# Privacy Policy for Image to PDF: Scan, Edit, Sign
**Developer:** Beauty Dream Studio
**Contact email:** contact@yuzhensoftware.com
**Effective date:** September 23, 2026
**Application:** Image to PDF: Scan, Edit, Sign
**Android package:** `com.beautydream.imagetopdf.pdfconverter.pdfmaker`
This Privacy Policy explains how Beauty Dream Studio ("we," "us," or "our") handles information when you use Image to PDF: Scan, Edit, Sign (the "App").
## 1. Versions covered by this policy
The App's data practices depend on the version installed on your device:
- Version 1.0.1 and earlier process documents locally and do not include advertising, Firebase analytics, RevenueCat subscriptions, or network-based application services.
- Version 1.0.2 and later continue to process document content locally but include advertising, consent management, analytics, remote configuration, install-attribution classification, and optional Premium subscriptions as described below.
- The current release, version 1.0.6, also includes an in-app photo selector, device PDF discovery, local folders and a recycle bin, Firebase Crashlytics, and notification-related services using Firebase Cloud Messaging. Some of these capabilities were introduced in updates after version 1.0.2. They apply where present in the version you use.
This version-specific explanation allows this Policy to cover both an older version that may still be installed and the current version distributed through Google Play.
## 2. Privacy summary
- Document conversion, editing, scanning and text recognition are performed on your device. We do not operate a server that processes your documents for these features.
- The App does not require an account or sign-in.
- Version 1.0.2 and later use Google Mobile Ads and Google User Messaging Platform (UMP), Firebase Analytics and Remote Config, Google Play Install Referrer, Google Play Billing, and RevenueCat. These services process limited advertising, analytics, device, installation, and purchase information.
- The current release also uses Firebase Crashlytics for technical diagnostics and Firebase Cloud Messaging for app messages. These services process information described in Sections 4.6 and 4.7; local document processing does not mean the App makes no network connections.
- Photo access, all-files access and notification permission are controlled through Android. You can decline all-files access and select individual PDFs through the system document picker.
- You decide whether to send feedback and which screenshots or images to attach. The App opens an email or sharing application you select so that you can review the message before sending it.
## 3. Documents and information processed locally
To provide the features you request, the App may access or create the following information on your device:
- Photos, album information and thumbnails made available to the in-app photo selector under the access you grant, or images you select through an Android system picker;
- Images provided by the document-scanning interface when you choose to scan;
- PDF files that you select, import, create, edit, merge, split, compress, protect, unlock, convert, preview, share, or export;
- Text recognized from a document using the on-device text-recognition model included with the App;
- Signatures that you create and place in a PDF;
- File names and document settings such as page size, orientation, margins, image order, rotation, crop region, filter, quality, compression, and output location;
- Passwords entered to create, open, protect, or unlock a PDF; and
- Temporary images, thumbnails, previews, and task files required to complete an operation;
- PDF names, local paths or URIs, sizes and timestamps used to display and index accessible device documents, and local folder assignments, favorites, recent-file history and recycle-bin records; and
- Notification preferences, document counts, delivery counters and local event records used to decide whether and when a reminder may appear.
Document information is used to perform the operations you request, display and manage local files, and support relevant local reminders where enabled. The All files feature discovers PDFs in accessible shared-storage locations. Browsing a device PDF does not automatically import it into the App's private library; editing it creates an App-managed copy.
Our document-processing features do not upload document contents for remote processing. Our custom analytics events are designed to exclude document contents, file names, paths or URIs, recognized text, signatures and PDF passwords. Technical crash diagnostics are described separately in Section 4.6. Files that you deliberately share, export to a cloud provider or attach to a support message are handled by your selected destination.
PDF passwords are used in memory only for the operation that requires them. They are not saved in App preferences, the document database, analytics events, or a developer server. Neither the App nor Beauty Dream Studio can recover a forgotten PDF password.
## 4. Information processed by connected services in version 1.0.2 and later
### 4.1 Advertising and privacy choices — Google Mobile Ads and Google UMP
The App may display banner, native, interstitial, and app-open advertisements through the Google Mobile Ads SDK. Google UMP requests and stores privacy choices where required and determines whether advertisements may be requested.
Depending on your region, device settings, consent choices, and Google's advertising configuration, Google Mobile Ads may process or share:
- Your IP address, which may be used to estimate general location;
- App launches, advertisement impressions, taps, clicks, video views, and other product interactions;
- App and SDK performance information such as startup time, hang rate, and energy usage;
- Android Advertising ID, App Set ID, and other applicable device or account identifiers;
- Advertising-attribution and Android Privacy Sandbox signals, such as protected attribution or Topics signals, when supported and permitted; and
- Consent status and privacy-message interactions managed by UMP.
Google states that data collected by the Google Mobile Ads SDK is encrypted in transit and used for advertising, analytics, and fraud prevention. Advertising may be personalized or non-personalized according to applicable law, your consent choices, device settings, and Google's policies.
When Google UMP indicates that a privacy-options entry point is required, the App displays **Settings → Privacy choices**, where you can review or change the available choices. You can also reset or delete the Android Advertising ID through Android settings where that control is available.
Premium removes advertisements from the App while the Premium entitlement remains active. Other services needed for analytics, remote configuration, subscription verification, security, and legal compliance may continue to operate.
### 4.2 Analytics and remote configuration — Firebase
The App uses Firebase Analytics to understand aggregate use, diagnose where users leave a workflow, evaluate feature reliability, measure advertising and subscription funnels, and improve the App. Examples include:
- App launch, onboarding completion, page or feature entry, and navigation source;
- The start, success, cancellation, or failure of a document task;
- Coarse buckets for input count and processing duration;
- Output actions such as save, save to gallery, share, open, create another document, or return home;
- Rating-prompt, exit-sheet, Paywall, and advertisement lifecycle events; and
- Notification eligibility, suppression, delivery submission, taps, dismissal and destination entry, together with the trigger category, content/configuration version and derived audience category.
These analytics events are deliberately designed not to include document contents, file names, file paths or URIs, PDF passwords, document or image identifiers, exact file sizes, email message bodies, or search text.
For analytics continuity, the App derives a pseudonymous analytics user identifier by hashing the Android ID together with the App's package identity using SHA-256. The original Android ID is not sent by our code to Firebase. The resulting value is still a persistent device-related identifier and is treated as such under this Policy.
Firebase Analytics and its supporting services may also process app-instance identifiers, device and app information, operating-system version, language, general region, IP address, and interaction information in accordance with Google's documentation.
The App uses Firebase Remote Config to obtain configuration values for advertising, feature behavior, home-screen tools, notification content and frequency, and Paywall presentation without requiring an App update. It may also support controlled product and wording experiments. Remote Config may process a Firebase Installation ID, country and language codes, time zone, platform and operating-system version, Firebase App ID, package name, SDK version, user properties, and first-open time. We do not use Remote Config to upload document content.
### 4.3 Install attribution — Google Play Install Referrer
The App uses the Google Play Install Referrer API to obtain referral information supplied by Google Play. The referral string is examined locally to classify the installation into a broad user category used for advertising behavior, notification frequency and aggregate analytics.
The App does not save or upload the raw install-referrer string, a raw `gclid`, or raw campaign parameters. It stores whether referral classification has completed and a derived attributed/not-attributed result.
### 4.4 Premium subscriptions — Google Play Billing and RevenueCat
The App offers optional Premium subscriptions through Google Play. Available plans, prices, billing periods and any trial terms are shown before purchase. Google Play processes payment credentials and the transaction. We do not receive or store your full payment-card or bank-account details.
RevenueCat is used to display the Paywall, validate purchases, determine whether the `pdf_pro` entitlement is active, restore purchases, manage subscription status, and provide subscription analytics. RevenueCat and Google Play may process:
- A randomly generated, anonymous RevenueCat App User ID;
- Product, offering, and package identifiers;
- Purchase history, subscription status, renewal and expiration information;
- Google Play purchase tokens or receipts used to validate a transaction;
- Price, currency, store, and transaction metadata; and
- App, device, operating-system, locale, and network information reasonably required to provide, secure, troubleshoot, and analyze the subscription service.
The App does not create an account, send your name or email address to RevenueCat, or deliberately set RevenueCat customer attributes containing contact information. Purchase, renewal, cancellation, refund, and revenue records are handled by Google Play and RevenueCat as the authoritative subscription services.
You can manage or cancel a subscription through Google Play. Uninstalling the App does not cancel an active subscription.
### 4.5 Feedback, feature requests, and support email
If you choose **Send feedback** or **Request a feature**, the App prepares a message and opens an email or sharing application that you select. Before sending, you can inspect, edit, or cancel the message.
The prepared message may contain:
- The categories and text you enter;
- App version, device model, Android version, screen size, App language, and time zone; and
- Screenshots or images that you deliberately attach.
The prepared message does not automatically include document contents, document identifiers, file paths, Android ID, Advertising ID, or PDF passwords. If you send the message, we may receive your sender email address and any other information added by you or your email provider. The selected email or sharing service processes the message under its own privacy policy.
### 4.6 Crash reporting — Firebase Crashlytics
The current release uses Firebase Crashlytics to identify failures and improve reliability. Crash reports may include stack traces, exception types and messages, installation-related identifiers, app and operating-system versions, device characteristics, and technical events. Crash reporting is enabled in the current release; the App does not provide a separate in-app switch for it.
We do not deliberately attach PDFs, images, recognized text, signatures or passwords to crash reports. Exception messages generated by Android or libraries may contain contextual information, such as a file path. Such information may be included in a technical diagnostic report; the exclusions for our custom analytics events do not guarantee that every system-generated diagnostic message is free of file-related information.
### 4.7 Notifications and Firebase Cloud Messaging
The App uses Firebase Cloud Messaging and Firebase Installations to receive app messages and configuration signals. Google processes installation identifiers, messaging registration tokens and related delivery information. Topic registration is managed through Firebase; our code does not upload messaging tokens to a separate Beauty Dream Studio backend.
Where notifications and relevant file access are allowed, the App may display PDF reminders and a persistent shortcut panel for My files, image import and scanning. Local signals, such as leaving the App, unlocking the device or changes to accessible recent files, may be used to decide whether a reminder is relevant. Document availability, notification preferences, subscription status, install-attribution category, frequency limits and remotely configured rules can affect what is displayed and when.
A reminder may show a thumbnail of a recent photo or screenshot. The App creates these previews locally and does not upload them for notification generation. Previews may be visible to anyone who can see your notification shade or lock screen, depending on Android settings. Background monitoring and notification updates are subject to Android's process, permission and power restrictions.
You can disable visible notifications in Android settings. This does not disable Firebase's technical messaging services, analytics, crash reporting or subscription verification. Removing advertisements through Premium likewise does not by itself disable these services or all notifications.
## 5. Permissions and device access
Depending on your Android version and the feature you use, the App may request or declare:
- **Photo access:** to display permitted albums and thumbnails in the in-app selector and select images for PDFs. Depending on Android, you may allow selected photos, grant broader photo access or deny access. On older Android versions, external-storage read permission supports access to permitted images and documents.
- **All-files access:** to find, list, search and work with PDFs across accessible shared-storage folders through All files. The document index and processing remain on your device. This access is granted through Android's special-access settings. You can decline or revoke it and choose individual PDFs through the system document picker instead.
- **System document access:** to open, import or export files at locations you select through Android's document picker, including third-party document providers.
- **Document scanning and camera:** the current release opens Google's document-scanning interface when you choose Scan. Camera access is handled through that interface and Google Play services; the current App package does not declare its own CAMERA permission. Earlier versions may use a different camera flow. You can use imported images instead of scanning.
- **Notifications:** to show PDF reminders, shortcut actions and processing status. You can deny or disable notifications in Android settings without losing access to the PDF tools.
- **Foreground service for data sync:** to run PDF creation and export tasks that you start, including while you switch to another app. A processing notification displays status and offers Cancel, subject to Android notification settings. The service refreshes the local document count after the task and stops on completion, failure or cancellation. It is not kept running solely to maintain a shortcut notification or continuously monitor files.
- **Boot completion:** to recheck saved notification preferences and reschedule applicable reminders after a device restart, subject to Android restrictions. It does not start an ongoing PDF-processing service at boot.
- **Legacy external-storage write access on Android 9 and earlier:** to save an output selected by the user on older Android versions.
- **Internet and network state:** for advertisements, privacy messages, analytics, remote configuration, crash reporting, messaging, subscriptions, and related network-status handling.
- **Advertising and attribution permissions:** for Google Mobile Ads and supported Android advertising services.
- **Google Play Billing:** to offer and manage optional subscriptions.
- **Google Play Install Referrer:** to retrieve install-attribution information from the Google Play Store.
The App does not use these permissions to upload your documents for remote processing.
## 6. How we use information
We use information described in this Policy to:
- Provide the document, scanning, editing, conversion, export, and subscription features you request;
- Save your preferences and locally manage your documents;
- Display relevant local reminders, shortcut actions and task progress, and apply notification frequency limits;
- Display, measure, and secure advertisements;
- Record and honor applicable advertising privacy choices;
- Understand aggregate feature use and workflow performance;
- Diagnose crashes and technical failures;
- Deliver safe remote configuration and conduct controlled product tests;
- Classify install attribution without retaining raw campaign values;
- Validate, restore, and manage Premium access;
- Prevent fraud, abuse, invalid advertising activity, and unauthorized purchases;
- Respond to support requests and improve the App; and
- Comply with legal obligations and enforce applicable terms.
Where required by law, our legal bases may include performance of a contract or steps you request before entering a contract, your consent, our legitimate interests in operating and improving the App, and compliance with legal obligations. Where processing relies on consent, you may withdraw it through the available privacy controls without affecting processing already completed lawfully.
## 7. When information is shared
We may make information available to the following service providers only as needed for the purposes described above:
- **Google LLC and its affiliates:** Google Mobile Ads, Google UMP, Firebase Analytics, Firebase Remote Config, Firebase Crashlytics, Firebase Cloud Messaging, Firebase Installations, Google Play services for document scanning, Google Play Install Referrer, Google Play Billing, Google Play subscription management, and Android system services;
- **RevenueCat, Inc.:** Paywall delivery, purchase validation, entitlement management, restoration, subscription analytics, and fraud prevention; and
- **The email or sharing provider you select:** only when you deliberately send feedback, a feature request, or an attachment.
We may also disclose information if reasonably necessary to comply with law or a valid legal process; protect users, the public, our rights, or the security of the App; investigate fraud or abuse; or complete a merger, acquisition, financing, reorganization, or transfer of the App, subject to appropriate safeguards and notice where required.
We do not sell your document contents. Under some privacy laws, disclosure of advertising identifiers or activity to an advertising provider for personalized advertising may be considered a "sale," "sharing," or targeted advertising even when no money is exchanged. Where applicable, you can use the UMP privacy choices shown in the App and Android advertising controls to exercise available choices.
## 8. Storage, retention, and deletion
### Information stored on your device
- App-managed PDFs, signatures, local document records and preferences remain in App-controlled storage until removed by you or the App's cleanup behavior, or until you clear App data or uninstall the App.
- Documents moved to the recycle bin remain on your device until permanently deleted or removed under the App's applicable retention behavior. Removing an item from the active file list is not necessarily permanent deletion.
- Device-file indexes, folder assignments, favorites, recent-file history, notification preferences, delivery counters and preview caches are stored locally and are updated or removed as their features require, or when App data is cleared.
- Temporary conversion, crop, scan, preview, thumbnail, and export files are removed when the relevant task completes, is cancelled, or is cleaned up by the App.
- The derived install-attribution state and other preferences remain until App data is cleared or the App is uninstalled.
- Android cloud backup and device-transfer backup are disabled for App-owned documents, databases, settings, and temporary files.
PDFs discovered through All files may already exist outside App-controlled storage. Clearing App data or uninstalling the App does not automatically delete those originals. Files that you export, save to a gallery or shared location, or send to another application must also be deleted from their destination separately. A document provider you select may synchronize an exported file under its own settings.
### Information processed by service providers
Firebase, Google Mobile Ads, Google Play, and RevenueCat retain information according to their service settings, contractual requirements, security needs, and privacy policies. Analytics retention settings may limit event-level retention, while aggregated reports may remain longer. Firebase retains a Firebase Installation ID until deletion is requested through the relevant Firebase mechanism and may take additional time to remove it from live and backup systems. Subscription and transaction records may be retained as needed to provide entitlements, prevent fraud, resolve disputes, comply with financial or legal obligations, and maintain required business records.
Crash diagnostics and messaging records follow the applicable Firebase retention and deletion processes. Clearing App data, disabling notifications or uninstalling the App does not automatically delete records already held by these providers.
Support messages and attachments that you send may be retained for as long as reasonably necessary to respond, investigate the reported issue, protect against abuse, and maintain appropriate support records, after which they may be deleted or anonymized unless a longer period is required by law.
You may request deletion of personal information controlled by Beauty Dream Studio by emailing contact@yuzhensoftware.com. Because the App has no account and most remote identifiers are pseudonymous, we may ask for information reasonably necessary to locate and verify the relevant record. We may be unable to identify a record that cannot reasonably be connected to your request. We may retain information when legally required or when necessary to establish, exercise, or defend legal claims.
## 9. Security
We use reasonable technical and organizational safeguards appropriate to the nature of the information. These include local App-controlled storage, Android scoped-access and secure-sharing mechanisms, avoiding document data in analytics, hashing the analytics identifier before transmission, and encrypted network transport used by Google and RevenueCat.
No device, storage system, or network transmission is completely secure. Protect your device credentials and PDF passwords, keep Android and the App updated, and share sensitive documents only with destinations you trust.
## 10. Your choices and controls
Depending on your location and device, you can:
- Use **Settings → Privacy choices** when shown to review or change available advertising choices;
- Reset or delete the Android Advertising ID and manage other advertising controls in Android settings;
- Purchase Premium to remove advertisements while the entitlement is active;
- Manage, cancel, or restore subscriptions through Google Play and the App's subscription controls;
- Use imported images instead of document scanning;
- Review or revoke photo access, all-files access and notification permission in Android settings;
- Decline all-files access and select individual PDFs through the system document picker;
- Cancel an active PDF generation or export task using the available task controls;
- Choose which photos, files, output locations, sharing targets, and feedback attachments the App may access;
- Move supported App-managed documents to the recycle bin, permanently delete them, clear App storage, or uninstall the App; exported copies and external originals may need to be deleted separately;
- Cancel a feedback or feature-request message before sending it; and
- Contact us to exercise applicable privacy rights.
Changing an advertising choice does not delete information previously processed. Disabling notifications is not a general opt-out from analytics, crash reporting or Firebase technical services. Removing the App does not cancel a Google Play subscription and does not automatically delete records that Google, RevenueCat, an email provider, or another destination retains under its own policy or legal obligations.
## 11. International data transfers
Google, RevenueCat, and other service providers may process information in countries other than the country where you live, including the United States. Those countries may have different data-protection laws. Where required, the relevant provider and Beauty Dream Studio rely on recognized safeguards such as contractual protections, adequacy decisions, or other lawful transfer mechanisms.
## 12. Your privacy rights
Depending on your jurisdiction, you may have rights to request access to, correction of, deletion of, or a copy of personal information; restriction of or objection to certain processing; withdrawal of consent; and appeal or lodge a complaint with a competent data-protection authority.
Residents of jurisdictions that regulate targeted advertising, sale, or sharing may also have the right to opt out of those activities. The advertising privacy choices presented through Google UMP and Android advertising controls are the primary in-App mechanisms for such choices where available.
To submit a request, email contact@yuzhensoftware.com with the subject **Privacy Request — Image to PDF** and describe the right you wish to exercise. We will respond as required by applicable law. We will not discriminate against you for exercising a privacy right.
## 13. Children's privacy
The App is a general productivity tool and is not designed, directed, or promoted to children. The Google Play target audience for the App is adults aged 18 and over. We do not knowingly collect personal information from children through an account because the App does not provide accounts.
If you believe a child has sent personal information to us through a support channel, contact us at contact@yuzhensoftware.com so that we can investigate and take appropriate action.
## 14. Accounts
The App does not create or require a Beauty Dream Studio account. There is no Beauty Dream Studio server-side user profile or account-deletion flow. RevenueCat assigns an anonymous App User ID solely to manage subscription status. Google Play subscriptions are associated with the applicable Google Play account and are managed through Google Play.
## 15. Third-party destinations and links
When you choose to share, export, save, print through a system destination, open a web page, send email, or manage a subscription, Android or the selected third-party application or service handles the information under its own terms and privacy policy. We do not control how a destination selected by you processes a copied or exported file.
Relevant service-provider policies and information include:
- [Google Privacy Policy](https://policies.google.com/privacy)
- [Google Mobile Ads data disclosure](https://developers.google.com/admob/android/privacy/play-data-disclosure)
- [Firebase Privacy and Security](https://firebase.google.com/support/privacy)
- [RevenueCat Privacy Policy](https://www.revenuecat.com/privacy)
- [RevenueCat Google Play Data Safety guidance](https://www.revenuecat.com/docs/platform-resources/google-platform-resources/google-plays-data-safety)
## 16. Changes to this Policy
We may update this Policy when the App, third-party SDKs, legal requirements, or our data practices change. We will update the effective date and, where required, provide additional notice. The version-specific statement in Section 1 explains the practices applicable to older and current App versions.
## 17. Contact us
For privacy questions, requests, or complaints, contact:
**Beauty Dream Studio**
**Email:** contact@yuzhensoftware.com
**Suggested subject:** Privacy Request — Image to PDF
This Privacy Policy is intended to describe the App's actual data practices. It is not a contract that limits rights provided by applicable law.