Privacy Policy
Dokument (“the app”, “we”, “us”) is a private, offline document scanner and PDF vault, published by Handrow Studio. This policy explains what the app does with data — which turns out to be a very short story.
Last updated: 29 July 2026
Dokument does not collect any data. At all.
There is no account and no sign-in. The app cannot send your documents anywhere, because it has no permission to use the internet — the network permission is deliberately removed from the Android app, so the operating system itself prevents any connection. This is not something you have to take on trust; it is enforced by Android.
1. What we collect
Nothing. We do not collect, transmit, sell or share any personal information. Dokument has:
- No user accounts and no sign-in of any kind
- No advertising and no ad networks
- No analytics and no crash reporting
- No third-party SDKs that gather data for us
- No access to your location, contacts or microphone
- No in-app purchases
2. How scanning and text recognition work
Camera capture is handled by your device’s own document scanner component (Google Play services’ scanner on Android, Apple VisionKit on iOS). The pages it captures are handed straight back to Dokument and stay on your device. Text recognition runs entirely on-device using Google ML Kit — your pages are never uploaded to read them.
To be precise about the boundary: the scanner and recognition components are provided by Google Play services / the operating system, which may perform their own operational housekeeping under Google’s privacy policy. Dokument itself sends nothing, and your document images and text are processed locally.
3. What is stored on your device
Everything the app makes lives in its private storage on your phone and never leaves it: your scanned PDFs, page thumbnails, the text recognized inside your scans (kept so you can search them), your signature only if you turn on “Save for reuse” when signing, and your settings — theme, sort order, auto-enhance, and the app-lock preferences. Device backups of this vault are deliberately disabled, so copies do not slip into cloud backups either.
4. Permissions
The Android app requests only biometric permission, and only if you turn on Require unlock. Your fingerprint or face is checked by the operating system; Dokument only learns “unlocked” or “not unlocked” and never sees biometric data. Camera and photo access are handled by the system scanner and picker components, so the app itself holds no camera permission.
5. Sharing and export
When you share a PDF (or export your vault as a ZIP), Dokument hands the file to your device’s own share menu. We never receive the file and do not see where it goes. Whichever app you choose handles it under that app’s own privacy policy. The link to our studio site in Settings simply opens your browser.
6. Deleting your data
Delete any document inside the app (with a short undo window), or remove everything by uninstalling the app. Because nothing is ever uploaded, there is nothing on our side to request, correct or delete — we do not have a copy and could not obtain one.
7. Children’s privacy
Dokument is a general-audience utility and is not directed at children. Because the app collects no personal information from anyone, it collects none from children.
8. Changes to this policy
If a future version of Dokument ever collects anything, this page will be updated before that version is released, and the change will be described in the app’s release notes on Google Play.
9. Contact
Questions about this policy: Handrow Studio — handrowcahyadi@gmail.com.