Privacy Policy for the App “DocuHub”

Last Updated: 24.09.2025


1. Introduction and Scope

This Privacy Policy informs you about the nature, scope, and purpose of the processing of personal data (hereinafter “Data”) within our mobile app “DocuHub” (hereinafter “App”). The publisher of this app is a private individual operating under the name Unifyzer.

Protecting your privacy is the foundation of our App, which was developed according to the principles of “Privacy by Design” and “Privacy by Default.” The core functions of the App—such as managing documents and recognizing text—are performed exclusively on your device. Your documents and the data extracted from them are not transmitted to us.

This policy outlines which data is processed locally on your device, what limited data is processed by third-party providers for functionality and security, and explains your rights under the EU General Data Protection Regulation (GDPR) and relevant U.S. data protection laws, such as the California Privacy Rights Act (CPRA).


2. Controller and Point of Contact for Data Protection

The controller responsible for data processing within the meaning of the GDPR is Unifyzer.

Our full contact details, including our official postal address, can be found in our Website Imprint (Legal Notice).

For all data protection-related inquiries—particularly for exercising your rights—you can reach us directly at the following email address, which serves as your central point of contact:

Email: docuhub@unifyzer.de

We strive to respond to inquiries without undue delay and at the latest within the statutory period of one month.


3. No Obligation to Appoint a Data Protection Officer

a) Legal Situation in the European Economic Area (EEA)
Pursuant to Art. 37 GDPR and relevant national laws (such as § 38 of the German Federal Data Protection Act - BDSG), we are not currently obligated to appoint a Data Protection Officer. Our core activity consists neither of large-scale processing of special categories of personal data (Art. 9 GDPR) nor of operations that require large-scale, regular, and systematic monitoring of data subjects. An obligation to appoint may arise under certain circumstances, for instance, if a Data Protection Impact Assessment (Art. 35 GDPR) becomes necessary. We continuously evaluate these criteria. Should an obligation to appoint a Data Protection Officer arise, we will promptly designate a qualified individual and publish their contact details here.

b) Legal Situation in the USA
Under U.S. law, there is no uniform federal requirement to appoint a “Data Protection Officer.” However, certain federal or state laws (e.g., CCPA/CPRA) may establish specific responsibilities. We ensure compliance with all applicable regulations through ongoing review.


a) Data Processing on Your Device (Core Functionality)

The App processes the following data exclusively locally within your device’s secured storage. This data never leaves your device to be sent to our servers or third parties, unless you explicitly initiate an action like a cloud backup.

  • Type of Data:
    • Images you capture using the camera function or import from your photo library.
    • Text data extracted from these images via Optical Character Recognition (OCR).
    • Metadata you create, such as categories, keywords, correspondents, notes, and reminders.
    • This content may potentially contain personal or sensitive personal information, depending on the documents you choose to manage.
  • Purpose of Processing: To enable the core features of the App: capturing, organizing, searching (including full-text search), and managing your documents, as well as setting reminders.
  • Legal Basis (GDPR): The processing is necessary for the performance of the user agreement to provide the App’s features (Art. 6(1)(b) GDPR). You actively initiate this processing by using the App.
  • Retention Period: This data is stored locally within the App’s private storage on your device until you manually delete it or uninstall the App. The automatic document shredder feature allows you to configure automatic deletion after a set period.

b) Optional Cloud Backup (User-Initiated Transfer)

The App offers an optional feature to back up your document database to your personal cloud storage.

  • Type of Data: The App’s entire local database, which contains all data listed in Section 4.a). The App provides a feature to encrypt this backup file with a password of your choice before it is transferred.
  • Purpose of Processing: To allow you to safeguard your data against device loss or damage and to restore it on a new device.
  • Third-Party Provider: This feature uses the official APIs for services like Google Drive. When you use this feature, you transfer the backup file to your own account at the chosen cloud provider. The processing of your data by that provider is then subject to their privacy policy.
  • Legal Basis (GDPR): Your explicit consent, which you provide by actively initiating the backup process (Art. 6(1)(a) GDPR). You can revoke this consent at any time by ceasing to use this feature.
  • Controller: You and the respective cloud provider (e.g., Google LLC for Google Drive) are the controllers for the data stored in your cloud account.

c) Data Processing by Third Parties (Text Recognition Service)

For the on-device text recognition functionality, we integrate the “ML Kit” Software Development Kit (SDK) from Google.

  • Content Processing (On-Device): The processing of your images and the extraction of text occur entirely on your device. According to Google, neither your images nor the recognized text are transmitted to Google’s servers.
  • Diagnostic Data Collection (by Google): To maintain and improve its services, Google’s ML Kit collects limited diagnostic data. According to Google’s data disclosure information, this includes:
    • Performance metrics (e.g., latency, success rate of API calls).
    • Information about API usage (e.g., which API and version are used).
    • A non-user-specific installation identifier to count usage.
    • Device type and crash logs.
  • Purpose of Processing: To ensure the stability, functionality, security, and improvement of the ML Kit service provided by Google.
  • Legal Basis (GDPR): Our legitimate interest in using a functional, state-of-the-art, and stable third-party library to provide the App’s core OCR feature (Art. 6(1)(f) GDPR).
  • Data Controller: For this diagnostic data collection, Google (Google Ireland Limited for users in the EEA/UK/Switzerland, or Google LLC for all other users) is the independent controller. For more information, please refer to the Google Privacy Policy.

d) Data Processing for Contact and Support

  • Type of Data: Your email address and any other information you voluntarily provide to us in your inquiry.
  • Purpose of Processing: To process and respond to your support or general inquiries.
  • Legal Basis (GDPR): The processing is necessary to handle your request (Art. 6(1)(b) GDPR) or based on our legitimate interest in providing efficient user support (Art. 6(1)(f) GDPR).
  • Retention Period: Your inquiries will be deleted after the matter is fully resolved, provided there are no legal retention obligations.

5. App Permissions

To provide its full functionality, the App requires access to certain device functions. These permissions are requested before first use and can be managed or revoked by you at any time in your device’s settings.

  • Camera: To capture images of documents directly within the App.
  • Files and Media / Storage Access: To import existing document files from your device’s storage and to save the local app database.
  • Notifications: To display a notification for reminders you have set for specific documents.
  • Internet Access: Required for the optional cloud backup feature and for Google’s ML Kit to download language models and transmit the diagnostic data described in Section 4.c). The App’s core document management features work offline.

6. Data Disclosure and Transfer to Third Countries

We do not disclose your personal data to third parties, with the exception of the limited diagnostic data collected by Google ML Kit as described in Section 4.c).

The transfer of this diagnostic data to Google’s servers, which may be located in the USA, is protected by appropriate safeguards. Google LLC is certified under the EU-U.S. Data Privacy Framework, which the EU Commission has recognized as providing an adequate level of data protection through an adequacy decision. This serves as the legal basis for the transfer.


7. Your Rights as a Data Subject

You have several rights regarding your personal data.

Rights under GDPR (for users in the EEA, UK, and Switzerland):

  • Right of Access (Art. 15 GDPR): You have the right to request information about your data. As all content data is stored locally, you can access it directly in the App at any time.
  • Right to Rectification (Art. 16 GDPR): You can correct inaccurate data. You can edit your documents and associated metadata directly in the App.
  • Right to Erasure (Art. 17 GDPR): You have the right to request the deletion of your data. You can delete individual documents or all data at any time within the App or by clearing the App’s data/uninstalling it.
  • Right to Restriction of Processing (Art. 18 GDPR): You can request the restriction of the processing of your data. Regarding email inquiries sent to us (Chapter 4.d), this would mean that we would store your inquiry but not process it further (except for storage) until the matter is resolved.
  • Right to Data Portability (Art. 20 GDPR): You can export a copy of your data via the backup function.
  • Right to Object (Art. 21 GDPR): You have the right to object to the processing of your data based on our legitimate interests (i.e., the integration of ML Kit for diagnostic purposes) on grounds relating to your particular situation.
  • Right to Withdraw Consent (Art. 7(3) GDPR): Where processing is based on consent (e.g., for cloud backups), you can withdraw it at any time with future effect by no longer using the feature.
  • Right to Lodge a Complaint with a Supervisory Authority (Art. 77 GDPR).

To exercise your rights concerning the local data, you can use the App’s built-in features. For inquiries regarding the diagnostic data collected by Google ML Kit, please contact Google directly. For all other inquiries, please contact us.

Additional Rights for Residents of U.S. States (e.g., California under CPRA):

  • Right to Know/Access: The right to know what personal information is collected, used, and disclosed. This policy provides this information.
  • Right to Delete: The right to request the deletion of your personal information. As described above, you can delete your data directly within the App.
  • Right to Correct: The right to correct inaccurate personal information, which you can do directly within the App.
  • Right to Opt-Out of Sale/Sharing: We do not “sell” or “share” (for cross-context behavioral advertising) your personal information.
  • Right to Limit Use of Sensitive Personal Information: This App was designed so that any sensitive personal information you process remains on your device. We do not use it for any purpose other than providing the App’s core functionality.
  • Right to Non-Discrimination: We will not discriminate against you for exercising any of your privacy rights.

8. Data Security

By design, all your sensitive document data is stored within the App’s sandboxed environment on your device. The security of this data is reinforced by the security mechanisms of your operating system. We strongly recommend that you secure your device with a strong passcode or biometric authentication. For the optional cloud backup, the App offers client-side password encryption to protect your data before it is transferred. You are solely responsible for the secure management of that password.


9. Children’s Privacy

This App is not directed at children under the age of 16 (in the EEA/UK) or 13 (in the U.S.), and we do not knowingly collect personal information from children. If a parent or guardian becomes aware that their child has provided us with data (e.g., through a support request), they should contact us so that we can delete such information promptly.


10. Changes to this Privacy Policy

We reserve the right to amend this Privacy Policy to ensure it always complies with current legal requirements or to implement changes to our services. In the event of material changes, we will inform you in an appropriate manner, for example, via a notice within the App.