TextTrace
Privacy Policy
This policy explains how TextTrace handles information when you use the iOS application. Questions and privacy requests can be sent to ataerdal.dev@gmail.com.
Information processed
- Content you select: WhatsApp TXT/ZIP exports and included attachments, screenshots, photos, scans, or screen recordings and the visible text derived from them. Retained originals and previews remain in the app’s local storage until you delete the record or app.
- Cloud verification data: for screenshots, photos, scans, and screen recordings, after your in-app consent, bounded evidence crops containing selected visible text, a content hash, and operational metadata are sent to the TextTrace backend and Google Vision for final OCR. WhatsApp transcript text is imported directly from the TXT/ZIP and is not sent to Google Vision for OCR.
- Account and purchase status: Firebase creates an anonymous user identifier. RevenueCat receives that identifier and App Store purchase information needed to determine subscription access.
- Diagnostics and product analytics: Firebase Analytics receives content-free interaction events such as import stage, duration, export format, paywall views, and purchase outcome. Firebase Crashlytics receives crashes and sanitized technical errors. TextTrace does not put recognized text, record titles, file names, file contents, URLs, hashes, tokens, or Firebase user IDs in these events.
Why information is used
Information is used to provide OCR verification and exports, authorize paid features, prevent abuse, operate and secure the service, diagnose failures, and understand where users abandon core workflows. It is not sold, used for third-party advertising, or used by TextTrace to train generative AI models.
Processors
TextTrace uses Apple frameworks for on-device processing; Google Cloud, Firebase Authentication, App Check, Analytics, Crashlytics, and Google Vision for backend, integrity, diagnostics, analytics, and OCR; RevenueCat for subscription status; and Apple for App Store billing. Their handling is also governed by their applicable privacy terms.
Retention and deletion
Uploaded evidence is deleted after processing, cancellation, terminal failure, or acknowledgement by the device. A scheduled sweeper, database TTL rules, and a storage lifecycle rule provide deletion backstops; uploaded objects are capped at 24 hours. Successful remote result metadata is deleted after the device safely stores and acknowledges it. Local records and retained originals remain until you delete the record or the app.
You can delete a record from within TextTrace. For an account-level deletion or a privacy request, use the deletion request in Settings or contact support from the email address above. Anonymous authentication records and associated operational data will be deleted or de-identified as applicable, subject to security, fraud-prevention, and legal retention requirements.
Security and transfers
TextTrace uses HTTPS, App Attest/App Check, private cloud storage, short-lived upload URLs, least-privilege service identities, and integrity hashes. No system is completely secure. Cloud processing may involve international transfers under the safeguards offered by the processors listed above.
Children and changes
TextTrace is not directed to children under 13. We may update this policy as the service changes; the effective date above will be revised for material updates.