Last updated: August 11, 2026
Unscanny ("we", "us", "our") is a mobile application and companion website that extracts structured information from images, including text, contact data, and QR codes, and that optionally performs face-based profile searches through a third-party facial recognition provider, FaceCheck.id. This Privacy Policy explains how we collect, use, store, and protect your data when you use the Unscanny app or the Unscanny website (www.unscanny.com). After a face search, the Unscanny app shows only the number of matches found; if you choose to view the matched profiles themselves, that happens on the Unscanny website, which opens in your device's browser and is covered by this same Privacy Policy.
We generate and store a unique installation identifier for your device using platform-provided APIs (iOS Keychain / Android ANDROID_ID). This identifier is used to associate your searches with your device, enforce usage limits, and record your consent. It is not linked to your name, email, or any other personally identifying information.
When you use the image scan or face search features, your image is transmitted to our servers over an encrypted HTTPS connection. Images submitted for face search are forwarded to our third-party face recognition provider, FaceCheck.id. Images are not stored on our servers beyond the duration required to complete processing and are deleted immediately after.
We do not use your image, or any facial geometry data derived from it, for advertising, marketing, or profiling, and we do not use it to train AI/ML models. Under our agreement with FaceCheck.id, we require that they process your image solely to fulfil your search request and do not use it for their own advertising, marketing, or model training.
The results of face searches (profile URLs and match scores returned by FaceCheck.id) are stored in our database and associated with a short-lived access token. Results are automatically deleted after 7 days. You may request earlier deletion at any time (see Section 7).
When you consent to the face search feature, we record the timestamp, your device identifier, your app version, and your IP address. This record is retained for legal compliance purposes for up to 3 years.
Standard server logs (request timestamps, IP addresses, HTTP status codes) are retained for up to 30 days for security and debugging purposes.
The app uses Google AdMob to serve advertisements to non-premium users. AdMob may collect the device advertising identifier (IDFA on iOS, GAID on Android), IP address, device model, OS version, and app usage data to serve relevant ads. On iOS, this data is only used for advertising purposes after you grant permission via the App Tracking Transparency prompt. You can opt out of personalised ads at any time via your device settings (iOS: Settings → Privacy → Advertising; Android: Settings → Google → Ads). AdMob never receives your submitted photos, face search results, or any biometric data — its data collection is limited to the standard advertising identifiers and device information described above.
We use Google Firebase Analytics to understand how users interact with the app. Firebase collects device model, OS version, app version, general location (country/region), and in-app events (e.g. features used, screens viewed). This data is aggregated and anonymised and is not linked to your identity. You can opt out of Firebase Analytics data collection via your device settings (iOS: Settings → Privacy → Analytics; Android: Settings → Google → Usage & diagnostics).
If you purchase a premium subscription, transaction data is processed by Apple (App Store) or Google (Play Store) and by RevenueCat, our subscription management provider. RevenueCat receives your device identifier, purchase tokens, and subscription status to manage entitlements. We do not receive or store your payment card details. RevenueCat's privacy policy is available at revenuecat.com.
The face search feature processes facial geometry from images you submit. This constitutes biometric data under applicable laws including the Illinois Biometric Information Privacy Act (BIPA), the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA/CPRA), the Texas Capture or Use of Biometric Identifier Act (CUBI), and the Washington My Health MY Data Act.
We do not collect biometric data unless you explicitly opt in to the face search feature. Before every search, the app displays a separate consent screen that explicitly states your photo will be sent to FaceCheck.id and requires you to affirmatively confirm this before the search proceeds; this consent may be withdrawn at any time. We do not sell, lease, trade, or otherwise profit from biometric data.
Face recognition processing is performed by FaceCheck.id, a third-party sub-processor. Their privacy policy is available at facecheck.id. By using the face search feature, you acknowledge that your image will be transmitted to FaceCheck.id for processing.
The face search feature may only be used to search for photos of adults. Submitting a photo of a minor as the subject of a search is strictly prohibited under our Terms of Service. If we become aware that a search targeted a minor, we immediately delete the search and its results and may suspend access for the device or account involved.
Retention schedule: Facial images are not stored. Search result data derived from face recognition is stored for a maximum of 7 days and then permanently deleted.
For users in the European Economic Area, our legal bases are:
Unscanny is not directed at children under the age of 13 in the United States, or under the applicable age of digital consent in other jurisdictions (16 in most EU member states). The face search feature requires users to confirm they are 18 or older before each search. If you believe a minor has submitted data through our service, contact us immediately at the address in Section 10 and we will delete it.
We share data with the following sub-processors only:
We do not sell your data to third parties. We do not share data with data brokers.
Depending on your jurisdiction, you may have the right to:
To delete your data, email us at unscannyinfo@gmail.com with the subject line "Data Deletion Request", including your device identifier if you have it. We will respond and complete deletion within 30 days. For BIPA requests, we will respond within the timeframe required by Illinois law. Face search results are automatically deleted after 7 days regardless of any request, and submitted images are deleted immediately after processing.
| Data type | Retention |
|---|---|
| Submitted images | Deleted immediately after processing |
| Search results | 7 days |
| Device identifier | Until deletion requested |
| Consent records | 3 years (legal compliance) |
| Server logs | 30 days |
| Analytics data (Firebase) | 14 months (Firebase default) |
| Subscription data (RevenueCat) | Per RevenueCat retention policy |
All data is transmitted over TLS 1.2 or higher. Our database is hosted on AWS RDS in a private network not accessible from the public internet. We apply the principle of least privilege to all system access. No system has access to more data than required for its function.
For privacy requests, data deletion, or questions about this policy, contact us at:
unscannyinfo@gmail.com
We may update this policy to reflect changes in our practices or applicable law. Material changes will be communicated via an in-app notice. Continued use of the app after notice constitutes acceptance of the updated policy.