SCANDOCUMENT
Your documents, and what happens to them
ScanDocument processes photos and generates PDFs on your device. There is no document-processing server or automatic document upload.
Optional website analytics
With your permission, Google Analytics 4 measures public-page visits and Microsoft Clarity records public-page interactions for heatmaps and session replay. These services receive connection and device information and may store analytics cookies. Advertising consent stays off. Neither runs on scanner or phone-pairing screens. Clarity also skips pricing pages and URLs with query strings or fragments, and page text is masked. We send no document data or custom user identifiers. Where analytics is offered, use Analytics settings in the public-page footer to allow or withdraw consent. Elsewhere, analytics stays off. Withdrawal reloads the page and removes accessible first-party analytics cookies. Your choice is saved in this browser. Local previews and offline visits do not start analytics.
Single-device scanning
Photos, previews, page order, and crop settings stay in this browser. The scanner does not send document bytes, filenames, or document-derived analytics. There is no session replay or third-party analytics on scanner or phone-pairing screens.
Browser drafts and offline assets
Draft photos and edits are stored in IndexedDB when available. Delete draft removes them from this browser. Clearing browser data, private browsing, or storage eviction can remove drafts. Offline caching stores application assets, not a cloud copy of your document.
Optional phone transfer
When you pair devices, the phone encrypts page content using AES-GCM before our Cloudflare relay forwards it. The encryption key stays in the pairing link fragment and on your devices. The relay handles connection credentials, timing, sizes, and encrypted traffic. It stores temporary coordination metadata, not document files. Keep the pairing link private.
Connection and hosting data
The hosting service necessarily receives ordinary connection information, such as IP address and requested URL. Pairing requires both devices online and expires after one hour at most, or after 15 minutes of inactivity. Unused invitations expire after two minutes.
Payments
PaywallHQ handles your purchase email, customer identifier and payment information, never document contents. A browser credential remembers access. When sign-in is enabled, verify your purchase email on Paywall to recover access across devices and use its hosted billing dashboard. Entering an email at checkout is not proof of ownership. Documents stay in their original browser. Paid access requires an online check; Preview works offline once ready.
Your next clean PDF is a few photos away.
Start scanning ↗