PLUTON TECHNOLOGIES (OPC) PRIVATE LIMITED (“we,” “us,” or “our”) operates the ScanO mobile application (the “App”) available on Android. This Privacy Policy explains how we collect, use, store, share, and protect your personal information when you use our App and related services.
This policy is designed to comply with the General Data Protection Regulation (GDPR), the India Digital Personal Data Protection Act, 2023 (DPDP Act), the California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA), the UK General Data Protection Regulation (UK GDPR), Brazil’s Lei Geral de Proteção de Dados (LGPD), and other applicable privacy laws worldwide.
By using ScanO, you agree to the collection and use of information in accordance with this policy. If you do not agree, please do not use the App.
1. Information We Collect
1.1 Information You Provide
- Account Information: When you create an account, we collect your name, email address, and profile picture (optional). You may also sign in via third-party authentication providers (e.g., Google Sign-In), in which case we receive your name and email from that provider.
- Support Communications: If you contact us for support, we collect the content of your message, your email address, and any attachments you provide.
- Documents and Signatures:
- When you upload or import a document in the App to perform an operation, the document is stored locally on your device by default and is not uploaded to our servers, except where you use a cloud-based AI/OCR feature (see Section 2), in which case it is processed and then automatically deleted after a short retention period (see Section 5).
- When you use the eSign feature, you create or upload a signature image. Signatures are stored locally on your device and are never uploaded to our servers.
1.2 Information Collected Automatically
- Device Information: Device model, operating system version, unique device identifiers, screen resolution, and language settings.
- App Usage Data: Features used, scan frequency, tools accessed, session duration, and in-app navigation patterns. This data is collected via Firebase Analytics and is used solely to improve the App.
- Credit and Usage Information: To manage fair usage of AI/OCR features, we record your usage-credit balance (credits allotted, used, and remaining) associated with your account. Credits have no monetary value and cannot be purchased.
- Crash and Performance Data: Crash logs, stack traces, and performance metrics collected via Firebase Crashlytics to identify and fix bugs.
- Camera and Image Data: When you use the scanner, the App accesses your device camera in real time. Captured images are processed on-device for edge detection and stored locally. Images are never uploaded to our servers except when you explicitly use a cloud-based AI/OCR feature (see Section 2).
- Local File Access: The App accesses files on your device storage that you explicitly select for processing (e.g., importing a PDF for merging). We do not scan or index your device storage.
1.3 Information We Do NOT Collect
- We do not collect payment, credit card, bank, or UPI information (the App is free).
- We do not collect biometric data.
- We do not collect location data (GPS, network-based, or otherwise).
- We do not collect contacts, call logs, or SMS data.
- We do not serve ads, and we do not collect data for advertising purposes.
- We do not sell, rent, or trade your personal information to any third party.
2. How We Use Your Information
We use the information we collect for the following purposes:
- Provide and maintain the App: Enable scanning, file management, PDF tools, AI/OCR processing, and eSign.
- Cloud-based AI/OCR Processing: When you use AI-powered features (Layout OCR, Translate, To Word, Enhance, Extract Tables), your document is transmitted to our secure cloud servers for processing by third-party AI/OCR service providers. Your uploaded files and the generated results are retained only for a short, fixed period so we can deliver the output and let you re-download it, and are then automatically deleted (see Section 5). They are not used for AI model training.
- Usage and credit management: Maintain your usage-credit balance and enforce fair-use limits on AI/OCR features.
- Analytics and improvement: Understand usage patterns, identify bugs, and improve app performance and features.
- Customer support: Respond to your inquiries and resolve issues.
- Security: Detect and prevent fraud, abuse, and security incidents.
- Legal compliance: Comply with applicable laws, regulations, and legal processes.
3. Legal Basis for Processing (GDPR / UK GDPR)
If you are located in the European Economic Area (EEA), United Kingdom, or another jurisdiction that requires a legal basis for processing personal data, we rely on the following:
- Performance of a contract: Processing necessary to provide the App and its features to you (Article 6(1)(b) GDPR).
- Legitimate interests: Analytics, security, and product improvement, where these interests are not overridden by your rights (Article 6(1)(f) GDPR).
- Consent: Where required by law, such as for certain analytics cookies or marketing communications. You may withdraw consent at any time (Article 6(1)(a) GDPR).
- Legal obligation: Where processing is required to comply with applicable laws (Article 6(1)(c) GDPR).
4. Data Sharing and Third-Party Services
We do not sell your personal data. We share data only in the following limited circumstances:
4.1 Service Providers
- Cloud AI/OCR Providers: Documents submitted for AI/OCR processing are transmitted to our third-party AI service providers. These providers process your data solely on our behalf, under contractual obligations that prohibit them from using or sharing your data for any other purpose, or using it for AI model training. Retention is limited to the short periods described in Section 5.
- Firebase (Google): Analytics, crash reporting, and performance monitoring. Google processes data under its Data Processing Terms.
4.2 Legal Requirements
We may disclose your information if required to do so by law, regulation, legal process, or governmental request, or if we believe disclosure is necessary to protect our rights, your safety, or the safety of others.
4.3 Business Transfers
In the event of a merger, acquisition, or sale of assets, your personal data may be transferred to the acquiring entity. We will notify you via email or a prominent in-app notice before your data is transferred and becomes subject to a different privacy policy.
5. Data Retention
- Account data: Retained for as long as your account is active. Upon permanent account deletion, all associated personal data is permanently deleted within 30 days, except where retention is required by law.
- Cloud processing data (AI/OCR): When you use a cloud AI/OCR feature, the related data is automatically deleted after a short, fixed retention period:
- Uploaded images/PDFs: 48 hours
- Rendered preview pages: 24 hours
- Extracted text and layout data: 7 days
- Generated files (DOCX, PDF, HTML, TXT): 7 days
- Job records (status, filename, page count): 7 days
- Credit and usage data: Retained while your account is active; deleted with your account data upon permanent deletion.
- Analytics data: Aggregated and anonymized analytics data may be retained indefinitely. Data that can be linked to an individual is retained for no longer than 26 months.
- Support communications: Retained for up to 24 months after resolution, then deleted.
- Locally stored documents: Files stored on your device remain under your control. We do not access, sync, or delete local files unless you explicitly request it.
6. Your Rights
6.1 Rights Under GDPR / UK GDPR
If you are in the EEA or UK, you have the following rights:
- Access: Request a copy of the personal data we hold about you.
- Rectification: Request correction of inaccurate or incomplete data.
- Erasure: Request deletion of your personal data (“right to be forgotten”).
- Restriction: Request that we limit processing of your data in certain circumstances.
- Data Portability: Receive your data in a structured, machine-readable format.
- Objection: Object to processing based on legitimate interests.
- Withdraw Consent: Where processing is based on consent, withdraw it at any time without affecting prior processing.
- Lodge a Complaint: File a complaint with your local data protection authority.
6.2 Rights Under India DPDP Act, 2023
If you are in India, you have the following rights under the Digital Personal Data Protection Act:
- Right to access: Obtain a summary of your personal data and processing activities.
- Right to correction and erasure: Request correction of inaccurate data or erasure of data no longer necessary for its original purpose.
- Right to grievance redressal: File a complaint with our Grievance Officer (see Section 13) or the Data Protection Board of India.
- Right to nominate: Nominate another individual to exercise your rights in the event of your death or incapacity.
6.3 Rights Under CCPA / CPRA (California, USA)
If you are a California resident, you have the right to:
- Know what personal information we collect, use, and disclose.
- Request deletion of your personal information.
- Opt out of the sale or sharing of personal information. (We do not sell or share your data.)
- Non-discrimination for exercising your privacy rights.
6.4 Rights Under LGPD (Brazil)
If you are in Brazil, you have the right to confirmation of processing, access, correction, anonymization, portability, deletion, and information about sharing. Contact us to exercise these rights.
6.5 Exercising Your Rights
To exercise any of the above rights, contact us at support@plutontechnology.com. We will respond within 30 days (or sooner if required by applicable law). We may request verification of your identity before fulfilling your request.
7. Data We Store and Your Right to Access
We are committed to being transparent about the information we store. Registered users can request and access the data associated with their ScanO account.
7.1 Who Can Request Their Data
Only registered users can request their stored data. To protect user privacy and prevent unauthorized access, a data request must be made from the email address registered with the user’s ScanO account. Guest users cannot request or access stored account data because they do not have a registered account.
7.2 What Data a Registered User Can Access
While your account exists — including during the 30-day recovery period described in Section 8 — you may request the following information associated with your account:
- Account information: Account creation date.
- Credit and usage information: Credits allotted, used, and remaining.
- Document and processing information: Uploaded images or PDF files (where still retained) and extracted OCR text and layout data.
Please note that most document-processing files are temporary and are automatically deleted according to our retention schedule (see Section 5). As a result, some previously processed files may no longer be available at the time a data request is made. Once an account has been permanently deleted, its data can no longer be provided.
7.3 How to Request Your Data
To request your stored data, send an email from the email address registered with your ScanO account to support@plutontechnology.com, clearly stating that you want to access or receive a copy of your account data. For security purposes, requests sent from an email address that is not associated with the account may not be processed.
8. Account Deletion
You may request deletion of your ScanO account and associated data at any time, directly from the App or, if you cannot access the App, through our web form at plutontechnology.com/delete-account. After deletion is completed, your personal account data is removed from our active systems. Temporary document-processing files are also deleted according to our retention schedule. We do not retain personal account data after deletion, except where retention is required by applicable law or for security, fraud-prevention, or other legitimate legal obligations.
8.1 How to Delete Your Account
- Log in to the App using your registered account.
- Go to the Profile section and open the Account section.
- Select the Delete Account option at the bottom.
- Review the information provided regarding account deletion.
- Confirm your request when prompted.
8.2 What Happens After You Request Deletion
- Once you confirm, your account is marked for deletion and a confirmation is displayed indicating that your request was submitted successfully.
- Your account and associated data are not permanently deleted immediately.
8.3 Account Recovery Period
After you submit a deletion request, a 30-day grace period is provided before permanent deletion occurs. During this period:
- Your account remains recoverable.
- You can cancel the deletion request simply by logging back into the App.
- Upon successful login, your account is restored automatically and the deletion request is cancelled.
8.4 Permanent Deletion
If you do not log in and restore your account during the 30-day grace period, your account and associated data are permanently deleted at the end of that period. Once the account has been permanently deleted:
- The deletion cannot be reversed.
- Access to the account is no longer possible.
- Associated user data is removed in accordance with our data retention schedule (Section 5).
- Documents stored locally on your device are not affected by account deletion and remain under your control.
9. Data Security
We implement industry-standard security measures to protect your data:
- All data transmitted between the App and our servers is encrypted using TLS 1.2 or higher.
- Access to our production systems is restricted to authorized personnel with multi-factor authentication.
- We conduct regular security reviews and vulnerability assessments.
- Sensitive tokens and credentials stored on-device use the Android Keystore or equivalent encrypted storage.
No method of transmission or storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security. If you discover a security vulnerability, please report it to us immediately.
10. Children’s Privacy
ScanO is not directed at children under the age of 13 (or the applicable age in your jurisdiction). We do not knowingly collect personal information from children. If we learn that we have inadvertently collected data from a child, we will delete it promptly. If you believe a child has provided us with personal data, please contact us at support@plutontechnology.com.
11. International Data Transfers
Your data may be processed in countries other than your own, including India and the United States, where our servers and service providers are located. When we transfer data internationally, we ensure appropriate safeguards are in place:
- Standard Contractual Clauses (SCCs) approved by the European Commission for transfers from the EEA.
- UK International Data Transfer Agreement (IDTA) for transfers from the UK.
- Contractual commitments with all third-party processors to maintain equivalent data protection standards.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by posting the updated policy in the App and updating the “Last Updated” date at the top. For significant changes, we will also provide notice via email or a prominent in-app notification. Your continued use of the App after the changes take effect constitutes acceptance of the revised policy.
13. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, contact us at:
Company: PLUTON TECHNOLOGIES (OPC) PRIVATE LIMITED
Email: support@plutontechnology.com
Website: www.plutontechnology.com
Registered Office: Ward No. 02, Shantinagar, Bagbahara, Mahasamund, Chhattisgarh, India – 493449
Grievance Officer (for users in India under the DPDP Act):
Name: Vivek Sahu
Email: support@plutontechnology.com
We aim to respond to all inquiries within 30 days or sooner as required by applicable law.
14. Jurisdiction-Specific Disclosures
European Economic Area and United Kingdom
You may contact us regarding your data at support@plutontechnology.com, and you have the right to lodge a complaint with your local supervisory authority.
India
We process your data in accordance with the Digital Personal Data Protection Act, 2023 and applicable rules. Our Grievance Officer is identified in Section 13 above.
California, USA
We do not sell personal information as defined by the CCPA/CPRA. We do not use or disclose sensitive personal information for purposes other than those permitted by the CCPA/CPRA.
Brazil
We process your data in accordance with the LGPD. You may contact us at the email listed in Section 13 to exercise your rights.
See also the ScanO Terms of Service.