iOS Document Scanner

Privacy Policy

How Scan Partner handles your data. Short version: it stays on your iPhone.

Last updated: 2026-06-14

1. Who we are

Finmak Softwares (referred to as “we”, “us”, “our”) is the developer and operator of Scan Partner (“the app”), distributed via the Apple App Store under the bundle identifier

2. Short version

  • Scans, OCR text, and extracted fields stay on your iPhone. We never receive them.
  • We do not run analytics SDKs, ad networks, or third-party trackers.
  • We do not sell, share, or rent any personal information.
  • Optional integrations (Tally, QuickBooks, Zoho, Vyapar, Busy, SAP, custom webhooks) send data directly from your phone to your chosen server — we are not in the middle.
  • Apple StoreKit handles your subscription purchase. We see only whether your account is Pro or Free.
  • Apple Sign In and Google Sign In are optional; if used, they share the email address you authorize.

3. What we collect

3.1 Data the app collects on your device only

This data never leaves your iPhone, never reaches our servers, and is not accessible to us:

  • Scanned images (saved into the app's private sandbox)
  • OCR text extracted from your scans
  • Extracted fields (vendor name, GSTIN, totals, dates, etc.)
  • File metadata (filename, creation date, page count)
  • Your folder structure, recent files list, scan counters
  • App preferences (theme, default save format, capture quality, biometric lock)
  • Tally/webhook configuration (endpoint URL, optional bearer token) — stored encrypted in the iOS Keychain

3.2 Data the app sends only if you explicitly trigger a send

When you press “Send to [Tally/QuickBooks/Zoho/…]”, the app posts the document metadata and OCR fields directly to the endpoint you configured. The destination is your own server, not ours. We do not see this traffic, do not log it, and do not retain it.

3.3 Data Apple collects on our behalf

  • Subscription status (free, monthly, yearly, lifetime) via Apple StoreKit
  • Crash reports if you opted in via iOS Settings → Privacy → Analytics & Improvements → Share With App Developers

We do not get personal information from these — only aggregate trends.

3.4 Account data (only if you sign in)

If you choose Apple Sign In or Google Sign In, the identity provider shares your name and email with the app, stored in iOS Keychain. We do not transmit this anywhere.

4. What we do NOT collect

  • Names, contact information, or address books
  • Photos other than the documents you choose to scan
  • Browsing history, location, or device identifiers
  • Health, financial, or biometric data
  • Advertising IDs (we have no ads)
  • Third-party analytics events

5. Permissions the app requests

PermissionWhy
CameraTo scan documents
Photo Library (read)To import existing photos as scans
Photo Library (add)To save scans back to Photos when you ask
Face ID / Touch IDTo unlock the app
Local NetworkTo reach a Tally Prime server on your office LAN

Each permission is enforced by iOS — denying it disables only the related feature.

6. Sharing your data

We share your data with no one. There is no advertising partner, no data broker, no marketing list, no third-party analytics, no AI training pipeline.

The only entities that can receive data from the app are:

  1. The accounting / webhook endpoint you configure yourself (Tally, Zoho, QuickBooks, Vyapar, Busy, SAP, custom URL) — the app sends data directly to your server when you press Send.
  2. Apple StoreKit / iCloud Backup — purchase processing and (if you enable iCloud Backup) the app sandbox is backed up under your iCloud account.
  3. Apple Sign In or Google Sign In providers — only when you choose to sign in.

7. Children

Scan Partner is not directed at children under 13 and does not knowingly collect data from them.

8. Security

  • Scanned files and configuration live in iOS Data Protection containers (NSFileProtectionComplete).
  • Sensitive values such as webhook bearer tokens and Tally credentials are stored in the iOS Keychain.
  • PDF export supports passcode-protected encryption.
  • Face ID / Touch ID locks the app at launch when enabled.

9. Your rights

Because we don't hold your data on any server, most data-subject rights apply to data on your device:

  • Access / Export — every scan exports as PDF, JPG, or JSON.
  • Delete — delete scans inside the app, or uninstall the app to wipe everything.
  • Reset — Settings → Reset App Data clears all scans, OCR text, and integrations.

If you signed in with Apple or Google and want the small amount of identity data forgotten, email admin@finmaksoftwares.in with the subject “Delete my account” — we will confirm within 7 days.

10. Data retention

  • Scans and metadata: until you delete them or uninstall the app.
  • Sign-in identity in Keychain: until you sign out or uninstall.
  • Server-side: none — we hold no copies.

11. International users

Because data stays on your iPhone, no cross-border transfer happens on our side. Apple's privacy practices for the App Store and StoreKit apply globally per Apple's policy.

12. Changes to this policy

We will update this page when material changes occur. The “Last updated” date at the top will reflect the most recent revision. Subscribers will see an in-app notice for substantial changes.

13. Contact

Questions, requests, or complaints:

This policy is governed by the laws of India.