RAKUNA SCAN
Rakuna Scan Privacy Policy
Introduction
This Privacy Policy explains how Rakuna ("Rakuna," "we," "us," or "our") handles information when you use the Rakuna Scan mobile application and its related authentication, export verification, subscription, and optional Cloud AI services (collectively, "Rakuna Scan").
This policy applies specifically to Rakuna Scan. Rakuna Recruit and other Rakuna products may collect different information and are covered by their own privacy notices.
Scope and roles
Rakuna Scan is designed for people who collect contact information during recruiting and professional events. The app user decides which resumes and contacts to capture, how to use them, and where to export them. An employer or organization using the app may also be responsible for that processing under applicable law.
Only collect a resume or contact when you have authority to do so. If your information was captured by a recruiter, contact that recruiter or their organization first about copies held only on their device. Rakuna generally cannot access or retrieve local-only records.
Information we process
1. Content stored on your device
Depending on how you use the app, local content may include:
- Resume or document photos, selected images, locally recognized text, QR code data, and attachments.
- Names, email addresses, phone numbers, notes, and other fields that you enter or extract from a document.
- Contacts you choose to import, create, or save through device contact features.
- Interactions, custom form templates, drafts, and generated CSV or ZIP export files.
Local OCR and supported on-device AI features process content on the device. Rakuna does not receive that content solely because you scanned or edited it.
2. Account and sign-in information
You may use a guest account or sign in with Apple or Google. We process a Firebase user identifier and the sign-in provider. If the provider makes them available, we may also receive your name, email address, provider identifier, and profile information. Rakuna does not receive your Apple or Google password.
3. Export email and consent preferences
Free export may require a reachable email address and a one-time verification code. We process the email, normalized email, verification status and time, general email category, consent choice, and daily export usage. One-time codes are protected and are not stored as readable codes.
Export files are generated locally. When you save or share an export to email, cloud storage, messaging, or another app, that destination receives the file at your direction and applies its own privacy practices.
4. Subscription and purchase information
For Rakuna Scan Pro, we process subscription identifiers and status information such as product, store, entitlement, purchase ownership, expiration, renewal, refund, and environment. Apple or Google processes the payment. Rakuna and RevenueCat do not receive your full payment card details from the store.
5. Optional Cloud AI information
Cloud AI is off by default. If you enable it, Rakuna Scan may send a selected resume image to Rakuna's secured Google Cloud service when local recognition needs assistance. The service processes the image to return proposed contact fields such as name, email, and phone number.
Rakuna Scan does not write the request image or returned contact content to Firestore. The cloud service keeps only limited quota, request-status, and abuse-prevention metadata. Google may process the request as our service provider under its applicable agreements.
6. Usage, device, and security metadata
We process limited operational data needed to run and protect the service. This may include platform, app version, authentication provider, first and last activity dates, aggregate active days, aggregate contacts captured or exported, request timestamps, pseudonymous or hashed device/request identifiers, quota usage, subscription verification state, and App Check attestation results. Hosting providers may also generate network and security logs, including IP address and request diagnostics.
These operational records do not contain locally stored resume images, candidate notes, or the contents of exported files.
7. Optional marketing contact
The marketing checkbox is off by default. If you expressly allow contact, Rakuna may provide its sales team with your verified email, general email category, aggregate capture/export/activity counts, and first or last activity dates through Rakuna's internal Slack workspace. You can withdraw this consent in Settings. Withdrawal stops future sales routing but does not automatically remove messages already delivered to the workspace.
8. Communications with Rakuna
If you contact Support or our Data Protection Officer, we process the information in your message and any attachments you choose to send so we can respond and maintain appropriate records.
How we use information
We use the information described above to:
- Authenticate guest, Apple, and Google identities.
- Verify export email ownership and enforce export quotas.
- Provide, restore, and validate Rakuna Scan Pro access.
- Provide optional Cloud AI enhancement after you enable it.
- Prevent fraud, replay, quota abuse, and unauthorized access.
- Diagnose failures and understand aggregate app usage without uploading local candidate records.
- Contact you about Rakuna Recruit only when you have opted in.
- Comply with law, enforce our terms, and protect users and Rakuna.
Legal bases
Where applicable law requires a legal basis, we rely on performance of our agreement to provide requested app services; your consent for optional Cloud AI and marketing contact; our legitimate interests in security, service reliability, and limited aggregate measurement; and compliance with legal obligations. You may withdraw consent at any time without affecting processing that occurred before withdrawal.
Storage and retention
| Information | Typical retention |
|---|---|
| Local scans, contacts, drafts, templates, and app-sandbox exports | Until you clear them, delete the account, or remove the app. Copies saved or shared elsewhere remain with that destination. |
| One-time email verification codes | Up to 10 minutes; related abuse-prevention limits may remain up to 30 days. |
| Export authorizations | Up to 15 minutes. |
| Account-merge and AI request-status records | Up to 24 hours. |
| Free-export quota records | Up to 7 days. |
| Rate-limit records | Up to 30 days. |
| Cloud AI quota metadata | Up to 45 days. |
| RevenueCat webhook event metadata | Up to 90 days; it does not contain resume or contact content. |
| Account profile and subscription state | While the account is active, until you delete it, or as needed for legal, security, and transaction-record obligations. |
Other service-provider records are retained only as needed to provide the service and meet applicable business, security, and legal requirements. You may contact us to request deletion where applicable.
How we protect information
We use technical and organizational safeguards appropriate to the nature of the information, including encrypted network transport, platform data protection, server-side authorization, App Check, restricted service identities, signed subscription/export state, per-user data separation, rate limits, and security testing.
No method of storage or transmission is completely secure. You are responsible for protecting your device, store account, and sign-in credentials and for choosing secure export destinations.
Your choices and privacy rights
Rakuna Scan provides the following controls:
- Edit or delete individual local records.
- Export selected records to a destination you choose.
- Disable Cloud AI in Settings at any time.
- Keep marketing contact off or revoke it in Settings.
- Clear the current local workspace without deleting the account.
- Delete a guest, Apple, or Google account from Settings.
- Manage or cancel a store subscription from Settings or the Pro screen.
Depending on your location, you may have rights to request access, correction, deletion, restriction, objection, or portability of personal information held by Rakuna; withdraw consent; and complain to a data protection authority. We may need to verify your identity before completing a request.
Because candidate records are generally stored only on the app user's device, Rakuna may not possess a server copy to provide, correct, or erase. In that case, the app user or their organization controls the local record.
Account deletion and subscriptions
Clear All Data removes the current account's local workspace. Delete Account removes the local workspace and requests deletion of the associated Firebase profile, verified email and consent fields, direct account metadata, RevenueCat customer, and Firebase Authentication identity. Sign in with Apple authorization is also revoked when applicable.
Deleting a Rakuna Scan account does not cancel an Apple App Store or Google Play subscription. To stop renewal, use Manage or cancel subscription in Settings or on the Pro screen before deleting the account. A store cancellation normally leaves paid access available until the end of the current billing period unless the store indicates otherwise.
Children's privacy
Rakuna Scan is a professional recruiting utility and is not directed to children. Do not use the app if you are below the age at which you may consent to data processing in your jurisdiction, unless use is authorized by a parent, guardian, or other lawful basis.
Changes to this policy
We may update this policy as Rakuna Scan, our providers, or legal requirements change. We will publish the revised policy and update the date at the top. Where required, we will provide additional notice before a material change takes effect.
Contact us
For product or privacy questions, contact support@rakuna.co. To exercise a data protection right or contact Rakuna's Data Protection Officer, email dpo@rakuna.co.