ScanKeeper App Privacy Policy
Last updated: 6 September 2026
This Privacy Policy explains how Nomadix Apps LLC ("Nomadix Apps", "we", "our", or "us") handles information when you use the ScanKeeper mobile application for iOS or Android (the "App") or visit scankeeper.app (the "Site").
Nomadix Apps LLC is the controller of the information described in this Policy unless a section says that another company processes information under its own relationship with you.
You can contact us at support@scankeeper.app or at 5830 E 2nd St, Casper, WY 82609-4308, United States.
1. Summary
- Your codes stay under your control. Barcode and QR code values, names, folders, and images are stored in the App on your device. We do not operate a server that receives this content.
- No account is required. ScanKeeper does not ask for your name, email address, or phone number to use the App.
- iCloud Sync is optional and iOS-only. If you enable it, the App copies your data to your private iCloud container. Nomadix Apps cannot access that container.
- No ads or advertising tracking. The current App contains no advertising SDK, does not read IDFA or GAID, and does not track you across other companies' apps or websites.
- Limited product and diagnostic data. TelemetryDeck helps us understand feature use, Sentry helps us diagnose errors and performance, and RevenueCat manages Premium entitlements. Details are below.
- The Site has no analytics script. It is a static website delivered through Cloudflare and does not intentionally set marketing or analytics cookies.
2. Data Stored on Your Device
ScanKeeper stores the following information in its private application storage:
- Barcode and QR code values
- Names and other card details you enter
- Folders, archive state, sort order, and usage information such as when a card was opened
- Images and thumbnails attached to cards
- App preferences, including theme, language, onboarding state, iCloud Sync preference, and Premium status cached from the store
- A randomly generated installation identifier used for diagnostics and purchase entitlement management
This information remains on your device unless you choose to sync it through iCloud, export or share it, or a limited technical event described in Section 3 is generated. The App is designed not to include barcode values, card names, folders, or images in analytics events.
You can delete individual cards inside ScanKeeper. Uninstalling the App or clearing its data removes its local database and preferences, subject to your operating system's backup and restore features. Archiving a card does not delete it.
3. Data Sent From the App
3.1 TelemetryDeck product analytics
We use TelemetryDeck to understand whether features work and which parts of the App are useful. Events can include:
- An event name, such as opening Settings, scanning or saving a code, exporting CSV, viewing a paywall, restoring a purchase, or completing onboarding
- Coarse event details such as barcode format, scan source (camera, selected image, or manual entry), feature name, result code, and counts or count ranges
- App version and build, operating system and version, device model, platform, language, and region
- A salted and hashed installation identifier
We do not intentionally send barcode or QR values, card names, images, free-form text, email addresses, advertising identifiers, or precise location to TelemetryDeck. TelemetryDeck states that it double-hashes identifiers and does not store IP addresses.
RevenueCat receives a TelemetryDeck attribution value so that purchase events can be measured alongside product analytics without providing TelemetryDeck with your store account or payment details.
3.2 Sentry diagnostics and performance
We use Sentry to diagnose crashes, unhandled exceptions, startup failures, and performance problems. A diagnostic event may include:
- Exception messages and stack traces
- App version and build, operating system, device model, locale, and technical runtime state
- Performance transactions and profiles, sampled at 20% in production
- Operation labels and memory-use breadcrumbs used to diagnose crashes or out-of-memory conditions
- The random installation identifier as a pseudonymous Sentry user ID
Sentry is configured with sendDefaultPii set to false. We do not attach a name or email address. Session Replay is disabled: both normal-session and error-session replay sample rates are 0, so the App does not send screen recordings to Sentry.
The App is designed not to add barcode values, card names, or images to Sentry. A technical exception can nevertheless contain incidental technical information, such as a local file path or a generated record identifier. Please avoid placing sensitive information in card names or files where it is not needed.
3.3 RevenueCat and store purchases
We use RevenueCat to show purchase screens and determine whether Premium is active. RevenueCat may receive:
- The random installation identifier as the App User ID
- Store receipt or purchase token, product identifier, purchase and renewal dates, entitlement status, refund or cancellation state, and store country
- App, operating-system, device, locale, and network request information
- The hashed TelemetryDeck attribution value described above
RevenueCat does not receive your payment card details from us. Apple or Google processes payment and store-account information under its own terms and privacy policy. ScanKeeper does not promise that a purchase made through one store will transfer to the other platform.
3.4 Optional iCloud Sync
On iOS, you can turn on iCloud Sync in Settings. When enabled, ScanKeeper stores your codes, folders, metadata, and associated images in the private iCloud container connected to your Apple Account. Apple processes that data under your iCloud relationship and Apple's Privacy Policy.
Nomadix Apps has no server-side access to your iCloud container. Turning off iCloud Sync stops future synchronization but does not automatically erase data already stored in iCloud. You can manage or delete that data through Apple and device settings.
3.5 Sharing and export
When you choose Share or Export, the operating system shows destinations available on your device. Information goes only to the destination you select. That recipient processes it under its own terms and privacy policy. We do not receive a list of your installed apps or a copy of what you share.
A shared card link contains its name, code value, format, colour, and optional expiry date. It does not include the card image. The content is encoded, not encrypted: anyone with the link can read or import the card. The card is stored in the URL fragment, which is processed in the recipient's browser and is not sent to our Site server.
When a recipient chooses to install ScanKeeper from a shared card page on Android, the complete card link is passed to Google Play as an install referrer so the App can retrieve it after installation. Google therefore receives that link. On iOS, the recipient's tap copies the link to the clipboard before opening the App Store; the recipient then explicitly pastes it in the App. The App does not automatically read the clipboard to look for cards.
3.6 Support communications
If you email us, we receive your email address, message, and anything you choose to attach. Please do not send barcode values, payment information, or other sensitive content unless it is necessary for us to help you.
4. Device Permissions and Local Processing
ScanKeeper requests or uses device capabilities only when needed for a feature:
- Camera: to scan a barcode or QR code or take a card image. Camera frames and captured images are processed locally and are not uploaded to Nomadix Apps.
- Selected photos: to import codes or images you choose through the system photo picker. On current supported iOS and Android versions, the picker gives the App access to selected items rather than the entire photo library.
- Screen brightness and keep-awake controls: to make a displayed code easier for a scanner to read. These controls do not collect brightness history or motion data.
- File save and share controls: to place a CSV or other export in the destination you select.
- Clipboard: to copy a shared card link after a tap on the Site and to import it after an explicit paste action in the App.
You can revoke camera access in system Settings. Features that need a revoked capability will stop working, but the rest of the App remains available.
5. The Website
The Site is a static website. It does not include a TelemetryDeck, Google Analytics, advertising, social-media, or fingerprinting script, and it does not intentionally set analytics or marketing cookies.
The shared card page displays the code only when you choose to view it in the browser. It does not save a browser-view preference or send card content to an analytics service.
The Site is hosted and delivered through Cloudflare. Like other hosting and security providers, Cloudflare processes request information such as IP address, requested URL, browser or user-agent information, timestamp, security signals, and response status to deliver the Site, prevent abuse, and maintain its network. Cloudflare may set a strictly necessary security cookie if it presents a security challenge. We do not combine Site request data with App analytics or use it for advertising.
6. Why We Process Information
We process information for these purposes:
- To provide the App features you request, store and display your codes, perform optional iCloud Sync, and deliver exports
- To verify and restore Premium purchases and provide subscription management
- To understand product use in aggregate and improve usability
- To detect, diagnose, and fix errors, crashes, and performance problems
- To secure and operate the Site and prevent abuse
- To respond to support requests and comply with applicable law
Where the GDPR, UK GDPR, or a similar law applies, our legal bases are:
- Performance of a contract: core App functionality and Premium entitlement management
- Legitimate interests: privacy-preserving product analytics, diagnostics, security, support, and product improvement, balanced against your rights
- Your request or consent: optional device permissions and iCloud Sync where consent is required
- Legal obligation: records and disclosures required by law
We do not use your information for advertising, cross-context behavioural advertising, or automated decisions that produce legal or similarly significant effects.
7. Who Receives Information
We do not sell personal information and do not share it for cross-context behavioural advertising. We disclose only the information needed for the purposes described above:
- TelemetryDeck: privacy-preserving product analytics
- Sentry: crash, error, and performance monitoring
- RevenueCat: Premium purchase screens and entitlement management
- Apple: App Store distribution and payment processing; optional iCloud storage and synchronization
- Google: Google Play distribution and payment processing; the shared card link in the install referrer when a recipient installs from the shared card page on Android
- Cloudflare: Site hosting, delivery, and security
- Our email provider: support communications you initiate
We may also disclose information if required by law, to protect rights or safety, or as part of a merger, acquisition, financing, or sale of all or part of the business. In such a transaction, the recipient must handle information consistently with this Policy and applicable law.
8. Retention
- Local App data: until you delete it, clear the App's data, or uninstall the App, subject to device backups.
- iCloud data: until you remove it from iCloud or Apple deletes it under its policies.
- TelemetryDeck, Sentry, and RevenueCat data: according to the retention settings and legal or operational requirements of our account and the provider. We retain it only while needed for analytics, diagnostics, entitlement delivery, security, or legal obligations.
- Site request data: according to Cloudflare's security and operational retention schedules.
- Support email: while needed to answer and document the request, then deleted or archived only where reasonably required for legal, security, or business records.
We periodically review whether information is still needed. Aggregated or irreversibly anonymized information may be retained because it no longer identifies an individual.
9. International Transfers
Nomadix Apps is based in the United States, and our providers may process information in the United States, the European Economic Area, or other countries. Where applicable law requires a transfer mechanism, we and our providers rely on measures such as adequacy decisions, the EU Standard Contractual Clauses, the UK Addendum or International Data Transfer Agreement, or another lawful safeguard described in the provider's terms.
10. Your Choices and Rights
You can control most ScanKeeper data directly:
- Delete cards in the App or uninstall the App to remove local data
- Turn off iCloud Sync and manage existing iCloud data in Apple settings
- Revoke camera access in system Settings
- Cancel or manage a subscription through the App's Purchases and subscription screen, the App Store, or Google Play
- Stop future analytics and diagnostics by discontinuing use and uninstalling the App
Depending on where you live, you may also have rights to request access, correction, deletion, restriction, portability, or objection; withdraw consent where processing is based on consent; opt out of sale, sharing, targeted advertising, or certain profiling; and appeal a denied request. We do not sell personal information, share it for cross-context behavioural advertising, or use it for targeted advertising or significant-effect profiling.
To make a request, email support@scankeeper.app with the subject "Privacy request". Because ScanKeeper has no user account and most records use a random identifier, we may have limited ability to identify a particular record. We will not ask for more information than reasonably needed to verify and fulfil the request. You may also complain to your local data-protection or consumer-protection authority.
11. Children's Privacy
ScanKeeper is a general-audience utility and is not directed to children. We do not knowingly collect a child's name, contact details, precise location, barcode content, or advertising identifier. If you believe a child has provided personal information through a support communication or another channel, contact us at support@scankeeper.app so we can investigate and take appropriate action.
12. Security
We use reasonable technical and organisational safeguards, including device application sandboxes, transport encryption, restricted operational access, pseudonymous or anonymized identifiers, no advertising SDK, and disabled Sentry Session Replay. No system is completely secure, and we cannot guarantee absolute security.
13. Changes to This Policy
We may update this Policy to reflect changes in the App, providers, or law. We will change the date above and publish the revised Policy at scankeeper.app/privacy-policy/. If a change materially affects your rights or how we use information, we will provide any additional notice or request any consent required by law.
14. Contact
Nomadix Apps LLC
5830 E 2nd St
Casper, WY 82609-4308
United States
Email: support@scankeeper.app