The short version
- Your scans, PDFs and recognised text are stored only on your phone.
- Text recognition runs on the device. No images are uploaded to read them.
- No account is needed. There are no ads, and we never sell data.
- Anonymous usage counts and crash reports help us fix bugs. They never include your documents, and one switch in Settings turns them off.
- Google Play handles payments. We never see your card.
- Optional encrypted backup (Scansy Vault (not yet available)) is end-to-end encrypted: we cannot read your documents.
- You can access, correct or delete your data at any time by emailing scansy@ellipsia.app.
About this policy
This Privacy Policy explains how Ellipsia Inc (“we”, “us”, “our”) handles information when you use the Scansy — Document Scanner & PDF tools app for Android (“Scansy” or “the app”), the optional Scansy Vault encrypted backup service (not yet available), and this website at scansy.ellipsia.app (together, the “Services”).
“Personal data” (or “personal information”) means information that identifies you or could reasonably be linked to you. Scansy is designed so that we receive as little of it as possible. Much of this policy describes what we don’t collect, because your documents never leave your phone unless you choose to back them up.
This policy does not cover services run by other companies that you reach from Scansy, such as Google Play or the apps you share documents to. Their own privacy policies apply.
Who is responsible for your data
Ellipsia Inc is the controller (the organisation that decides how and why personal data is processed) for the limited personal data described in this policy.
- Legal entity: Ellipsia Inc
- Email for privacy requests: scansy@ellipsia.app
What we process, at a glance
The table below lists every category of information that reaches us or our service providers. Anything not listed here, including your scans, stays on your device.
| Information | Why | Legal basis (EEA/UK) | Kept for |
|---|---|---|---|
| Anonymous usage events (e.g. “a scan was saved”), device and app version | Understand which features are used and improve them | Legitimate interests; you can object with the switch in Settings | 2 months |
| Crash diagnostics | Find and fix bugs | Legitimate interests; you can object with the switch in Settings | Up to 90 days |
| Purchase records and an anonymous app user ID | Unlock Scansy Pro and restore it on a new device | Performance of a contract; legal obligation (tax records) | As long as needed to restore purchases, and as tax law requires |
| Vault (not yet available): email address, account ID, encrypted files, file sizes and upload times | Provide the encrypted backup you asked for | Performance of a contract | Until you delete your backup or account (see below) |
| Website server logs kept by our host | Keep the site secure and working | Legitimate interests | A short period set by our hosting provider |
What stays on your device
The following never leaves your phone and is never sent to us:
- scanned images, PDFs, document names, folders and text recognised from your pages, which are stored only on your device;
- the images you run text recognition (OCR) on. OCR runs on your device using Google ML Kit’s on-device model, so images are not uploaded to be read;
- passwords you add to PDFs, and signatures you add to documents.
You do not need an account to use the app. Because we never receive this content, we cannot see it, recover it or delete it for you. Deleting it in the app, clearing the app’s data or uninstalling the app removes it.
App permissions
- Camera: only to scan documents.
- Photos / storage (older Android versions): only to import images you choose and to save files you export.
Scansy does not request microphone, location or contacts permissions. You can review or revoke permissions at any time in Android Settings → Apps → Scansy → Permissions.
Anonymous usage analytics and crash reports
Scansy uses Google Firebase Analytics and Firebase Crashlytics to understand which features are used and to fix crashes. They collect only:
- counts and event types, for example “a scan was saved” or “the PDF compress tool was used”;
- device and app version information, such as Android version and device model;
- crash diagnostics describing what the app was doing when it crashed;
- a random app-instance identifier that is not linked to your name or email.
They never collect document content, file names, file paths, recognised text or images. The advertising ID and Google signals are disabled, so this data is not used for advertising or combined with your Google account. Analytics data is kept for 2 months.
You can turn both off in the app under Settings, with one switch. While it is off, no analytics events or crash reports are sent.
Purchases (Google Play Billing and RevenueCat)
- Payments are processed by Google Play under Google’s terms. We never see or store your card or payment details.
- We use RevenueCat to manage purchases. RevenueCat receives purchase records (what was bought, when, the store transaction details and status) and an anonymous app user ID, so your purchase can be verified and restored on a new device.
- Google Play may send us aggregated sales reports and, for purchases, an order number. We use these only for accounting, refunds and support.
Other Google Play services
In-app review prompts and in-app updates are handled by Google Play. When they appear, you are interacting with Google Play, under Google’s Privacy Policy. We do not receive the content of reviews you write through the prompt unless you publish them on Google Play, where they are public.
Optional encrypted backup: Scansy Vault
Not yet available. This section describes how Scansy Vault will work when it launches.
Scansy Vault is optional and off by default. Nothing in this section applies unless you choose to turn on backup. If you do:
- Sign-in is with Google or a one-time code sent to your email. We store your email address and an account ID with Supabase, our authentication and database provider.
- Your documents are end-to-end encrypted on your phone before upload (AES-256-GCM, with a unique key for each document) and stored as encrypted files with our storage provider, Cloudflare R2. We cannot read your backed-up documents.
- The key that unlocks your backup is kept either in your own Google account (Android Block Store / Google Drive app data, which you control) or only by you as a recovery key. We never hold a usable copy.
- Your RevenueCat user ID is linked to your account ID so your subscription works across your devices.
- We store the encrypted files, their sizes and upload timestamps to run the service and enforce the 10 GB storage limit.
Zero-knowledge means we cannot recover your documents. If you lose access to your key (for example, you lose your recovery key and no longer have the Google account that stored it), your backed-up documents cannot be decrypted by anyone, including us. That is the trade-off of encryption we can’t read.
This website
This website sets no cookies of its own and runs no analytics, tracking or advertising scripts. A preference for light or dark mode is saved in your browser’s local storage and never sent to us.
Like any website, our hosting provider may keep standard server logs (such as IP address, browser type, the page requested and the time) for a short period to keep the site secure and working. We do not use them to identify you. Links to Google Play take you to Google’s site, where Google’s policies apply; those links carry a label saying which part of this site you clicked from, but nothing about you.
How we use information
We use the limited information described above only to:
- provide Scansy and its features, including unlocking and restoring purchases;
- provide Scansy Vault, if you use it;
- understand which features are used, fix bugs and improve the app;
- respond to your messages and support requests;
- keep our Services secure and prevent abuse; and
- meet legal, tax and accounting obligations.
We do not make decisions about you based solely on automated processing, and we do not build profiles of you.
What we never do
- We never sell your data.
- We never share your data for advertising, and Scansy shows no ads.
- We never use your documents to train AI models.
- We never read your documents, on your phone or in Vault.
When information is shared
We share information only in these cases:
- Service providers that process it on our behalf and under contract to run the Services (listed in Service providers below).
- Legal reasons, when we are required to by law, court order or a valid request from a public authority, or to protect the rights, safety or property of our users, the public or us. Your documents are not available to us, so we cannot disclose them.
- Business transfers, if Ellipsia Inc is involved in a merger, acquisition or sale of assets. Any successor must continue to protect your information as this policy describes, and we will tell you before that happens.
- With your consent, or when you direct it, for example when you share a document to another app.
Service providers
| Provider | What for | Privacy policy |
|---|---|---|
| Google (Firebase Analytics, Crashlytics, Google Play, ML Kit) | Anonymous analytics, crash reports, payments, app updates and review prompts | Google · Firebase |
| RevenueCat | Purchase management and restoring purchases | RevenueCat |
| Supabase | Vault sign-in and account database (only if you use Vault) | Supabase |
| Cloudflare (R2) | Storage of encrypted Vault files (only if you use Vault) | Cloudflare |
International transfers
Our service providers may process information in countries other than yours, including the United States. Where the law requires it, these transfers are protected by appropriate safeguards, such as the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, or an adequacy decision. Your documents are never transferred unless you use Vault, and then only in encrypted form we cannot read.
How long information is kept
| Information | Where it lives | How long |
|---|---|---|
| Scans, PDFs, names, folders, recognised text | Your device only | Until you delete them or uninstall the app |
| Anonymous usage analytics | Google Firebase | 2 months |
| Crash reports | Firebase Crashlytics | Up to 90 days |
| Purchase records and anonymous app user ID | RevenueCat, Google Play | As long as needed to restore purchases, and as required by tax and consumer law |
| Vault: email, account ID, encrypted files and metadata | Supabase, Cloudflare R2 | Until you delete your backup or account; deleted within 30 days of your request |
| Emails you send us | Our email provider | As long as needed to help you, then deleted |
How to delete your data, and what is kept for legal reasons, is explained on the account and data deletion page.
Security
- Your documents are never uploaded, so there is no copy of them on our side to leak.
- Analytics, crash reports and purchase data are sent over encrypted connections (HTTPS).
- Vault backups are end-to-end encrypted with AES-256-GCM on your phone before upload, with a unique key per document. We never hold a usable key.
No method of transmission or storage is completely secure, but we design Scansy to minimise what could ever be exposed. Keeping your phone protected with a screen lock is the best way to protect documents stored on it. If we become aware of a breach affecting your personal data, we will notify you and the relevant authorities where the law requires.
Your choices and controls
- Analytics and crash reports: turn them off in Scansy’s Settings.
- Permissions: revoke camera or storage access in Android Settings. Scansy will ask again only when you use a feature that needs it.
- Your documents: delete them in the app, or uninstall Scansy to remove everything on your phone.
- Vault (not yet available): delete your backup or your account in the app at any time.
Your privacy rights
Depending on where you live, you may have the right to: access the personal data we hold about you; have it corrected; have it deleted; receive a copy in a portable format; restrict or object to our processing; and withdraw consent at any time, without affecting processing that happened before.
How to make a request: email scansy@ellipsia.app. For Vault requests, write from the email address on your account so we can verify it is you. Because we do not hold names or accounts for most users, we may be unable to link anonymous analytics or purchase records to you; if so, we will explain why. We will respond within one month (or the period your local law sets), and we never charge for a request unless it is manifestly unfounded or excessive.
If we decline a request, we will tell you why, and you may ask us to reconsider by replying to our answer.
Additional information for the EEA and UK
If you are in the European Economic Area or the United Kingdom, the GDPR or UK GDPR applies to our processing of your personal data. The legal bases we rely on are listed in What we process, at a glance. Where we rely on legitimate interests (anonymous analytics, crash reports and website security), we have balanced them against your rights. The data involved is minimal and not linked to your identity, and you can object at any time with the switch in Settings.
You have the right to lodge a complaint with your local data protection authority. In the UK, that is the Information Commissioner’s Office (ICO). We would appreciate the chance to address your concern first, so please contact us.
Additional information for California residents
Under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA), in the past 12 months we have collected these categories of personal information:
| Category | Examples | Sold or shared? |
|---|---|---|
| Identifiers | Anonymous app-instance and app user IDs; email address and account ID only if you use Vault | No |
| Commercial information | Records of Scansy Pro or Vault purchases | No |
| Internet or other electronic network activity | Anonymous feature-use events and crash diagnostics | No |
We collect this information from you and your device, for the business purposes described in How we use information, and disclose it only to the service providers listed above. We do not sell or “share” personal information (as those terms are defined in California law), including of consumers under 16, and we do not use or disclose sensitive personal information. Retention periods are listed in How long information is kept.
You have the right to know what personal information we collect, use and disclose; to delete it; to correct it; and not to be discriminated against for exercising these rights. You may use an authorised agent, and we may ask for proof of the agent’s authority. Because we do not sell or share personal information, there is nothing to opt out of, and we treat Global Privacy Control signals as an opt-out request in any case. California’s “Shine the Light” law does not apply because we do not disclose personal information to third parties for their direct marketing.
Additional information for India
If you are in India, the Digital Personal Data Protection Act, 2023 (DPDP Act) applies. This policy is our notice under that Act. You have the right to: obtain a summary of the personal data we process and the processing activities; correct, complete, update and erase your personal data; withdraw consent at any time, as easily as you gave it; nominate another person to exercise your rights in the event of your death or incapacity; and grievance redressal.
Our grievance contact is reachable at scansy@ellipsia.app. We will respond within the period required by law. If you are not satisfied with our response, you may complain to the Data Protection Board of India.
Other regions
Residents of other places, including Brazil (LGPD), Canada (PIPEDA), Australia, Japan, Switzerland and other US states with privacy laws, may have similar rights. We honour those rights as required by the applicable law; contact us to use them.
Children
Scansy is not directed at children under 13 (or the minimum age of digital consent where you live, if higher), and we do not knowingly collect personal information from them. If you believe a child has given us personal information, for example by creating a Vault account, contact us and we will delete it.
Links to other services
The app and this website link to services we don’t control, such as Google Play and the privacy policies of our providers. When you share a document from Scansy to another app, that app’s privacy policy applies to what you share. We are not responsible for the practices of those services.
Google Play Data safety summary
This restates the facts above in the categories Google Play uses, so the Play listing and this policy agree.
Data collected
- App activity (app interactions): anonymous feature-use counts. Optional; can be turned off in Settings. Purpose: analytics.
- App info and performance (crash logs, diagnostics). Optional; can be turned off in Settings. Purpose: app functionality and bug fixing.
- Device or other IDs: an anonymous analytics instance ID and an anonymous app user ID for purchases. Purpose: analytics and restoring purchases.
- Financial info (purchase history): purchase records via Google Play and RevenueCat. Purpose: app functionality (unlocking and restoring Pro).
- Personal info (email address, user IDs): only when Vault is available and if you turn on Vault. Purpose: account management.
Scanned documents, photos and recognised text are not collected: they stay on your device. Vault backups are end-to-end encrypted and cannot be read by us.
Data shared
No data is shared with third parties. The providers above process data only on our behalf to run the app.
Security practices
- Data is encrypted in transit.
- You can request that data be deleted.
- Analytics and crash reporting are optional and can be turned off in the app.
Changes to this policy
We may update this policy as Scansy changes or the law requires. We will change the “Last updated” date at the top of this page. If a change is significant (for example, a new kind of data or a new purpose), we will tell you in the app or in the Google Play release notes before it takes effect and, where the law requires, ask for your consent. Earlier versions are available on request.
Contact us
For questions, requests or complaints about privacy, email scansy@ellipsia.app.
Scansy is published by Ellipsia Inc (ellipsia.app). See also our Terms of Service.