Privacy Policy
This Privacy Policy describes how Artem Lapshin ("we", "us", or "our"), as the operator of the NativeScan mobile application ("App") and any related websites (collectively, the "Service"), handles information from users of the Service. It is incorporated by reference into our Terms of Service and our AI Use Disclosure.
We have intentionally designed the App to minimise the personal information that leaves your device. The categories below describe what is processed, when, and by whom. Read Section 3 for the AI features specifically — those are where document content leaves your device.
To let you find documents from the iOS system search screen, the App adds each document's name, its AI category, and a short excerpt of its recognised text (approximately the first 280 characters) to Apple's on-device Core Spotlight index. This index is maintained by iOS on your device. It is not transmitted to us. Note that content in the Spotlight index can surface in system search results outside the App, and may be included in encrypted device backups made by iOS. Deleting the App removes its Spotlight entries.
Please read this carefully — it corrects a statement in the previous version of this policy. When you use the microphone to dictate a Recall question, the App uses Apple's SFSpeechRecognizer. Depending on your device model, the language you speak, and your iOS settings, Apple's speech recognition may process your audio on Apple's servers rather than on your device. The App does not force on-device-only recognition. Audio handled this way is processed by Apple under Apple's privacy policy, not ours — we never receive the audio itself, only the resulting transcribed text, which is then used as your Recall question (and therefore transmitted as described in Section 3). If you would prefer that no audio ever leaves your device, type your Recall questions instead of dictating them, or deny the microphone and speech-recognition permissions.
The App counts how many people use it. This is the App's only outbound telemetry that is not part of a feature you invoked.
We use this solely to know how many people use NativeScan, how many are active, and which App and iOS versions are in use so we can decide what to support. It is not used to profile you, is not sold or shared, and is not combined with any other source.
Our proxy records technical failures so we can detect outages — for example, if the AI provider starts rejecting requests. Each record contains a timestamp, which feature failed ("naming", "recall", "auth", or "request"), an error code, an HTTP status, and a short sanitised technical detail capped at 200 characters describing the shape of the problem (for example, the length of a malformed response). Records contain no identifiers, no document content, no OCR text, no chat messages, and no AI output. Successful requests are not logged at all.
To stop any single source from exhausting our AI quota, our proxy counts requests per IP address within a rolling one-hour window. Your IP address is used transiently as a lookup key in Cloudflare's edge cache and expires automatically at the end of that window. It is not written to our database, not associated with your install identifier, and not retained.
These third parties operate under their own terms and privacy policies. We have no control over, and accept no responsibility for, their practices. You are responsible for reviewing their policies.
Free users are shown Apple's App Tracking Transparency prompt shortly after first entering the App, and, where required by law, a Google-provided consent form for advertising. If you allow tracking, AdMob may use your advertising identifier to personalise ads. If you decline, ads are still shown but are less personalised — the App works exactly the same either way, and no NativeScan feature is withheld. You can change your choice at any time in iOS Settings → Privacy & Security → Tracking. Our own analytics described in Section 2.4 do not use the advertising identifier and are unaffected by this choice.
NativeScan's AI features are powered by Google's Gemini models, reached through a proxy we operate on Cloudflare. When you use one, the data listed below is transmitted from your device, through our proxy, to Google, and the response is returned to you. Our proxy does not retain the request or the response. See the AI Use Disclosure for the full description, including the limitations of AI output.
| Feature | What is transmitted | When |
|---|---|---|
| AutoName — suggests a document title | One page image from the document, downscaled, plus the recognised text of the document | Automatically after a scan finishes processing, and when you manually re-run it |
| AutoSort — suggests a category folder | Same single request as AutoName — no additional data is sent | Same as AutoName (result applied for Pro subscribers) |
| Recall — ask questions about your documents | Your question, plus the title and an excerpt of recognised text from up to five documents the App judges most relevant, plus recent messages in the current conversation | When you send a Recall message |
| Recall suggestions — proposes questions you might ask | The title, category, and a short text excerpt from your three most recent documents | Automatically, once your library reaches three documents, then refreshed periodically |
| Key dates — finds due dates, expiry and renewal dates | The recognised text of the document, plus today's date. This is the largest text payload of any feature. | Automatically in the background, only when on-device date detection finds nothing. Free tier: your two oldest documents. Pro: all documents. |
Two of these run automatically. AutoName runs after every scan, and key-date extraction and Recall suggestions run in the background without a separate prompt each time. There is currently no in-app switch to disable AI processing — it is integral to how NativeScan works. If you do not want a particular document's contents processed this way, do not scan it into NativeScan. Your acceptance of the AI Use Disclosure during onboarding is your consent to this processing.
No account, real name, email address, or persistent user identifier is attached to AI requests by us. The anonymous analytics identifier described in Section 2.4 is not sent with AI requests and cannot be used to link an AI request back to an install.
Pro subscribers can enable reminders for key dates found in their documents. These are local notifications scheduled by the App on your device — nothing is sent to a server, and we cannot see them. Notification permission is requested only at the moment you turn the feature on, never at launch.
Be aware: a reminder's text includes the document's name (for example, "Chase Bank Statement — in 3 days"), and iOS may display that on your lock screen. If your document names are sensitive, either leave reminders off or configure iOS to hide notification previews when locked (Settings → Notifications → Show Previews).
We use the limited information that reaches our infrastructure solely to:
We do not:
For users in the European Economic Area, the United Kingdom, or Switzerland:
The App is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided information to us, contact nativescan.tool@gmail.com and we will take reasonable steps to address it.
We are based in Canada. When you use AI features, your content is transmitted to Cloudflare's global edge network and to Google's Gemini API, which may process it in the United States or other countries. Our analytics database is hosted by Cloudflare. By using the App you understand and accept that your information may be transferred to and processed in countries other than your own, including countries with different data-protection rules, and you consent to such transfers where your consent is required.
We do not back up your documents and have no ability to recover them. Because all scanned documents are stored locally on your device, the loss, theft, damage, replacement, or factory reset of your device, uninstallation of the App, failure of iCloud or any other sync service, or any software malfunction may result in the permanent and irrecoverable loss of your data. You are solely responsible for backing up anything that matters to you by exporting it through the App's share feature and storing copies somewhere you control. We will not be liable for any loss of data and have no obligation to attempt recovery.
We use commercially reasonable security measures, including HTTPS in transit, an authenticated channel between the App and our proxy, iOS file protection on sensitive caches, and abuse-prevention measures. No method of transmission or storage is 100% secure and we cannot guarantee absolute security. Because documents are stored on your device, their security depends primarily on the security of your device, your passcode, and your iCloud configuration. We strongly recommend enabling a device passcode and the in-app Face ID / Touch ID lock. We are not liable for unauthorised access to your device or documents resulting from your device being lost, stolen, shared, jailbroken, or otherwise outside our reasonable control.
Depending on where you live, you may have rights to know what personal information we hold, request access to it, request correction or deletion, object to or restrict processing, request portability, withdraw consent, and lodge a complaint with a supervisory authority (in the EEA, your national data-protection authority; in Canada, the Office of the Privacy Commissioner of Canada; in California, the California Attorney General).
In practice, because the App stores documents only on your device and our servers hold no information that identifies you:
In the twelve months preceding the effective date of this Policy we did not "sell" or "share" personal information for cross-context behavioural advertising as defined under California law, other than through the operation of Google AdMob for free users where you permitted tracking. You may opt out at any time through iOS Settings → Privacy & Security → Tracking, and through any in-app advertising consent form. We do not discriminate against users who exercise their privacy rights.
NativeScan's own analytics do not track you across apps or websites and do not use the advertising identifier. Google AdMob may use tracking for personalised advertising where you have allowed it through Apple's App Tracking Transparency prompt. Our website is a static informational site, does not track visitors, sets no cookies, and loads no analytics scripts, so no separate "Do Not Track" handling is required.
The Service depends on third-party platforms and providers including Apple, Google (Gemini and AdMob), and Cloudflare. Those third parties operate under their own terms and privacy policies. We do not control them and are not responsible for any act, omission, change in policy, outage, data breach, security incident, or misuse on their part. Any claim arising out of a third party's conduct must be brought against that third party, not against us.
While we have designed the App to minimise the personal information that leaves your device, we do not warrant or guarantee any particular privacy outcome. Bugs, third-party changes, or future product changes may alter what is transmitted; where material, we will disclose those changes through an update to this Policy and an in-app re-acceptance prompt. Your use of the App is at your own risk, and our total liability for any privacy-related claim is subject to the limitation of liability in the Terms of Service.
We may update this Policy from time to time. When we make material changes we update the version number and effective date at the top of this document. Where a change materially affects how we handle your information, we will require renewed in-app consent. Your continued use of the App after an update constitutes acceptance of the updated Policy.
Questions, requests, and privacy complaints: nativescan.tool@gmail.com.