ScanKeeper App Privacy Policy
Last updated: 16 August 2026
1. Introduction
This Privacy Policy explains how Nomadix Apps ("Nomadix Apps", "we", "our", or "us") handles personal information in connection with the ScanKeeper mobile application for iOS and Android (the "Application" or "ScanKeeper") and the marketing website at https://scankeeper.app/ (the "Site").
ScanKeeper is a barcode and QR code scanner. It lets you scan, create, store, organize, and display codes on your device. The Application contains no advertising: there is no ad SDK, no ad mediation, and no advertising identifier is read, in any version. It is offered free of charge, with an optional paid Premium upgrade (a monthly or yearly subscription, or a one-time lifetime purchase) that unlocks additional features such as folders, collection search, home screen widgets, and CSV export.
Nomadix Apps is the data controller for personal information processed through the Application and the Site, except where this Policy says otherwise (for example, Apple is the controller for content stored in your iCloud, and Apple and Google are independent controllers for app distribution and payment processing).
You can reach us at info@nomadixapps.org. We have not appointed a Data Protection Officer; please send any privacy-related question to the same address and a member of our team will respond.
By using the Application, you confirm that you have read this Policy. If you do not agree with it, please do not install or use ScanKeeper.
2. Summary at a Glance
A short, plain-English overview. The rest of this Policy gives the details.
- Your scans stay on your device. Barcode and QR data, names, folders, and images are stored in a local database on your phone. Nothing is uploaded to our servers.
- No account, no email, no login. You do not create an account to use ScanKeeper.
- Optional iCloud sync (iOS only). If you turn it on in Settings, your data syncs through your own Apple iCloud. We cannot read it.
- No ads, no ad tracking, in any version. ScanKeeper ships without an advertising SDK. It does not read your advertising identifier (IDFA/GAID), does not show an App Tracking Transparency prompt, and does not run an advertising consent form.
- Pseudonymous diagnostics. We use TelemetryDeck for privacy-focused usage signals and Sentry for crash reporting. We do not attach your name or email address.
- No sale or sharing of personal information. We do not sell personal information, and we do not "share" it for cross-context behavioural advertising as those terms are used in California law.
- You have rights. Depending on where you live, you can request access, deletion, correction, opt-out, and more. See Section 11.
3. Information We Collect
3.1 Barcode and Application Data (stays on your device)
When you scan or create a code, ScanKeeper stores the following locally inside the application sandbox on your device, in a local Hive database:
- The contents of the barcode or QR code
- Any name, label, note, or folder you assign
- Cached images and adaptive thumbnails of barcodes
- Application settings, theme, and preferences
This data is not transmitted to Nomadix Apps. It does not leave your device unless you turn on iCloud Sync (see Section 3.1.1) or you choose to share an item yourself (for example, by exporting an image).
3.1.1 Optional iCloud Sync (iOS only)
On iOS you can enable an "iCloud Sync" toggle in Settings. When it is on, ScanKeeper saves your barcode data and images into your personal iCloud Drive container, so your codes are available across your Apple devices.
- Apple, not Nomadix Apps, controls and stores the content of your iCloud container. We cannot read it.
- iCloud uses Apple's transport and at-rest encryption per Apple's terms.
- You can disable iCloud Sync at any time from Settings. Disabling it stops new uploads; you can also remove the existing container from your iCloud storage in iOS Settings if you wish.
3.2 Device and Diagnostic Data
Our analytics and crash-reporting providers automatically receive a small set of technical attributes so that we can understand how the Application performs across devices. These typically include:
- Device model and manufacturer
- Operating system and version
- Application version and build
- Language and region settings
- A pseudonymous identifier generated by the Application or analytics SDK
We do not link this data to your name, email, or phone number, because we do not collect those.
3.3 Camera and Photo Library
ScanKeeper requests the following operating-system permissions only when you use a feature that needs them:
- Camera (
NSCameraUsageDescriptionon iOS /CAMERAon Android) — to scan barcodes and QR codes in real time. Camera frames are processed locally; we do not record video and we do not transmit camera input. - Photo Library — read (
NSPhotoLibraryUsageDescriptionon iOS /READ_MEDIA_IMAGESon Android) — to import a barcode image you already have. - Photo Library — add (
NSPhotoLibraryAddUsageDescriptionon iOS) — to save a barcode image you generate to your photos. - Brightness (
NSBrightnessUsageDescriptionon iOS) — to temporarily brighten the screen so a scanner can read your displayed code. - Motion (
NSMotionUsageDescriptionon iOS) — for screen-orientation handling.
You can change or revoke these permissions in your device's system Settings at any time.
3.4 Advertising Identifiers — not collected
ScanKeeper does not collect or use advertising identifiers. The Application contains no advertising SDK and no ad mediation. It does not read the IDFA on iOS or the GAID on Android, it does not request App Tracking Transparency permission, and it does not run a consent form for advertising purposes.
Earlier versions of ScanKeeper did include advertising in the free tier. Advertising was removed from the Application entirely; the ad SDKs and their mediation partners are no longer bundled and no longer receive any data from the Application. Any consent or tracking preference you set for advertising in an earlier version has no further effect, because there is nothing left for it to control. Identifiers previously collected are retained, if at all, by the former ad partners under their own policies; we never received them.
3.5 Analytics Signals (TelemetryDeck)
We use TelemetryDeck for privacy-focused product analytics. TelemetryDeck receives anonymous, aggregated event signals from the Application, such as:
- Screen views and feature interactions (for example, "scanner opened", "barcode created")
- Recoverable, expected error states (for example, "camera permission denied")
- Technical attributes listed in Section 3.2
TelemetryDeck does not receive your email address, name, file paths, barcode contents, or any advertising identifier. The device identifier sent to TelemetryDeck is hashed and cannot be reversed by us.
TelemetryDeck's privacy notice: https://telemetrydeck.com/privacy
3.6 Crash and Performance Data (Sentry)
We use Sentry to detect crashes, unhandled exceptions, and performance problems so that we can fix them. We have configured Sentry as follows:
sendDefaultPiiis set to false, so Sentry does not automatically attach default personal information such as your IP address. We deliberately attach a stable pseudonymous Application user ID so that related crashes can be grouped across sessions. This ID is not your name, email address, or barcode content.- Session Replay is disabled. Both
sessionSampleRateandonErrorSampleRateare set to 0.0, so no screen recordings of your use of the Application are captured or uploaded — neither routinely nor when an error occurs. - Performance traces are sampled at
tracesSampleRateof 0.2 and profiles atprofilesSampleRateof 0.2.
Sentry processes the data on our behalf as a processor. Their privacy notice: https://sentry.io/privacy/
If you deliberately open the feedback form in Settings and submit it, Sentry receives the feedback text you type and, if you include one, the screenshot shown in the form. The form is user-initiated and is not sent until you choose to submit it. Please do not enter barcode contents or other sensitive information in feedback.
3.7 Subscription Data (RevenueCat)
If you purchase ScanKeeper Premium — as a monthly or yearly subscription, or as a one-time lifetime purchase — we use RevenueCat to manage your entitlement across platforms. RevenueCat receives:
- An anonymous app-user ID generated by the SDK
- The state of your transaction (for example, active, expired, refunded)
- Technical attributes such as platform and country code reported by the store
RevenueCat does not receive your payment card details. Your payment is handled directly by Apple (App Store) or Google (Google Play). RevenueCat's privacy notice: https://www.revenuecat.com/privacy
3.8 Sharing and Export You Initiate
When you use a Share or Export action, your operating system shows the destinations available on your device. Data is sent only to the destination you choose. That destination handles the data under its own terms and privacy policy. We do not receive a list of the apps installed on your device, and we do not list every possible share destination here because the available choices depend on your device and installed apps.
3.9 Marketing Website
The Site at https://scankeeper.app/ is a static site. We do not intentionally set cookies, run analytics scripts, or use trackers on the Site. The hosting provider and content delivery network may keep standard request logs (for example, IP address, user-agent, requested URL, timestamp) for security, abuse prevention, and operational purposes, in line with their own policies. We do not combine these logs with Application data.
4. How We Use Information
We use the categories of information described above for the following purposes:
- Operate ScanKeeper. Store, organise, and display the codes, names, folders, and images you create, on your device and (if you opt in) in your iCloud.
- Provide features that need device hardware. Use the camera to scan, the photo library to import or save images, and the brightness API to display codes.
- Manage the Premium upgrade. Verify whether the Premium entitlement is active so that we can unlock the paid features.
- Understand product use. Use anonymous TelemetryDeck signals to see which features are used and where users encounter friction.
- Improve quality and stability. Use Sentry crash, error, and performance data to diagnose bugs.
- Respect your privacy choices. Honour the operating-system permissions you grant or revoke, and respect opt-out requests you send us.
- Comply with law. Respond to legitimate legal requests, enforce our Terms, and prevent fraud or abuse.
We do not use your information for automated decisions that produce legal or similarly significant effects on you, and we do not build user profiles from barcode contents.
5. No Advertising, No Cross-App Tracking
This Section states plainly what ScanKeeper does not do, and what controls remain available to you.
5.1 No ads and no ad SDKs
ScanKeeper contains no advertising. There are no banner, interstitial, native, or rewarded ad placements anywhere in the Application, and no advertising or mediation SDK is bundled with it. This applies to the free Application as well as to Premium — it is not a benefit you have to pay for.
5.2 No ATT prompt and no advertising consent form
Because the Application does no advertising and reads no advertising identifier:
- iOS does not show Apple's App Tracking Transparency prompt for ScanKeeper, and we do not request tracking permission.
- No advertising consent management platform (such as Google's User Messaging Platform) runs in the Application, and no IAB TCF consent string is created, stored, or transmitted.
- Consequently, ScanKeeper Settings no longer contains a "Privacy options" entry: there is no advertising consent left to manage.
5.3 No cross-app or cross-site tracking
We do not track you across other companies' applications or websites, we do not build advertising profiles, and we do not join your data with data from data brokers or ad networks. The only data leaving your device is described in Sections 3.5 to 3.7 (pseudonymous analytics, crash diagnostics, and subscription state).
5.4 What Premium changes
Premium unlocks additional features — folders, collection search, home screen widgets, and CSV export. It does not change anything about advertising, tracking, or the data described in this Policy, because the free Application already carries no advertising.
5.5 Device-level controls
The operating-system controls below no longer affect ScanKeeper, but you may still wish to use them for other applications:
- iOS: Settings → Privacy & Security → Tracking; Settings → Privacy & Security → Apple Advertising.
- Android: Settings → Google → Ads (delete or reset the advertising ID).
6. Third Parties and Sharing
We do not sell your personal information, and we do not share it with advertising networks — the Application no longer integrates any. We use the following third-party providers, each acting either as our processor or as an independent controller as noted. Each provider is governed by its own privacy notice:
| Provider | Role | Purpose | Privacy notice |
|---|---|---|---|
| TelemetryDeck | Processor | Anonymous product analytics. | https://telemetrydeck.com/privacy |
| Sentry | Processor | Crash, error, and performance data. | https://sentry.io/privacy/ |
| RevenueCat | Processor | Subscription state management. | https://www.revenuecat.com/privacy |
| Apple iCloud | Independent controller | Stores barcode data in your personal iCloud if you opt in. | https://www.apple.com/legal/privacy/ |
| Apple App Store | Independent controller | App distribution and payment processing on iOS. | https://www.apple.com/legal/privacy/ |
| Google Play | Independent controller | App distribution and payment processing on Android. | https://policies.google.com/privacy |
There are no advertising or ad-mediation partners on this list, because the Application integrates none.
The user-initiated Share and Export actions described in Section 3.8 do not send data to a fixed list of recipients: the destination is the app or service you select at that moment.
We may also disclose information when we are required to do so by law, when necessary to protect our rights or the safety of others, or in connection with a merger, acquisition, or sale of assets — in which case we will require the recipient to honour this Policy.
6.1 "Sale" and "sharing" under California law
Under the California Privacy Rights Act ("CPRA"), disclosing online identifiers such as IDFA/GAID for cross-context behavioural advertising counts as "sharing" even when no money changes hands. ScanKeeper does not do this: the Application reads no advertising identifier and integrates no advertising network, so there is no cross-context behavioural advertising to opt out of.
We do not sell personal information for money or other valuable consideration, we do not share it for cross-context behavioural advertising, and we do not sell or share the personal information of users we know to be under 16.
Earlier versions of the Application did serve personalised advertising through Google AdMob, which may have constituted "sharing" at the time. That processing has ended with the removal of advertising from the Application.
7. Legal Bases (GDPR / UK GDPR / Swiss FADP)
If you are in the European Economic Area, the United Kingdom, or Switzerland, we rely on the following legal bases under the GDPR, the UK GDPR, and the Swiss revised Federal Act on Data Protection ("FADP"):
- Performance of a contract (Art. 6(1)(b) GDPR) — to provide the core functionality of the Application that you ask us to provide, and to manage the paid Premium upgrade.
- Consent (Art. 6(1)(a) GDPR) — for camera and photo-library access at the operating-system level. You can withdraw this consent at any time in your device settings; withdrawal does not affect the lawfulness of processing carried out before withdrawal. We do not rely on consent for advertising, because the Application does no advertising.
- Legitimate interests (Art. 6(1)(f) GDPR) — for product analytics, crash reporting, security, and product improvement (diagnostics through TelemetryDeck and Sentry). Our interests are running and improving a working, sustainable application; we balance these against your rights and offer the controls described in Section 11. We do not rely on legitimate interests for advertising or ad measurement of any kind.
- Compliance with a legal obligation (Art. 6(1)(c) GDPR) — to respond to lawful requests and meet retention or disclosure duties.
Under the Swiss FADP, the equivalent grounds (consent, contractual necessity, overriding legitimate interest, legal obligation) apply.
8. International Transfers
Our processors are global companies. Personal information may be processed in the United States and other countries that may not have the same data protection standards as your country.
Where transfers of personal information from the EEA, the UK, or Switzerland occur, we rely on appropriate safeguards. In practice, this means the European Commission's Standard Contractual Clauses (and the UK Addendum / Swiss equivalent where applicable) entered into by our processors, and supplementary measures these processors document in their own privacy notices linked in Section 6. You can request a copy of the relevant safeguard by contacting info@nomadixapps.org.
9. Data Retention
- Barcode and Application data on your device. Retained until you delete it from within ScanKeeper or uninstall the Application.
- iCloud-synced data. Retained in your iCloud until you disable iCloud Sync and/or delete the data from your iCloud storage. Apple's retention rules apply.
- Analytics signals. Retained by TelemetryDeck per its policy.
- Crash, error, and performance data. Retained by Sentry per its policy.
- Subscription state. Retained by RevenueCat for as long as needed to provide the Premium entitlement and meet legal requirements, per its policy.
- Advertising signals. None are generated. Any signals collected by the former ad partners before advertising was removed are retained by those companies under their own policies; we hold none of them.
- Support emails. If you write to info@nomadixapps.org, we keep the email for as long as needed to handle your request and keep a record of it, then we delete it.
In general, we retain personal information for as long as necessary for the purposes described in this Policy, and no longer than required by applicable law.
10. Data Security
We take reasonable, industry-standard technical and organisational measures to protect personal information, including:
- Storing barcode and Application data inside your device's application sandbox (iOS Data Protection / Android app-specific storage).
- Using HTTPS/TLS for traffic between the Application and our processors.
- Configuring third-party SDKs with privacy-protective settings (for example, disabling Sentry Session Replay entirely and hashing device IDs in TelemetryDeck).
- Shipping no advertising or ad-mediation SDK, which removes a whole class of third-party data collection from the Application.
- Restricting access to operational tools to a small team.
No system is perfectly secure, and we cannot guarantee absolute security. If we ever become aware of a personal data breach that affects you and is required to be reported under applicable law, we will notify you and the relevant supervisory authority within the time frames the law requires.
11. Your Rights
Your specific rights depend on where you live. To exercise any right, contact us at info@nomadixapps.org. We will need to verify that the request is genuine; because we do not collect account credentials, we may need to ask for additional context (such as a device identifier you can read from inside Settings) to locate any data tied to you.
You may also use an authorised agent, where the law allows, by providing written authorisation we can verify.
We will not discriminate against you for exercising any of these rights. We answer all valid requests within the time periods required by the applicable law (typically 30–45 days, with one extension where permitted).
11.1 EEA, United Kingdom, and Switzerland
If you are in the EEA, the UK, or Switzerland, you have the rights to:
- Access the personal information we hold about you and obtain a copy
- Rectify inaccurate or incomplete information
- Erase your personal information ("right to be forgotten")
- Restrict processing in certain circumstances
- Data portability for information you provided to us, in a structured, commonly used, machine-readable format
- Object to processing carried out under our legitimate interests, including direct marketing
- Withdraw consent at any time, without affecting the lawfulness of processing before withdrawal
- Lodge a complaint with your local data protection supervisory authority. A list of EEA authorities is available at https://edpb.europa.eu/about-edpb/about-edpb/members_en. UK residents can complain to the Information Commissioner's Office at https://ico.org.uk/. Swiss residents can contact the Federal Data Protection and Information Commissioner (FDPIC) at https://www.edoeb.admin.ch/.
11.2 United States
We respect the privacy rights granted by US state privacy laws. The rights below apply to residents of the corresponding state, subject to verification and to the exceptions set out in those laws.
California (CCPA / CPRA)
California residents have the right to:
- Know what categories of personal information we collect, use, disclose, and "share", and the sources, purposes, and recipients
- Access the specific pieces of personal information we hold about you
- Delete personal information we have collected, subject to legal exceptions
- Correct inaccurate personal information
- Opt out of the "sale" or "sharing" of personal information. As noted in Section 6.1, we do neither: we do not sell personal information, and the Application runs no advertising that could constitute "sharing" under the CPRA.
- Limit the use and disclosure of sensitive personal information (we do not knowingly process sensitive personal information beyond what is necessary to provide the requested service)
- Non-discrimination for exercising these rights
- Use an authorised agent to submit requests on your behalf
Do Not Sell or Share My Personal Information
There is nothing to opt out of: ScanKeeper does not sell personal information and does not share it for cross-context behavioural advertising. No opt-out link is required, and none of your data is disclosed to an advertising network.
If you would like this confirmed in writing, or you want to exercise any other right in this Section, email info@nomadixapps.org with the subject line "Do Not Sell or Share — California" and we will respond within the statutory period.
We honour Global Privacy Control ("GPC") signals. In practice, a GPC signal requires no action from us, because we carry out no sale or sharing that it could stop.
Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Montana (MCDPA), Oregon (OCPA), Delaware (DCDPA), Iowa (IICCC), and other US states with comparable laws
If you are a resident of one of these states (or another state that, by the time you read this, has adopted a comparable consumer privacy law), you have substantially similar rights to:
- Access / confirm the processing of your personal information
- Delete personal information we have collected
- Correct inaccurate personal information (where the law provides this right)
- Data portability in a usable format
- Opt out of targeted advertising, the sale of personal information, and certain types of profiling — none of which we carry out
To exercise any of these rights, follow the same steps as California residents above. If we deny your request, you may have a right to appeal; if so, reply to our response email and we will reconsider in the time frame your law requires.
11.3 Brazil (LGPD)
If you are in Brazil, you have the rights under the Lei Geral de Proteção de Dados (LGPD) to confirm whether we process your personal information; to access, correct, anonymise, block, or delete it; to data portability; to information about public and private entities with which we share your data; to information about the option of refusing consent and the consequences of refusal; and to revoke consent. You may also lodge a complaint with the Autoridade Nacional de Proteção de Dados (ANPD) at https://www.gov.br/anpd/.
11.4 Quebec, Canada (Law 25)
If you are a resident of Quebec, you have rights under "Law 25" (An Act to modernize legislative provisions as regards the protection of personal information) to access, rectify, withdraw consent, and request the cessation of dissemination of your personal information, and the right to data portability for computerised personal information you provided to us. You may also complain to the Commission d'accès à l'information du Québec at https://www.cai.gouv.qc.ca/.
11.5 Other jurisdictions
If you live elsewhere and your local law gives you privacy rights, contact us at info@nomadixapps.org and we will do our best to honour your request in line with that law.
12. Children's Privacy
ScanKeeper is a general-audience utility and is not directed to children. We do not knowingly collect personal information from children under 13 (or under the higher age of digital consent set by the EU Member State where the child resides, which can be up to 16). The Application shows no advertising to anyone, and it is not used to build profiles of children.
We comply with the US Children's Online Privacy Protection Act ("COPPA"). If you believe that a child has provided personal information to us, please email info@nomadixapps.org and we will delete the information promptly.
13. Changes to This Policy
We may update this Privacy Policy from time to time, for example to reflect changes to the Application, to our processors, or to applicable law. When we make a change, we will update the "Last updated" date at the top of this page and post the updated Policy at https://scankeeper.app/privacy-policy. For material changes, we will take additional steps required by law, such as showing an in-app notice or asking for renewed consent.
We encourage you to review this page periodically.
14. Contact
If you have any question about this Privacy Policy or about how Nomadix Apps handles your personal information:
- Email: info@nomadixapps.org
- Publisher: Nomadix Apps
- Website: https://scankeeper.app/
We have not appointed a Data Protection Officer; please use the email address above and a member of our team will respond.