PrivaScan 隐私政策
本政策基于 PrivaScan 1.0.0 当前功能、权限和第三方服务编制。产品、SDK、权限或数据流发生实质变化时,我们将同步复核并更新本政策。
运营者: Nanjing Baoluan Information Technology Co., Ltd.
联系邮箱: njbaoluan2025@gmail.com
生效日期: 2026 年 7 月 16 日
最近更新日期: 2026 年 7 月 16 日
版本: 1.1.0
PrivaScan(以下简称“本应用”)是一款由 Nanjing Baoluan Information Technology Co., Ltd.(以下简称“我们”)发布和运营的移动文档工具,提供文档扫描、导入、OCR 文字识别、PDF 编辑、文件整理、导出和分享功能。本政策说明我们如何处理个人信息及如何保护您的隐私。请在使用前认真阅读。
1. 我们处理的信息
本应用的核心文档处理默认在您的设备本地完成。我们不会因您仅使用扫描、OCR、PDF 编辑、文件夹管理或本地导出功能而将文档内容上传至我们的服务器。
| 信息或权限 | 使用场景 | 处理方式 |
|---|---|---|
| 相机 | 您主动扫描纸质文件、二维码或条码时 | 读取相机画面以完成扫描;生成的文件保存在设备本地。 |
| 相册中的图片 | 您主动从相册导入图片,或主动保存导出图片到相册时 | 仅访问您选择导入或保存的内容。 |
| 本地文件及文件夹 | 您主动导入、导出、浏览或管理文档时 | 读取您选定的文件;Android 设备可能为兼容系统版本申请媒体/存储读取权限。 |
| 文档内容、OCR 文本和编辑结果 | 扫描、文字识别、PDF 处理、结构化导出、搜索和本地管理时 | 默认仅存于设备本地应用数据、您选择的本地目录或系统相册。OCR 主要使用设备端能力和本地 SDK 处理。 |
| 文件名、文件路径、文件元数据 | 在资料库中显示、搜索、排序、导出和分享时 | 默认仅在设备本地保存和使用。 |
| 设备本地认证结果 | 您启用文档保护、指纹或面容认证时 | 调用系统生物识别能力,仅接收认证成功或失败结果;本应用不读取或保存您的指纹、面容模板等生物识别特征。 |
| 订阅与交易状态 | 您查看订阅、购买、恢复购买或刷新权益时 | 由应用商店和 RevenueCat 处理,用于核验购买和提供订阅权益。我们不直接处理您的银行卡、支付账户或支付密码。 |
| SDK 授权校验信息 | 应用启动后初始化 Genius Scan SDK 及刷新其授权状态时 | Genius Scan SDK 可能通过网络处理完成授权校验所必需的应用标识、应用版本、设备及网络技术信息和授权状态。该授权校验不包含您的扫描文件、相机画面、OCR 文本或文档内容。 |
| 通知内容 | 您允许通知后,用于显示 OCR、导出、任务完成或提醒信息 | 通知由系统在本机展示;通知文字可能包含文件名。 |
| 安装实例级使用情况和应用活动 | 您明确允许“使用情况分析”后,用于统计首次打开、有效使用、留存、扫描/保存/导出完成情况和购买流程转化 | 通过与发行渠道匹配的分析服务处理,包括应用实例标识、设备和系统基本信息、应用版本、粗略地区及低基数业务事件。这些数据不等同于完全匿名数据;我们不会发送扫描件、文件、OCR 文本、文件名或文件路径。拒绝或撤回分析授权不影响核心功能。 |
2. 权限说明
我们仅在相关功能实际需要时申请权限。您可以拒绝非必要权限,但相应功能可能无法使用。
- 相机权限:用于扫描文档、二维码和条码。
- 照片/媒体和存储权限:用于导入您选择的图片或文件,以及在您指示时保存导出内容。Android 13 及以上主要使用图片/媒体访问权限;旧版 Android 可能使用存储读取或写入权限以保持兼容。
- 通知权限:用于在本机显示任务、OCR 或导出完成通知;您可在系统设置中关闭。
- 生物识别/设备凭据:仅在您启用文档保护或验证操作时调用系统认证。
- 网络权限:用于订阅状态、购买、恢复购买等与应用商店及 RevenueCat 的通信,以及 Genius Scan SDK 授权校验和授权状态刷新;在您明确允许后,也用于向当前发行渠道对应的分析服务发送安装实例级使用事件。本应用不以网络权限上传您的扫描文件、相机画面、OCR 文本或其他文档内容。
本应用可能查询设备是否安装了可供分享或导出的应用(例如即时通信、办公、云盘或 Obsidian),仅用于展示可用目标或发起您选择的系统跳转,不会因此读取这些应用中的内容。
3. 第三方服务和信息共享
本应用使用以下第三方服务支持订阅、扫描、您明确允许的使用情况分析,以及您主动选择的导出或分享功能。除您主动分享、打印或导出所选内容外,我们不会向这些第三方提供您的文档内容。首次确认页会显示当前发行渠道对应的分析服务;法律文件确认与分析选择分别记录。
- Apple App Store/Google Play 和 RevenueCat。当您使用订阅、购买、恢复购买或权益校验功能时,交易和订阅状态将由相应应用商店及 RevenueCat 按其隐私规则处理。涉及的信息通常包括商店交易信息、订阅状态、应用/设备标识符及技术日志。请分别阅读其适用政策。
- Genius Scan SDK。本应用使用 Genius Scan SDK 提供文档边缘检测、扫描和图像处理能力。应用启动后可能联网校验和刷新 SDK 授权状态,并处理完成校验所必需的应用标识、应用版本、设备及网络技术信息和授权状态。扫描文件、相机画面、OCR 文本和文档内容默认在设备本地处理,不会因 SDK 授权校验而上传。
- Google Firebase Analytics。适用于 Google Play Android 和 App Store iOS。在您明确允许后,用于统计安装实例级功能使用、应用活动、留存和产品转化。处理的信息包括应用实例标识、设备和系统基本信息、应用版本、粗略地区及本政策所述的低基数业务事件;这些数据不等同于完全匿名数据。本应用关闭广告标识、广告个性化、iOS IDFV 和设备端广告转化数据,不设置账号或 RevenueCat 用户 ID,也不会发送扫描件、文件、OCR 文本、文件名或文件路径。详细信息请参阅 Google Firebase 隐私与安全说明。
- 友盟+移动统计。适用于接入该服务的中国大陆 Android 发行包,用途和业务事件范围与上述使用情况分析一致。未接入友盟 SDK 的构建不会向友盟发送数据;正式接入后,我们也不会发送扫描件、文件、OCR 文本、文件名或文件路径。
- 系统分享、打印和“保存到相册/下载”。仅在您主动确认后,本应用才会将您选定的文件交给系统分享面板、打印服务或您选择的目标应用。目标应用对信息的处理由其自身政策约束。
- Obsidian。当您主动选择导出到 Obsidian 时,本应用会通过 Obsidian URL Scheme 将您选定的文本内容和文件名交给 Obsidian,以创建或追加笔记。后续处理由 Obsidian 及您选择的库位置决定。
本应用不接入广告 SDK,不提供基于文档内容的广告定向,也不将您的扫描件、OCR 文本或本地文件出售给第三方。
4. 存储、保留与删除
- 文档、缩略图、OCR 文本、文件夹、设置及部分任务信息通常保存在设备本地。您可以在应用内删除文件、文件夹或本地账户数据;也可以卸载应用清除应用私有目录中的数据。
- 导出到系统下载目录、相册、第三方应用或外部笔记库的副本,不会因您在本应用内删除原件而自动删除,请您在相应位置自行管理。
- 临时预览和导出缓存会在功能完成后或按应用维护策略清理;不应将本应用作为唯一备份方式。
- 订阅记录由应用商店和 RevenueCat 按其各自保留规则保存。若您需要处理该等信息,请通过其提供的渠道行使权利。
- Firebase Analytics 数据由 Google 按 Firebase/Google Analytics 的适用保留设置处理。您在应用内撤回同意后,本设备会停止后续分析采集并重置本设备的 Firebase 分析数据;已汇总或依法需要保留的数据按 Google 的规则处理。
- 友盟分析数据由友盟按其适用规则和控制台配置处理。您在应用内撤回同意后,本设备会停止后续分析采集,并在 SDK 支持时重置本设备的分析数据。
5. 您的权利和选择
您可以:
- 在系统设置中授予、拒绝或撤回相机、照片/媒体、通知及生物识别相关授权;
- 在应用内删除本地文档、OCR 结果、文件夹和本地设置;
- 通过应用商店管理、取消或恢复订阅;
- 在首次全屏确认页选择是否开启分析,并可在“我的/账号 - 系统设置 - 使用情况分析”中再次允许或关闭安装实例级分析;同意前、拒绝后和撤回后不发送新的分析事件;
- 通过上述联系邮箱提出访问、更正、删除、撤回同意、复制或解释个人信息处理规则等请求。
为保护您的数据安全,我们可能在处理请求前验证您的身份。对于仅存在于您设备本地且我们无法访问的数据,您可直接在设备或应用中完成删除和管理。
6. 安全措施
我们采取合理措施减少未经授权的访问、使用、披露或丢失风险,包括尽量采用本地处理、使用系统权限控制、在启用文档保护时使用设备认证,以及限制不必要的数据传输。但请理解,任何系统都无法保证绝对安全。请妥善保管设备解锁方式、应用内设置的密码和导出文件。
7. 未成年人
本应用并非专为未成年人设计。未成年人应在监护人同意和指导下使用。若您认为未成年人未经监护人同意向我们提供了需要由我们处理的个人信息,请通过上述渠道联系我们。
8. 政策更新
当功能、权限、第三方服务或适用规则发生重大变化时,我们会更新本政策,并在应用内、应用商店页面或其他适当位置提示。更新后继续使用本应用,即表示您已阅读更新后的政策;法律要求另行取得同意的除外。
9. 联系我们
如对本政策或个人信息处理有疑问、意见或投诉,请联系:
- 运营者:Nanjing Baoluan Information Technology Co., Ltd.
- 邮箱:njbaoluan2025@gmail.com
- 建议邮件主题:“PrivaScan 隐私请求”“PrivaScan 数据删除”或“PrivaScan 购买支持”
为帮助我们定位问题,您可以提供设备型号、操作系统版本、PrivaScan 版本和问题发生页面。请勿在邮件中提供完整银行卡信息、支付密码或与请求无关的敏感文档内容。
© 2026 Nanjing Baoluan Information Technology Co., Ltd. All rights reserved.
PrivaScan Privacy Policy
This policy reflects PrivaScan 1.0.0, its current permissions, features, and third-party services. We review this policy when material product, SDK, permission, or data-flow changes occur.
Operator: Nanjing Baoluan Information Technology Co., Ltd.
Email: njbaoluan2025@gmail.com
Effective date: July 16, 2026
Last updated: July 16, 2026
Version: 1.1
PrivaScan is a mobile document utility operated by Nanjing Baoluan Information Technology Co., Ltd. It provides document scanning, import, OCR, PDF editing, file organization, export, and sharing. This policy explains how information is handled and how your privacy is protected.
1. Information We Process
Core document processing is performed locally on your device by default. Merely using scanning, OCR, PDF editing, folder management, or local export does not upload document content to our servers.
| Information or permission | When used | How it is handled |
|---|---|---|
| Camera | When you scan documents, QR codes, or barcodes | Camera frames are read to perform scanning. Generated files are stored locally. |
| Photos | When you import selected images or save exported images | Only content you select for import or saving is accessed. |
| Local files and folders | When you import, export, browse, or manage documents | Selected files are read. Older Android versions may require media or storage access for compatibility. |
| Documents, OCR text, and edits | For scanning, OCR, PDF processing, structured export, search, and local management | Stored locally in app data, a location you select, or the system photo library. OCR primarily uses on-device capabilities and local SDKs. |
| File names, paths, and metadata | For display, search, sorting, export, and sharing | Stored and used locally by default. |
| Local authentication result | When document protection or biometric authentication is enabled | Only success or failure is received. We do not access or store biometric templates. |
| Subscription and transaction status | When viewing, purchasing, restoring, or refreshing entitlements | Handled by the app store and RevenueCat. We do not directly process payment-card details or payment passwords. |
| SDK license verification information | When Genius Scan SDK initializes and refreshes its license after app launch | The SDK may process application identifiers, app version, device and network technical information, and license status required for verification. Scans, camera frames, OCR text, and document content are not included. |
| Notification content | When you allow task, OCR, export, or reminder notifications | Displayed locally by the system and may include a file name. |
| Installation-level usage and app activity | After you explicitly allow Usage Analytics, to measure first opens, valid usage, retention, scan/save/export completion, and purchase-funnel conversion | Processed by the analytics service associated with the distribution channel. This includes an app-instance identifier, basic device and operating-system information, app version, coarse region, and low-cardinality product events. This data is not fully anonymous. We do not send scans, files, OCR text, file names, or file paths. Refusing or withdrawing analytics consent does not affect core features. |
2. Permissions
Permissions are requested only when required for a related feature. Refusing an optional permission may prevent that feature from working.
- Camera: scanning documents, QR codes, and barcodes.
- Photos, media, and storage: importing selected content and saving exports at your direction.
- Notifications: local task, OCR, export, and reminder notices.
- Biometrics or device credentials: system authentication for document protection.
- Network: app-store and RevenueCat subscription operations, Genius Scan SDK license verification and refresh, and, after your explicit permission, installation-level usage events sent to the analytics service associated with the current distribution channel. This permission is not used to upload scans, camera frames, OCR text, or document content.
The app may query whether compatible sharing or export applications are installed solely to display available targets or perform a system handoff. It does not read content from those applications.
3. Third-Party Services and Sharing
The following services support subscriptions, scanning, usage analytics you explicitly allow, and user-initiated export or sharing. Document content is provided to a third party only when you choose to share, print, or export it. The first-run screen identifies the analytics service for the current distribution channel, and legal acceptance is recorded separately from your analytics choice.
- Apple App Store, Google Play, and RevenueCat. They process store transaction information, subscription status, app or device identifiers, and technical logs under their own policies.
- Genius Scan SDK. It provides document-edge detection, scanning, and image processing. It may connect to verify and refresh its license using the technical information needed for that purpose. Document content remains on device by default and is not uploaded for license verification.
- Google Firebase Analytics. This applies to Google Play Android and App Store iOS. After your explicit permission, it measures installation-level feature usage, app activity, retention, and product conversion. Information includes an app-instance identifier, basic device and operating-system information, app version, coarse region, and the low-cardinality product events described in this policy. This data is not fully anonymous. The app disables advertising identifiers, ad personalization, iOS IDFV collection, and on-device ads conversion data; it does not set an account or RevenueCat user ID. We do not send scans, files, OCR text, file names, or file paths. See Google's Firebase privacy and security information.
- Umeng+ Mobile Analytics. This applies to mainland China Android distributions that integrate the service, with the same purpose and product-event scope described above. Builds without the Umeng SDK do not send data to Umeng. After formal integration, we will not send scans, files, OCR text, file names, or file paths.
- System sharing, printing, Photos, and Downloads. Selected files are handed to the system service or target application only after your action. The recipient's own privacy policy applies.
- Obsidian. When selected, the app uses the Obsidian URL scheme to provide selected text and a file name for creating or appending a note.
The app contains no advertising SDK, does not use document content for ad targeting, and does not sell scans, OCR text, or local files.
4. Storage, Retention, and Deletion
- Documents, thumbnails, OCR text, folders, settings, and some task information are normally stored locally. You may delete them in the app or remove private app data by uninstalling.
- Copies exported to Downloads, Photos, another app, or an external note vault are not automatically removed when the original is deleted.
- Temporary preview and export caches are cleared after use or under app maintenance policies. Do not treat the app as your only backup.
- App stores and RevenueCat retain subscription records under their own rules.
- Google retains Firebase Analytics data under the applicable Firebase/Google Analytics retention settings. After you withdraw consent in the app, this device stops subsequent analytics collection and resets its local Firebase analytics data. Aggregated data or data that must be retained by law is handled under Google's rules.
- Umeng retains analytics data under its applicable rules and console settings. After you withdraw consent in the app, this device stops subsequent analytics collection and resets local analytics data when supported by the SDK.
5. Your Rights and Choices
You may manage permissions in system settings, delete local documents and settings in the app, and manage subscriptions through the app store. On the first-run screen, you may choose whether to enable analytics. You can later allow or disable installation-level analytics under My/Account - System Settings - Usage Analytics. No new analytics events are sent before consent, after refusal, or after withdrawal. You may also contact us to request access, correction, deletion, withdrawal of consent, a copy, or an explanation of processing rules. Locally stored data inaccessible to us can be managed directly on your device.
6. Security
We use reasonable safeguards including local processing, system permission controls, device authentication for protected documents, and limiting unnecessary transfers. No system can guarantee absolute security; protect your device credentials, app passwords, and exported files.
7. Children
The app is not designed specifically for children. Minors should use it with a guardian's consent and guidance.
8. Policy Updates
We may update this policy when features, permissions, third-party services, or applicable requirements materially change. Where appropriate, notice will be provided in the app, store listing, or another reasonable channel.
9. Contact Us
- Operator: Nanjing Baoluan Information Technology Co., Ltd.
- Email: njbaoluan2025@gmail.com
- Suggested subjects: “PrivaScan Privacy Request,” “PrivaScan Data Deletion,” or “PrivaScan Purchase Support.”
You may include your device model, operating-system version, PrivaScan version, and affected screen. Do not send full card details, payment passwords, or unrelated sensitive documents.
© 2026 Nanjing Baoluan Information Technology Co., Ltd. All rights reserved.