Privacy Policy
Your privacy is important to us. This policy explains what data we collect, how we use it, and your rights.
Last updated: March 25, 2026
Data Controller
ScanThisText is operated by Blue Mint Technologies LLC. For any privacy-related inquiries, contact us at support@scanthistext.com. This policy applies to all data collected through our website, mobile applications (iOS and Android), and related services (collectively, "the Service").
Your Data Protection Promise
- We do NOT permanently store your uploaded images or scans. Images are processed and automatically deleted from our servers within 24 hours.
- We do NOT sell your personal data to third parties, ever.
- We do NOT read or access the content of your scanned documents except for automated AI processing to provide the Service.
- Your documents are NOT used to train AI models. Content is processed solely for text extraction and analysis, then deleted.
Information We Collect
Data You Provide
- Images and documents you upload for OCR processing (temporarily stored, auto-deleted within 24 hours)
- Account information — email address, display name, and account preferences
- Support communications — messages you send to our support team
- Account deletion feedback — optional reason provided when deleting your account
Data Collected Automatically
- Device information — browser type, operating system, device model, screen resolution
- Usage data — features used, scan frequency, error logs, timestamps
- Analytics data — page views, session duration, referral sources (anonymized)
- Cookies and local storage — for session management, preferences, and consent tracking
Mobile App Data
- Camera access — only when you actively use the scan feature; we never access your camera in the background
- Photo library access — only when you choose to select an existing image for scanning
- Local storage — scan history and preferences stored on your device
How We Use Your Data
- Provide our Service — Process your uploaded documents using AI-powered OCR and return extracted text and analysis
- Improve our services — Analyze aggregated, anonymized usage patterns to enhance accuracy, performance, and user experience
- Manage your account — Authenticate your identity, manage subscriptions, and enforce plan limits
- Communicate with you — Send service updates, security alerts, and respond to support requests
- Process payments — Facilitate subscription billing through our payment processor
- Ensure security — Detect fraud, abuse, and protect our systems and users
- Legal compliance — Comply with applicable laws, regulations, and legal processes
Legal Basis for Processing (GDPR)
If you are in the European Economic Area (EEA), UK, or Switzerland, we process your personal data on the following legal bases:
- Contract performance — Processing necessary to provide the Service you requested (document scanning, account management)
- Legitimate interests — Analytics, fraud prevention, and service improvement, balanced against your privacy rights
- Consent — Where required (e.g., marketing communications), which you may withdraw at any time
- Legal obligation — Where processing is required to comply with applicable law
Data Retention
| Data Type | Retention Period |
|---|---|
| Uploaded images | Deleted within 24 hours after processing |
| Extracted text (if saved) | Until you delete it or account closure |
| Account information | Until account deletion + 30-day grace period |
| Usage analytics | Up to 2 years (anonymized) |
| Payment/billing records | As required by tax/accounting law (typically 7 years) |
| Support communications | Up to 2 years after resolution |
Zero Ads — No Exceptions
We believe your experience matters more than ad revenue. ScanThisText will never display advertisements on any platform — web or mobile.
- • No banner ads — ever
- • No video ads — ever
- • No sponsored content — ever
- • No selling your data to advertisers — ever
- • No ad tracking or profiling — ever
We sustain the Service through paid subscription plans. Your scanned content is never shared with anyone.
Third-Party Service Providers
We use trusted third-party service providers to operate the Service. Each provider only receives the minimum data necessary for their function:
- • AI processing providers — For document text extraction, classification, and analysis. Your document content is not used to train AI models.
- • Payment processors — For secure subscription billing. We never store your full credit card number; all payment data is handled under PCI DSS compliance.
- • Cloud infrastructure providers — For hosting and secure data processing.
- • Email service providers — For transactional emails (account verification, password resets, support).
- • Analytics providers — For anonymized usage statistics and performance monitoring.
These providers are contractually bound to protect your data and use it only for the purposes we specify. We do not use any advertising networks.
Account Deletion Process
You can delete your account at any time from the Settings page on both the web app and mobile app. When you request deletion:
- Your account is immediately deactivated
- Active subscriptions are cancelled immediately
- Your data enters a 30-day grace period during which you can contact support to recover your account
- After 30 days, all personally identifiable information is permanently anonymized
- Billing records are retained as required by law
Your Rights (GDPR, CCPA & Global)
Depending on your location, you have the following rights regarding your personal data:
- Access — Request a copy of your personal data we hold
- Correction — Request correction of inaccurate personal data
- Deletion — Request deletion of your data at any time (account settings or by contacting us)
- Portability — Export your data in a standard, machine-readable format
- Restriction — Request that we limit how we process your data
- Objection — Object to processing based on legitimate interests
- Withdraw consent — Where processing is based on consent, withdraw it at any time without affecting prior processing
To exercise any of these rights, contact us at support@scanthistext.com. We will respond within 30 days (or sooner as required by law).
California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
- Right to know — what personal information we collect, use, disclose, and sell
- Right to delete — request deletion of your personal information
- Right to non-discrimination — we will not discriminate against you for exercising your rights
We do not sell personal information. We do not share personal information for cross-context behavioral advertising. We do not use or disclose sensitive personal information for purposes beyond what is necessary to provide the Service.
Children's Privacy
The Service is not intended for children under 13 years of age (or under 16 in the EEA). We do not knowingly collect personal information from children under these age thresholds. If we discover that we have inadvertently collected data from a child under the applicable minimum age, we will promptly delete it. If you believe a child has provided us with personal information, please contact us at support@scanthistext.com.
International Data Transfers
Your data may be processed in the United States and other countries where our service providers operate. When we transfer data outside of the EEA, UK, or Switzerland, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission or equivalent mechanisms. By using the Service, you acknowledge and consent to the transfer and processing of your data in the United States.
Data Security & Breach Notification
We implement industry-standard security measures to protect your data, including encryption in transit (TLS) and at rest, secure authentication, and regular security reviews. However, no method of transmission over the internet is 100% secure.
In the event of a data breach that poses a risk to your rights and freedoms, we will:
- Notify affected users via email within 72 hours of becoming aware of the breach
- Report the breach to relevant supervisory authorities as required by law
- Provide details on what data was affected and steps you can take to protect yourself
Payment Information
All payment processing is handled by a PCI DSS Level 1 certified payment processor. We never receive, store, or have access to your full credit card number. We only store a reference to your payment account and basic subscription metadata (plan type, billing dates, payment status) necessary to manage your account.
Changes to This Policy
We reserve the right to modify, update, or replace this Privacy Policy at any time, at our sole discretion. Changes may reflect new data practices, legal requirements, third-party service changes, or other operational needs.
When we make material changes, we will: (a) update the "Last updated" date at the top of this page; (b) notify registered users via email at least 14 days before the changes take effect, except where changes are required by law.
Your continued use of the Service after changes become effective constitutes your acceptance of the revised Privacy Policy. If you do not agree, you must stop using the Service and may delete your account. We encourage you to periodically review this policy.
Privacy Questions?
Contact us at support@scanthistext.com
EEA residents may also lodge a complaint with your local data protection authority.
View Terms of Service →