Privacy Policy

AI Scanner · Levon Altunyan

Last updated: August 26, 2026

Summary

AI Scanner is built to be private by default. Your documents are stored on your device. Scanning, text recognition and QR reading all run on-device. We show no ads and we never sell or share your personal information for advertising. Three things can send data off your device, and you control all three: cloud sync (requires signing in and an active subscription), AI features (off until you turn them on — and which send a page image rather than text when a document is in a script the on-device reader cannot handle), and anything you export or share yourself. This policy explains each one in detail.

Who is responsible for your data

Levon Altunyan is the publisher of AI Scanner and the data controller for the processing described here. You can reach us at ie.levon.altunyan@gmail.com for any question about this policy, or to exercise the rights described below. We are an individual developer based in Armenia. The app is available worldwide, and the service providers listed below process data in the United States and the European Union, so your information is handled in countries other than your own.

Information stored on your device

Scans and their page images, generated PDFs, thumbnails, recognized text (OCR), signatures, tags, document names, expiry dates, parsed receipt details, your recent-clipboard history and your app settings are stored locally on your device. This information stays on the device unless you turn on cloud sync, use an AI feature, or export or share it yourself. Uninstalling the app removes it. Two things worth knowing: the recent-clipboard list keeps whatever text you copied out of a scan, which can include account numbers or document numbers, and it is held in the app’s private storage without additional encryption — you can clear it at any time from the clipboard screen. Identity documents are the exception and are always encrypted, as described below.

Processing that happens only on your device

Document edge detection and capture, text recognition (OCR), QR and barcode decoding, receipt field parsing, document naming, and the sensitive-data detection that flags card numbers, IBANs, passport numbers and tax IDs for redaction all run entirely on your device using on-device libraries. None of these features send your document or its contents to us or to anyone else. On-device text recognition reads the Latin alphabet only; documents in other scripts are read by the optional AI features instead, which are described below and are off until you turn them on.

Your app identifier

When you first open the app, we create an anonymous account so your documents, settings and any purchase stay attached to you without asking you to register. This identifier is not linked to your name or email unless you later choose to sign in. It is created automatically and is used for app functionality, purchases and, if you enable them, AI features. Deleting the app removes it from your device.

Account and sign-in (optional)

Scanning and every on-device feature work without an account. If you choose to sign in with Google or Apple, we receive from that provider a user identifier and, where you permit it, your email address and display name, and we create an account for you using Firebase Authentication. Signing in links your existing anonymous data to that account. You can sign out at any time, which returns the app to an anonymous session.

Cloud sync (optional, premium)

Cloud sync runs only when you are signed in, have an active subscription, and have cloud backup switched on (it is on by default for subscribers). It is off in every other case, including for signed-in users without a subscription. When it runs, we upload to your private storage area: your page images and thumbnails; document names, creation and modification dates, page counts, document type, tags, favourite and pinned status, and expiry dates; the recognized text (OCR) of your documents; parsed receipt details including merchant, total, VAT, currency, date, category and payment method; and your AI chat history, described below. Access is restricted to your account by security rules — no other user can read your files. You can turn cloud backup off at any time in Settings. When you do, anything held only in the cloud is downloaded to this device first, and your uploaded scans and AI chat history are then removed from the cloud; the copies on this device are kept. Removing data from the cloud never erases the documents stored on a device — on another device that was syncing, the affected documents move to its Trash, where you can restore them. Signing out also stops sync.

Identity documents are never uploaded

Documents you scan in ID mode are encrypted on your device with AES-GCM-256, with the key held in the iOS Keychain or the Android Keystore. Their page images and recognized text are never uploaded or synced, even when you are signed in with sync active, and their text is never written to the searchable database. This applies to AI as well: the page images of an identity document are never sent to our AI provider, even when the document is in a script that on-device text recognition cannot read.

AI features (optional, off by default)

AI features are turned off until you enable them in Settings, and they require either an active subscription or available AI credits. When you invoke an AI action (understand, summarize, chat, rewrite, translate, compare or study aids), the text of the document you selected — up to roughly 24,000 characters — together with your question or instruction, is sent over an encrypted connection to our processing gateway, which forwards it to our AI provider, OpenAI, L.L.C., to generate a response. In one case the page images themselves are sent as well: on-device text recognition can only read the Latin alphabet, so when a document is written in another script — for example Chinese, Japanese, Korean, Arabic, Hebrew, Greek, Armenian or Cyrillic — there is no recognized text to send, and up to two pages of the document are included as images so the AI can read the document itself. When you compare two documents, this means one page image from each of the two documents you selected. This happens only when the on-device pass found no usable text, only for the document or documents you chose, and never for identity documents, which are never uploaded at all. Page images are downscaled and stripped of metadata such as location before they are sent. Our gateway does not store the text or images you send or the answer you receive; it records only a counter of how many requests you have made, so we can apply the usage limits described in the Terms. OpenAI processes this content on our behalf as our service provider under its API terms, does not use it to train its models, and may retain it briefly for abuse monitoring before deleting it. Processing takes place in the United States. Do not use AI features on content you are not comfortable sending to a cloud provider; you can turn them off in Settings at any time.

AI chat history

Your conversations with the AI assistant, including your questions and the answers, are saved on your device so you can return to them. If cloud sync is active, they are also copied to your private cloud storage so a conversation survives reinstalling the app or moving to a new device. Chat history is added to, not overwritten — deleting a document also deletes its conversation from the cloud, and deleting your account erases all of it.

Analytics and crash reporting

We use Firebase Analytics and Firebase Crashlytics to understand which features are used and to fix crashes. These reports never include the content of your documents, your page images, recognized text, file names or AI conversations. They contain app events and counts (for example that a scan completed, how many pages it had and how long it took), plus technical information such as app version, device model, operating system version, language, coarse region and, for crashes, the error and stack trace. Firebase also assigns your installation of the app a random identifier of its own, separate from the account identifier described above, so repeat events can be counted without knowing who you are. These reports start switched on. You can turn analytics and crash reporting off at any time in Settings → Privacy, which stops collection at the source rather than merely hiding it; the app works fully with them off, and the identifier is reset if you turn them back on.

Purchases and subscriptions

Subscriptions and AI credit packs are sold and processed by the Apple App Store and Google Play. We never receive or store your card number or billing address. To unlock what you paid for, we verify your purchase with Apple or Google and store, linked to your account, whether you are premium, the product purchased, the store it came from, the renewal or expiry date, a purchase identifier, your AI credit balance, and — for Apple purchases — the App Store receipt, which is the only way to re-check your subscription status later. We keep records of purchases for as long as needed to provide the service, resolve disputes and meet tax and accounting obligations.

Features you connect or trigger yourself

Some features send data only at the moment you ask them to. Exporting expenses to Notion uses an integration token that you provide, stored on your device, and sends the selected receipt data to Notion under Notion’s own privacy policy. Exporting expenses for a spreadsheet copies the data to your clipboard. Adding a document expiry to your calendar creates an event in the calendar app you choose. Sharing or exporting a document sends it to whatever destination you pick in the system share sheet. Opening a link decoded from a QR code hands that link to your browser or the relevant app. We do not receive any of this data.

Device permissions

The app asks for the camera to scan documents and read QR codes; photo library access, only if you import an existing image; notifications, only if you enable expiry reminders; and Face ID, Touch ID or your device passcode if you turn on the app lock. Biometric checks are performed by your operating system — we never receive your fingerprint or face data. You can refuse or revoke any of these in your device settings; only the related feature stops working.

Notifications

If you enable expiry reminders, the app schedules local notifications on your device to warn you before a document expires. They are generated and delivered on the device and are not sent to us or through any server. We do not send marketing push notifications.

How we protect your information

Data in transit is encrypted with TLS. Cloud files and records are stored in Google Firebase with access restricted to your own account by server-enforced security rules. ID-mode documents are additionally encrypted at rest on your device. Our AI provider key is held server side and never ships inside the app. No system is perfectly secure, and you are responsible for keeping your sign-in method and device lock secure. If a breach affects your personal information, we will notify you and any regulator as required by law.

How long we keep information

Documents you delete go to Trash and are removed after 30 days — automatically the next time you open Trash, or immediately if you empty it. Local data stays until you delete it or uninstall. Cloud data stays until you delete the document, turn off cloud backup, or delete your account. Your anonymous app identifier lasts until you delete your account or uninstall the app. Analytics data is retained by Firebase for up to 14 months; crash reports for up to 90 days. AI usage counters reset monthly and daily. When you delete your account we erase your entitlement and usage records too. One exception: a single ledger entry per purchase is kept so the same receipt can never be redeemed twice, and your account identifier is stripped from it, leaving nothing that points back to you. Apple and Google keep their own records of your purchase under their own policies.

Who we share information with

We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We disclose information only to service providers who process it on our behalf under contract: Google (Firebase authentication, database, file storage, cloud functions, analytics, crash reporting and remote configuration), OpenAI (AI processing, only if you enable AI features), and Apple and Google as the stores that process your payments. We may also disclose information if required by law or valid legal process, or to protect our rights, users or the security of the service. If the app is ever sold or transferred, information may transfer with it, and we will give notice before your data becomes subject to a different policy.

International transfers

We are established in Armenia, and our service providers process data in the United States and the European Union. If you are in the European Economic Area, the United Kingdom or Switzerland, your information is transferred outside your country to jurisdictions, including Armenia and the United States, that are not covered by a European Commission adequacy decision and whose data protection laws differ from your own. For those transfers we rely on the European Commission’s Standard Contractual Clauses, or the UK Addendum, together with the technical measures described above — encryption in transit, account-scoped access rules, and keeping identity documents on your device entirely. You may request a copy of the safeguards we rely on by emailing ie.levon.altunyan@gmail.com.

Your privacy rights

You can use the app without an account, keep everything on-device, leave AI features off, turn analytics off, export a full backup you own, and delete any document or your entire account from Settings at any time. Depending on where you live, you may also have the right to access the personal information we hold, correct it, delete it, obtain a portable copy, object to or restrict certain processing, and withdraw consent you previously gave. Email ie.levon.altunyan@gmail.com to exercise any of these; we will respond within the time your law allows and will not treat you differently for asking.

Legal bases (EEA and UK users)

Where the GDPR or UK GDPR applies, we process your information: to perform our contract with you (providing the app, syncing your documents, delivering AI results and honouring your purchase); with your consent (AI features, expiry notifications, and connecting Notion), which you may withdraw at any time in Settings; and for our legitimate interests in keeping the service secure, preventing abuse of usage limits, understanding which features are used and fixing defects. Analytics and crash reporting rest on that legitimate interest rather than on consent, which is why they start switched on — you can object at any time by turning them off in Settings, and we stop collecting immediately. You may lodge a complaint with your national supervisory authority.

Automated processing

The app processes your documents automatically — recognizing text, guessing a document type and name, reading fields off a receipt, flagging what looks like sensitive data, and generating AI results. None of this produces a legal or similarly significant decision about you: nothing is scored, ranked, approved or refused, and no outcome is shared with anyone. Every result is a suggestion you can edit or ignore, and all of it except the AI features runs on your device.

California privacy rights

If you are a California resident, you have the right to know what personal information we collect and how we use and disclose it, to request its deletion or correction, to obtain a copy, and to limit the use of sensitive personal information. We do not sell or share personal information as those terms are defined by the CCPA, and we have not done so in the preceding twelve months. We do not use or disclose sensitive personal information for purposes beyond those permitted without a right to limit. We do not knowingly collect personal information from anyone under 16. Email ie.levon.altunyan@gmail.com to make a request; we will verify it through the account or device the request concerns, and you may use an authorized agent.

Children’s privacy

AI Scanner is not directed to children. You must be at least 13 years old to use it, or 16 if you are in the European Economic Area or the United Kingdom. We do not knowingly collect personal information from children below those ages. If you believe a child has provided us information, contact ie.levon.altunyan@gmail.com and we will delete it.

Changes to this policy

We may update this policy as the app evolves. When we do, we will change the “last updated” date above and, for significant changes, give notice in the app before they take effect. Continuing to use the app after that means the updated policy applies to you.

Contact us

Questions about this policy, or about your data? Email ie.levon.altunyan@gmail.com and we will help. Please tell us which country or state you are writing from so we can apply the right rules.