Last updated: September 29, 2026
Applies to: All Document Reader version 0.1.0 and later
Developer: Muhammad Ishfaq
Contact: ishfaqcompk6@gmail.com
This Privacy Policy explains what All Document Reader ("the App", "we", "us") does with information when you use it. The App opens and reads PDF, Word, Excel, PowerPoint and text files, and includes PDF tools (scan to PDF, images to PDF, merge, split, compress, protect, unlock and PDF to images). This policy describes all of it.
Your documents stay on your device. We have no server and no account system. We cannot see your files, file names, folders or searches.
At launch, the App is completely free with no ads. Every feature is unlocked for everyone.
Later, we plan to add ads and a Premium upgrade. When that happens, free users will see ads from Google AdMob, and an optional Premium purchase through Google Play will remove the ads and unlock the premium PDF tools. This policy already describes how both will work (sections 9 and 10).
We collect anonymous usage statistics and crash reports through Google Firebase. They describe how features are used, not what your documents contain.
All of the following happens locally. Nothing is uploaded and nothing is processed on a server:
Finding and listing the documents on your device, sorting and filtering them by type, and searching them by name.
Opening and reading PDF, Word (doc/docx), Excel (xls/xlsx), PowerPoint (ppt/pptx) and text files. The PDF engine and the Office document engine are built into the App.
Managing files: rename, delete, favorite, bookmark a page, and remembering the page you stopped at.
All PDF tools: scan to PDF, images to PDF, merge, split, compress, protect with a password, unlock, and PDF to images.
We do not upload, transmit or back up your document contents, file names or folder structure to any server of ours. The App has no cloud storage and no user accounts.
The App requests broad storage access ("All files access", MANAGE_EXTERNAL_STORAGE, on Android 11 and newer). Android hides non-media files such as PDF, Word and Excel from normal apps, so a document reader needs this access to:
Scan your device storage to find and list your documents.
Read a document so you can open, view, print or share it.
Rename or delete a document when you ask it to.
Save the results of the PDF tools (a new, merged, split, compressed, protected or unlocked PDF, or exported images) into normal folders on your device.
On Android 12L and older, the App uses the older storage permission instead. On Android 9 and older, it also uses the write permission so the PDF tools can save their output.
None of this leaves your device.
When you tap Share, Open with or Print, the App passes that one document to the app or printer you pick, using Android's standard share, open and print screens. What happens to the document after that is governed by the app or print service you chose, not by us.
The camera is used in one place only: Scan to PDF, and only while that screen is open.
You photograph pages, and they become a PDF that you save.
While you scan, the photos are kept in the App's private temporary storage. They are not added to your gallery and are not uploaded. They are deleted when you save or discard the scan, and also the next time the App starts.
The App never uses the camera in the background. Camera hardware is marked optional, so the App still installs and works on devices without a camera.
Images to PDF uses Android's system photo picker. The App can only see the photos you pick, and does not get access to your whole gallery.
We use Google Firebase for four things.
Firebase Analytics. The App records a small set of events:
which screens you open;
when you change the app language;
which PDF tool you ran, whether it succeeded, failed or was cancelled, how many files went into it, and how long it took;
once Premium is available, the purchase steps (paywall shown, purchase started, completed, cancelled or failed, and the product ID).
These events do not include your file names, document contents or search text. Firebase also records standard information such as device model, OS version, app version, language, country (derived from your IP address) and an app-instance identifier.
Firebase Crashlytics. If the App crashes or hits a serious error, a crash report is sent so we can fix the bug. It includes the stack trace, device model, OS version, app version and similar technical details. It can also include short technical log messages from just before the error. We attach no name, email or account to these reports. However, error messages produced by Android or by the App can sometimes contain the name of a document involved in the failed operation, for example a PDF you were trying to create. Crash reporting runs in the released app only.
Firebase Remote Config. This lets us change certain settings without shipping a new version, for example ad frequency and placement, the "update required" and "update available" prompts, and maintenance notices. It sends only settings from us to the App. It does not carry any personal data from you.
Firebase Cloud Messaging (push notifications). The App can receive notifications, such as news about a new version. Firebase gives your device a push token for this. The App does not send that token to any server of ours. Notifications are shown only if you allow notifications.
Firebase also generates an installation identifier for the App on your device, which Google uses to keep these statistics consistent.
In-app updates: the App asks Google Play whether a newer version is available and, if so, can download and install it through Google Play. There is an "Auto update" switch in Settings. Google Play handles the check and the download.
Rate the app: the App may show Google Play's built-in review prompt, or open the App's Play Store page. Your rating and review are handled by Google Play; we never see who left which review.
If you email us for support or feedback, we receive whatever you put in that email, including your email address. We use it only to reply to you.
The App keeps the following on your device, and nowhere else:
your settings (theme, language, auto update);
your favorites, including the name, size and location of each favorite document;
recently opened documents, the page you stopped at in each PDF, and your page bookmarks;
your recent search terms;
your Premium status, once Premium is available.
If device backup is switched on, Android Auto Backup may include this app data (settings, favorites, recent documents, bookmarks and recent searches) in the backup of your device to your own Google account. Google handles that backup; it is not sent to us. Your actual documents are not part of the App's backup.
Uninstalling the App, or clearing its storage in Android Settings, removes all of the above from your device.
At launch, the App shows no ads. Every user currently has all features unlocked for free. The Google Mobile Ads SDK is already built into the App and starts up with it, but no ads are requested or shown.
We plan to turn on ads in a future update. When we do, free users will see ads from Google AdMob:
a full-screen (interstitial) ad when the App starts;
occasional full-screen ads at natural moments, such as opening or closing a document, or opening or finishing a tool. These are frequency-capped;
small "native" ads on screens such as Files, Browse, Search, Favorites, Tools, Settings and the document reader;
an app-open ad when you return to the App.
Buying Premium (section 10) removes all of them.
To show and measure ads, the AdMob SDK may collect and process the following on Google's behalf:
your device's advertising ID, which is a resettable identifier, not your name, email or phone number;
general device information, such as device model, OS version, language, and approximate location derived from your IP address;
ad interaction data, such as impressions, clicks and whether an ad loaded.
We do not receive or store this data ourselves. Google processes it under the Google Privacy Policy and How Google uses information from sites or apps that use our services.
Consent. When ads are turned on, users in regions that require it (the EEA, the UK, Switzerland and certain US states) will see a Google User Messaging Platform (UMP) consent form at launch before any ad is loaded. You can also opt out of personalized ads, or reset or delete your advertising ID, in your device's Google or Ads settings.
At launch, nothing is for sale. Every feature is free for everyone.
We plan to add an optional Premium upgrade in a future update. It will remove all ads and unlock the premium PDF tools (split, compress, PDF to images, protect and unlock). Reading documents, images to PDF, scan to PDF and merge will stay free.
When Premium is available:
Google Play Billing processes the purchase. Google collects and handles your payment method, card details and billing address. We never see or store them.
RevenueCat, our subscription-management provider, receives the purchase receipt from Google Play, a random anonymous user ID generated by the App, and basic device and app information. RevenueCat uses this to confirm that your purchase is valid and to unlock Premium on your device. We do not give RevenueCat your name or email address, because the App does not have them.
Because Google Play keeps a record of your purchase, you can restore it after reinstalling the App or on a new device, without creating an account with us.
You can manage or cancel a subscription at any time in the Google Play Store under Payments & subscriptions.
We do not require or support accounts, sign-in or login.
We do not collect your document contents, file names, folder paths or search terms. (See section 5 for the one exception: a crash report may occasionally contain a file name.)
We do not collect your location. The App has no location feature and does not request location permission.
We do not access your microphone, contacts, calendar or phone calls.
We do not use any ad network other than Google AdMob.
We do not sell your data, and we do not share it with data brokers.
We do not upload your documents or photos anywhere.
All files access (MANAGE_EXTERNAL_STORAGE), plus storage (READ_EXTERNAL_STORAGE, Android 12L and older only) and write storage (WRITE_EXTERNAL_STORAGE, Android 9 and older only): to find, open, rename and delete your documents, and to save PDF tool output.
Camera (CAMERA): Scan to PDF only. Requested only when you open that screen. Declared optional.
Notifications (POST_NOTIFICATIONS): to show push notifications, such as update news. Android 13 and newer asks for your permission.
Internet and network state (INTERNET, ACCESS_NETWORK_STATE): ads, Firebase (analytics, crash reports, Remote Config, push), Google Play Billing, in-app updates, and opening this privacy policy. Never used to send your documents.
Advertising ID (com.google.android.gms.permission.AD_ID, and the Android Privacy Sandbox ad permissions ACCESS_ADSERVICES_AD_ID, ACCESS_ADSERVICES_ATTRIBUTION and ACCESS_ADSERVICES_TOPICS): added by the Google Mobile Ads SDK so AdMob can show and measure ads. These permissions are not used while ads are off, or once you have Premium.
Basic phone state (READ_BASIC_PHONE_STATE): added by the Google Mobile Ads SDK. It gives only basic, non-identifying device state. It does not give access to your phone number, calls or contacts.
Google Play Billing (com.android.vending.BILLING): for the optional Premium purchase.
Receive push messages, wake lock, foreground service and start at boot (com.google.android.c2dm.permission.RECEIVE, WAKE_LOCK, FOREGROUND_SERVICE, RECEIVE_BOOT_COMPLETED): added by the Firebase and Google Play libraries so push notifications and background analytics uploads work reliably.
Install referrer (BIND_GET_INSTALL_REFERRER_SERVICE): added by Firebase Analytics to learn which Play Store campaign, if any, led to the install.
Display over other apps and mount filesystems (SYSTEM_ALERT_WINDOW, MOUNT_UNMOUNT_FILESYSTEMS): declared by the built-in Office document engine. The App never requests or uses them. Android does not grant them to normal apps without your explicit action.
Google AdMob and the Google Mobile Ads SDK, including the User Messaging Platform consent tool. See policies.google.com/privacy and policies.google.com/technologies/partner-sites.
Firebase Analytics, Firebase Crashlytics, Firebase Remote Config and Firebase Cloud Messaging (Google). See policies.google.com/privacy and firebase.google.com/support/privacy.
Google Play Billing, Google Play In-App Updates and Google Play In-App Review (Google). See play.google.com/about/play-terms.
RevenueCat (RevenueCat, Inc.), which manages the Premium purchase once it is available. See revenuecat.com/privacy.
We share data with these providers only as this policy describes. They process it as our service providers under their own terms.
Your documents stay where you put them. The App keeps no copies on any server.
On-device data (settings, favorites, recent documents, bookmarks, searches) stays on your device until you delete it, clear the App's storage, or uninstall the App.
Firebase Analytics data is kept under Google's standard Firebase retention settings (up to 14 months) and then deleted automatically.
Crashlytics reports are kept under Google's Crashlytics retention policy, which is typically about 90 days.
Advertising ID and ad interaction data are kept and managed by Google under its AdMob policies. We do not store them separately.
RevenueCat purchase records are kept for as long as needed to provide and verify your Premium purchase, and to meet accounting and legal obligations.
Support emails are kept only as long as needed to handle your request.
All Document Reader is not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us with personal information, contact us and we will delete it.
Ads and consent: once ads are on, buying Premium removes them completely. Where a consent form applies, you can make a new choice by clearing the App's storage in Android Settings; the consent form will appear again on the next launch. You can also reset or delete your device's advertising ID, or opt out of personalized ads, in your device's Google or Ads settings.
Permissions: you can revoke storage, camera or notification permission at any time in your device's Settings. The App will then be unable to do the matching task.
Analytics: where your device supports it, you can limit collection at the system level by turning off "Usage & diagnostics" sharing.
Subscriptions: you can manage or cancel Premium in the Google Play Store under Payments & subscriptions.
Delete everything: uninstall the App, or clear its storage in your device's Settings, to remove all app data stored on your device.
Your legal rights: if you are in the EEA, the UK, California or another region with similar laws, you can ask to access, correct or delete personal data about you, and you can object to how it is processed. We hold no account and no server-side copy of your data, so in practice this concerns the anonymous Firebase, AdMob and RevenueCat data linked to your device's identifiers. Email us and we will act on your request with those providers, within 30 days. We do not sell or share your personal information for money.
We may update this Privacy Policy from time to time, for example when we turn on ads or Premium, or add new features. Changes are posted on this page with a new "Last updated" date. If you keep using the App after a change, you accept the updated policy.
Muhammad Ishfaq
Email: ishfaqcompk6@gmail.com