personal data.
- Correct inaccurate data.
- Delete data.
- Restrict or object to certain processing.
- Data portability.
- Withdraw consent at any time (where processing is based on consent).
- Lodge a complaint with your local supervisory authority.
B. CCPA/CPRA (California)
You may have rights to:
- Know/access categories and specific personal information.
- Request deletion.
- Request correction.
- Limit use/disclosure of sensitive personal information (where applicable).
- Opt out of sale or sharing for cross-context behavioral advertising.
Current statement: We do not sell personal information and do not enable AdMob in this version.
C. PIPEDA (Canada)
You may request:
- Access to personal information.
- Correction of inaccuracies.
- Information about how your data is used and disclosed.
- Withdrawal of consent, subject to legal/contractual limits.
D. How to submit a privacy request
Submit requests using the support contact listed on the PDFScanner App Store product page, with subject line: "Privacy Request".
13. International Transfers
If you use third-party services (such as Apple iCloud/CloudKit or Google Firebase Cloud Messaging), your information may be processed in countries other than your own.
Where required, service providers apply transfer safeguards under their legal frameworks (for example, contractual safeguards and comparable protection mechanisms).
14. Children’s Privacy
PDFScanner is not directed to children under 13 and is not intended to knowingly collect personal information from children under 13.
If you believe a child has provided personal information, contact us through the support contact listed on the App Store page, and we will take appropriate steps.
15. Changes to This Policy
We may update this Privacy Policy from time to time to reflect legal, technical, or product changes.
When we make material changes, we will update the "Effective Date" and, where required, provide additional notice.
16. Contact Information
For privacy questions or rights requests, use the support contact listed on the PDFScanner App Store product page and include:
- Your request type (access, deletion, correction, consent withdrawal, etc.)
- Your country/state of residence
- The email address associated with your Apple account communication (if relevant)
This helps us process your request efficiently and in compliance with applicable law.