Privacy Policy
Last updated: 9 May 2026
PDF Scanner is a document-scanning app for Android. This page explains exactly what data we collect, what stays on your device, where data is stored, and the choices you have.
Plain-English summary: the documents and images you scan stay on your phone — we never see them. We do collect anonymous usage data, crash reports, and performance measurements that help us improve the app. You can request deletion of any data tied to your install at any time.
What stays on your phone
All of these are stored locally on your device in the app's private storage and are never uploaded to our servers:
- Scanned documents (full-resolution images)
- Photos imported from your gallery
- Document titles, folder names, page notes, and anything you type
- Signatures and stamps you create
- QR-history entries (text/URLs/Wi-Fi codes you generate or scan)
- OCR text extracted from scans
- Exported PDFs and images
When you tap Share, Save to Gallery, Print, or Export, the destination app receives the file the same way it would from any other source. That action is initiated by you and is outside this policy's scope.
What we do collect
1. Anonymous usage statistics (sent to our servers)
PDF Scanner collects aggregated, anonymous usage statistics along with your phone manufacturer + model + Android version + app version. These are stored against a per-install random UUID generated on your first launch. The UUID is not linked to your Google account, phone number, email, IP address, or any other personal identifier. The content of your scans is never included.
These statistics are sent at most every 5 minutes to a server we operate ourselves at mydocscanner.com. The server does not run third-party trackers; the data lives in our own Postgres database and is visible only to the operations team.
2. Crash reports (Firebase Crashlytics)
When the app crashes, we collect a stack trace, the affected app version, the device model + Android version, and the time of the crash. We use Google Firebase Crashlytics for this. The stack trace contains internal code references, not the content of your scans. Crashlytics data is governed by Google's Privacy Policy.
3. Performance measurements (Firebase Performance Monitoring)
We measure how long key operations take — opening a page in the editor, saving a document, applying a filter, processing a scan capture — so we can identify slow paths and improve them. These measurements include the timing in milliseconds, the device model, and the app version. They never include the content being processed.
4. App-usage events (Firebase Analytics)
We log a small set of anonymous events that describe the flow of using the app, such as scan_captured, scan_session_completed, error_shown, and crop_corrected_after_scan. Each event carries non-content metadata such as the capture mode (Document / ID / Passport), filter chosen, and approximate timing. These events are governed by Google's Privacy Policy.
What we never collect
- The full-resolution image of any scan
- The text content of your scans (OCR runs on-device only; results are not uploaded)
- Document titles, folder names, or anything you type
- Your contacts, location, accounts, calendar, microphone, or other system-level data
- Names, emails, phone numbers, or other directly identifying information
- Your IP address as a stored data point (it appears in transient server access logs only and is not associated with your usage data)
Where data is stored
The data described above is stored in two places:
- Our own server at
mydocscanner.com(Postgres database on a DigitalOcean droplet). This is where anonymous usage statistics live. - Google Cloud / Firebase, which receives the Crashlytics, Performance, and Analytics data, and exports it to a Google BigQuery dataset under our project. This is governed by Google's Privacy Policy.
How long we keep it
- Usage counters in our Postgres database: kept for as long as the app is supported, or until you request deletion (see "Your rights" below).
- Crashlytics data: 90 days (Google's default).
- Firebase Analytics events: 14 months in the Firebase console; indefinitely in our BigQuery dataset unless explicitly purged.
- Firebase Performance data: 90 days in console; indefinitely in BigQuery.
Your rights
You can:
- Request deletion of all data tied to your install. Contact us at the email below with your install UUID (visible in Settings → About in the app), and we'll purge it from our Postgres database and the BigQuery export within 30 days.
- Request a copy of all data we hold for your install. Same process.
- Stop the app from sending any further data by uninstalling it (which clears your device's install UUID — a fresh install starts a new one). For more granular in-app control, in-app opt-out toggles are planned for a future release.
If you are in the European Economic Area, the United Kingdom, or California, additional rights apply under GDPR / UK GDPR / CCPA — including the right to lodge a complaint with your local data protection authority. The contact email below is the route for any such request.
Children
PDF Scanner is not directed at children under 13. We do not knowingly collect data from children. If you believe a child has provided us data, contact the email below and we will delete it.
Changes to this policy
If we make material changes to what we collect, we will update the "Last updated" date at the top of this page. Significant changes will also be announced inside the app on next launch.
Contact
Privacy questions, deletion requests, data-export requests: [email protected].