PrivaScan Privacy Policy

This policy reflects PrivaScan 1.0.0, its current permissions, features, and third-party services. We review this policy when material product, SDK, permission, or data-flow changes occur.

Operator: Nanjing Baoluan Information Technology Co., Ltd.

Email: njbaoluan2025@gmail.com

Effective date: July 16, 2026

Last updated: July 16, 2026

Version: 1.1

PrivaScan is a mobile document utility operated by Nanjing Baoluan Information Technology Co., Ltd. It provides document scanning, import, OCR, PDF editing, file organization, export, and sharing. This policy explains how information is handled and how your privacy is protected.

1. Information We Process

Core document processing is performed locally on your device by default. Merely using scanning, OCR, PDF editing, folder management, or local export does not upload document content to our servers.

Information or permissionWhen usedHow it is handled
CameraWhen you scan documents, QR codes, or barcodesCamera frames are read to perform scanning. Generated files are stored locally.
PhotosWhen you import selected images or save exported imagesOnly content you select for import or saving is accessed.
Local files and foldersWhen you import, export, browse, or manage documentsSelected files are read. Older Android versions may require media or storage access for compatibility.
Documents, OCR text, and editsFor scanning, OCR, PDF processing, structured export, search, and local managementStored locally in app data, a location you select, or the system photo library. OCR primarily uses on-device capabilities and local SDKs.
File names, paths, and metadataFor display, search, sorting, export, and sharingStored and used locally by default.
Local authentication resultWhen document protection or biometric authentication is enabledOnly success or failure is received. We do not access or store biometric templates.
Subscription and transaction statusWhen viewing, purchasing, restoring, or refreshing entitlementsHandled by the app store and RevenueCat. We do not directly process payment-card details or payment passwords.
SDK license verification informationWhen Genius Scan SDK initializes and refreshes its license after app launchThe SDK may process application identifiers, app version, device and network technical information, and license status required for verification. Scans, camera frames, OCR text, and document content are not included.
Notification contentWhen you allow task, OCR, export, or reminder notificationsDisplayed locally by the system and may include a file name.
Installation-level usage and app activityAfter you explicitly allow Usage Analytics, to measure first opens, valid usage, retention, scan/save/export completion, and purchase-funnel conversionProcessed by the analytics service associated with the distribution channel. This includes an app-instance identifier, basic device and operating-system information, app version, coarse region, and low-cardinality product events. This data is not fully anonymous. We do not send scans, files, OCR text, file names, or file paths. Refusing or withdrawing analytics consent does not affect core features.

2. Permissions

Permissions are requested only when required for a related feature. Refusing an optional permission may prevent that feature from working.

The app may query whether compatible sharing or export applications are installed solely to display available targets or perform a system handoff. It does not read content from those applications.

3. Third-Party Services and Sharing

The following services support subscriptions, scanning, usage analytics you explicitly allow, and user-initiated export or sharing. Document content is provided to a third party only when you choose to share, print, or export it. The first-run screen identifies the analytics service for the current distribution channel, and legal acceptance is recorded separately from your analytics choice.

  1. Apple App Store, Google Play, and RevenueCat. They process store transaction information, subscription status, app or device identifiers, and technical logs under their own policies.
  2. Genius Scan SDK. It provides document-edge detection, scanning, and image processing. It may connect to verify and refresh its license using the technical information needed for that purpose. Document content remains on device by default and is not uploaded for license verification.
  3. Google Firebase Analytics. This applies to Google Play Android and App Store iOS. After your explicit permission, it measures installation-level feature usage, app activity, retention, and product conversion. Information includes an app-instance identifier, basic device and operating-system information, app version, coarse region, and the low-cardinality product events described in this policy. This data is not fully anonymous. The app disables advertising identifiers, ad personalization, iOS IDFV collection, and on-device ads conversion data; it does not set an account or RevenueCat user ID. We do not send scans, files, OCR text, file names, or file paths. See Google's Firebase privacy and security information.
  4. Umeng+ Mobile Analytics. This applies to mainland China Android distributions that integrate the service, with the same purpose and product-event scope described above. Builds without the Umeng SDK do not send data to Umeng. After formal integration, we will not send scans, files, OCR text, file names, or file paths.
  5. System sharing, printing, Photos, and Downloads. Selected files are handed to the system service or target application only after your action. The recipient's own privacy policy applies.
  6. Obsidian. When selected, the app uses the Obsidian URL scheme to provide selected text and a file name for creating or appending a note.

The app contains no advertising SDK, does not use document content for ad targeting, and does not sell scans, OCR text, or local files.

4. Storage, Retention, and Deletion

5. Your Rights and Choices

You may manage permissions in system settings, delete local documents and settings in the app, and manage subscriptions through the app store. On the first-run screen, you may choose whether to enable analytics. You can later allow or disable installation-level analytics under My/Account - System Settings - Usage Analytics. No new analytics events are sent before consent, after refusal, or after withdrawal. You may also contact us to request access, correction, deletion, withdrawal of consent, a copy, or an explanation of processing rules. Locally stored data inaccessible to us can be managed directly on your device.

6. Security

We use reasonable safeguards including local processing, system permission controls, device authentication for protected documents, and limiting unnecessary transfers. No system can guarantee absolute security; protect your device credentials, app passwords, and exported files.

7. Children

The app is not designed specifically for children. Minors should use it with a guardian's consent and guidance.

8. Policy Updates

We may update this policy when features, permissions, third-party services, or applicable requirements materially change. Where appropriate, notice will be provided in the app, store listing, or another reasonable channel.

9. Contact Us

You may include your device model, operating-system version, PrivaScan version, and affected screen. Do not send full card details, payment passwords, or unrelated sensitive documents.

© 2026 Nanjing Baoluan Information Technology Co., Ltd. All rights reserved.