RAKUNA HELP CENTER

RAKUNA SCAN

Rakuna Scan Privacy Policy

Introduction

This Privacy Policy explains how Rakuna ("Rakuna," "we," "us," or "our") handles information when you use the Rakuna Scan mobile application and its related authentication, export verification, subscription, and optional Cloud AI services (collectively, "Rakuna Scan").

This policy applies specifically to Rakuna Scan. Rakuna Recruit and other Rakuna products may collect different information and are covered by their own privacy notices.

Scope and roles

Rakuna Scan is designed for people who collect contact information during recruiting and professional events. The app user decides which resumes and contacts to capture, how to use them, and where to export them. An employer or organization using the app may also be responsible for that processing under applicable law.

Only collect a resume or contact when you have authority to do so. If your information was captured by a recruiter, contact that recruiter or their organization first about copies held only on their device. Rakuna generally cannot access or retrieve local-only records.

Information we process

1. Content stored on your device

Depending on how you use the app, local content may include:

  • Resume or document photos, selected images, locally recognized text, QR code data, and attachments.
  • Names, email addresses, phone numbers, notes, and other fields that you enter or extract from a document.
  • Contacts you choose to import, create, or save through device contact features.
  • Interactions, custom form templates, drafts, and generated CSV or ZIP export files.

Local OCR and supported on-device AI features process content on the device. Rakuna does not receive that content solely because you scanned or edited it.

2. Account and sign-in information

You may use a guest account or sign in with Apple or Google. We process a Firebase user identifier and the sign-in provider. If the provider makes them available, we may also receive your name, email address, provider identifier, and profile information. Rakuna does not receive your Apple or Google password.

3. Export email and consent preferences

Free export may require a reachable email address and a one-time verification code. We process the email, normalized email, verification status and time, general email category, consent choice, and daily export usage. One-time codes are protected and are not stored as readable codes.

Export files are generated locally. When you save or share an export to email, cloud storage, messaging, or another app, that destination receives the file at your direction and applies its own privacy practices.

4. Subscription and purchase information

For Rakuna Scan Pro, we process subscription identifiers and status information such as product, store, entitlement, purchase ownership, expiration, renewal, refund, and environment. Apple or Google processes the payment. Rakuna and RevenueCat do not receive your full payment card details from the store.

5. Optional Cloud AI information

Cloud AI is off by default. If you enable it, Rakuna Scan may send a selected resume image to Rakuna's secured Google Cloud service when local recognition needs assistance. The service processes the image to return proposed contact fields such as name, email, and phone number.

Rakuna Scan does not write the request image or returned contact content to Firestore. The cloud service keeps only limited quota, request-status, and abuse-prevention metadata. Google may process the request as our service provider under its applicable agreements.

6. Usage, device, and security metadata

We process limited operational data needed to run and protect the service. This may include platform, app version, authentication provider, first and last activity dates, aggregate active days, aggregate contacts captured or exported, request timestamps, pseudonymous or hashed device/request identifiers, quota usage, subscription verification state, and App Check attestation results. Hosting providers may also generate network and security logs, including IP address and request diagnostics.

These operational records do not contain locally stored resume images, candidate notes, or the contents of exported files.

7. Optional marketing contact

The marketing checkbox is off by default. If you expressly allow contact, Rakuna may provide its sales team with your verified email, general email category, aggregate capture/export/activity counts, and first or last activity dates through Rakuna's internal Slack workspace. You can withdraw this consent in Settings. Withdrawal stops future sales routing but does not automatically remove messages already delivered to the workspace.

8. Communications with Rakuna

If you contact Support or our Data Protection Officer, we process the information in your message and any attachments you choose to send so we can respond and maintain appropriate records.

How we use information

We use the information described above to:

  • Authenticate guest, Apple, and Google identities.
  • Verify export email ownership and enforce export quotas.
  • Provide, restore, and validate Rakuna Scan Pro access.
  • Provide optional Cloud AI enhancement after you enable it.
  • Prevent fraud, replay, quota abuse, and unauthorized access.
  • Diagnose failures and understand aggregate app usage without uploading local candidate records.
  • Contact you about Rakuna Recruit only when you have opted in.
  • Comply with law, enforce our terms, and protect users and Rakuna.

Legal bases

Where applicable law requires a legal basis, we rely on performance of our agreement to provide requested app services; your consent for optional Cloud AI and marketing contact; our legitimate interests in security, service reliability, and limited aggregate measurement; and compliance with legal obligations. You may withdraw consent at any time without affecting processing that occurred before withdrawal.

Service providers and sharing

We do not sell or rent personal information collected through Rakuna Scan. We disclose limited information to service providers only for the purposes described in this policy:

Provider Purpose Information involved
Firebase and Google Cloud Authentication, server functions, security, quotas, and optional Cloud AI Account, operational metadata, verified email, subscription state, and an AI image only when enabled
Apple and Google Sign-in, app distribution, payment, and subscription management Provider account and store transaction information
RevenueCat Subscription entitlement verification and restoration Firebase-linked customer identifier and subscription history/status
Twilio SendGrid Delivery of one-time email verification codes Verified export email and delivery metadata
Slack Internal sales follow-up only after marketing opt-in Verified email and limited aggregate usage/activity information
User-selected destinations Saving or sharing exported files The export file you choose to send

We may also disclose information when required by law, to protect legal rights or safety, or as part of a corporate transaction subject to appropriate safeguards and notice where required.

International processing

Rakuna and its providers may process information in countries other than where you live. Privacy laws may differ in those countries. Where required, we use appropriate contractual and legal safeguards for international transfers.

Storage and retention

Information Typical retention
Local scans, contacts, drafts, templates, and app-sandbox exports Until you clear them, delete the account, or remove the app. Copies saved or shared elsewhere remain with that destination.
One-time email verification codes Up to 10 minutes; related abuse-prevention limits may remain up to 30 days.
Export authorizations Up to 15 minutes.
Account-merge and AI request-status records Up to 24 hours.
Free-export quota records Up to 7 days.
Rate-limit records Up to 30 days.
Cloud AI quota metadata Up to 45 days.
RevenueCat webhook event metadata Up to 90 days; it does not contain resume or contact content.
Account profile and subscription state While the account is active, until you delete it, or as needed for legal, security, and transaction-record obligations.

Other service-provider records are retained only as needed to provide the service and meet applicable business, security, and legal requirements. You may contact us to request deletion where applicable.

How we protect information

We use technical and organizational safeguards appropriate to the nature of the information, including encrypted network transport, platform data protection, server-side authorization, App Check, restricted service identities, signed subscription/export state, per-user data separation, rate limits, and security testing.

No method of storage or transmission is completely secure. You are responsible for protecting your device, store account, and sign-in credentials and for choosing secure export destinations.

Your choices and privacy rights

Rakuna Scan provides the following controls:

  • Edit or delete individual local records.
  • Export selected records to a destination you choose.
  • Disable Cloud AI in Settings at any time.
  • Keep marketing contact off or revoke it in Settings.
  • Clear the current local workspace without deleting the account.
  • Delete a guest, Apple, or Google account from Settings.
  • Manage or cancel a store subscription from Settings or the Pro screen.

Depending on your location, you may have rights to request access, correction, deletion, restriction, objection, or portability of personal information held by Rakuna; withdraw consent; and complain to a data protection authority. We may need to verify your identity before completing a request.

Because candidate records are generally stored only on the app user's device, Rakuna may not possess a server copy to provide, correct, or erase. In that case, the app user or their organization controls the local record.

Account deletion and subscriptions

Clear All Data removes the current account's local workspace. Delete Account removes the local workspace and requests deletion of the associated Firebase profile, verified email and consent fields, direct account metadata, RevenueCat customer, and Firebase Authentication identity. Sign in with Apple authorization is also revoked when applicable.

Deleting a Rakuna Scan account does not cancel an Apple App Store or Google Play subscription. To stop renewal, use Manage or cancel subscription in Settings or on the Pro screen before deleting the account. A store cancellation normally leaves paid access available until the end of the current billing period unless the store indicates otherwise.

Children's privacy

Rakuna Scan is a professional recruiting utility and is not directed to children. Do not use the app if you are below the age at which you may consent to data processing in your jurisdiction, unless use is authorized by a parent, guardian, or other lawful basis.

Changes to this policy

We may update this policy as Rakuna Scan, our providers, or legal requirements change. We will publish the revised policy and update the date at the top. Where required, we will provide additional notice before a material change takes effect.

Contact us

For product or privacy questions, contact support@rakuna.co. To exercise a data protection right or contact Rakuna's Data Protection Officer, email dpo@rakuna.co.