The short version
- Your photos, videos, contacts, calendar events and Secret Vault never leave your iPhone. We cannot see them.
- Scratchy has no accounts, shows no ads and does not track you across other companies’ apps or websites.
- A leak check you start sends only what is needed to the Have I Been Pwned service. Passwords are checked without ever being sent.
- To run subscriptions and understand which campaigns bring people to the app, we use Adapty and AppsFlyer. They receive technical and purchase data, never your library.
01Who we are
Scratchy (“the App”) is provided by RESPONSE GT LIMITED (“we”, “us”). We are responsible for the limited personal data described in this policy. You can reach us at [email protected].
02Data that stays on your iPhone
Scratchy’s main features work entirely on your device, using Apple frameworks such as Photos, Vision, Contacts and EventKit. None of the following is sent to us or to anyone else.
- Photos and videos. With your permission, Scratchy reads your library to find duplicates, similar and blurry shots, screenshots, documents, large videos and Live Photos. The results of this analysis (such as image fingerprints and sizes) are stored on your device to make later scans faster.
- Contacts. If you open the contacts cleaner, Scratchy reads your contacts to find duplicate and incomplete cards. Merges and deletions happen in your device’s Contacts, only after you confirm.
- Calendar. If you open the calendar cleaner, Scratchy reads past events so you can remove old ones. Nothing is deleted until you confirm.
- Secret Vault. Items you move to the vault are encrypted with AES-GCM using a key stored in your device’s Keychain. They are excluded from backups and can be opened only with Face ID, Touch ID or your passcode. Face ID data is handled by iOS and is never available to the App.
- Settings and history. Your preferences, cleanup history, privacy checklist and the list of email addresses you monitor are stored on your device.
If your library uses iCloud Photos, iOS may download originals from Apple’s servers when Scratchy displays or analyzes them. That transfer is handled by Apple under Apple’s privacy policy.
03Data that leaves your iPhone
Leak checks you start
- Email Breaches. When you check an email address, that address is sent over an encrypted connection to the Have I Been Pwned service (haveibeenpwned.com), which returns the known breaches it appears in. It is not sent to us. The Have I Been Pwned privacy policy applies to that request.
- Password Check. Your password is hashed on your device, and only the first 5 characters of that hash are sent to the Pwned Passwords service. The service returns a list of possible matches and the comparison happens on your iPhone (a technique called k-anonymity). Your password and its full hash never leave your device.
- Latest Breaches. Scratchy downloads the public list of recent breaches from Have I Been Pwned. No personal data is sent.
Service providers
| Provider | Why | What it receives |
|---|---|---|
| Apple | App distribution, payments, optional crash reports | Purchases are processed by Apple; we never receive your payment details. If you choose to share analytics with developers in iOS Settings, Apple provides us with anonymous crash and usage reports. |
| Adapty (Adapty Tech Inc.) | Showing subscription plans, processing and validating purchases, managing Pro access | A random app user ID, the identifier for vendor (IDFV), device model, iOS and app version, language and region, IP address (to determine country), and your subscription and purchase history (product, price, currency, dates, trial status). |
| AppsFlyer (AppsFlyer Ltd.) | Measuring which marketing campaigns lead to installs and subscriptions | The IDFV, an AppsFlyer device ID, IP address, device model, iOS and app version, and events such as install, app open, trial start and subscription. |
We do not request access to the advertising identifier (IDFA), and Scratchy does not show the App Tracking Transparency prompt. Adapty and AppsFlyer process data on our behalf and under their own privacy policies.
04What we don’t do
- We don’t sell or rent personal data.
- We don’t show ads or build advertising profiles.
- We don’t collect your name, email or phone number, and there is no account to create.
- We don’t access the content of your photos, videos, contacts, calendar or vault.
05Why we process data
If you are in the European Economic Area, the United Kingdom or a similar jurisdiction, we rely on these legal bases:
- Performance of a contract: providing the App and your subscription.
- Legitimate interests: understanding how people find the App, preventing fraud and keeping the App reliable.
- Your request: leak checks happen only when you start them.
06Permissions
Scratchy asks for access to Photos, and when you use the related features, Contacts, Calendars, Face ID and notifications. Each permission is used only for the feature that needs it. You can change or revoke access at any time in iOS Settings → Scratchy.
07How long data is kept
Data stored on your device stays there until you delete it in the App or delete the App. Note that deleting the App permanently deletes the contents of the Secret Vault. Data held by our service providers is kept only as long as needed for the purposes above and is then deleted or anonymized, except where purchase records must be kept longer for tax and accounting reasons.
08International transfers
Our service providers may process data in the United States and other countries. Where required, these transfers are protected by appropriate safeguards such as the European Commission’s Standard Contractual Clauses.
09Your rights
Depending on where you live, you may have the right to access, correct, delete or receive a copy of your personal data, to object to or restrict certain processing, and to withdraw consent. You also have the right to complain to your local data protection authority. California residents: we do not sell personal information or share it for cross-context behavioral advertising.
To make a request, email [email protected]. Because Scratchy has no accounts, we may ask for information from your device to locate your data, and we will tell you exactly what we need.
10Security
We use encryption in transit for every network request the App makes, keep Secret Vault content encrypted at rest, and limit the data we work with to what is described here. No method of transmission or storage is completely secure, but we work to protect your information.
11Children
Scratchy is not directed to children under 13, and we do not knowingly collect personal data from them. If you believe a child has provided us personal data, contact us and we will delete it.
12Changes to this policy
We may update this policy as the App changes. The current version is always available at this address, and the effective date above shows when it was last changed.
13Contact
RESPONSE GT LIMITED
Email: [email protected]