Privacy Policy
Docborg — Document Scanner PDF
Published by Stackborg · Last updated 5 August 2026
Your scans never leave your phone.
Docborg has no server. There is no account to create, nothing to sign in to, and no copy of your documents anywhere but on your own device. If you turn off mobile data, every scanning, editing and exporting feature still works.
What we do collect is limited to what makes the app run and pays for it: crash reports, anonymous usage statistics, and the advertising identifiers our ad partners need. Nothing in that list contains your documents, the text inside them, their names, or anything you typed.
If you buy Docborg Pro, the ads and their identifiers stop entirely.
1. What stays on your device — always
The following never leaves your phone, is never uploaded, and is never visible to us or to anyone else:
- Your scans — every page, in the original photograph and the processed form
- Text recognised from your scans (OCR results)
- Document names, folder names, tags and notes
- Anything you search for inside the app
- Your PIN or recovery code, if you set an app or folder lock
- Signatures you draw or save
These are stored in the app's private storage, which the Android operating system keeps isolated from other apps. Uninstalling Docborg deletes all of it permanently.
We could not read your documents even if we were asked to. There is no copy to hand over.
2. What we collect, and why
2.1 Crash reports — Firebase Crashlytics
When the app crashes, we receive a technical report: the line of code that failed, your device model, the Android version, and how much memory was free.
A crash report never contains your document names, recognised text, file paths, folder or tag names, search queries, or anything you typed. We strip these deliberately, not incidentally.
Why: an app that crashes on a phone we have never seen is an app we cannot fix without this.
2.2 Usage statistics — Firebase Analytics
We record which screens are opened and which features are used — for example, "a document was exported" — as anonymous counts. We do not record what was exported.
2.3 Advertising — Google AdMob and Meta Audience Network
The free version of Docborg shows ads. To do that, these networks receive:
- Your device's advertising ID (a resettable identifier — see section 6)
- Your approximate location, derived from your IP address, usually no more precise than the city
- Basic device information (model, Android version, language, screen size)
We do not request or hold location permission. The approximate location comes from the ad networks reading the IP address of your connection, which every internet request carries. We are naming it here because Google Play holds us responsible for what the software we include does, and we agree with that rule.
Docborg Pro removes ads completely, and with them this entire section.
2.4 Purchases — Google Play Billing
If you subscribe or buy the lifetime unlock, Google Play processes the payment and tells the app whether the purchase is valid.
We never see your card number, billing address or full name. Google shows us an anonymised order token, nothing else.
2.5 Configuration — Firebase Remote Config
The app periodically fetches a small settings file that lets us change things like how often ads appear, without shipping an update. This is a download, not an upload. No information about you is sent to request it.
3. Who we share data with
Only the four services above, and only the data described beside each:
| Service | Operated by | What they receive | Their policy |
|---|---|---|---|
| Firebase (Crashlytics, Analytics, Remote Config) | Google LLC | Crash reports, anonymous usage counts, device ID | Link |
| Google AdMob | Google LLC | Advertising ID, approximate location, device info | Link |
| Meta Audience Network | Meta Platforms, Inc. | Advertising ID, approximate location, device info | Link |
| Google Play Billing | Google LLC | Purchase validation | Link |
We do not sell your data. We have never sold data. There is nothing here that would be worth buying.
4. In the European Economic Area, the UK and Switzerland
Before any personalised ad is shown, Docborg presents a consent form built on Google's User Messaging Platform, as the GDPR and the ePrivacy Directive require.
You may refuse. If you do, you will still see ads, but they will be non-personalised — chosen without an advertising identifier. Refusing costs you no feature of the app. You can change your answer at any time in Settings → Privacy → Ad privacy options.
Our legal basis for the limited processing we do:
- Consent (Art. 6(1)(a)) — personalised advertising
- Legitimate interest (Art. 6(1)(f)) — crash reporting and anonymous usage statistics, so the app can be kept working
5. Children
Docborg is intended for people aged 18 and over. It is not directed at children, we do not knowingly collect information from children, and the app carries no content designed to appeal to them.
6. Your choices and rights
| What you want | How |
|---|---|
| Delete everything | Uninstall the app. Everything Docborg stores is inside its own folder and goes with it. See our data deletion page. |
| Delete some documents | Delete them in the app, then empty the bin (Settings → Storage). |
| Stop personalised ads | Settings → Privacy → Ad privacy options; or Android Settings → Privacy → Ads → Delete advertising ID. |
| Stop ads entirely | Buy Docborg Pro. |
| Stop crash and usage reporting | Settings → Privacy → turn off the diagnostics switch. |
| Ask what we hold about you | Email legal@stackborg.com. The honest answer is almost certainly "nothing that identifies you", and we will say so plainly. |
Under the GDPR you also have rights of access, rectification, erasure, restriction, portability and objection, and the right to complain to your national supervisory authority.
7. Retention
- Your documents — until you delete them or uninstall the app. We keep no copy and therefore have no retention period of our own.
- Crash reports — Firebase's default, 90 days.
- Usage statistics — Firebase's default, 14 months, in aggregate form.
- Advertising identifiers — held by the ad networks under their own policies, linked above.
8. Security
Your files sit in Android's app-private storage, which other apps cannot read. If you enable the app lock or a locked folder, the PIN is stored only as a cryptographic hash — the original is never written down anywhere.
That lock is real. Without your recovery code, we cannot open it for you. We would rather tell you that plainly than pretend otherwise.
All network traffic — the little there is — uses HTTPS.
9. Changes
If this policy changes materially, the new version will appear here with a new date, and the app will tell you about it before the change takes effect.
10. Contact
Stackborg
Email: legal@stackborg.com
We read every message.