GDPR CompliantCCPA ReadyOn-Device Processing
Privacy Policy

QuickScan Docs

How this app handles your documents, your identity data, and the information your device sends while you use it.

Application
QuickScan Docs
Package
com.quickscan.docs
Publisher
GraTech Dev Studio
Effective
7 October 2026

01Where your data goes

QuickScan Docs does most of its work on your phone. Some features need the internet, and when they do, this is exactly where the data goes. Everything else in this policy expands on this table.

DataDestinationWhen
Scanned pages, photos, imported files Your device Always. Stored in the app's private storage.
Recognised text (OCR), barcodes, detected faces Your device Always. Google ML Kit runs offline, on the phone.
ID chip data, including the facial image Your device Always. Never transmitted anywhere.
A document image and its text Groq Only when you use an AI feature, and only after you accept the in-app notice.
Documents you choose to sync Google Drive Only if you turn on Drive sync and sign in.
Advertising ID, IP address, device model Google AdMob While ads are shown, which is to say unless you hold QuickScan Pro.
Feature usage events, crash reports Firebase Always, while the app is installed.
Purchase and subscription status Google Play When you buy or restore QuickScan Pro.
Read this twice

The AI features send your document to a company outside Google called Groq. That is a real transfer of your content off your phone. It happens only if you use those features and only after you accept a notice that says so. Section 4 explains it in full.

02What stays on your device

These parts of QuickScan Docs never send anything over the internet. They work in aeroplane mode, and you can verify that yourself by switching it on.

Your documents live in the app's private sandbox and in the folders you explicitly choose when you export. We operate no server that stores your documents.

03Data we collect

Content you create or import

Scanned pages, photographs, PDFs, Word and Excel files you import, the text extracted from them, the names you give documents and folders, signatures you draw, and the contents of business cards you build. This is yours. It stays on your device unless a feature described in sections 4, 9 or 10 moves it, and each of those is something you switch on.

Identity document data

If you scan an ID card, passport or residence permit, we process the machine-readable zone and, over NFC, the chip contents. This includes your name, document number, date of birth, nationality, sex, expiry date, the facial image stored on the chip and, where present, a scanned signature. Under the GDPR the facial image is biometric data. It is read on your device, shown to you, saved on your device, and never transmitted. See section 5.

Device and diagnostic data

Collected automatically by Google's SDKs:

Usage events

We record which features you reach and whether they succeed: that a scan completed and how many pages it produced, which screen led you to the upgrade page, whether a purchase went through, whether onboarding was finished or skipped. These events carry category labels such as scan_type, page_count and source. They never carry the contents of your documents, their file names, or any text extracted from them.

Purchase data

If you buy QuickScan Pro, Google Play tells the app which products you own and when a subscription expires. Payment itself happens inside Google Play. We never see your card number, bank details or billing address.

What we never collect

The app declares no microphone permission and contains no audio recording code. It requests no location permission and reads no GPS. It has no contacts, call log, SMS or calendar access. It creates no user account of its own.

04AI features and Groq

QuickScan Docs offers optional features powered by a large language model: document summaries, chat about a document, AI-assisted text clean-up, and AI document generation.

What leaves your device

To answer, these features send to the AI provider:

If that page holds personal, confidential, medical, financial or identity information, that information is part of what is sent.

Who receives it

The provider is Groq, Inc., at the endpoint api.groq.com. Groq processes the request on its own infrastructure and returns a result. Its handling of the data is governed by its own terms and privacy policy, published at groq.com/privacy-policy. We do not control Groq's retention periods, and we cannot delete data on your behalf once it has been sent.

Your consent

No AI feature contacts any server until you have read an in-app notice naming Groq and stating that your document content will be sent there, and have accepted it. If you decline, nothing is sent and the feature simply does not run; declining is not recorded as a permanent refusal, so you may be asked again next time you tap an AI feature. Every other part of the app keeps working either way.

Our advice

Do not run AI features on documents you are not willing to send to a third party. For anything sensitive, use the on-device features in section 2, which cover scanning, OCR, PDF creation, signing and redaction without any transfer.

We send no account identifier, advertising ID or device identifier alongside these requests. Groq receives the document content, the instruction, and the network metadata inherent to any internet request, such as your IP address.

05ID documents and NFC chips

QuickScan Docs can read the contactless chip in a biometric passport or ID card, using the key derived from the document's machine-readable zone, exactly as a border control reader does.

From the chip we read these ICAO data groups:

DG1
Machine-readable zone: name, document number, nationality, date of birth, sex, expiry date
DG2
The facial image stored on the chip
DG7
The displayed signature, where present
DG11
Additional personal details, where present
DG12
Additional document details, where present

All of it is read by the app on your phone, over NFC, with no network involved. It is stored on your device alongside the document you created. None of it is transmitted to us, to Google, to Groq, or to anyone else. Deleting the document deletes it.

Because the facial image is biometric data under the GDPR, we process it on the single basis of your explicit consent, given by choosing to scan the chip, and solely to display and store the document for you. We do not use it for identification, matching or any form of profiling.

If you place such a document in the encrypted Vault, it is additionally protected as described in section 15.

06Advertising

The free version of QuickScan Docs shows ads supplied by Google AdMob. Some are banners, some appear between actions, and some are ads you choose to watch in exchange for an extra use of a Pro feature. That choice is always yours; declining costs you nothing beyond the extra use.

To serve and measure these ads, AdMob collects your advertising ID, IP address, device model and information about the ads shown. Google's own description of this is at business.safety.google/privacy.

Your choices

07Analytics and crash reports

We use Google Analytics for Firebase to understand which features are used and where people get stuck, and Firebase Crashlytics to find and fix crashes.

Crash reports contain a stack trace, the device model, the OS version, the app version and the state of the app at the moment it failed. They do not contain your documents.

Analytics events are listed in section 3. They describe actions, never content.

This data is tied to an installation of the app, not to you by name: we hold no account, email address or phone number that could link it back to a person. Uninstalling the app ends the collection.

If you want us to stop processing this data about your installation while you keep using the app, write to gratech.dev@gmail.com and we will act on it.

08Purchases

QuickScan Pro is sold through Google Play Billing, as a subscription or a one-time purchase depending on what you choose. Google handles the payment, holds your payment details, and tells the app only which entitlements you own.

Refunds, cancellations and billing disputes are handled by Google Play. Manage or cancel a subscription at play.google.com/store/account/subscriptions.

We record the fact that a purchase succeeded or failed, and a reason code when it fails, so we can tell a genuine problem from a change of mind. No payment details reach us at any point.

09Google Drive sync

Drive sync is off until you turn it on and sign in with a Google account. When you do, the app asks for two narrowly scoped permissions:

Documents you sync are copied to your own Google Drive, under your own account. They are not copied to us. We have no server that receives them and no ability to read your Drive.

You can disconnect at any time in the app's Settings, and revoke the app's access entirely at myaccount.google.com/permissions. Files already in your Drive remain yours; delete them there if you want them gone.

10Share to PC

Share to PC starts a small web server on your phone so that a computer on the same Wi-Fi network can download your documents through a browser. It runs only while you keep the screen open, and stops when you leave it.

Treat the code as you would a password, and prefer a network you trust. Anyone on the same Wi-Fi who has the code can download the documents you are sharing.

11Digital business cards

When you share a digital business card, the app builds a link to a page that displays it. Your details are encoded in the part of the link after the # sign.

Browsers never transmit that part to a web server. The card is assembled in the recipient's browser, from the link itself. Your name, phone number and email address are therefore never uploaded to or stored on our hosting.

The link does contain your details in encoded form, so anyone you send it to, or who obtains it afterwards, can read them. Share it as deliberately as you would share the card itself.

12Permissions

PermissionWhy
CAMERATo scan documents, ID cards and QR codes. The camera runs only on the scanning screens.
INTERNETAds, analytics, purchases, Drive sync and AI features. Never to upload documents on its own initiative.
NFCTo read the chip in a passport or ID card, when you ask for it.
AD_IDTo let AdMob serve and measure ads.
POST_NOTIFICATIONSTo tell you when a background job, such as a sync or an export, has finished.
WAKE_LOCKTo keep long processing running while the screen dims.
VIBRATEHaptic feedback when a page edge locks on.
READ_EXTERNAL_STORAGETo import files you pick. Requested only on Android 12 and older; newer versions use the system picker, which grants access to the one file you chose.
WRITE_EXTERNAL_STORAGETo save exports. Requested only on Android 10 and older.

You can withdraw camera or storage permission at any time in Android Settings, under Apps, QuickScan Docs, Permissions. Features needing a withdrawn permission will ask again or stop offering themselves.

13Who we share with

We do not sell your personal information, and we do not share it for cross-context behavioural advertising beyond the AdMob processing described in section 6.

Data reaches these parties, and no others:

RecipientWhat they receiveTheir policy
Google AdMobAdvertising ID, IP address, device and ad interaction dataGoogle
Google FirebaseUsage events, crash reports, installation identifierFirebase
Google PlayPurchase and subscription dataGoogle
Google DriveOnly documents you choose to sync, into your own accountGoogle
Groq, Inc.Document images and text, only for AI features you acceptGroq

We may also disclose information where the law requires it, to respond to a valid legal process, or to protect our rights or the safety of others. Since we hold no copy of your documents, there is nothing of that kind for us to disclose.

When you export a document yourself, by email, messaging app, printer or any other route, you are the one sharing it, and the receiving service's own policy applies.

14Keeping and deleting data

On your device

Your documents stay until you delete them. Deleting a document removes its pages, its extracted text and its ID chip data. Uninstalling the app removes everything it stored on the phone, including the Vault and its encryption key, which makes any Vault backup unreadable.

In your Google Drive

Synced files remain in your Drive after you uninstall. Delete them from Drive, or revoke the app's access, as described in section 9.

With Google

Analytics and crash data are retained under Firebase's policies, which currently keep event-level analytics data for up to 14 months and crash reports for up to 90 days. Advertising data is retained by Google under its own terms.

With Groq

Retention of anything sent to an AI feature is governed by Groq's policy, linked in section 4. We cannot delete it for you, which is the plainest reason to think before sending a sensitive page.

Asking us to delete

We hold no account for you and keep no copy of your documents, so there is usually nothing on our side to erase. If you believe we hold data about you, write to gratech.dev@gmail.com with the subject Data deletion request. We respond within 30 days.

15Security

No system is perfectly secure. If you find a vulnerability in QuickScan Docs, please tell us at gratech.dev@gmail.com before disclosing it publicly, and we will work with you.

16Children

QuickScan Docs is a productivity tool for adults. It is not directed to children, and it is not listed in Google Play's Designed for Families programme.

We do not knowingly collect personal information from children under 13, or under the higher age of consent where local law sets one, such as 16 in parts of the European Union. If you are a parent or guardian and believe your child has provided us with personal information, write to gratech.dev@gmail.com and we will delete it.

17International transfers

Our service providers operate globally, which means data described in this policy may be processed in countries other than yours, including the United States.

Where personal data moves out of the European Economic Area, the United Kingdom or Switzerland, that transfer relies on the European Commission's Standard Contractual Clauses or on an adequacy decision, as set out in each provider's own terms. Google's are published at business.safety.google/adsprocessorterms.

18Your rights

Depending on where you live, you have some or all of the following rights. We honour every request we receive, wherever you are.

Legal bases under the GDPR. We rely on contract performance to provide the app's core functions; your explicit consent for AI features and for ID chip data; your consent for personalised advertising where the ePrivacy rules require it; and our legitimate interest in a stable, non-fraudulent product for crash reporting and aggregate analytics, which you may object to at any time.

For California residents. We do not sell personal information and have not done so in the preceding twelve months. We do not knowingly sell or share the personal information of consumers under 16.

To exercise any of this, write to gratech.dev@gmail.com. We may ask for information that lets us confirm the request is genuinely yours, and we respond within 30 days.

19Changes to this policy

When we add a feature that handles data differently, we update this policy and move the effective date at the top.

For a change that materially affects you, such as a new recipient of your document content, we will tell you in the app before it takes effect, and ask again for consent where consent is the basis we rely on.

Previous versions are available on request.

20Contact us

GraTech Dev Studio
Developer of QuickScan Docs (com.quickscan.docs)

Privacy enquiries, access and deletion requests, and security reports:
gratech.dev@gmail.com

Please put Privacy in the subject line so your message reaches the right place. We answer within 30 days, and usually much sooner.