ScanInsight Privacy Policy
Effective date and document version: 19 August 2026, revision 8
1. Controller identity and contact details
ScanInsight is operated by GOLDWAVE DYNAMICS LIMITED ("Gold Wave Dynamics", "we", "us"), which is the controller of personal data it receives in connection with the app.
- Public and legal name: GOLDWAVE DYNAMICS LIMITED
- CRO registration number: 822127
- Legal form: Private Company Limited by Shares (LTD)
- Registered in: Dublin, Ireland
- Date incorporated: 24 July 2026
- Geographic and correspondence address: Venture Hub, 136 Capel Street, Dublin 1, D01 T2C9, Ireland
- Privacy and general contact: admin@goldwavedynamicslimited.com
2. Scope and privacy-first local processing
This Policy covers ScanInsight and related support and purchase-entitlement interactions. ScanInsight processes imported documents, scans, images, OCR text, titles, tags, previews, search indexes and PIN-protected vault data locally on the user's device. Private document content is not uploaded to Gold Wave Dynamics servers. We do not use document content for advertising, profiling or analytics, and we do not sell it.
For this Policy, "ScanInsight Pro" means the paid entitlement available through the monthly subscription, annual subscription or ScanInsight Pro one-time purchase option (described in some technical or store records as "Lifetime"). "Lifetime" refers to the supported lifetime of the ScanInsight Android product, not the purchaser's lifetime. References to ScanInsight include ScanInsight Pro. Both are operated by GOLDWAVE DYNAMICS LIMITED; selecting Pro changes feature entitlement but does not change the local-processing commitments described in this Policy.
Because local document content is not disclosed to us, we normally cannot see, recover, correct, export or delete it for a user.
3. Information processed and purposes
The app may process:
- files, scans, OCR results, metadata and security settings locally, to provide requested document-management functions;
- Google Play purchase and entitlement data: the app package name, product and base-plan identifiers, raw purchase token, purchase state, acknowledgement state, auto-renewal state, purchase time, expiry time and lifecycle information such as grace, pause, suspension, cancellation, revocation, refund or chargeback status, to complete, verify and restore purchases, maintain an accurate Pro entitlement, resolve billing status and prevent fraud or misuse;
- limited Google ML Kit diagnostic and usage information, including device and application information, a per-installation identifier, performance metrics, API configuration such as image format and resolution, feature input and output sizes, feature events and error codes, to support diagnostics and usage analytics. OCR input images and recognized text are processed on the device and are not sent to Google or Gold Wave Dynamics for OCR processing;
- the accepted Terms and Privacy Policy versions, document fingerprints, acceptance time and application version/build, stored only in the encrypted local database to record the user's legal acknowledgement; and
- information a person voluntarily includes in a support request, to answer the request, diagnose a problem and keep necessary business records.
ScanInsight does not receive payment-card details. Google processes payments as an independent service provider under its own terms and privacy documentation.
4. Legal bases
Where GDPR applies, processing needed to provide paid features, restore entitlements or respond to a service request is based on performance of a contract or steps requested before entering one. Security, fraud prevention and limited service administration may be based on our legitimate interests, provided those interests are not overridden by the individual's rights. Records required for accounting, tax, legal claims or regulatory compliance are processed to comply with legal obligations or establish, exercise or defend legal claims. Consent is used where applicable law specifically requires it and may be withdrawn for future processing.
5. Permissions and recipients
- Camera access is used only when the user chooses to scan.
- File access is initiated by the user to import, open, share or export.
- Biometric authentication, when enabled, is handled by the device operating system; we do not receive biometric templates.
- Internet and network-state access are used for Google Play purchase and entitlement functions and actions the user expressly initiates.
- When the user chooses Copy, the selected OCR or document text is placed on the device's system clipboard and marked as sensitive where the Android version supports that protection. Clipboard content is then controlled by Android and may be accessible to keyboards or other apps according to the device's operating-system rules. Users should avoid leaving sensitive information on the clipboard longer than necessary and may overwrite or clear it using their device controls.
Purchase and entitlement verification information is transmitted over an encrypted connection to Gold Wave Dynamics' production verification service hosted on Google Cloud. The service sends the package name and raw purchase token to the Google Play Developer API and receives the associated purchase history and lifecycle state. The raw token is used to perform verification and is not stored in the entitlement database. The database uses a SHA-256-derived token key and stores the authoritative product, base-plan, purchase, expiry, renewal, acknowledgement, revocation and entitlement state needed to maintain and restore Pro access. Ordinary network/security metadata such as IP address and request time may also be processed by infrastructure providers. Google Cloud acts as a processor for the verification service; Google processes Play purchases under its own terms and privacy documentation.
ScanInsight uses Google ML Kit for on-device OCR. Document images and recognized text are processed locally and are not uploaded to Google or Gold Wave Dynamics for OCR processing. The ML Kit SDK may automatically transmit the limited device, application, installation, configuration, performance, feature-event and error information described in Section 3 to Google for diagnostics and usage analytics. According to Google's ML Kit documentation, this information is encrypted in transit and is not transferred by ML Kit to third parties. ML Kit may also contact Google to obtain items such as bug fixes, updated models and hardware-accelerator compatibility information. Google processes this information under its own privacy documentation.
Private documents, OCR text, filenames, titles, tags, previews, searches, PINs, biometric information and encryption keys are not sent to the entitlement-verification service. A file is disclosed to another app or recipient only when the user invokes an open, share or export action. We do not disclose private document content or purchase data to advertisers or data brokers.
6. International transfers
The app does not transfer private document content to Gold Wave Dynamics. Google or another recipient selected by the user may process information outside the European Economic Area under its own arrangements. Where Gold Wave Dynamics makes a restricted transfer, we will use a lawful transfer mechanism and required safeguards.
7. Storage, retention and deletion
Local app data remains on the device. The standard Delete action marks a document as deleted, removes it from the active library and keeps its encrypted local files and related records in the on-device recycle bin so the user can restore it. Clearing app storage or uninstalling removes the app's local database, encryption material and vault data and may make documents permanently unrecoverable. Users must export or independently back up documents they wish to retain before clearing app data, uninstalling, resetting or replacing a device.
ScanInsight may create temporary working and cache files in the app's private storage while importing, previewing, editing or processing documents. These temporary files may contain decrypted document content. They remain within the app's private storage on the device and may be removed automatically or through the cleanup controls in Settings. Permanent document vault files and the local database are stored encrypted.
The local legal-acceptance history remains in encrypted app storage until app data is cleared or the app is uninstalled. The raw Google Play purchase token is used during verification and is not stored in the entitlement database. Its SHA-256-derived key and the related purchase and entitlement history are retained while needed to provide or restore the entitlement and afterwards only for applicable accounting, tax, fraud-prevention, security, dispute, legal-claim or statutory-limitation periods. Verification-service logs are retained only for operational security and troubleshooting under the configured Google Cloud retention period. Support correspondence is retained only as long as reasonably necessary for the request and related business or legal obligations. Records are then deleted or anonymised where appropriate.
8. Security
ScanInsight uses an encrypted local database, encrypted permanent document-vault storage and operating-system-protected key storage. Temporary working and cache files are protected by the operating system's app-private sandbox but are not represented as encrypted vault files. Access controls and device security remain important. No technical measure can guarantee absolute security or recovery following device loss, corruption, operating-system failure or user action.
9. Rights and complaints
Depending on applicable law, individuals may have rights of access, rectification, erasure, restriction, objection, portability and withdrawal of consent, and the right not to be subject to certain solely automated decisions. Requests, including requests concerning server-side purchase and entitlement records, may be sent to admin@goldwavedynamicslimited.com or to our postal address above. A request should identify the Google account used for the purchase and provide sufficient non-sensitive purchase information for us to locate the record; users must not email a full purchase token or payment-card details. We may need to verify identity and may retain information where the law permits or requires it. Erasing a server-side entitlement record does not cancel a Google Play purchase and may prevent server-side restoration or verification; subscriptions must be cancelled separately through Google Play.
An individual may complain to the Irish Data Protection Commission or another competent supervisory authority. The Irish Data Protection Commission can be contacted through its online contact form or at 6 Pembroke Row, Dublin 2, D02 X963, Ireland.
California privacy rights
Where the California Consumer Privacy Act, as amended (CCPA), applies, California residents may have the right to know and access the personal information covered by the CCPA that we collect, use or disclose; request deletion; request correction; opt out of the sale or sharing of personal information; limit certain uses or disclosures of sensitive personal information where the right applies; and receive equal service and pricing without unlawful discrimination for exercising CCPA rights. ScanInsight does not sell personal information or share it for cross-context behavioural advertising. Requests may be sent using the contact details in Section 1. We may verify the request and apply exceptions permitted by law. Because private document content remains on the device and is not received by Gold Wave Dynamics, we normally cannot access, correct or delete that local content on a user's behalf.
10. Children
ScanInsight is not directed to children under 13 and we do not knowingly collect their personal data through an account service. A parent or guardian who believes a child has sent personal information to support should contact us.
11. Changes
We may update this Policy when functionality, processing or legal requirements change. Material changes will be presented in the app before they take effect where required. ScanInsight records acknowledgement of the Policy; acknowledgement is not treated as GDPR consent where another lawful basis applies. The effective date identifies the current version.