Legal Information

Privacy Policy

Privacy Policy for ContactScanner AI according to GDPR

Sections of the ContactScanner AI privacy policy

Effective from: August 16, 2025 · Last updated: September 2, 2026

Data Controller:

Baudis AI UG (haftungsbeschränkt)
Paul-Zobel-Straße 8d, 10367 Berlin, Germany

Email: info@contactscanner.ai

Product: "ContactScanner AI" mobile app

1. What Data Does the App Process?

1.1 Content You Actively Process

  • Images/photos (e.g., cards, email signatures, badges, posters, screens, whiteboards) that you use in the app to extract contact data.
  • Recognized/extracted contact data according to schema (e.g., first/last name, company, job title, phone/fax/mobile, email, website, street, postal code, city, country).

1.2 App Technology & Pseudonymous Identifiers

  • Device ID (provided by the device) and Client ID (locally generated, persistent key in the keychain).
  • For Apple Ads performance measurement: a locally generated install ID/app account token, Apple Ads attribution data (e.g., campaign, ad group, keyword, country/region, conversion type), and StoreKit purchase data (e.g., product ID, transaction ID, purchase date, price, currency, and storefront country).
  • For the staged measurement of our own ChatGPT ads in the iOS app, we use AppsFlyer Strict. AppsFlyer SDK measurement is off by default and starts only if you explicitly enable it using the measurement toggle in the app settings. You can withdraw your consent there at any time; doing so stops AppsFlyer SDK measurement, while Apple's aggregated measurement through SKAdNetwork/AdAttributionKit remains active. AppsFlyer then processes install events and purchase/subscription events from StoreKit-verified initial purchases. The StoreKit transaction is verified locally; its transaction ID is used only for on-device deduplication and is not sent to AppsFlyer. We send AppsFlyer the event type, product ID and, where available, revenue and currency. For this integration, we do not access IDFA or IDFV, set an AppsFlyer Customer User ID, or pass our own locally generated ContactScanner install ID. AppsFlyer may generate its own pseudonymous SDK identifier to provide the service. Scanned images and extracted contact data are not transmitted.
  • For Android app analytics and Google Ads performance measurement: Firebase/Google Analytics app instance ID, technical device and app information, Advertising ID or Google advertising services identifiers where provided by the device, and events such as first_open, paywall_view, begin_checkout, purchase, quota_exceeded_paywall, and scan_completed. Purchase events may include product ID, transaction/purchase identifier, price, and currency. These events do not contain scanned images or extracted contact data.
  • For consent-based measurement of our own ChatGPT ads on this website: the OpenAI click reference (oppref), a pseudonymous browser reference, the visited page path, App Store click, timestamp, and technical data such as IP address and user agent. Scanned images and contact data are not included.
  • These are sent as headers to the proxy to prevent abuse (rate limiting/quotas).
  • Subscription status (as "X-Sub" flag) for enforcing free quotas.

1.3 No Third-Party Ads, Limited Campaign Measurement

We do not display third-party ads in the app, do not use a crash backend, and do not use push notifications. To measure our own Apple Ads campaigns, we use Apple's AdServices/StoreKit interfaces and our own backend reporting. For our own ChatGPT ads, we use the OpenAI Measurement Pixel and OpenAI Conversions API on the website after you consent to measure page and App Store clicks. In the iOS app, we are staging AppsFlyer Strict for install events and StoreKit-verified purchase/subscription events from our own ChatGPT Ads campaigns. Data is shared with OpenAI only where permitted by the iOS tracking-consent status and AppsFlyer Advanced Privacy. In the Android app, we use Firebase/Google Analytics only to measure app usage, installs, paywall/checkout/purchase events, and the performance of our own Google Ads campaigns.

1.4 Support Contact Form

  • When you use the support form on our website, we process the information you enter: name, email address (optional), category, subject, and issue description.
  • Required fields for handling your request are name, subject, and description. The email address is optional, but required if you want to receive a reply by email.

1.5 QR-Code Generator on the Website

  • When you use the QR-Code generator on our website, you may voluntarily enter contact information (e.g., name, company, email, phone number, address, website, social profiles) into the form fields.
  • The vCard content and QR-Code are generated locally in your browser (client-side).
  • Contact data entered into the generator are not automatically stored by us on our servers.
  • When visiting the website, technically required connection data (e.g., IP address, timestamp, user agent) are processed by the hosting provider.

1.6 Company Licenses and Billing

When a company license is purchased or managed on our website, we process the company name, billing email, purchaser name, billing address, tax ID where supplied, selected plan and device quantity, and Stripe customer, checkout, invoice, payment, and subscription identifiers and status. Stripe processes the payment details; we do not receive complete card or bank account numbers. We store the billing-to-license assignment, company code, licensed devices, and one-time billing-link tokens in Upstash and use Resend to deliver the code and requested billing links. If you expressly opt in during checkout, we also use the billing email to send one reminder containing a secure recovery link when checkout is not completed. Processing is necessary to enter into and perform the license agreement, prevent abuse, and meet statutory accounting obligations. Billing records are retained for applicable legal periods; access and token data are deleted or expire when no longer required.

2. Where Are Data Stored/Processed?

2.1 On Your Device (Local)

  • Pending Scans: JPEG + thumbnail, Base64 in JSON are stored locally when no internet is available.
  • History: Fully processed images (original + edited version) are stored locally in the documents area.
  • Protection: iOS NSFileProtection is enabled (files are device-dependently protected).
  • Local Deletion: There is a setting in the app to delete the scan history.

2.2 Processing via Our Infrastructure

(without permanent server storage of your images)

  • The app sends image data to our edge proxy (Vercel). It is normally forwarded to the OpenAI API for extraction. If OpenAI times out or encounters a temporary server error, Google Gemini may be used as a technical fallback through Vercel AI Gateway.
  • We do not permanently store images or result JSONs on the proxy.
  • For abuse protection/quotas, we use Upstash KV (see retention periods).

2.3 External Recipients/Data Processing

  • OpenAI (API, Vision Model): receives the image data you send exclusively for the purpose of extracting contact data. API calls are made with parameter store: false (no training use commissioned by us).
  • Vercel (Edge Proxy): forwards the request/response stream.
  • Vercel AI Gateway and Google Gemini (fallback): may process the submitted image and extraction instruction if the primary OpenAI processing is unavailable. We instruct the gateway not to permit model training with these requests.
  • Upstash (KV): stores rate-limit/quota data and, when you connect a CRM, connection metadata, a hashed app session token, encrypted credentials for OAuth connections, and pseudonymous consent records (see 4.).
  • Salesforce, HubSpot, or Zoho: receives the contact data that you choose to synchronize. The selected provider processes that data under your account and its own terms.
  • Apple (App Store, StoreKit, Apple Ads/AdServices): provides purchase and subscription processing and Apple Ads attribution information so we can roughly connect installs and purchases to campaigns, ad groups, and keywords.
  • AppsFlyer (iOS): acts as our service provider for the staged measurement of our own ChatGPT Ads campaigns and processes the install, purchase/subscription, campaign, and attribution data described above.
  • Google/Firebase (Google Analytics for Firebase, Google Ads, Google Play): processes Android app usage, install, purchase/subscription, and attribution events for app analytics, conversion measurement, and optimization of our own campaigns. Google may process technical device information, app instance identifiers, and Google advertising identifiers where provided by the device and Google services.
  • OpenAI (ChatGPT Ads): after you consent, processes pseudonymous website and App Store click events through the Measurement Pixel and Conversions API to attribute visits from our own ChatGPT ads. Where permitted by the iOS tracking-consent status and AppsFlyer Advanced Privacy, OpenAI also receives AppsFlyer postbacks for attributed installs and verified purchase/subscription events. No AppsFlyer data about people using iOS 14.5 or later who have not consented is shared with OpenAI as an advertising partner.

Note on Data Transfers to Third Countries:
Depending on the provider and processing region, data may be transferred outside the EEA (for example, to the United States). Where required, we rely on adequacy decisions, including an applicable EU-US Data Privacy Framework certification, or EU Standard Contractual Clauses. Information about the safeguards used is available on request at the email address below.

3. What Do We Use the Data For? (Purposes and Legal Bases)

  • Providing Core Functionality: Reading contact data from your images and displaying the result in the app; optional saving to your device contacts.
  • Optional CRM synchronization: Connecting your Salesforce, HubSpot, or Zoho account and transmitting the contact fields selected for synchronization.
  • Abuse/Fraud Protection & Quotas: Enforcing rate limiting/quotas (IP-minute, device-month, daily/monthly caps, free quota per client ID).
  • Offline Usage: Temporary local buffering (pending queue) until internet is available again.
  • Support Handling: Processing submitted support requests and (if provided) replying by email.
  • Own campaign measurement and product growth: Evaluating which Apple Ads, Google Ads, and ChatGPT Ads campaigns, ad groups, keywords, countries, and ads lead to installs, paywall views, checkouts, and purchases. We use this reporting to optimize budgets, bids, keywords, countries, and ads for our own app. Where access to device identifiers or consent is required, this processing takes place only on the basis of your consent; non-essential measurement is not based on legitimate interests where consent is legally required.

Legal bases at a glance: We provide the core feature, optional CRM sync, and company licences to take steps before entering into and to perform a contract (Art. 6(1)(b) GDPR). Security, abuse prevention, and necessary operational logs rely on our legitimate interest in operating a secure and commercially viable service (Art. 6(1)(f) GDPR). Support is processed under Art. 6(1)(b) or (f), depending on the request, and legally required billing records under Art. 6(1)(c). Consent-based analytics and advertising measurement rely on Art. 6(1)(a) GDPR and applicable terminal-device privacy law. Consent may be withdrawn at any time with future effect.

If you upload images or contact data relating to other people, you or your organization are responsible for having an appropriate legal basis and providing any required privacy information.

We do not sell this data or display third-party ads in the app. We use measurement data only to analyze our app and our own campaigns as described above.

4. Retention Periods

4.1 Locally on Device

  • History: remains on your device until you delete it in the app (or uninstall the app).
  • Pending Queue: remains local until upload is successful (no automatic expiration time).

4.2 Upstash KV

  • rl:<ip>:<minute>: 60 seconds
  • cap:<YYYY-MM> (month): 40 days
  • cap:<YYYY-MM-DD> (day): 2 days
  • dev:<device>:<YYYY-MM>: 40 days
  • free:<client>: no automatic deletion (unlimited), until we delete on request.
  • CRM connection: connection metadata, a hashed app session token, and encrypted access/refresh tokens for OAuth connections are stored with a 365-day expiration. The expiration of a connection record restarts when that record is refreshed. Associated connection data is deleted when you disconnect the CRM or request deletion.
  • CRM consent records: pseudonymous records of connection, scope, policy version, and revocation are retained for up to 730 days for compliance evidence.

No images/result JSONs are permanently stored on the proxy itself.

4.3 Apple Ads Attribution and Purchase Events

  • We store pseudonymous Apple Ads install and purchase events in Upstash KV for up to 730 days so the campaign automation can understand trends, recurring purchases, and later optimization decisions.
  • These records do not contain scanned images or extracted contact data.

4.4 Firebase/Google Analytics and Google Ads (Android)

  • Android app usage, install, and purchase events are stored in Firebase/Google Analytics and Google Ads according to the retention and product settings configured there.
  • These events are used for aggregated app and campaign analysis and do not contain scanned images or extracted contact data.
  • Locally stored Google Analytics data can be reset by deleting the app data or uninstalling the app. For further access or deletion requests, you can contact us using the email address below.

4.5 AppsFlyer and ChatGPT Ads Measurement (iOS)

  • AppsFlyer processes iOS install events and StoreKit-verified events from initial subscriptions and one-time purchases, including event type, product ID and, where available, revenue and currency. The StoreKit transaction ID remains on the device solely for deduplication.
  • Our integration does not access IDFA or IDFV, set a Customer User ID, or transmit our own ContactScanner install ID, scanned images, or extracted contact data. AppsFlyer may generate its own pseudonymous SDK identifier and processes measurement data under the retention settings configured for the service.
  • AppsFlyer postbacks to OpenAI are sent only where permitted by the iOS tracking-consent status and AppsFlyer Advanced Privacy. For people using iOS 14.5 or later who have not consented, AppsFlyer does not share postbacks or event data with OpenAI.

4.6 ChatGPT Ads Measurement (Website)

  • The OpenAI Measurement Pixel loads only after your explicit consent. It stores the OpenAI click reference in a first-party cookie and measures page views and clicks to the iOS App Store.
  • For the same App Store click, our server may send an event with the identical event ID to the OpenAI Conversions API so duplicate events can be detected. API credentials remain server-side.
  • Rejecting prevents measurement and removes known OpenAI measurement cookies. You can change your choice at any time through “Measurement settings” in the footer.

4.7 Support Requests (Website)

  • Data from the contact form are transmitted to our team as support emails and stored there for request handling.
  • If you provide a valid email address, you will additionally receive an automatic confirmation of receipt.
  • The retention period depends on the processing purpose and, where applicable, statutory retention obligations.

5. Recipients/Categories

  • OpenAI – API processing of images you send for text recognition/extraction. After you consent, OpenAI also provides the Measurement Pixel and Conversions API used to measure our own ChatGPT ads and receives permitted AppsFlyer postbacks from the iOS app.
  • Vercel – Edge proxy that forwards the request to OpenAI and returns the response to the app, and AI Gateway for the technical Gemini fallback.
  • Google Gemini – Occasional processing of submitted images when the primary OpenAI processing is unavailable because of a timeout or server error.
  • Upstash – Key-value store for rate limiting/quota data, CRM connection metadata, a hashed app session token, encrypted CRM OAuth credentials, and pseudonymous consent records.
  • Salesforce, HubSpot, or Zoho – Receives the contact data that you choose to synchronize after connecting the corresponding account.
  • Resend – Email delivery service for support messages from the contact form (forwarding to info@contactscanner.ai and optional confirmation emails).
  • Apple – App Store/StoreKit purchase processing and Apple Ads/AdServices attribution for our own campaign measurement.
  • AppsFlyer – Strict SDK service provider for the staged iOS measurement of our own ChatGPT Ads campaigns; OpenAI partner postbacks are subject to the iOS tracking-consent status and AppsFlyer Advanced Privacy.
  • Google/Firebase – Google Analytics for Firebase, Google Ads, and Google Play for Android app analytics, install/purchase conversion measurement, and our own campaign optimization.

6. Security

  • Transport encryption (TLS) for all connections.
  • NSFileProtection for locally stored files.
  • Minimization: No image/result data is persisted server-side; only technical counters/keys are maintained.

7. Device Contacts

  • You can save recognized contact data to the contacts app on your device.
  • We do not read your entire address book; when opening a saved contact on iOS, it is specifically loaded from the CNContactStore.

8. Your Rights (GDPR, where applicable)

  • Access, rectification, erasure, restriction, data portability, objection.
  • You have the right to complain to a supervisory authority.
  • For deletion/access requests (including deletion of Upstash keys for your client/device ID) contact us: info@contactscanner.ai.

9. Minors

  • The app has no age verification and is aimed at general users. Please observe local legal requirements for minors.
  • Parents/guardians can contact us at any time with questions.

10. Changes

We may update this privacy policy from time to time when features, legal situation, or providers change. The validity stated above is decisive. Material changes will be announced within the app.

11. Contact

Baudis AI UG (haftungsbeschränkt)

Paul-Zobel-Straße 8d, 10367 Berlin, Germany

Email: info@contactscanner.ai