01 / SUMMARY
Your documents stay on your device by default.
SnapFolio stores documents in app-private storage on your device by default. We do not operate a SnapFolio document server, sell personal information, or include advertising. Documents leave app-private storage only when you direct the app to share, email, export, or back them up.
Google ML Kit processes document content on device, but its SDKs send limited diagnostics and usage information to Google as described below.
02 / DATA THE APP HANDLES
SnapFolio handles information needed for its tools.
This may include camera images, imported images, PDFs, text files, and office-document previews; file names, folders, tags, favorites, pins, archive/trash state, and document metadata; OCR text, barcode values, signatures, annotations, and scan-analysis results; scan, naming, privacy, app-lock, email, and backup settings; and a backup-folder URI and backup status when backup is enabled.
The app may also handle support and bug-report correspondence, including what you type and draft fields such as app version, Android release/API level, device manufacturer, and model; Google Play product, purchase, and entitlement status; reviewer credentials entered for App Review Access and temporary review-access grant metadata; and sanitized crash diagnostics stored locally.
Imported images may retain EXIF data such as GPS coordinates, device details, and capture timestamps. These categories may contain sensitive personal information if it appears in a document you choose to process.
03 / CAMERA, FILES, AND ML KIT
Scanning and text recognition happen on your device.
We process information to provide scanning, organization, OCR, barcode detection, editing, export, sharing, App Lock, purchase restoration, optional backup/restore, and authentication for authorized app reviewers. Document content is not used for advertising or sold.
SnapFolio requests Camera permission for its manual capture screen. Captured pages are stored in app-private storage and may be processed by Google ML Kit for OCR and barcode detection. Google states that ML Kit processes input images, video, and text, along with resulting outputs, on device and does not send that content to Google servers.
ML Kit may contact Google to obtain models, fixes, and hardware-compatibility information. It also collects device and app information, device or per-installation identifiers, performance metrics, API configuration, input/output sizes, feature versions, event types, and error codes for diagnostics, usage analytics, maintenance, improvement, and abuse detection. Google says this information is encrypted in transit and is not shared by ML Kit with third parties. Google handles it under its own terms.
Imports, exports, sharing, and backup locations use Android system pickers or share controls. SnapFolio receives access only to the items or folders you select, for the operations you request.
References: Google ML Kit Terms and ML Kit Android data disclosure.
04 / LOCAL DIAGNOSTICS
Crash reports stay local unless you share them.
SnapFolio stores a maximum of 50 sanitized diagnostic reports in app-private storage. Reports may contain an event name, severity, exception class, app stack location, fingerprint, and short sanitized context. They are designed not to contain document content, OCR text, file paths, email addresses, biometric data, backup-folder URIs, or purchase tokens.
Reports are not uploaded automatically. They leave your device only if you explicitly share them for support.
05 / BACKUP AND RESTORE
Backups go to the storage location you select.
Backup is optional. When enabled, SnapFolio copies library files, saved signatures, and selected library settings into a SnapFolio folder within the Android storage location you choose. Saved email addresses, App Lock and Private View settings, backup-connection details, and cached purchase entitlements are excluded. Automatic backup may run periodically and after document changes while enabled.
The selected storage provider receives and stores backup copies under its own terms and privacy policy. Restore reads the selected backup and copies permitted data back into SnapFolio. Disconnecting backup stops future synchronization but does not delete existing copies; delete those through the selected provider.
New backup generations encrypt document and settings payloads and authenticate the manifest and generation pointers with a user-visible recovery key. SnapFolio stores the key locally; you can view or copy it from Settings and must keep it safe to restore encrypted backups. Backups created before this protection may remain in the legacy format and are readable only as legacy backups. Providers can still see backup file and folder names and related storage metadata; encrypted manifest contents include file sizes, modification timestamps, and content hashes. App Lock protects the SnapFolio interface, not provider-held copies.
06 / BIOMETRICS AND APP LOCK
Your device verifies biometrics or its PIN.
Android performs biometric or device-credential verification. SnapFolio receives only the success, failure, or error result—not a fingerprint, face image, biometric template, or device PIN.
App Lock restricts access through the app interface. It does not mean every stored or backed-up file is independently encrypted by SnapFolio.
07 / PURCHASES
Google Play handles purchase payments.
Google Play processes subscription and one-time purchase payments. SnapFolio receives product, purchase, acknowledgement, and entitlement status needed to offer, unlock, restore, and manage Pro access. Google controls payment records under its own terms and privacy policy. SnapFolio does not receive full payment-card details.
SnapFolio uses Google Play Billing directly to query product and purchase status and acknowledge purchases. Purchase tokens are handled locally by the app for this Play Billing flow and are not sent to a SnapFolio server. SnapFolio does not operate a purchase-verification backend.
The local entitlement cache is protected from casual editing by an app-specific Android Keystore key. Purchase confirmation can remain pending while Google Play acknowledgement is retried and is reconciled with Google Play on refresh.
08 / APP REVIEW ACCESS
Reviewer sign-in is temporary and limited.
App Review Access is restricted to authorized reviewers using developer-issued credentials; it does not create a personal SnapFolio account. When you select Unlock, SnapFolio sends the entered username and password over HTTPS to a developer-operated authentication service hosted on Cloudflare Workers to check authorization. This request does not include documents, OCR text, or Google Play purchase tokens.
SnapFolio keeps credentials temporarily in memory and does not save them to disk. If authorized, the app stores an encrypted temporary access grant containing issue and expiry times and a device boot counter in app-private storage. The grant is valid for no more than one hour, and restarting the app does not extend it. Expired or invalid grants are ignored, and the app attempts to remove them when checked. Clearing app storage or uninstalling removes the local grant.
Cloudflare may process connection information, including IP addresses and request metadata, to deliver and secure the service. Related service records are retained under Cloudflare’s applicable policies. See the Cloudflare Privacy Policy. Contact us about privacy or deletion requests concerning data sent to the review-access service.
09 / SHARING, EMAIL, EXPORT, AND LINKS
You choose where shared information goes.
When you share, email, export, open a detected link, or save a document elsewhere, the selected content is sent to the app, storage location, or service you choose. That recipient independently controls its copy. Review the destination before sending sensitive documents.
When you choose Contact or Report a Bug, SnapFolio opens a draft addressed to the developer. Bug-report drafts include the app version, Android release/API level, device manufacturer and model, along with the questions or description you enter. Your email app controls whether the draft is sent. Sent support correspondence is retained in the developer’s email account only as long as reasonably necessary to respond, document, or protect against the reported issue, then deleted unless law requires longer retention.
Copying OCR, barcode, Wi-Fi, contact, or document text places it in Android’s system clipboard outside SnapFolio’s app-private storage. SnapFolio marks its clipboard entry sensitive on Android 13 and later and clears or empties its own entry after one minute when it is still current. Android and other apps control clipboard previews, history, and later retention.
Imported images may retain EXIF metadata, including location, device, and capture-time fields. Original PDF and Office imports may retain document properties such as author, company, timestamps, and hidden properties, as well as embedded attachments or objects. Review or remove metadata before sharing or backing up when it could be sensitive.
10 / RETENTION AND DELETION
Copies outside the app are managed separately.
- Local documents and metadata: retained until you delete them, clear app storage, or uninstall. Items in in-app Trash remain until permanently deleted.
- Deletion: SnapFolio uses ordinary Android/filesystem deletion and does not promise forensic secure erasure or guaranteed overwriting. Recoverable remnants may remain depending on the device and filesystem.
- Settings and saved email: retained in app-private preferences until changed, cleared, or the app is uninstalled.
- Decrypted and editing caches: temporary files use app-private cache storage. Cleanup is best effort after sensitive flows, during a cold launch, and when the app finishes normally. Process death or task eviction can defer cleanup until the next launch or Android cache eviction.
- Share caches: temporary share copies are capped at 50 MB and expire after one hour during normal cleanup. SnapFolio also makes a best-effort cleanup on a cold launch and when it finishes normally; process death or task eviction can defer cleanup.
- Local crash diagnostics: limited to the latest 50 reports and removed when app storage is cleared or the app is uninstalled.
- Review access: app credentials are not saved to disk. Local encrypted grants last no more than one hour. Cloudflare service records follow its applicable policies.
- Backups and shared/exported copies: retained by the selected provider or recipient until you delete them there. Deleting or uninstalling SnapFolio does not delete them.
- Google Play and ML Kit records: retained by Google under its applicable policies.
- Support correspondence: retained only as long as reasonably necessary to answer, document, or protect against the reported issue, unless law requires longer retention.
SnapFolio has no personal user-account creation or developer-operated document server, so there is no personal SnapFolio account to delete. Developer-issued reviewer credentials are used only for App Review Access. To delete local data, use in-app deletion, Android’s Clear storage control, or uninstall. For data held by another provider, contact that provider. Contact us to request deletion of support correspondence or data sent to the review-access service.
11 / SECURITY
App protections secure the interface and data flows.
We use Android credential-protected app-private storage, the Android application sandbox, scoped system pickers, restricted URI grants, screenshot blocking on SnapFolio’s own window while App Lock or Private View is enabled, local diagnostic sanitization, backup integrity checks, and encrypted SDK/service transport where provided.
Activities owned by other apps, including an external scanner opened by SnapFolio, control their own screenshot behavior. App Lock and Private View restrict access through SnapFolio but do not add a separate encryption layer to every document or create an encrypted Vault.
No storage or transmission method is guaranteed secure. Device security and the security of selected backup and sharing providers remain important, especially for identity, medical, financial, tax, or legal documents.
12 / CHILDREN
SnapFolio is a general-audience productivity app.
SnapFolio is not directed to children under 13. We do not knowingly request personal information directly from children. A parent or guardian who believes a child sent information directly to the developer may contact us for deletion.
13 / YOUR CHOICES AND RIGHTS
You control what you import and share.
You control document imports, sharing/export destinations, backup connection, saved email address, and App Lock settings. Depending on your location, you may have rights concerning personal data sent directly to the developer, including rights to access, correct, delete, object to, or restrict processing, and to complain to a privacy regulator. Contact us to exercise an applicable right.
This does not override rights you must exercise directly with Google or a selected storage or sharing provider.
14 / INTERNATIONAL PROCESSING
Selected providers may process data abroad.
Google, Cloudflare, and storage, email, or sharing providers you select may process information in countries other than yours under their own terms and transfer mechanisms. The review-access authentication service is hosted on Cloudflare Workers. SnapFolio does not operate its own document-processing or purchase-verification server.
15 / CHANGES
We update this notice when practices change.
We may update this policy when app functionality or legal requirements change. The effective date above identifies the current version. Materially different data handling will be disclosed before or when it takes effect as required.
16 / CONTACT
Contact H/Studio with privacy questions.
SnapFolio is provided by Hector Cruz. For privacy questions or requests, email [email protected] or [email protected].