VibeScan

Privacy Policy

Last updated: July 19, 2026 · Applies to VibeScan for iOS & iPadOS

VibeScan is a document scanner built to be private by design. Your documents are processed entirely on your device and are never uploaded to us or any third-party server. This policy explains what that means, and the limited data that advertising, optional analytics, and crash diagnostics involve.

The short version. We do not run servers that receive your documents. Scans, images, extracted text (OCR), PDFs, signatures, passwords, and contact details from business cards stay on your device. The app is free and supported by ads, which involve a device advertising identifier — only with your consent — and optional, anonymous usage analytics and crash diagnostics you can turn off together.

1. Who we are

VibeScan (the “App”) is provided by TU LUU (“we”, “us”). You can reach us at tuluu1902@gmail.com.

2. Data processed on your device (never sent to us)

The core features of the App run locally using Apple frameworks (VisionKit, the Vision framework, PDFKit, and the iOS Keychain). The following are created and stored only on your device, and we have no access to them:

This version of the App stores your documents locally on your device and does not sync them to iCloud or any cloud service. Documents remain until you delete them; deleting a document or the App removes its files from your device.

3. Data collected by third parties for ads and analytics

Because the App is free and ad-supported, it includes the services below. This is the only data leaving your device, and it never includes the content of your documents.

ServiceDataPurposeTracking?
Google AdMob (advertising) Device advertising identifier (IDFA) and ad-interaction data Show and measure ads Yes — only if you allow it (see consent below)
Google User Messaging Platform Your consent choices Manage ad consent (GDPR/EEA/UK) No
Firebase Analytics (optional) Anonymous product-interaction events (e.g., a scan was completed) Understand feature usage to improve the App No — not linked to your identity, no advertising ID
Firebase Crashlytics (optional) Crash logs (stack traces), device model & OS version, and, because analytics is enabled, a short trail of in-app actions preceding the crash Diagnose and fix crashes No — not linked to your identity, no advertising ID

Advertising uses the following domains: googleads.g.doubleclick.net and googleadservices.com. Firebase Analytics and Crashlytics are collected only when analytics sharing is enabled, and never include your advertising identifier.

4. Your consent & choices

5. Device permissions

The App requests these permissions only for the feature that needs them, and all processing stays on your device:

6. Children

The App is not directed to children under 13, and we do not knowingly collect personal information from children.

7. Data retention & security

We do not store your documents on any server, so there is nothing on our side to retain. On-device data is protected by iOS app sandboxing; document passwords use the iOS Keychain. Third-party services retain data under their own policies.

8. Third-party policies

9. Your rights

Depending on your region (e.g., GDPR or CCPA), you may have rights to access, correct, or delete personal data. Because we don’t hold your documents or a personal account, most of these are exercised directly on your device (delete documents, disable analytics, change ad consent). For requests about third-party ad/analytics data, contact us at tuluu1902@gmail.com.

10. Changes to this policy

We may update this policy as the App evolves. Material changes will be reflected here with a new “Last updated” date.

Contact. Questions about privacy? Email tuluu1902@gmail.com.