Privacy Policy
Last updated: August 8, 2026
1. Who we are
ScanDocfy is a document scanning app. The controller of the data described here is Meigston da Silva Ramos (trading as Meigston Serviços Tech), registered in Brazil under CNPJ 32.598.125/0001-51, at Rua 24 de Maio, 411, Conj. 201, Andar Sobreloja, Cond. Folador, Ed. Bloco Bl A, Rebouças, ZIP 80220-060, Curitiba/PR, Brazil, reachable at support@scandocfy.com.
2. What stays on your device only
The following is written to the app's private storage and is not sent to us or to anyone else, with the single exception described in section 4:
- the images you scan;
- the PDF files the app generates — unless you create a public link for one of them yourself (section 4);
- the signatures you draw;
- the text recognized by OCR, document names and folders;
- your preferences (language, filter, OCR language) and usage counters.
Text recognition (OCR) runs on the device, using the operating system itself — ML Kit on Android and Vision on iOS. Scanning, generating PDFs, reading the text, organizing into folders, searching and signing all work with no internet connection.
3. What leaves the device, and when
Only when you tap summarize, extract fields, chat with the AI or translate does the app send the text the OCR already recognized to our server over an encrypted connection (HTTPS). Our server forwards that text to Google's artificial intelligence service (Gemini API) and returns the answer to the app.
- The document image is never sent in any of these operations — only the text.
- Our server does not store the text you send or the answers. It keeps no content database: it receives, forwards, replies and forgets.
- Google processes that text as a processor, under the Gemini API terms.
4. Public link (AI+)
This is the only feature in the app that sends the file — not just the text — to our server. It never happens on its own: only when you open a document, choose "Public link" and confirm creating it.
- A copy of the PDF is stored on our server and anyone holding the address can open it, without installing the app and without identifying themselves. That is the point of the feature — treat the address the way you would treat the document itself.
- The address carries a random 128-bit code. It cannot be guessed or enumerated, but it stops being secret the moment you send it to someone.
- The copy is deleted automatically after 7 days, and you can revoke it earlier at any time from the same screen. Revoking deletes the file from the server immediately.
- Alongside the file we keep only the identifier of the device that created it, the file name and the creation and expiry dates — the identifier exists so that only the creator can revoke it.
- We do not open, index or analyse the content of these files.
5. Device identifier
AI calls carry a random identifier generated on your device the first time you use the feature (a UUID). It serves one purpose: applying the per-device call limit that keeps the service from being abused.
That identifier is not linked to you: it contains no name, e-mail, phone number or store identifier. Reinstalling the app generates a new one, and the counters tied to it expire together with the rate-limit window.
6. Advertising
On the free plan the app shows ads through Google AdMob. To do that, Google may collect and use data from your device — including the advertising identifier — under its own privacy policy. We have no access to that data and never receive it.
- On iOS, the system asks for your permission to track first (App Tracking Transparency). Declining blocks no feature of the app: you still see ads, just less personalized ones.
- Buying the Pro plan removes the ads and, with them, the collection done by the ad network.
7. Purchases
Purchases happen on the App Store or Google Play. No card data ever passes through the app or our server — Apple or Google processes the payment.
We use RevenueCat to keep the purchase receipt and check which plan you are entitled to. For that, RevenueCat stores the receipt issued by the store and an anonymous installation identifier. We send no name, e-mail or other identifying data.
8. Permissions
- Camera: on Android, the scanning camera is opened by Google Play Services in a separate process — which is why the app does not request the camera permission. On iOS, the system asks for access the first time you open the scanner.
- Files: the app writes only to its own private storage. When you share a document, the file is copied to a temporary area the system may clear later.
9. Children
The app is not directed at children, and we do not knowingly collect data from anyone under 13.
10. Your rights
Because we keep no account and no sign-up, there is no profile of yours on our side to access, correct or delete. In practice:
- Delete everything: uninstalling the app removes every document, PDF, signature and preference stored on the device. This is final — we hold no copy to restore.
- Purchases: these stay tied to your store account, and the Restore purchase button brings them back on any device signed in to the same account.
- If you still want to exercise a right under the GDPR or Brazil's LGPD, write to support@scandocfy.com.
11. Third-party services
These are all the third parties involved, and what each is for: Google Gemini API (producing the AI answers), Google AdMob (ads on the free plan), RevenueCat (validating the purchase receipt) and Apple/Google (processing payment and distributing the app). Each handles data under its own policy.
12. Changes
If this policy changes, the date at the top changes with it. Any material change in how data is handled will be announced inside the app.