Privacy Policy
Last updated: 2026-07-27
Please read this Privacy Policy carefully to understand how your personal data is processed. By using this app or website, you confirm that you have read, understood, and agreed to this Policy.
I. Introduction
e-Scanner is a document scanning application developed and published by PB Solutions Co., Ltd ("we", "us", or "our"). This policy applies to both the e-Scanner application and this website, outlining how we handle your data, when data leaves your device, and the third parties involved in processing.
Data Controller & Contact Information:
- Data controllerPB Solutions Co., Ltd
- Postal addressNo. 12, Lane 56, Le Quang Dao Street, Residential Group 6, Tu Liem Ward, Hanoi, Vietnam
- Contact & Support Emailsupport@pbsolutions.io
II. Data we process
The website and the e-Scanner app operate independently, and the way each of them processes data is entirely different.
1. On this website
- IP AddressHosting servers and integrated services may log your IP address to display the webpage and analyze traffic such as determining geographic location or referral sources. This data is processed strictly in aggregate and is not linked to any personal information.
- Support FormWhen submitted, the information you enter (e-mail address, your message and the device details) is transmitted via Web3Forms directly to our inbox and is used exclusively to respond to your inquiry.
2. For the e-Scanner app
- Personal Document DataScans, PDFs, OCR text, and thumbnails are stored securely on your local device. Nothing is ever sent to our servers.
- Data Sent to CloudOccurs only when you explicitly use online features (such as PDF to Word, Word to PDF, or advanced text extraction). Your files are stripped of original file names and transmitted via encrypted connections for processing. All files are automatically and permanently deleted from our servers immediately after completion.
- Usage & Quota DataUses an anonymous device ID along with page counts solely to manage your plan limits. Zero file contents, file names, or text are collected.
- App LogsAutomatic crash reports (via Firebase) help fix bugs and secure the app. This data never includes document contents, file names, or personal info.
- Device PermissionsOnly requests essential permissions: Camera to scan, Photo Library to import files, and Face ID/Touch ID for app lock. Data accessed via these permissions is never collected or sent out.
- Offline Processed DataAll scanning, basic OCR, and PDF tasks (merge, split, compress, rotate, password protection, etc.) run 100% locally on your device without needing an internet connection.
III. Why we process it
Data collected is processed strictly for the following specific purposes:
- Fulfilling Service RequestsProcessing and converting files as requested (such as advanced OCR or PDF format conversion) and returning results to your device.
- Quota & Plan ManagementTracking page counts and usage limits via anonymous device IDs to enforce Free and Premium plan tiers.
- App Stability & Bug FixingAnalyzing crash logs and technical stack traces to identify and resolve software errors.
- Security & Abuse PreventionVerifying requests originate from official app builds to prevent fraud, automated abuse, or quota exploitation.
- Customer SupportProcessing and responding to inquiries, feedback, or support requests submitted by you.
- In-App Purchase VerificationVerifying subscription status using transaction receipts from official app stores (such as the Apple App Store or Google Play Store).
We never use your documents, extracted text, or OCR data for advertising, user profiling, or AI model training. We do not process your data for any unstated purposes.
For users under GDPR jurisdiction, our legal bases for processing include:
(1) Contractual necessity to fulfil the services you request.
(2) Your explicit consent for online processing features, which you may discontinue at any time.
(3) Our legitimate interest in maintaining service stability and preventing abuse.
IV. Data Sharing & Third-Party Processors
We absolutely do not read, analyze the content of your documents, or perform user profiling. The only exception is when you explicitly use online features. Even then, your data is never used to train any AI models, whether ours or any third party's.
Below is the complete list of third-party partners who process data on our behalf:
- Apple Inc. (USA)App distribution via App Store and Premium subscription payment processing. Privacy Policy: https://www.apple.com/legal/privacy/
- Mathpix, Inc. (USA)Advanced OCR processing. Receives only files with the original name removed, and every request carries Mathpix's opt-out flag so the file is not used to improve their models. Privacy Policy: https://mathpix.com/privacy
- Google LLC - Firebase (USA)Crash reporting, generating anonymous identifiers, and app integrity verification. Privacy Information: https://firebase.google.com/support/privacy
- RevenueCat, Inc. (USA)Managing and synchronizing subscription status. Privacy Policy: https://www.revenuecat.com/privacy
- Web3Forms (USA)Processing and forwarding website contact form submissions to our inbox. Privacy Policy: https://web3forms.com/privacy
V. International Data Transfers
- Our ServersLocated in Vietnam, handling online tasks such as advanced OCR and PDF conversion.
- Third-Party Partners (Section IV)Process and store data in the United States, Singapore, or within the provider's global data center network, depending on your geographic location.
For users located in the European Economic Area (EEA) or the United Kingdom (UK), your data leaves your region only when you explicitly use online features. Cross-border data transfer safeguards comply with Standard Contractual Clauses (SCCs) or the respective privacy policies of each provider linked in Section IV.
VI. Data Security & Local Storage
Four layers of maximum protection, 100% stored locally on your device:
- Local DatabaseEncrypts all document content using the AES-256 algorithm, including titles, tags, text content, and thumbnails.
- Encryption KeyGenerated directly on your device and securely stored within the device's hardware key store (Keychain/KeyStore). Keys never leave the device or sync to the cloud, ensuring that even we cannot decrypt your documents.
- App LockYour PIN is stored locally as a secure salted hash and is never transmitted anywhere. Biometric authentication is handled directly by the operating system; the app only receives the verification result.
- Data DeletionDeleted documents move to a local Trash first. Permanent deletion overwrites the file data and destroys the corresponding decryption key, ensuring files are unrecoverable.
VII. Data Retention Period
- Documents & MetadataStored exclusively on your local device until you delete them. Uninstalling the app permanently removes all associated data from the device.
- Files Sent for Advanced OCRProcessed directly via encrypted connections without being stored on servers; OCR partners do not retain any data.
- Word-to-PDF Conversion FilesAutomatically deleted immediately upon successful download, or permanently purged within a maximum of 30 minutes from upload.
- Usage & Quota DataAnonymous device IDs, page counts, and conversion counts are retained as long as necessary to enforce plan limits. Zero document content is stored.
- Crash Logs (Firebase)Retained for approximately 90 days on Google's infrastructure for debugging purposes, after which they are automatically deleted.
- Support Requests & CommunicationsRetained during the request resolution period and for a reasonable time thereafter to assist with follow-up inquiries.
VIII. Your Rights
Depending on the applicable laws in your jurisdiction, you may have the following rights regarding your personal data:
- AccessRequest a copy of the personal data we hold about you.
- Rectify or DeleteRequest that we correct or erase your personal data.
- Restrict or ObjectRequest to limit or object to the processing of your personal data.
- Lodge a ComplaintFile a complaint with your local data protection authority.
In practice, you fully control and manage your documents directly on your device. The only data we may hold is your support history and anonymous subscription status.
To exercise your rights, please email support@pbsolutions.io. Since we do not collect personal identities, we will need the email address you previously used to contact us to locate your records.
IX. Opting Out of Optional Features
You can manage or disable these features directly in the app without contacting support:
- Advanced OCRToggle off in Settings. Once disabled, no documents will leave your device.
- Documents & MetadataDelete directly within the app and empty the Trash. Uninstalling the app permanently purges both the library and its encryption key.
- Support Requests & CommunicationsContact us, and we will delete your correspondence history.
- Crash ReportsCurrently lacks an in-app toggle. Reports contain no names, emails, or document content, and are automatically deleted by Google after approximately 90 days.
There are no marketing emails to unsubscribe from and no advertising IDs to reset, simply because the app does not use them.
X. Data Security
Our multi-layered data protection architecture:
- Data at RestThe entire library (documents & database) is encrypted using AES-256. The decryption key is stored separately in the device's hardware-backed key store (Keychain/KeyStore).
- Data in TransitAll data transmitted by the app is strictly encrypted via TLS protocol.
- Server-Side EnforcementRequests missing a valid integrity attestation token are automatically rejected.
- Application LogsEncryption keys, document content, and OCR text are never logged, reported, or transmitted to any analytics system.
Note: No system is entirely immune to security risks. However, our local-first architecture keeps your most sensitive data exclusively on your device - safely out of reach even in the event of a server-side breach.
XI. Children's Privacy
e-Scanner is not intended for children under the age of 13 (or under 16 where required by local law), and we do not knowingly collect personal information from children. If you believe a child has used the app without parental or guardian consent, please contact us for prompt assistance.
XII. Policy Changes
We may update this Privacy Policy as the app evolves. The "Last Updated" date at the top always reflects the current version. For major changes affecting how your data is processed, we will highlight them in the app update notes or prominently at the top of this page.