1. Who this policy covers
This policy applies to Scanflow: QR Code & Generator (Android application IDs com.appnimbly.scanflow and com.appnimbly.scanflow.dev), version 1.0.0 (version code 1), published by AppNimbly. For privacy questions, contact appnimbly72@gmail.com. Effective date: August 30, 2026.
2. Information processed on your device
- Camera: Scanflow uses android.permission.CAMERA only when you choose live scanning. Camera frames are decoded on-device with CameraX and Google ML Kit. The app does not record or upload camera frames or decoded payloads.
- Photos and images: You may select an image through Android’s photo picker or share an image to Scanflow for local barcode decoding. Image content is processed on-device. The app may store the resulting decoded payload in history in the same way as a live scan.
- Text shared to Scanflow: When you explicitly share text to Scanflow from another app, Scanflow treats it as content to scan and may save the resulting item to local history.
- Contacts: When you choose Import contact for a vCard QR code, Scanflow requests android.permission.READ_CONTACTS and reads the selected contact’s name, phone number, email address, organization, and website to build the code locally. Android treats this as Contacts permission; you can revoke it at any time in device Settings.
- Wi-Fi: A scanned Wi-Fi QR code may contain an SSID and password. Scanflow can use Android Wi-Fi APIs to suggest that network only after you choose Connect. It does not send those credentials to AppNimbly.
- Device settings: Scanflow stores preferences such as theme, language, retention choice, and scanning settings locally.
3. Local storage, retention, and deletion
- History: Saved scans and codes may include decoded payloads, URLs, Wi-Fi credentials, contact details, notes, tags, favorites, timestamps, and generation metadata. They are stored in the app’s private Room/SQLite database. The app does not independently encrypt this database; its protection relies on Android application sandbox and device security.
- Generate draft: Scanflow persists the selected code type and generic content typed in the Generate screen in private Android DataStore to restore a draft. This may include sensitive text such as a URL, phone number, email address, or contact name. It is separate from scan history.
- Retention: Auto-delete removes non-favorited history items older than the selected period. Favorite items are retained until you delete them manually. Deleting history does not remove the Generate draft.
- Deletion: You can delete individual history items and set retention in the app. To remove all private application data, including history, settings, and Generate drafts, clear Scanflow storage in Android Settings or uninstall the app. Deleting or uninstalling does not remove files you previously exported or images created in your shared Pictures collection.
4. Exports, printing, clipboard, and sharing
- Exports: When you choose Export, Scanflow writes history as CSV or JSON, or a generated code as PNG, JPEG, or PDF, to the Android location you select. Those files are governed by that location’s storage and backup settings.
- Sharing a generated QR image: Before the Android share sheet opens, Scanflow creates a PNG in Pictures/Scanflow and shares its content URI. That image remains in Pictures/Scanflow until you delete it with your gallery or file manager, even if you later delete history or uninstall Scanflow.
- Sharing scanned content: When you choose Share, Copy, Open link, Call, Email, Add to calendar, Save contact, or Connect Wi-Fi, Scanflow passes only the information necessary for the action to Android or the app/service you choose. The receiving app or service handles that information under its own privacy policy.
- Printing: Printing is initiated only by you through Android’s system print service; the selected print service handles the print data under its own policy.
5. Diagnostic data sent to Google
Scanflow includes Google Firebase Crashlytics when Firebase configuration is present in the app build. Crashlytics collection is enabled automatically in those configured builds, including development and production builds; it is not currently an opt-in feature. Crashlytics may receive crash reports, fatal exception data, app state, device and hardware information, Android OS version, and a Crashlytics installation identifier to diagnose stability problems.
Scanflow does not deliberately add decoded QR/barcode payloads, Wi-Fi passwords, imported contact fields, history notes, or generated content as Crashlytics custom keys or logs. Google processes Crashlytics diagnostic data under the Google Privacy Policy at https://policies.google.com/privacy. We do not use Firebase Analytics, advertising SDKs, or a first-party analytics tracker in Scanflow.
6. Backups, security, and data sharing
Android cloud backup and device-transfer backup are disabled for Scanflow’s private app data. This does not control backups made by other apps or services after you export or share data. Scanflow does not sell personal information or maintain a cloud copy of scan history. User-initiated sharing and system actions can transfer data to another app or service, as described above.
7. Your choices and contact
- You may deny or revoke Camera and Contacts permissions in Android Settings.
- You may delete history entries manually and choose automatic retention for non-favorites.
- You may remove generated share images from Pictures/Scanflow and exported files from the location you selected.
- You may clear app storage or uninstall the app to remove private local app data.
- For questions about this policy or Crashlytics diagnostics, email appnimbly72@gmail.com. Because Scanflow has no accounts or cloud history, we cannot retrieve or delete local data on your device for you.
8. Policy changes
We will update this policy when Scanflow’s data practices materially change and will revise the effective date above.
Contact Support