NativeScan · Legal
Privacy Policy
Version 3.0 · effective August 1, 2026.
1. Who this Policy Applies To
This Privacy Policy describes how Artem Lapshin ("we", "us", or "our"), as the operator of the NativeScan mobile application ("App") and any related websites (collectively, the "Service"), handles information from users of the Service. It is incorporated by reference into our Terms of Service and our AI Use Disclosure.
2. Information We Process
We have intentionally designed the App to minimise the personal information that leaves your device. The categories below describe what is processed, when, and by whom. Read Section 3 for the AI features specifically — those are where document content leaves your device.
2.1 Stored locally on your device only
- Scanned documents and associated metadata — captured images, edited pages, document titles, categories, custom folders, extracted key dates, and timestamps. These are stored in the App's private storage on your device. They are not uploaded to us and we keep no copy. Document content is transmitted for processing when you use an AI feature — see Section 3.
- App preferences — onboarding status, appearance setting, biometric-lock setting, subscription state, legal-acceptance flags, AI quota counters, ad frequency counters, and similar small values stored in iOS UserDefaults.
- Biometric data — Face ID / Touch ID / Optic ID for the optional app lock is handled entirely by iOS. We never see, receive, process, or transmit your biometric data; iOS only tells the App whether authentication succeeded.
- On-device text recognition (OCR) — performed locally using Apple's Vision framework. The OCR step itself involves no network connection. The resulting text is stored on your device and may later be transmitted if you use an AI feature.
- On-device date detection — the first pass at finding due dates and expiry dates uses Apple's on-device NSDataDetector over your OCR text, with no network connection.
- Derived caches — the App caches AI results and extracted dates on your device to avoid repeat processing. These are removed when you delete the App.
2.2 Spotlight indexing
To let you find documents from the iOS system search screen, the App adds each document's name, its AI category, and a short excerpt of its recognised text (approximately the first 280 characters) to Apple's on-device Core Spotlight index. This index is maintained by iOS on your device. It is not transmitted to us. Note that content in the Spotlight index can surface in system search results outside the App, and may be included in encrypted device backups made by iOS. Deleting the App removes its Spotlight entries.
2.3 Voice input for Recall
Please read this carefully — it corrects a statement in the previous version of this policy. When you use the microphone to dictate a Recall question, the App uses Apple's SFSpeechRecognizer. Depending on your device model, the language you speak, and your iOS settings, Apple's speech recognition may process your audio on Apple's servers rather than on your device. The App does not force on-device-only recognition. Audio handled this way is processed by Apple under Apple's privacy policy, not ours — we never receive the audio itself, only the resulting transcribed text, which is then used as your Recall question (and therefore transmitted as described in Section 3). If you would prefer that no audio ever leaves your device, type your Recall questions instead of dictating them, or deny the microphone and speech-recognition permissions.
2.4 Anonymous usage analytics
The App counts how many people use it. This is the App's only outbound telemetry that is not part of a feature you invoked.
- What is sent: a random identifier the App generates for itself on first launch, the App's version number, and your major iOS version (for example "iOS 26"). Nothing else.
- When: at most once per hour, when you open the App. It is sent in the background and never delays anything.
- The identifier is a random value created by the App. It is not the Apple advertising identifier (IDFA), not the vendor identifier (IDFV), and is not derived from any hardware or account identifier. It exists nowhere else and cannot be matched to you, to your Apple ID, or to your activity in any other app or website. Deleting NativeScan destroys it permanently; reinstalling generates a brand-new one.
- What we store: our server stores only a one-way SHA-256 hash of that identifier, the timestamp we first saw it, the App version, and the iOS major version. We store two things per user: one permanent row recording that an install exists, and one row per hour in which the App was opened.
- What is never sent or stored with it: your IP address, device model, device name, locale, location, or any document, image, OCR, or chat content.
We use this solely to know how many people use NativeScan, how many are active, and which App and iOS versions are in use so we can decide what to support. It is not used to profile you, is not sold or shared, and is not combined with any other source.
2.5 Service-reliability telemetry (our server)
Our proxy records technical failures so we can detect outages — for example, if the AI provider starts rejecting requests. Each record contains a timestamp, which feature failed ("naming", "recall", "auth", or "request"), an error code, an HTTP status, and a short sanitised technical detail capped at 200 characters describing the shape of the problem (for example, the length of a malformed response). Records contain no identifiers, no document content, no OCR text, no chat messages, and no AI output. Successful requests are not logged at all.
2.6 Abuse prevention
To stop any single source from exhausting our AI quota, our proxy counts requests per IP address within a rolling one-hour window. Your IP address is used transiently as a lookup key in Cloudflare's edge cache and expires automatically at the end of that window. It is not written to our database, not associated with your install identifier, and not retained.
2.7 Collected by third-party services we do not control
These third parties operate under their own terms and privacy policies. We have no control over, and accept no responsibility for, their practices. You are responsible for reviewing their policies.
- Apple. If you purchase a subscription, Apple processes the transaction through StoreKit. We receive only your subscription status — never your Apple ID, name, email address, or payment method. Apple's speech recognition may also process dictated audio (Section 2.3).
- Google AdMob (free users only). AdMob may collect device identifiers (including Apple's Identifier for Advertisers where you have permitted tracking), ad-interaction data, coarse location, IP address, and similar information in order to select, serve, and measure advertising. Ad formats used are banner, interstitial, rewarded, app-open, and native ads. AdMob's processing is governed by Google's privacy policy.
- Google (Gemini API). Processes the document content you submit for an AI feature. Governed by Google's API terms and applicable Gemini data-use policies.
- Cloudflare. Hosts our proxy and our analytics database. May process technical information such as IP address and request metadata as part of providing the service, governed by Cloudflare's privacy policy.
2.8 App Tracking Transparency and advertising consent
Free users are shown Apple's App Tracking Transparency prompt shortly after first entering the App, and, where required by law, a Google-provided consent form for advertising. If you allow tracking, AdMob may use your advertising identifier to personalise ads. If you decline, ads are still shown but are less personalised — the App works exactly the same either way, and no NativeScan feature is withheld. You can change your choice at any time in iOS Settings → Privacy & Security → Tracking. Our own analytics described in Section 2.4 do not use the advertising identifier and are unaffected by this choice.
3. AI Features — what leaves your device
NativeScan's AI features are powered by Google's Gemini models, reached through a proxy we operate on Cloudflare. When you use one, the data listed below is transmitted from your device, through our proxy, to Google, and the response is returned to you. Our proxy does not retain the request or the response. See the AI Use Disclosure for the full description, including the limitations of AI output.
| Feature | What is transmitted | When |
|---|---|---|
| AutoName — suggests a document title | One page image from the document, downscaled, plus the recognised text of the document | Automatically after a scan finishes processing, and when you manually re-run it |
| AutoSort — suggests a category folder | Same single request as AutoName — no additional data is sent | Same as AutoName (result applied for Pro subscribers) |
| Recall — ask questions about your documents | Your question, plus the title and an excerpt of recognised text from up to five documents the App judges most relevant, plus recent messages in the current conversation | When you send a Recall message |
| Recall suggestions — proposes questions you might ask | The title, category, and a short text excerpt from your three most recent documents | Automatically, once your library reaches three documents, then refreshed periodically |
| Key dates — finds due dates, expiry and renewal dates | The recognised text of the document, plus today's date. This is the largest text payload of any feature. | Automatically in the background, only when on-device date detection finds nothing. Free tier: your two oldest documents. Pro: all documents. |
Four of these run automatically. AutoName and AutoSort run after every scan, and key-date extraction and Recall suggestions run in the background without a separate prompt each time. There is currently no in-app switch to disable AI processing — it is integral to how NativeScan works. If you do not want a particular document's contents processed this way, do not scan it into NativeScan. Your acceptance of the AI Use Disclosure during onboarding is your consent to this processing.
No account, real name, email address, or persistent user identifier is attached to AI requests by us. The anonymous analytics identifier described in Section 2.4 is not sent with AI requests and cannot be used to link an AI request back to an install.
4. Notifications
Pro subscribers can enable reminders for key dates found in their documents. These are local notifications scheduled by the App on your device — nothing is sent to a server, and we cannot see them. Notification permission is requested only at the moment you turn the feature on, never at launch.
Be aware: a reminder's text includes the document's name (for example, "Chase Bank Statement — in 3 days"), and iOS may display that on your lock screen. If your document names are sensitive, either leave reminders off or configure iOS to hide notification previews when locked (Settings → Notifications → Show Previews).
5. How We Use Information
We use the limited information that reaches our infrastructure solely to:
- operate the AI features you invoke;
- count unique and active users, and see which App and iOS versions are in use;
- detect and diagnose outages and bugs;
- prevent abuse of our AI proxy; and
- comply with applicable law.
We do not:
- sell, rent, or trade your information;
- use your documents, images, OCR text, or chat messages to train, evaluate, or fine-tune any AI model;
- retain document content, AI requests, or AI responses on our servers after the request completes;
- combine our analytics with any other source, or with advertising data, to build a profile of you;
- attach your analytics identifier to AI requests, ad requests, or anything else;
- send marketing email (we do not have your email address); or
- use your scanned content to build advertising audiences.
6. Legal Bases for Processing (where applicable)
For users in the European Economic Area, the United Kingdom, or Switzerland:
- Performance of a contract — providing the App and the features you invoke;
- Consent — your acceptance of these documents at installation, and your advertising-consent and tracking choices;
- Legitimate interests — counting users, operating and securing the App, preventing abuse, diagnosing outages, and defending legal claims, balanced against your rights and freedoms; and
- Compliance with legal obligations — where applicable.
7. Children
The App is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided information to us, contact nativescan.tool@gmail.com and we will take reasonable steps to address it.
8. International Transfers
We are based in Canada. When you use AI features, your content is transmitted to Cloudflare's global edge network and to Google's Gemini API, which may process it in the United States or other countries. Our analytics database is hosted by Cloudflare. By using the App you understand and accept that your information may be transferred to and processed in countries other than your own, including countries with different data-protection rules, and you consent to such transfers where your consent is required.
9. Data Retention, Backups, and Loss
- On your device: data persists until you delete the document, clear the App's data, or uninstall the App.
- AI requests in our proxy: not persisted at all. Request and response bodies exist only for the duration of the request.
- Analytics: the hashed install identifier and the hourly activity rows are retained indefinitely, because their entire purpose is counting users over time. They contain no personal data and cannot be traced to you.
- Reliability telemetry: retained indefinitely; contains no identifiers or content.
- Abuse-prevention counters: expire automatically within one hour.
- Third parties retain information according to their own policies, which we do not control.
We do not back up your documents and have no ability to recover them. Because all scanned documents are stored locally on your device, the loss, theft, damage, replacement, or factory reset of your device, uninstallation of the App, failure of iCloud or any other sync service, or any software malfunction may result in the permanent and irrecoverable loss of your data. You are solely responsible for backing up anything that matters to you by exporting it through the App's share feature and storing copies somewhere you control. We will not be liable for any loss of data and have no obligation to attempt recovery.
10. Security
We use commercially reasonable security measures, including HTTPS in transit, an authenticated channel between the App and our proxy, iOS file protection on sensitive caches, and abuse-prevention measures. No method of transmission or storage is 100% secure and we cannot guarantee absolute security. Because documents are stored on your device, their security depends primarily on the security of your device, your passcode, and your iCloud configuration. We strongly recommend enabling a device passcode and the in-app Face ID / Touch ID lock. We are not liable for unauthorised access to your device or documents resulting from your device being lost, stolen, shared, jailbroken, or otherwise outside our reasonable control.
11. Your Rights
Depending on where you live, you may have rights to know what personal information we hold, request access to it, request correction or deletion, object to or restrict processing, request portability, withdraw consent, and lodge a complaint with a supervisory authority (in the EEA, your national data-protection authority; in Canada, the Office of the Privacy Commissioner of Canada; in California, the California Attorney General).
In practice, because the App stores documents only on your device and our servers hold no information that identifies you:
- To delete everything: uninstall the App. That removes every document, every cache, every preference, and the analytics identifier itself. Because we store only an unlinkable hash, once you uninstall there is nothing left that could ever be connected back to you.
- To delete a single document: swipe to delete it in the Library.
- For third-party-held data (Google, Cloudflare, AdMob, Apple), direct requests to those providers.
- For anything requiring our action, contact nativescan.tool@gmail.com. Note that we may be unable to locate "your" analytics record, because by design we cannot tell which hashed identifier is yours.
12. California Residents (CCPA / CPRA)
In the twelve months preceding the effective date of this Policy we did not "sell" or "share" personal information for cross-context behavioural advertising as defined under California law, other than through the operation of Google AdMob for free users where you permitted tracking. You may opt out at any time through iOS Settings → Privacy & Security → Tracking, and through any in-app advertising consent form. We do not discriminate against users who exercise their privacy rights.
13. Tracking and Do Not Track
NativeScan's own analytics do not track you across apps or websites and do not use the advertising identifier. Google AdMob may use tracking for personalised advertising where you have allowed it through Apple's App Tracking Transparency prompt. Our website is a static informational site, does not track visitors, sets no cookies, and loads no analytics scripts, so no separate "Do Not Track" handling is required.
14. Third-Party Non-Liability
The Service depends on third-party platforms and providers including Apple, Google (Gemini and AdMob), and Cloudflare. Those third parties operate under their own terms and privacy policies. We do not control them and are not responsible for any act, omission, change in policy, outage, data breach, security incident, or misuse on their part. Any claim arising out of a third party's conduct must be brought against that third party, not against us.
15. No Warranty as to Privacy Outcomes
While we have designed the App to minimise the personal information that leaves your device, we do not warrant or guarantee any particular privacy outcome. Bugs, third-party changes, or future product changes may alter what is transmitted; where material, we will disclose those changes through an update to this Policy and an in-app re-acceptance prompt. Your use of the App is at your own risk, and our total liability for any privacy-related claim is subject to the limitation of liability in the Terms of Service.
16. Changes to this Policy
We may update this Policy from time to time. When we make material changes we update the version number and effective date at the top of this document. Where a change materially affects how we handle your information, we will require renewed in-app consent. Your continued use of the App after an update constitutes acceptance of the updated Policy.
17. Contact
Questions, requests, and privacy complaints: nativescan.tool@gmail.com.