PaceScan Privacy Policy

This policy reflects PaceScan's current permissions, features, and third-party services. We review it when material product, SDK, permission, or data-flow changes occur.

Operator: Nanjing Baoluan Information Technology Co., Ltd.

Email: zsw@baoluaninfo.com

Phone: 13951741865

Effective date: August 4, 2026

Last updated: August 26, 2026

PaceScan is a mobile document utility operated by Nanjing Baoluan Information Technology Co., Ltd. It provides document scanning, import, OCR, PDF editing, file organization, export, and sharing. This policy explains how information is handled and how your privacy is protected.

1. Information We Process

Core document processing is performed locally on your device by default. Merely using scanning, local OCR, PDF editing, folder management, or local export does not upload document content to our servers. Selected content is processed over the network only after you enable Cloud Curve Correction or select or capture content in an AI tool and tap an explicit Run, Submit, or Send command. The selected content then passes through our first-party backend and the services described below; other library files are not processed automatically.

Information or permissionWhen usedHow it is handled
CameraWhen you scan documents, QR codes, or barcodesCamera frames are read to perform scanning. Generated files are stored locally.
PhotosWhen you import selected images or save exported imagesOnly content you select for import or saving is accessed.
Local files and foldersWhen you import, export, browse, or manage documentsSelected files are read. Older Android versions may require media or storage access for compatibility.
Documents, OCR text, and editsFor scanning, OCR, PDF processing, structured export, search, and local managementStored locally in app data, a location you select, or the system photo library. OCR primarily uses on-device capabilities and local SDKs.
Cloud curve-correction imageWhen you explicitly enable Cloud Curve Correction and a scan page requires dewarpingThe current cropped page is sent through our HTTPS signing proxy to Youdao Zhiyun Image Correction to return a corrected image. Disabling the option keeps processing local.
Content, instructions, and context selected for AI toolsWhen you use recognition, correction, conversion, document analysis, essay correction, photo problem solving, or AI tutoring and tap Run, Submit, or SendThe selected image, PDF, Office/text file, file name, stroke data, necessary extracted text, and any instruction, question, language, grade, title, requirement, or relevant conversation context are sent over HTTPS to our first-party backend. The backend provides only the content required by the selected feature to Youdao Zhiyun, Baidu AI Cloud, or Alibaba Cloud EduTutor and returns the result. Local scanning remains available without these tools.
File names, paths, and metadataFor display, search, sorting, export, and sharingStored and used locally by default.
Local authentication resultWhen document protection or biometric authentication is enabledOnly success or failure is received. We do not access or store biometric templates.
Account and security informationWhen using anonymous accounts, phone or Apple login, device management, recovery codes, or manual recoveryMainland Android processes an E.164 phone number, password hash, phone-verification result, anonymous and installation identifiers, device sessions, recovery codes, and recovery applications. For mainland China App Store iOS, Sign in with Apple provides an identity token, authorization code, nonce, and any email or name Apple makes available on first authorization; Alibaba Cloud Fusion Authentication may process the information required for phone binding or login. Passwords and recovery codes are not written to plaintext logs.
Subscription and transaction statusWhen viewing, purchasing, restoring, or refreshing entitlementsGoogle Play Android and overseas App Store iOS use the app store and RevenueCat. Mainland China App Store iOS uses Apple App Store and RevenueCat and binds entitlements to a non-phone backend account identifier. Mainland Android uses our order service and the selected WeChat Pay or Alipay service. We do not read or store payment-card numbers or payment passwords.
SDK license verification informationWhen Genius Scan SDK initializes and refreshes its license after app launchThe SDK may process application identifiers, app version, device and network technical information, and license status required for verification. Scans, camera frames, OCR text, and document content are not included.
Notification contentWhen you allow task, OCR, export, or reminder notificationsDisplayed locally by the system and may include a file name.
Installation-level usage and app activityFor Google Play Android and App Store iOS, after you allow analytics on the first-run screen; for mainland China Android, after you accept this policy and enter the app. Used to measure first opens, valid usage, retention, scan/save/export completion, and purchase-funnel conversion.Processed by the analytics service associated with the distribution channel. This includes an app-instance identifier, basic device and operating-system information, app version, coarse region, and low-cardinality product events. This data is not fully anonymous. We do not send scans, files, OCR text, file names, or file paths. Choosing Set up later on international builds or disabling analytics on any build does not affect core features.

2. Permissions

Permissions are requested only when required for a related feature. Refusing an optional permission may prevent that feature from working.

The app may query whether compatible sharing or export applications are installed solely to display available targets or perform a system handoff. It does not read content from those applications.

3. Third-Party Services, First-Party Analytics, and Sharing

The following services support subscriptions, account authentication, scanning, usage analytics, cloud curve correction, AI tools, and user-initiated export or sharing. Document content is provided to another service only when you choose to share, print, or export selected content, enable Cloud Curve Correction, or select or capture content in an AI tool and tap an explicit Run, Submit, or Send command. The current AI flow treats that feature command as the network-processing action and does not promise a second upload prompt. International first-run screens show a concise analytics notice; mainland China Android does not show a separate analytics notice.

  1. Apple App Store, Google Play, and RevenueCat. RevenueCat applies to Google Play Android and App Store iOS, including mainland China App Store iOS. They process store transaction information, subscription status, app or device identifiers, and technical logs under their own policies. Mainland China App Store iOS binds a non-phone backend account identifier to RevenueCat and uses backend entitlement status to control membership access. Mainland Android does not include RevenueCat, Google Play Billing, or Amazon Appstore SDK.
  2. WeChat Pay and Alipay. They process payment-account, transaction, and risk-control information for mainland Android fixed-term plans. The app passes signed server-generated payment parameters to the selected SDK, and our server grants entitlement only after verified order settlement. We do not read or store payment passwords.
  3. Google ML Kit. Android and iOS use the applicable on-device text, QR-code, or barcode components. Document content is not uploaded to our servers for this local recognition.
  4. Genius Scan SDK. It provides document-edge detection, scanning, and image processing. It may connect to verify and refresh its license using the technical information needed for that purpose. Document content remains on device by default and is not uploaded for license verification.
  5. Sign in with Apple. This applies to mainland China App Store iOS only when you choose it. Apple provides an identity token, authorization code, and any email or name available on first authorization so that we can create or link the backend account.
  6. Alibaba Cloud Fusion Authentication and carrier components. Mainland Android and mainland China App Store iOS use the Alibaba Cloud Fusion Authentication, SMS, or China Mobile, China Unicom, and China Telecom local-number capability actually selected by the login flow. It may process a phone or masked phone number, authentication result, IP address, network type, carrier and SIM status, device model, operating system, and app information for authentication and security risk control.
  7. First-party backend and Youdao Zhiyun AI services. Cloud curve correction and applicable recognition, conversion, and document-analysis features send the required content through our HTTPS first-party backend before it is provided to Youdao. Inputs may include the cropped page, image, document, file name, stroke data, necessary extracted text, instruction, and language.
  8. First-party backend and Baidu AI Cloud. Essay correction, exam correction, photo problem solving, and some document-recognition features may provide the selected image, necessary text, grade, title, requirement, or question through our HTTPS first-party backend to Baidu for recognition, grading, answers, or explanations.
  9. First-party backend and Alibaba Cloud EduTutor. When you select images, enter a question, and tap Send in AI tutoring, our first-party backend provides the selected images, question, grade, and necessary conversation context to Alibaba Cloud EduTutor to generate the tutoring response. Other library content is not sent automatically.
  10. Google Firebase Analytics. This applies to Google Play Android and App Store iOS. After your explicit permission, it measures installation-level feature usage, app activity, retention, and product conversion. Information includes an app-instance identifier, basic device and operating-system information, app version, coarse region, and the low-cardinality product events described in this policy. This data is not fully anonymous. The app disables advertising identifiers, ad personalization, iOS IDFV collection, and on-device ads conversion data; it does not set an account or RevenueCat user ID. We do not send scans, files, OCR text, file names, or file paths. See Google's Firebase privacy and security information.
  11. Countly usage analytics. This applies to mainland China Android. After you accept this policy and enter the app, the Countly Flutter SDK sends an SDK-generated app-instance identifier, session information, basic device and operating-system information, app version, distribution channel, and low-cardinality feature events to a Countly service deployed and operated by us in mainland China. Location collection is disabled, and the app does not enable Countly crash reporting, user profiles, push, feedback, or remote configuration. You may disable analytics at any time under Permissions. It does not send phone numbers, scans, files, OCR text, file names, or file paths.
  12. System sharing, printing, Photos, and Downloads. Selected files are handed to the system service or target application only after your action. The recipient's own privacy policy applies.
  13. Obsidian. When selected, the app uses the Obsidian URL scheme to provide selected text and a file name for creating or appending a note.

The app contains no advertising SDK, does not use document content for ad targeting, and does not sell scans, OCR text, or local files.

4. Storage, Retention, and Deletion

5. Your Rights and Choices

You may manage permissions in system settings, delete local documents and settings in the app, and manage subscriptions through the app store. Google Play Android and App Store iOS let you allow analytics or choose Set up later on the first-run screen. Mainland China Android enables Countly analytics after you accept this policy and enter the app. All distributions let you disable or re-enable analytics under My/Account - System Settings - More Settings - Permissions. No new analytics events are sent before policy acceptance, after choosing Set up later, or after analytics is disabled. You may also contact us to request access, correction, deletion, withdrawal of consent, a copy, or an explanation of processing rules. Locally stored data inaccessible to us can be managed directly on your device.

6. Security

We use reasonable safeguards including local processing, system permission controls, device authentication for protected documents, and limiting unnecessary transfers. No system can guarantee absolute security; protect your device credentials, app passwords, and exported files.

7. Children

The app is not designed specifically for children. Minors should use it with a guardian's consent and guidance.

8. Policy Updates

We may update this policy when features, permissions, third-party services, or applicable requirements materially change. Where appropriate, notice will be provided in the app, store listing, or another reasonable channel.

9. Contact Us

You may include your device model, operating-system version, PaceScan version, and affected screen. Do not send full card details, payment passwords, or unrelated sensitive documents.

© 2026 Nanjing Baoluan Information Technology Co., Ltd. All rights reserved.