Last updated: July 19, 2026 · Applies to VibeScan for iOS & iPadOS
VibeScan is a document scanner built to be private by design. Your documents are processed entirely on your device and are never uploaded to us or any third-party server. This policy explains what that means, and the limited data that advertising, optional analytics, and crash diagnostics involve.
VibeScan (the “App”) is provided by TU LUU (“we”, “us”). You can reach us at tuluu1902@gmail.com.
The core features of the App run locally using Apple frameworks (VisionKit, the Vision framework, PDFKit, and the iOS Keychain). The following are created and stored only on your device, and we have no access to them:
This version of the App stores your documents locally on your device and does not sync them to iCloud or any cloud service. Documents remain until you delete them; deleting a document or the App removes its files from your device.
Because the App is free and ad-supported, it includes the services below. This is the only data leaving your device, and it never includes the content of your documents.
| Service | Data | Purpose | Tracking? |
|---|---|---|---|
| Google AdMob (advertising) | Device advertising identifier (IDFA) and ad-interaction data | Show and measure ads | Yes — only if you allow it (see consent below) |
| Google User Messaging Platform | Your consent choices | Manage ad consent (GDPR/EEA/UK) | No |
| Firebase Analytics (optional) | Anonymous product-interaction events (e.g., a scan was completed) | Understand feature usage to improve the App | No — not linked to your identity, no advertising ID |
| Firebase Crashlytics (optional) | Crash logs (stack traces), device model & OS version, and, because analytics is enabled, a short trail of in-app actions preceding the crash | Diagnose and fix crashes | No — not linked to your identity, no advertising ID |
Advertising uses the following domains: googleads.g.doubleclick.net and googleadservices.com.
Firebase Analytics and Crashlytics are collected only when analytics sharing is enabled, and never include your advertising identifier.
The App requests these permissions only for the feature that needs them, and all processing stays on your device:
The App is not directed to children under 13, and we do not knowingly collect personal information from children.
We do not store your documents on any server, so there is nothing on our side to retain. On-device data is protected by iOS app sandboxing; document passwords use the iOS Keychain. Third-party services retain data under their own policies.
Depending on your region (e.g., GDPR or CCPA), you may have rights to access, correct, or delete personal data. Because we don’t hold your documents or a personal account, most of these are exercised directly on your device (delete documents, disable analytics, change ad consent). For requests about third-party ad/analytics data, contact us at tuluu1902@gmail.com.
We may update this policy as the App evolves. Material changes will be reflected here with a new “Last updated” date.