UniScan
Effective Date: October 1, 2026
Welcome to our application (hereinafter referred to as the “App”). We value your privacy and are committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our iOS scanning application and companion applications. Please read this policy carefully. If you do not agree with the terms of this privacy policy, please do not access the application.
UniScan Companion is our remote viewfinder and control app. Its data handling is described below. It does not create accounts, manage subscriptions, upload models to cloud storage, or use Firebase Crashlytics. The account, subscription, custom-category, cloud-sharing, and Crashlytics statements in this policy apply to the main UniScan scanning app. References to desktop reconstruction and saved scan files describe the scanning and reconstruction apps, not the remote viewfinder.
iPhone-to-desktop streaming is available, and Studio subscriptions can be purchased in the iPhone app. Data handling for desktop streaming and subscriptions is described below.
Camera and Pairing: UniScan Companion requests camera access to read the pairing QR code displayed by UniScan. QR images are decoded on the device. QR images and decoded QR contents are not sent to Google or Improvis LLC for decoding. The companion uses the decoded connection address, port, pairing token, and certificate fingerprint to connect to the selected scanning device and verify its identity. The pairing token is sent to that device to authorize the session. You can revoke camera access in your device settings.
Remote Session: The paired scanning device sends a live preview to the companion for display. The companion sends touch gestures, text you enter, and display dimensions to the paired device so you can control UniScan. Preview images can include faces or other personal information. Session data travels directly between the paired devices over an encrypted local-network connection with certificate verification. These QR images, pairing credentials, preview images, gestures, and text are not sent to Improvis LLC or its cloud-sharing service by the companion. Actions you perform remotely can cause the scanning app to save or share data under the practices described elsewhere in this policy.
Storage and Deletion: The companion processes QR images and remote-session content in memory and does not save a recording, input history, or pairing credentials to app files. It releases session resources when the session ends and does not offer cloud backup of session content. Local system logs can contain connection addresses and technical connection errors. The device manages those logs; the companion does not upload them to Improvis LLC. Closing the companion does not delete data saved by the scanning app or another device. Those copies follow the retention and deletion rules for the app that saved them. There is no companion account to delete.
SDK Diagnostics: No UniScan Companion build with the earlier QR-scanning component was publicly released. The companion’s public release uses on-device QR decoding and does not send QR-scanning diagnostics. Earlier test builds that used the previous QR-scanning component sent Google device and app details, an installation identifier, and scanning-library usage and performance metrics. These include processing times, configuration, input and output sizes, and event or error information. Google uses these metrics for diagnostics, maintenance, improvement, and abuse prevention. They are separate from QR images and decoded contents. Metrics are transmitted over HTTPS. That component may also contact Google for updates and compatibility information. Google handles these metrics under its Privacy Policy; the main app’s 90-day Crashlytics retention period does not describe these metrics. SDK identifiers and diagnostic caches may be stored locally and removed by clearing the companion’s app data or uninstalling it; this does not itself delete metrics already received by Google.
We collect information to provide a better experience and advanced 3D scanning functionalities. The types of information we collect include:
TrueDepth Sensor and Camera Data (iOS): To perform 3D scanning, the App utilizes your device’s front-facing camera and Apple’s TrueDepth sensor. This captures color camera images, depth measurements, and mapping geometry. When a face is in the capture area, this data may include images of the face and its three-dimensional shape. Reconstructed point clouds and mesh models may also represent a face. The App also uses on-device face detection to derive face bounds, contour and landmark points, estimated head orientation, and confidence values for reconstruction. We refer to these images, measurements, facial geometry, and derived face information as face data in this policy.
We do not use face data to create biometric identification templates, identify individuals, authenticate users, or track people. The App Store version does not upload scans for research or model training.
3D Model Files: The app processes the depth data to generate 3D mesh models.
Account Information: When you sign in with Apple or Google, we receive an account identifier and may receive your email address, name, and profile image URL. We store account information needed to provide access, manage your subscription tier, and associate your data with your account.
Subscription and Usage Information: We process App Store purchase and subscription status and keep account-linked scan allowance records so we can provide the correct plan features and enforce plan limits.
Custom Scan Categories: When you create a custom scan category, we store its definition and any icon image you choose to provide.
User-Initiated Sharing: When you choose to share a model, we collect the 3D model file that you explicitly choose to upload.
Technical & Connectivity Data: In order to facilitate remote viewfinding and desktop reconstruction, the App may detect local network configurations or local IP addresses to establish a connection between your devices.
Device and Diagnostic Data: We use Firebase Crashlytics to collect crash reports and related diagnostic information, which may include the device model, operating system version, App version, and technical details about a crash.
We use the information we collect for the following dedicated purposes:
To generate, render, and display 3D models on your mobile device.
To transfer data to your desktop reconstruction application for advanced, high-performance computing and enhanced 3D rendering.
To send a camera preview to a paired device running UniScan Companion for remote viewing and control.
To generate unique, shareable cloud links only when you actively trigger the “Share” function.
Face Data Uses: If a scan contains a face, we use its face data for the same scanning functions: capture, reconstruction, display, measurements, and comparison of scans. During desktop reconstruction streaming, the receiving reconstruction device processes camera and depth data. During remote viewing, UniScan Companion displays the camera preview. When you choose cloud sharing, we upload the selected model, including any facial geometry it contains, to make it available under your sharing settings. We do not use face data for advertising, marketing, or user profiling.
To manage your account, verify subscriptions, and provide the features included in your access tier.
To measure account-level scan allowances and prevent fraud or abuse.
To save custom scan categories and their icon images for your account.
To diagnose crashes and improve App performance and compatibility.
We believe in absolute data minimization. Your data is shared under very strict parameters:
Device Transfers: During desktop reconstruction streaming, camera images and depth data are sent to the selected reconstruction device. During remote viewing, camera previews are sent to a paired device running UniScan Companion. These transfers may contain face data. They use the connection between your devices rather than our cloud model-sharing storage.
User-Initiated Sharing: 3D models used for cloud sharing are uploaded only when you manually select the “Share” option. If the model depicts a face, its facial geometry is included in the upload. Google/Firebase processes and stores that model to provide sharing. Invited-only access requires an authorized signed-in recipient with a verified email address. If you confirm public access, anyone with the link can view and download the model while the link is active. Recipients may keep downloaded copies; deleting the original share does not delete their copies.
Custom Scan Categories: Category definitions and icon images are uploaded when you create or edit a custom scan category.
No Commercial Sharing: We do not sell, rent, or trade your 3D models, camera data, or personal information to third-party advertisers or marketers.
Limited Operational Access: Authorized Improvis LLC personnel may access cloud data only when reasonably necessary to provide support, operate or secure the service, prevent abuse, or comply with legal obligations.
We use service providers to operate specific parts of UniScan:
These providers process data under their agreements with us and their applicable terms and privacy policies.
Local Storage by Default: The scanning and desktop reconstruction apps process camera images, TrueDepth measurements, and reconstructed models, including any face data, on their respective devices and may save them in local scan files. Desktop reconstruction streaming, remote viewing, and cloud sharing transfer data as described in Sections 3 and 4. UniScan Companion processes the remote preview in memory as described in Section 1.
Cloud Storage: Shared model files, including any facial geometry, and uploaded category images are stored in Google Firebase Cloud Storage in the US Central region of the United States. Account and sharing records are stored in Cloud Firestore in the United States. Cloud model uploads and downloads use HTTPS. The storage provider encrypts stored files at rest, but shared models are not end-to-end encrypted: the service must be able to read them for web viewing. Access is controlled by your sharing permissions. Authorized Improvis LLC personnel may access this cloud content only for the operational purposes described in Section 4.
Security Measures: We implement standard administrative, technical, and physical security measures to help protect your information. However, please be aware that no security measures are perfect or impenetrable.
Our mobile and desktop applications do not use cookies, pixels, or third-party tracking SDKs to track your behavior across other apps or websites.
We do not engage in targeted advertising based on your 3D scans or usage habits.
Local Data: Local 3D models remain on your device until you manually delete them or uninstall the App.
TrueDepth Data: TrueDepth sensor data is processed to create the 3D mesh and may be written to local scan files during capture. Local scan data remains on the device until it is deleted or the App is uninstalled.
Cloud Data, Including Face Models: Shared models have no automatic age-based deletion period. They remain stored until cloud deletion succeeds following removal of the share, deletion of the scan or account, or a deletion request handled by us. Public sharing links expire after 30 days; link expiry does not delete the stored model. Invited-only sharing has no fixed expiry.
Deletion Timing: Deleting a scan removes its local scan files and queues deletion of its cloud share. If the device is offline or the cloud request fails, local deletion can complete before cloud deletion. The App saves the pending request and retries when the owning account has authorized access in the App. Until the server processes the request, the cloud copy may remain accessible under the existing sharing settings. You can also contact us to request deletion.
Recovery After Cloud Deletion: After cloud file deletion succeeds, Google Cloud Storage retains a recoverable deleted copy for seven days. This copy is not available through normal sharing. The seven-day recovery period starts when cloud deletion succeeds, not when an offline request is made. Our Firestore database retains a short-term version history of one hour; extended point-in-time recovery and scheduled database backups are not enabled. These are service recovery periods, not a promise that every physical copy in the provider’s underlying systems is erased at that exact time.
Face Data on Other Devices: Local face images, depth files, and face models saved by the scanning app remain until the local scan is deleted or the scanning app is uninstalled. Deleting your account does not remove local scans. Copies saved on desktop reconstruction devices or downloaded by recipients remain under the control of those device owners and must be deleted separately. UniScan Companion does not save these scan files or record the remote preview; its session-data handling is described in Section 1.
Custom Scan Categories: Custom category definitions and icon images remain on our servers until you delete the category or request their deletion.
Account Data: We retain account information while your account is active. You can permanently delete your account from the Account screen in the App.
Diagnostic Data: Firebase Crashlytics retains crash stack traces, extracted minidump data, and associated identifiers for 90 days before starting the process of removing them from live and backup systems.
Deleting your account removes the account and its active cloud data, including uploaded models, custom categories, usage records, and sharing links. Local scans remain on your device until you delete them or uninstall the App. Deleted cloud files and database history are subject to the recovery periods described above. Interrupted cloud account deletion is retried by our server recovery process.
An App Store subscription is managed by Apple and continues to renew after UniScan account deletion unless you cancel it. The App lets you open Apple’s subscription-management screen before deleting your account, while still allowing immediate deletion.
We retain only the following limited records after deletion, and only for the stated purposes and while those purposes continue to apply:
These retained records do not contain your locally stored scans or deleted cloud models.
Depending on your location (such as the EU/EEA under GDPR or California under CCPA), you may have the following rights regarding your data:
The right to access or receive a copy of the personal data we hold about you, including your account information, custom scan categories, icon images, and 3D models stored on our servers.
The right to correct inaccurate personal data.
The right to request deletion of your personal data, including account information, custom scan categories, icon images, and uploaded 3D models, subject to applicable legal exceptions.
The right to withdraw consent for data processing at any time (e.g., by revoking camera permissions in your device settings).
To exercise any of these rights, please contact us using the information provided below.
We may update this Privacy Policy from time to time to reflect changes in our practices or for legal and regulatory reasons. We will notify you of any changes by updating the “Effective Date” at the top of this policy and, if necessary, providing a notice within the App.
If you have questions, comments, or requests regarding this Privacy Policy, please contact us at:
Email: uniscan@improvismail.com
Company: Improvis LLC, operating as UniScan
Address: Armenia, Yerevan 0069, 58 Kamarak