ChattyDOC is a document scanning and OCR app for iOS. We collect only what is necessary to deliver the service and give you control over cloud processing.
Data we process
Document content: Images, PDFs, filenames, extracted text, and questions you enter for document chat. Processed locally first; cloud transfer happens only after you approve the named provider in the app.
Device-scoped identifier: A vendor-scoped device identifier and app version are sent to our backend to issue short-lived proxy tokens. This is used for security and app functionality, not for advertising or tracking.
Account authentication (optional): If you use Sign in with Apple, our backend stores a pseudonymous representation of your Apple account identifier, an encrypted Apple authorization token, and session/device associations needed to secure your account. We do not store your Apple-provided name or email on our servers. Profile details remain in ChattyDOC storage on your device and, if enabled, your private iCloud database.
Purchase and subscription information: When connected processing is requested, ChattyDOC automatically obtains the App Store product identifier, original and latest transaction identifiers, expiration date, grace-period status, and subscriber status from StoreKit and sends them to the ChattyDOC backend. We use this only to verify entitlement, secure connected access, enforce usage limits, and prevent fraud.
Diagnostics: Crash, performance, and other diagnostic data are handled by the app and backend logging stack to keep the app working. Default personal-information collection, screenshots, and advertising tracking are disabled.
Apple Intelligence & Reason APIs
On-device Apple Intelligence and Vision APIs are preferred for OCR on supported iOS 26 devices.
Required Reason APIs declared in the privacy manifest: File Timestamp (C617.1), User Defaults (CA92.1), and Disk Space (E174.1).
Camera and Photo Library access are permission-based system features used only for capture, import, and export flows.
Cloud processing (optional and consent-based)
Before a cloud action begins, ChattyDOC identifies the recipient, the document data and prompt being sent, the purpose, and the retention choice. You can select Not Now and continue with local processing.
OpenAI cloud processing: selected document images or PDFs, filename, extracted text, and chat prompts may be sent to OpenAI through ChattyDOC’s secure service for connected OCR, analysis, and document chat. Responses application-state storage is disabled; temporary files are deleted after processing when possible.
Google one-time processing: selected PDFs, filename, extracted text, and prompts may be sent to Google for large or complex document processing. Temporary provider resources are queued for deletion after the result is returned.
Google document search: only after a separate approval, a selected PDF, its filename, and each follow-up question may be sent to Google to create and use a document-search index. The index remains until you delete the document, turn off document search in Settings, or permanently delete your account.
You can revoke any cloud-processing approval in ChattyDOC at Settings → Data & Privacy → Cloud Processing. Revocation blocks new transfers and queues deletion of retained cloud resources.
Third parties
We require every service provider that processes ChattyDOC data on our behalf to use it only for the purposes described here, apply privacy and security protections that are the same as or equivalent to ours, and delete or return it according to our instructions and the retention terms below.
OpenAI — optional connected OCR, analysis, and document chat. OpenAI’s API data controls and abuse-monitoring retention may apply.
Google — optional large-document processing and document search. Google API data controls and retention terms apply.
Vercel — secure backend and temporary relay infrastructure for authorized cloud requests.
Cloudflare — temporary R2 object storage used to securely stage authorized large documents.
App logging — crash and performance diagnostics handled by the app and backend logging stack; document bytes and base64 payloads are not logged.
Apple — on-device intelligence, Sign in with Apple, CloudKit sync, and system services (camera/photo access per your consent).
Your choices
Keep cloud processing off to stay fully on-device.
Review or revoke cloud-processing approvals at Settings → Data & Privacy → Cloud Processing.
Revoke camera/photos permission anytime in iOS Settings.
Permanently delete a signed-in ChattyDOC account in the app at Settings → Account → Delete Account. The app asks you to verify with Apple and confirm before deletion starts; no email or support request is required.
Permanent account deletion revokes the ChattyDOC authorization associated with Sign in with Apple, invalidates ChattyDOC sessions, and removes account credentials and device associations.
ChattyDOC then erases the account's profile, documents, OCR text, analyses, collections, private iCloud copies, and registered cloud-provider files or search indexes. Provider cleanup may finish shortly after the request if a service is temporarily unavailable; the app keeps the account locked and shows the deletion status while cleanup continues.
Deleting a ChattyDOC account does not cancel an App Store subscription. Subscriptions are managed separately through Apple.
Data retention
On-device data remains on your device until you delete it.
Temporary Vercel relay files, Cloudflare R2 staging objects, and OpenAI file objects are deleted after processing when possible. OpenAI abuse-monitoring logs may be retained for up to 30 days under its API data controls.
Google one-time upload resources are queued for deletion after processing. Managed document-search indexes remain available until you delete the associated document, turn off document search, or permanently delete your account; cleanup requests are sent when deletion begins.
After account deletion completes, we retain only a non-identifying deletion receipt for up to 30 days so the app can confirm completion and safely resolve repeated requests. The receipt is then purged.
Support emails are kept only as long as needed to resolve your request.
Your rights
Access, correction, or deletion of information you share with us in support channels.
Opt-out of cloud processing at any time in-app.
Initiate permanent account deletion directly in the app at Settings → Account → Delete Account.