Scannable processes personal information for the following purposes. Personal information collected will not be used for any purpose other than those stated below. If the purpose of use changes, the Company will obtain separate consent as required by law.
Scannable collects only the minimum personal information necessary for service provision.
Of the items above, usage statistics (Firebase Analytics) and error & performance diagnostics (Firebase Crashlytics Β· Performance Monitoring) are not collected in the European Economic Area (EEA) or the UK. Elsewhere they are collected by default to improve the app, but you can turn them off at any time in the app settings. Whether your advertising identifier is used for personalized ads is a choice available in every region (see Article 11 β‘ and β£ for how to opt out).
This information is collected only when you choose to submit a feature request, and is stored on Google Firebase (Cloud Firestore). Please do not enter personal information (such as your name, email, or phone number) in feature requests.
β Scannable processes and retains personal information within the retention and usage period prescribed by law or within the period consented to by the data subject at the time of collection.
β‘ The retention and processing periods for each category of personal information are as follows:
Scannable does not separately collect personal information of children under 14 years of age. This app can be used without account registration and there are no age-based usage restrictions. However, if a legal guardian of a child under 14 does not consent to the collection and use of the advertising identifier, they may restrict ad tracking through the device settings.
The Company uses users' personal information within the scope notified in Article 1 and does not use it beyond that scope or provide it to other individuals, companies, or organizations. However, exceptions are made in the following cases:
In other cases where disclosure to third parties is necessary, the Company may provide personal information to third parties after notifying users of the purpose of collection and use, items collected, and retention period, and obtaining their consent.
β Scannable outsources personal information processing as follows for smooth operations:
| Outsourcing Partner | Outsourced Tasks |
|---|---|
| Google LLC (AdMob) | Processing of advertising identifiers for personalized and rewarded advertising |
| Google LLC (Firebase) | Processing of error logs, performance metrics, and statistical data for app performance and stability; storage of user-submitted feature requests (Cloud Firestore) |
β‘ If there are any changes to the outsourced tasks or partners, the Company will promptly disclose them through this Privacy Policy.
Scannable uses global servers for advertising services, and accordingly, personal information is transferred overseas (outsourced processing) as follows:
| Recipient | Google LLC |
|---|---|
| Country of Transfer | United States and countries where Google's data centers are located |
| Transfer Method | Transmitted periodically via network when ads are displayed |
| Items Transferred | Advertising identifier (ADID/IDFA), device information, app instance identifier, IP address, service usage and error records (crash logs, performance metrics, usage statistics); feature request content voluntarily submitted by the user (Cloud Firestore, US region) |
| Purpose of Transfer | Personalized and rewarded advertising; app stability and performance improvement; receiving and reviewing feature requests |
| Legal basis for the transfer | Google LLC states that it relies on adequacy decisions, its certification under the EU-U.S. Data Privacy Framework, and Standard Contractual Clauses (SCCs) for transfers not covered by an adequacy decision. See Article 16 β₯ for details applicable to users in the EEA and the UK. |
| Retention Period | In accordance with Google's data retention policy |
The Company promptly destroys personal information when it is no longer needed, such as when the retention period has expired or the purpose of processing has been achieved.
When a user uninstalls the app, scanned documents and app data stored on the device are automatically deleted.
β Data subjects may exercise their rights to access, correct, delete, or suspend processing of personal information with respect to Scannable at any time.
β‘ Since this app can be used without account registration, requests regarding personal information can be made by contacting the Data Protection Officer via email, and the Company will take action without delay.
β’ If you do not wish to have your advertising identifier collected, you may restrict ad tracking through your device settings.
Scannable has implemented the following measures to ensure the security of personal information:
β Scannable uses "Advertising Identifiers (ADID/IDFA)" to provide personalized advertising to users.
β‘ Regarding the collection and use of behavioral information (AdMob, etc.):
β’ Basis for collecting diagnostics and statistics: In the European Economic Area (EEA) and the UK, usage statistics and error & performance diagnostics are not collected. We do not ask for consent there, and the app provides no switch to turn them on. Elsewhere they are collected by default to improve the app, but you can opt out at any time through the in-app settings described in β‘ above, and opting out never limits any feature.
β£ Ad consent (Google UMP): In certain regions such as the European Economic Area (EEA), a Google User Messaging Platform (UMP) consent form is shown before ads are displayed, asking for your choices regarding ad privacy. Even if you do not consent to personalized ads, non-personalized (limited) ads may still be shown. You can change your choices at any time via the ad privacy options in the app settings.
Scannable has designated the following Data Protection Officer to handle all matters related to personal information processing, complaints, and damage remediation:
Data subjects may apply for dispute resolution or consultation with the following organizations for remedies related to personal information infringement:
In the event of any additions, deletions, or modifications to this Privacy Policy, the Company will provide prior notice at least 7 days before the amendment on this Privacy Policy page (the screen linked from the app's settings) and, where appropriate, via in-app notice screens. However, for significant changes affecting users' rights, such as changes to the items of personal information collected or purposes of use, at least 30 days' prior notice will be given, and user consent may be obtained again if necessary.
This Privacy Policy was originally effective March 19, 2026, and this 3rd revision is effective September 10, 2026.
Revision history: 2026-03-19 enacted Β· 2026-06-26 2nd revision (added processing of feature-request data and a feedback clause) Β· 2026-09-10 3rd revision (more accurate disclosure and added user controls β app instance identifiers and performance metrics listed explicitly, in-app opt-out for collection and personalized ads documented, stated that usage statistics and error and performance diagnostics are not collected in the EEA or the UK, ad consent (UMP) guidance added, and a new Article 16 with additional information for users in the EEA and the UK; no new data categories and no broadened purposes). View previous revision
This Article provides the additional information required by the EU General Data Protection Regulation (EU GDPR) and the UK GDPR for users located in the EEA and the UK.
β Scope and controller
This Article applies to users located in the EEA or the UK. Where it differs from any other provision of this Privacy Policy, this Article prevails for those users. The controller that determines the purposes and means of the processing is the business identified in the Supplementary Provisions below; its contact details are those given in Article 12.
β‘ Purposes and legal bases
We process personal data for the following purposes, on the following legal bases.
| Purpose | Legal basis (GDPR Article 6(1)) |
|---|---|
| Providing the app's features β document scanning, text recognition (OCR), image editing and enhancement, PDF conversion and export, and document management (this processing happens on your device, and your scans, images, and recognized text are never sent to us or to any third party) | Performance of a contract β Article 6(1)(b), to the extent necessary to provide the features you request |
| Usage analytics (Firebase Analytics) | Not processed in the EEA or the UK β we do not collect this data there, so no legal basis is required. |
| Error and performance diagnostics (Firebase Crashlytics Β· Performance Monitoring) | Not processed in the EEA or the UK β we do not collect this data there, so no legal basis is required. |
| Serving advertising (Google AdMob) | Consent β Article 6(1)(a), obtained through the Google User Messaging Platform (UMP) consent form (see Article 11 β£). |
| Receiving and reviewing feature requests (Cloud Firestore) β content you write and submit yourself | Consent given by your act of submitting β Article 6(1)(a) β together with our legitimate interest in improving the Service β Article 6(1)(f) |
| Security and prevention of abuse | Legitimate interests β Article 6(1)(f), our interest in operating the Service safely and preventing misuse |
β’ Withdrawing consent
Where we rely on consent, you may withdraw it at any time. In the EEA and the UK the only processing we base on consent is serving advertising, and you can change that choice through Settings > Info > "Data & privacy" > "Ad privacy options" (Google UMP) in the app. Usage analytics and error and performance diagnostics are not collected in this region at all, so there is no consent to withdraw. Withdrawal takes effect going forward only and does not affect the lawfulness of processing carried out on the basis of consent before its withdrawal (GDPR Article 7(3)). Withdrawing consent never limits any feature of the app.
β£ Your rights
Subject to the conditions and limits set out in applicable law, you have the following rights. The article numbers in brackets below refer to the GDPR (for UK users, the corresponding UK GDPR provisions) β not to the articles of this Policy:
To exercise any of these rights, write to the email address in Article 12. We will respond within the period prescribed by law.
β€ Exercising your rights where we cannot identify you (GDPR Article 11)
The app has no sign-up and we do not collect identifiers such as your name or email address, so the data we hold does not on its own allow us to identify you. If you wish to exercise a right, please contact us at the email address in Article 12: we will tell you what information we need in order to locate the relevant data and will act on your request without undue delay so far as we can verify it. If you are unable to provide information that enables us to identify you, we may be unable to act on the request, and we will tell you why. Please also note that uninstalling the app or clearing its data on your device causes a new app instance identifier to be issued, so anything collected afterwards is no longer linked to the earlier records.
β₯ International transfers and safeguards
Google LLC, the provider we use, is located in the United States. The categories, destinations, purposes, and retention of the transferred data are set out in the table in Article 7. The nature of the relationship differs by service:
For transfers to the United States, Google LLC states that it relies on adequacy decisions, its certification under the EU-U.S. Data Privacy Framework, and Standard Contractual Clauses (SCCs) for transfers that are not covered by an adequacy decision β see Google's data transfer frameworks.
β¦ Retention
Retention periods are those set out in Article 3. Data transmitted to Google is retained according to Google's data retention settings, and withdrawing your consent stops any further collection from that moment.
β§ Automated decision-making
We do not carry out decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you (GDPR Article 22). Personalized advertising delivered by Google AdMob may constitute profiling; it takes place only where you have consented, and you can withdraw that consent at any time as described in β’ above.
β¨ Children
Under GDPR Article 8, the age at which a child can validly consent to information society services is set by each Member State at between 13 and 16 years. Below that age, consent is valid only if given or authorized by the holder of parental responsibility over the child. This is a separate standard from Article 4 above, which applies the under-14 threshold of the Korean Personal Information Protection Act.
β© Complaints to a supervisory authority
Without prejudice to any other remedy, you have the right to lodge a complaint with the supervisory authority of the Member State where you reside or work, or where you consider the infringement to have occurred (GDPR Article 77). We would appreciate the chance to address your concern first, at the contact details in Article 12.