Privacy Policy for ContactScanner AI according to GDPR
Effective from: August 16, 2025 · Last updated: September 2, 2026
Data Controller:
Baudis AI UG (haftungsbeschränkt)
Paul-Zobel-Straße 8d, 10367 Berlin, Germany
Email: info@contactscanner.ai
Product: "ContactScanner AI" mobile app
first_open, paywall_view, begin_checkout, purchase, quota_exceeded_paywall, and scan_completed. Purchase events may include product ID, transaction/purchase identifier, price, and currency. These events do not contain scanned images or extracted contact data.oppref), a pseudonymous browser reference, the visited page path, App Store click, timestamp, and technical data such as IP address and user agent. Scanned images and contact data are not included.We do not display third-party ads in the app, do not use a crash backend, and do not use push notifications. To measure our own Apple Ads campaigns, we use Apple's AdServices/StoreKit interfaces and our own backend reporting. For our own ChatGPT ads, we use the OpenAI Measurement Pixel and OpenAI Conversions API on the website after you consent to measure page and App Store clicks. In the iOS app, we are staging AppsFlyer Strict for install events and StoreKit-verified purchase/subscription events from our own ChatGPT Ads campaigns. Data is shared with OpenAI only where permitted by the iOS tracking-consent status and AppsFlyer Advanced Privacy. In the Android app, we use Firebase/Google Analytics only to measure app usage, installs, paywall/checkout/purchase events, and the performance of our own Google Ads campaigns.
When a company license is purchased or managed on our website, we process the company name, billing email, purchaser name, billing address, tax ID where supplied, selected plan and device quantity, and Stripe customer, checkout, invoice, payment, and subscription identifiers and status. Stripe processes the payment details; we do not receive complete card or bank account numbers. We store the billing-to-license assignment, company code, licensed devices, and one-time billing-link tokens in Upstash and use Resend to deliver the code and requested billing links. If you expressly opt in during checkout, we also use the billing email to send one reminder containing a secure recovery link when checkout is not completed. Processing is necessary to enter into and perform the license agreement, prevent abuse, and meet statutory accounting obligations. Billing records are retained for applicable legal periods; access and token data are deleted or expire when no longer required.
(without permanent server storage of your images)
Note on Data Transfers to Third Countries:
Depending on the provider and processing region, data may be transferred outside the EEA (for example, to the United States). Where required, we rely on adequacy decisions, including an applicable EU-US Data Privacy Framework certification, or EU Standard Contractual Clauses. Information about the safeguards used is available on request at the email address below.
Legal bases at a glance: We provide the core feature, optional CRM sync, and company licences to take steps before entering into and to perform a contract (Art. 6(1)(b) GDPR). Security, abuse prevention, and necessary operational logs rely on our legitimate interest in operating a secure and commercially viable service (Art. 6(1)(f) GDPR). Support is processed under Art. 6(1)(b) or (f), depending on the request, and legally required billing records under Art. 6(1)(c). Consent-based analytics and advertising measurement rely on Art. 6(1)(a) GDPR and applicable terminal-device privacy law. Consent may be withdrawn at any time with future effect.
If you upload images or contact data relating to other people, you or your organization are responsible for having an appropriate legal basis and providing any required privacy information.
We do not sell this data or display third-party ads in the app. We use measurement data only to analyze our app and our own campaigns as described above.
rl:<ip>:<minute>: 60 secondscap:<YYYY-MM> (month): 40 dayscap:<YYYY-MM-DD> (day): 2 daysdev:<device>:<YYYY-MM>: 40 daysfree:<client>: no automatic deletion (unlimited), until we delete on request.No images/result JSONs are permanently stored on the proxy itself.
We may update this privacy policy from time to time when features, legal situation, or providers change. The validity stated above is decisive. Material changes will be announced within the app.
Baudis AI UG (haftungsbeschränkt)
Paul-Zobel-Straße 8d, 10367 Berlin, Germany
Email: info@contactscanner.ai