Privacy Policy
Last updated 20 August 2026
Your scans never leave your device. Snapleaf has no account to create, no cloud library and no upload. Document images, PDFs and file names stay in the app's own storage on your iPhone until you delete them or share them yourself.
1. Who we are
Snapleaf is published by Tofesoft. For anything in this policy, including requests about your data, write to tofesoftware@gmail.com. Tofesoft is the data controller for the limited data described below.
2. What stays on your device
Everything you scan is processed and stored locally:
- captured page images and the edits you make to them (crop, rotation, filter);
- the PDF, JPEG or PNG files Snapleaf generates when you export;
- file names, page order, scan type and dates;
- your settings, including retention, App Lock, export preferences and language.
None of this is uploaded, backed up to our servers, or transmitted to us or to anyone else. Detection, perspective correction and filtering all run on the device. Snapleaf has no OCR and does not read the text of your documents.
Scans leave the device only when you send them: tapping Share, saving to Files or saving to Photos hands the file to iOS and to whatever app or service you choose. What happens after that is governed by that service, not by Snapleaf.
3. Camera and permissions
Snapleaf asks for camera access the first time you start a scan. The camera feed is used to detect a document and take the picture you asked for, nothing else. It is never recorded or streamed anywhere.
Snapleaf does not ask for photo library access: saving to Photos goes through the system share sheet, which does the writing on your behalf. It does not ask for contacts, location, microphone or notifications.
4. What we do collect
Snapleaf collects a small amount of technical and usage data so we can keep it working, fix crashes and understand which features are used. It is never joined to your identity, and it never contains a document, a page image, a file name or a file path.
| Data | Why | Processor |
|---|---|---|
| Anonymous app identifier | Distinguishes one installation from another so free-scan usage and purchases can be counted. Created silently; not linked to an email, a phone number or an Apple Account. | Firebase Authentication, RevenueCat |
| Usage events | Which scan mode was chosen, that a scan started or finished, which export format and quality were selected, that the paywall was seen. Values are fixed categories and counts in ranges — the app is built so free text cannot be sent. | Firebase Analytics |
| Device and app technical data | Device model, iOS version, app version, language and coarse region, so we can tell an iPhone-specific problem from a general one. | Firebase Analytics, Crashlytics |
| Crash diagnostics | Stack traces and technical state at the moment of a crash. No scan content is ever attached. | Firebase Crashlytics |
| Anti-abuse signals | An Apple-issued attestation that the request comes from a genuine, unmodified copy of Snapleaf, so free scans cannot be farmed automatically. | Firebase App Check, Apple App Attest / DeviceCheck |
| Purchase state | Whether a subscription or the lifetime purchase is active, which product it is, and the App Store receipt that proves it. We never see your payment card, billing address or Apple Account. | RevenueCat, Apple |
| Configuration requests | Fetching remote settings such as the minimum supported version returns configuration to the app; the request itself carries no personal data. | Firebase Remote Config |
5. No tracking, no advertising
Snapleaf shows no ads, contains no advertising or attribution SDK, and does not track you across other companies' apps or websites. It never asks for permission to track, because it never does. We do not sell or share personal information, and we have no reason to: we do not have any.
6. Purchases
All payments are handled by Apple through the App Store. Snapleaf receives only the result — that an entitlement is active — through RevenueCat, which stores the App Store receipt and the anonymous app identifier. Apple's own privacy policy governs the payment itself.
7. How long data is kept
- Your scans: for as long as you keep them. The retention setting (7, 30 or 90 days, or Never) moves scans to Recently Deleted automatically, and anything in Recently Deleted is erased permanently after 7 days. Deleting the app removes all of it at once.
- Usage events: retained by Google for up to 14 months.
- Crash reports: retained by Google for up to 90 days.
- Purchase state: kept for the life of the purchase, because a lifetime purchase has to be restorable years later.
8. Where data is processed
Our processors — Google (Firebase), RevenueCat and Apple — operate servers in the United States and elsewhere, so the limited data in section 4 may be processed outside your country. Those transfers rely on the standard contractual clauses and equivalent safeguards published by each provider.
9. Your rights
Depending on where you live, you may have the right to access, correct, delete, export or object to the processing of your personal data, and to complain to your local data protection authority. In the EU/EEA and the UK this comes from the GDPR; in Türkiye from KVKK; in California from the CCPA.
Two practical notes. First, the fastest exercise of your rights is on the device: deleting the app removes every scan and every local setting immediately and permanently. Second, the data in section 4 is not linked to your name or email, so we usually cannot find "your" records without an identifier from you. Write to tofesoftware@gmail.com and we will help with what we can identify.
Our legal basis for the data in section 4 is our legitimate interest in keeping Snapleaf stable, secure and worth improving, and, for purchases, performance of our agreement with you.
10. Children
Snapleaf is not directed at children under 13 and we do not knowingly collect personal data from them. There is nothing in the app that asks a child for information.
11. Security
Scans live inside the app's own container, protected by iOS file protection and your device passcode. You can add App Lock in Settings, which requires Face ID, Touch ID or your passcode before the app opens. All network traffic uses HTTPS. Snapleaf performs no encryption of its own and exported PDFs are not password protected.
12. Changes
If this policy changes we will update the date at the top of this page and, when the change is significant, say so in the app's release notes. The current version always lives at this address.
13. Contact
Tofesoft — tofesoftware@gmail.com