Privacy Policy — Scanly
Last updated: June 24, 2026
The short version
Your scanned documents stay on your phone. The free version of Scanly shows ads through Google AdMob, and Scanly Pro (a one-time purchase) removes them. We also use Google's Firebase for anonymous analytics, crash reports, and performance timing, plus Google Play Billing for Pro purchases. We never upload the contents of your scans.
We don't have accounts, sign-ups, or any way to identify you personally. Uninstalling the app wipes every scan, every OCR result, and every setting.
Email hieu.dtvt10@gmail.com if you have any privacy question.
1. Who we are
Scanly is developed by the Essenty Dev Team, based in Vietnam. Contact: hieu.dtvt10@gmail.com.
2. What Scanly does
Scanly is a document scanner for Android. It captures photos of paper documents with your phone's camera, turns them into PDFs, can extract text from them (OCR), and scans QR codes and barcodes. The app is standalone — no account, no sign-up.
3. Data we collect
3.1 On your device only (never sent to us)
- Scanned documents (PDFs), photos you import, OCR text results, QR scan history
- App settings (selected language, dark/light preference, Pro entitlement)
- Saved signatures (if you use the Sign feature)
All of this is stored locally in Scanly's app storage. Uninstalling the app deletes it.
3.2 Sent to Google (third party, not to us)
- Google Play Billing: when you purchase Pro, Google handles the transaction. We receive only a confirmation that you own the Pro entitlement — we never see your payment details. Google's handling of payment data is governed by Google's Privacy Policy.
- Google Play in-app review: when you tap "Rate Us" in Settings, Google's native rating prompt is launched.
- Google Play Services (ML Kit): the first time you use OCR for Korean, Chinese, Japanese, or Devanagari scripts, Google Play Services downloads the recognizer module to your device. After download, the recognition runs entirely on your phone — your scanned text is not sent to Google.
- Firebase Crashlytics: when Scanly crashes or experiences an ANR (Application Not Responding), Crashlytics sends an anonymous report to Google containing the crash stacktrace, your device model, Android version, Scanly version, and a few non-identifying tags we set (whether you're on Free or Pro tier, your current app language, and the last few screens you visited). This helps us fix bugs. No personal information is included.
- Firebase Analytics: Scanly sends anonymous usage events (e.g., "scan completed", "Pro upgrade tapped") to help us understand which features are used. Analytics also collects standard device info: model, Android version, country (derived from your IP), language, and Google's Advertising ID. We do not send any contents of your scans, your OCR text, your QR scans, or any personal information.
- Firebase Performance Monitoring: Scanly measures how long key operations take (e.g., OCR extraction time, PDF export time) and sends timing data to Google so we can detect performance regressions. No content is sent — only timing numbers.
- Google AdMob (ads — free version only): the free version of Scanly shows ads served by Google AdMob. To serve and measure ads, Google may process your device's Advertising ID, IP-derived coarse location, device information, and ad-interaction data, as described in how Google uses information from apps that use its services. In the EEA/UK, a Google consent screen (User Messaging Platform) lets you choose between personalized and non-personalized ads before any ad loads. The contents of your scans, OCR text, and QR scans are never shared with AdMob. Scanly Pro removes all ads — a Pro device never even initializes the ads SDK.
3.3 Data we explicitly do NOT collect
- No personal information of any kind (name, email, address, phone)
- No accounts, sign-ups, or any way to identify you personally
- No contents of your scans, OCR text, or QR scans — these never leave your device, including to the ad network
4. Permissions and why
- Camera — to scan documents and QR codes. Frames are processed on-device and not uploaded.
- Internet (added automatically by the Google Play Billing library) — used only for Pro purchase state communication with Google Play.
- Media access (Android 13+ scoped picker) — only the photos you explicitly select from the system picker are visible to Scanly. We do not have broad access to your photo library.
5. Third-party services
Scanly uses Google services. Each is covered by Google's privacy policy:
- Google Privacy Policy — covers Google Play Billing, Google Play in-app review, Google Play Services (ML Kit), Firebase Crashlytics, Firebase Analytics, and Firebase Performance Monitoring.
- Google AdMob (ads in the free version) and Google User Messaging Platform (EEA/UK consent) — see how Google uses information from apps that use its services. Scanly Pro removes all ads.
6. Future changes
Scanly may add additional third-party services (e.g., cloud sync, ad networks, in-app messaging) in future versions. If we do, we will:
- Update this page with the new disclosure and bump the "Last updated" date.
- Add a notice in Scanly's Settings screen pointing to the updated policy.
- Where consent is legally required (e.g. EEA/UK), show a consent screen before requesting personalized ads — as we already do for AdMob via Google's User Messaging Platform.
7. Your rights
7.1 All users
- Delete your data: uninstall Scanly. All local data is removed by the operating system.
- Contact us: any privacy question or request — email hieu.dtvt10@gmail.com. We aim to respond within 7 business days.
7.2 GDPR (European Union users)
Where the General Data Protection Regulation applies to you, you have the right to access, rectify, erase, restrict, object to, and port your personal data. Scanly itself stores no directly identifying data about you. The free version's ads (Google AdMob) process your Advertising ID and similar identifiers; in the EEA/UK you control personalized ads through the consent screen shown on first launch, and you can reset or delete your Advertising ID in Android Settings. Upgrading to Pro stops all ad-related data collection.
- Lawful basis: contract performance (processing your Pro purchase via Google Play Billing), your consent (for personalized ads, via Google's consent screen), and legitimate interest (basic app functionality, anonymous analytics, and non-personalized ads).
- Lodging a complaint: you have the right to lodge a complaint with your local Data Protection Authority. For a list, see EDPB member authorities.
7.3 CCPA (California users)
The California Consumer Privacy Act gives California residents specific rights regarding personal information. Scanly does not sell your personal information. In the free version, limited identifiers (such as your Advertising ID) are shared with Google AdMob to show ads — which California law may treat as "sharing" for cross-context behavioral advertising.
- Right to know: Scanly stores no personal information about you; the only data leaving your device is anonymous Firebase analytics/crash data and (in the free version) ad identifiers sent to Google.
- Right to delete: uninstalling Scanly deletes all local data.
- Right to opt-out of sharing: we don't sell data; to stop ad-related sharing, opt out of personalized ads via the consent screen (EEA/UK) or Android's ad settings, or upgrade to Pro to remove ads entirely.
- Right to non-discrimination: Scanly will not treat you differently for exercising any of these rights.
8. Children's privacy
Scanly is not directed at children under 13. We do not knowingly collect personal information from anyone. If you believe a child has used Scanly in a way that would create personal information for us, please contact us — though given the app does not collect personal information from any user, there is unlikely to be anything to delete.
9. Changes to this policy
Material changes will be announced in Scanly's Settings screen with a notice that links to the updated page. Continued use of Scanly after the effective date constitutes acceptance of the change.
All revisions to this policy are tracked in the public Git history of this page at github.com/daohieu91/scanly-privacy.
10. Governing law
Vietnamese law applies as the primary jurisdiction. Where mandatorily applicable, the GDPR (European Union) and CCPA (California) rights described in sections 7.2 and 7.3 are respected.
11. Contact
For any privacy question, data access request, or correction request:
Email: hieu.dtvt10@gmail.com
Response time: best-effort within 7 business days.