Privacy
Scanner PDF Editor Privacy Policy
What this app collects, why it collects it, and what you can ask us to delete.
Last updated: September 10, 2026
Scanner PDF Editor lets you scan, edit, organize and export documents. This policy explains the information used by the iOS and Android app and its optional cloud processing. For questions or a privacy request, use Scanner support.
App versions and legacy advertising
The document, cloud and recovery features described below apply to version 1.8.0 and later. Older versions may not offer all of these features.
Legacy iOS version 1.7.5 includes advertising features using Google Mobile Ads. Ad requests can include network information such as IP address, app or device identifiers, advertising interactions, crash logs and performance information. Google may use this information to provide and measure advertising, analyze use and improve its services. Access to the device advertising identifier depends on the permissions and platform restrictions that apply to your device. See Google’s Mobile Ads data disclosures and Google’s privacy policy.
Version 1.8.0 removes the advertising SDK and does not request advertising-ID access or serve third-party ads. Its diagnostics and consented cloud processing are described below. Updating the app does not erase information already held by an advertising provider; use that provider’s privacy controls for requests concerning its records.
Your document library
Your library, document names, annotations, signatures and saved revisions are stored on your device by default. Ordinary scanning, PDF editing, on-device text recognition and local exports do not upload your document library to our server. Files you select through a system cloud-file provider remain subject to that provider’s privacy practices. Device backups and exports you create are controlled by your device settings and the destination you choose.
Camera and photo/file access is used for the capture or import you request. You can decline or revoke permissions in your device settings. Optional library locking uses your device’s authentication service; Scanner does not receive your fingerprint, face template or device passcode.
AI and Office conversion
Cloud actions ask for consent before transferring selected content. Document understanding sends text from the pages you select to our service and an AI provider through OpenRouter. Editable Office conversion sends the selected document to our processing service. The consent screen identifies whether text or document bytes will be sent. Declining consent leaves the original unchanged.
Our AI requests select endpoints that support zero data retention and disable provider data collection for those requests. This does not mean that security, billing or request metadata is never retained. See OpenRouter’s privacy information. Office processing uses temporary working files; document content is not saved in your service activity record. Processing results are returned to the app, where you choose whether to save or export them. Avoid sending content you are not authorized to share.
Service identity, purchases and activity
Firebase provides an anonymous installation identity and App Check verifies requests from the app. Our service also uses an installation identifier and public verification key to protect requests against impersonation and replay. Registration and processing records include platform, dates, request status and usage counts. These support operation of the service, recovery, abuse prevention and the processing limits shown in the app.
Apple or Google processes purchases. We do not receive your payment-card details. Store transaction or purchase-verification data is used to confirm access, honor existing purchases and enforce usage limits. The service may retain encrypted purchase references to recheck linked entitlements and hashed purchase identities to apply limits consistently. Orphaned encrypted references are removed when the last active installation or recovery-key link is deleted; security and purchase-usage records may remain for abuse prevention and billing integrity. A subscription cancellation does not itself delete service records or end an already-paid period. Manage subscriptions through the relevant store.
Diagnostics
Firebase Analytics and Crashlytics help us understand feature use and diagnose failures. These services can process app-instance identifiers, device/app information, usage events, coarse location inferred from the network address, and crash information. We do not request precise device location for analytics. Our feature events use fixed event names and bounded numeric counts; they do not include document text, filenames, signatures, AI prompts or purchase proofs. See Firebase’s privacy information.
Sharing, printing and Wi-Fi transfer
Files are shared or printed only through destinations you select. The receiving application, printer or service controls its own handling of the file. Wi-Fi transfer is an explicit foreground session on your local network. It requires a pairing code and allows you to choose available downloads. It uses local HTTP, so use a trusted private network. Stopping the session or leaving the app stops the transfer server. Do not share the pairing code with someone you do not intend to receive access.
Your controls and retention
You can delete local documents, remove items from Recently deleted, export files and manage app permissions. Deleting a document in Scanner does not delete copies already exported, printed, shared or stored in a device backup.
Settings → Cloud privacy lets you view this installation’s activity record and delete its cloud account, active registration and activity. Deletion confirms our service’s acknowledgment and deletion of the associated Firebase user before removing the local service identity. If a connection or device interruption prevents confirmation, the app retains encrypted recovery state and reports that completion is unconfirmed. Retry from Cloud privacy or contact us for help. An expired verification credential is not treated as proof of deletion.
Local documents and Apple or Google purchases remain unchanged. Account deletion does not cancel a subscription; use Manage subscription in Cloud privacy or your store account. Using a cloud feature again after confirmed deletion creates a new account. Security identifiers, replay-prevention records and purchase-related usage limits may remain to prevent abuse and preserve billing integrity. A reinstall or local document deletion is not a request to erase server records.
Request account or data deletion
To request deletion without installing the app, the support page. Include “Scanner PDF Editor account deletion” and the installation identifier from an activity export if you have it. We may need to verify ownership before acting. Do not send document content, passwords, subscription recovery keys or store purchase tokens. We do not identify anonymous cloud accounts by email alone. If you cannot locate your identifier, explain the problem and we will help determine what can be verified. This request route does not require an active subscription.
Subscription recovery
An optional recovery key restores access only from an existing verified store entitlement. Our service associates the key with its owning installation and records authorized use; keys are stored as verification digests. Keep a recovery key private. Turning off your own keys or deleting their owning cloud account prevents further key restores. This does not cancel a store subscription or erase another device’s local documents.
Security and policy changes
Cloud service requests use HTTPS, authenticated identities, app attestation and signed installation requests. Access to your local library also depends on your device security and the permissions you give other applications. No storage or transmission method can guarantee absolute security.
We may update this policy when the app’s processing changes. The updated date and policy will be available through the app’s Privacy link.