Overview
Scanrivo is an Android barcode workflow app from Cerit Apps. It does not create a Scanrivo user account. Your profiles, scanned records, batches, and send status are stored on your device. When you use a configured sending or reader profile, the app communicates directly with the HTTPS endpoint you entered. Advertising and optional ad-removal purchases involve Google services described below.
On your device
The app stores profile settings, barcode values and formats, quantities, notes, batches, timestamps, send attempts, and related status in a local Room database. Profile API keys or bearer tokens are held separately and encrypted with a key from Android Keystore. The Android app disables automatic backup and device transfer of its app data.
If you choose to export profiles, the exported JSON contains profile configuration but excludes separately stored credentials. The exported file is then handled by the location and apps you choose to share it with.
Camera permission is used when you open the camera scanner. Barcode recognition uses the embedded ML Kit model on the device; Scanrivo does not send camera frames to its billing service.
Your configured endpoint
Scanrivo sends barcode records and any profile-configured fields directly to the HTTPS endpoint you provide. Depending on your profile, those fields can include barcode content and format, a record ID, quantity, timestamp, note, and batch ID. A reader profile can also send a barcode lookup and display the endpoint's response. If configured, an API key or bearer token is included for that endpoint.
The operator of that endpoint controls its processing, storage, and deletion practices. Review its privacy terms before connecting it. Scanrivo's purchase verification service does not receive barcode, profile, reader, or endpoint data.
Ads and consent
The free app uses Google AdMob Next-Gen SDK for advertising and Google User Messaging Platform (UMP) for applicable ad privacy choices. According to Google's SDK disclosure, the ads SDK automatically collects and shares the device IP address, product interactions (such as launches, taps, and video views), diagnostic information, and device or account identifiers (including the Android advertising ID where available) for advertising, analytics, and fraud prevention. IP address may indicate an approximate location. These data are transmitted to Google using TLS.
The app offers an Ad privacy options control in settings to revisit available UMP choices. You can also manage or reset the advertising ID in Android settings. Buying the optional ad-removal product removes in-app ads once the purchase is verified; it does not undo data already processed by Google.
Purchase and review access
Google Play handles the purchase of Remove ads. To verify or restore it, the app sends its package name, product ID, and Play purchase token to the separate Scanrivo billing API over HTTPS. The API checks the purchase with Google Play. Its database stores a SHA-256 digest of the token plus purchase state, acknowledgement and void status, and timestamps. It does not store the raw purchase token as the purchase identifier or receive barcode work data. Google Play notifications and voided-purchase checks can update the entitlement state.
App reviewers who enter a provided review code send that code to the same API over HTTPS. The API compares its SHA-256 digest with a configured digest, limits attempts by source IP, and does not store the code or create a purchase record. The app stores only the resulting access expiry on the device. Review access expires automatically and is separate from a Play purchase.
Your choices and deletion
- You can stop using a configured endpoint, edit a profile, or manage local work within the app.
- Clearing Scanrivo's app storage or uninstalling the app removes its local app data from that device. Exported files and data already sent to your chosen endpoint are separate and must be managed where they are held.
- For a request about billing-service purchase records or this website, email us below. Include the request details, but do not email purchase tokens, API keys, or barcode records unless needed to resolve your issue.
This site serves public static pages without a login or client-side analytics script. The web host may process standard connection information, such as IP address, to deliver and secure the pages.
Contact and updates
Contact Cerit Apps at ceritahmt@gmail.com for privacy questions or requests. We may update this policy as the app and its integrations change; the date above identifies this version.
For context: Google Play user data policy and Play app review guidance.