Privacy Policy
Effective October 3, 2026
This Privacy Policy explains what information Printer Pilot collects, how it is used, and the choices you have. Printer Pilot is operated by TOPSOL Innovative Solutions (“we”, “us”). We designed the app to keep as much processing as possible on your device, and to send content to our servers only when that is needed to deliver a feature.
Printer Pilot has no sign-up and no login. The first time you open the app, it creates an account for your device automatically, so features that need our servers — AI, document chat, signature requests, and subscriptions — work without asking you for an email address or password.
Your Device Account
When the app first starts, it generates a long random secret and keeps it in your device’s secure storage (the iOS Keychain or the Android Keystore). It sends that secret to our servers once to create your account, and we store only a one-way hash of it. On Android, the app also sends the device’s Android ID, which we store only as a one-way hash, so that reinstalling the app on the same device reconnects you to the same account instead of creating a new one. On iOS, no device identifier is sent; instead the secret itself survives reinstalling the app and is carried over by an encrypted iPhone backup, which has the same effect.
- We store your account ID, the hashed secret, your platform (iOS or Android), the hashed Android ID on Android, and when the device account was created and last used.
- Each time the app connects, we keep a session record with the app’s user agent string and a one-way hash of your IP address, to keep you connected and detect suspicious session reuse.
- If you created an account with an email address and password in an earlier version of the app, it keeps working. For those accounts we also hold the email address and the password as a one-way bcrypt hash; we never store the password itself.
Information You Provide
During setup, and later under Settings → Your Profile, you can give a name and an email address. Both are optional. We use them only for features that need them, never for marketing.
- Your name is shown to the people you send a document to for signature, and is placed on contracts you create.
- Your email address is used as the reply address on signature requests and support messages, so replies reach you. It is not verified and is never used to sign in.
- A postal address and a WhatsApp number, if you add them, are stored only on your device. The address pre-fills contracts you create; the WhatsApp number pre-fills the Help & Support form.
- Your AI consent setting and your chosen backup provider are stored with your account. Theme and notification preferences stay on your device.
- Support messages: the title and description you send through Help & Support, the reply email address or WhatsApp number you enter, and your account ID, so we can answer you.
- Reports of AI responses: if you report an AI response from inside the app, the response itself, the reason you chose, your optional note, and the app version and platform are sent to our support team along with your account ID.
Information Collected Automatically
We collect a small amount of technical information to run the service, keep it secure, and fix problems.
- Your IP address, recorded against requests to rate-limited parts of the service — creating a device account, signing pages, and similar — to prevent abuse.
- Push notification tokens, only if you grant notification permission.
- Crash and error diagnostics, and a sample of performance data, through Sentry in released versions of the app, used to fix stability problems. These reports contain technical information about the error and your device, and are not linked to your name or email address.
- Usage analytics through Google Analytics for Firebase, unless you turn it off. See “Usage Analytics” below.
- Session replays through Microsoft Clarity, under the same setting as usage analytics. See “Session Replays” below.
Usage Analytics
We use Google Analytics for Firebase to understand which features people use and where they run into trouble. It records which screens you open and whether core actions — scanning, importing, printing, using an AI feature, editing a PDF, subscribing — succeeded or failed. It also records a device-generated analytics identifier, your account ID, whether AI features are turned on, general device and app information, and your approximate location derived from your IP address by Google. If you subscribe, the transaction identifier, amount, and currency are included so we can measure subscription performance.
We do not send your documents, their contents, their file names, your extracted or AI-generated text, anything you type, your email address, or your name to Google Analytics.
- Usage analytics is on by default. You can turn it off at any time from Settings → AI and Privacy. Turning it off stops collection on that device and clears the analytics identifier held on it.
- Analytics data is processed by Google as our service provider under the Google Analytics for Firebase terms, and is retained for up to 14 months.
- We do not use analytics data for advertising. The app does not collect your device’s advertising identifier.
Session Replays
We use Microsoft Clarity to see how people move through the app, so we can find screens that are confusing or broken. While usage analytics is on, Clarity records how you interact with the app — taps, swipes, scrolling, and the layout of the screens you visit — so we can replay them as a reconstruction of the session. It also records a device-generated identifier, your account ID, general device and app information, and your approximate location derived from your IP address.
All text and images on screen are masked before anything is sent, so a recording shows the shape of a screen but not your documents, their names, or anything you type. Recording stops entirely on the camera, the document viewer, print preview, the document vault, and the signature and stamp screens.
- Session replays follow the usage analytics setting in Settings → AI and Privacy. Turning it off stops recording on that device.
- Recordings are retained by Microsoft Clarity for 30 days, and aggregated usage data such as heatmaps for up to 13 months.
- Clarity data is processed by Microsoft under the Microsoft Clarity Terms of Use and the Microsoft Privacy Statement. We tell Clarity that ad storage is not consented to, and we do not use recordings for advertising.
Our Website
Our website, printerpilot.app, is hosted by Vercel and uses Microsoft Clarity to understand how visitors use its pages: clicks, scrolling, and mouse movement, along with general device and browser information and your approximate location derived from your IP address. Anything you type into the website’s demos is masked before it is sent.
Clarity runs on the website without cookies, so each page you open is recorded as a separate visit and is not linked to your other visits. The website sets no cookies of its own and shows no advertising.
Advertising and Tracking
Printer Pilot contains no advertising, no advertising SDKs, and no attribution SDKs, and it does not collect your device’s advertising identifier. We do not track you across other companies’ apps or websites, so we do not ask for permission to do so. We do not sell personal information, and we do not share it for behavioural advertising.
Documents, Scans, and OCR
Document scanning and text extraction from images (OCR) run on your device using the platform OCR engine — Apple Vision on iOS and Google ML Kit on Android. Scanned images are not uploaded for text extraction.
Your document files stay on your device, except in the cases below, where a file passes through our servers. Extracting text from a PDF and unlocking a password-protected PDF send that PDF (and, for unlocking, the password you enter) to our servers; it is processed only for that request and is not kept. Backing up to Google Drive routes the file through our servers on its way to Drive, without storing it. Backing up to iCloud does not pass through our servers at all. Sending a document for signature uploads and stores the PDF, as described under “Signature Requests”.
So that your library, search, and document chat work, the following is sent to and stored on our servers for each document you add:
- Document metadata: file name, type, source, size, MIME type, and creation date.
- The extracted text of the document, including per-page text, once text extraction finishes.
- Passages of that text and their numerical representations (“embeddings”), used to find the relevant parts of a document when you ask about it. Creating embeddings sends the passages to our embedding provider, currently OpenAI.
- AI-generated summaries, extracted fields, tags, and categories, where you have used those features.
AI Features
AI features send the content they work on to third-party AI providers for processing. They include document summaries, document chat, field extraction, smart naming and tagging, explaining a letter, reading receipts into expenses, creating flashcards and quizzes, and drafting contracts. For most features this is the text of the document concerned, along with your questions and the answers; drafting a contract also sends the party names and addresses you enter. Which provider handles a given request depends on the feature and your plan; we currently use Google (Gemini), OpenAI, and DeepInfra.
- AI features require your consent. You are asked before your first AI request, and you can turn AI features on or off at any time from Settings → AI and Privacy. Scanning, OCR, the document library, and printing all work regardless of this setting.
- We do not send your name, email address, or account ID to any AI provider — only the content being processed.
- AI providers process content under their own API terms. We do not control, and do not make any commitment on their behalf about, how those providers handle data submitted through their APIs.
- AI output is stored with your document and in your chat history so you can revisit it, and is deleted when you delete the document or chat session.
- Identical requests can be answered from a processing cache for up to 30 days instead of being sent to a provider again.
- AI output can be wrong or offensive. You can report any AI response from the screen where it appears; see “Information You Provide”.
- Read Aloud uses your device’s built-in text-to-speech voice and sends nothing to us.
Signature Requests
When you send a document for signature, the app uploads the PDF to our servers together with the signer’s name, the signer’s email address if you enter one, your optional message, and where the signature should go. We keep it so the signer can open it at the link you share, and so you can see its status.
When the signer opens the link on sign.printerpilot.app, we record the signature image they draw or type, the name they sign with, whether they signed or declined (and any reason they give), and, for each step, the time, their browser’s user agent string, and a one-way hash of their IP address, as a record of the signature. The signing page loads a PDF viewer from the cdnjs content delivery network (Cloudflare), which receives the signer’s IP address. If you entered the signer’s email address, we email them the link through Resend, showing your name and using your email address as the reply address.
- Signature requests, their PDFs, signatures, and records are kept until you delete your account. Cancelling a request or letting it expire stops the link from working.
- If you are a signer and want your information removed, contact us at the address below.
Printing
Printer Pilot prints in two ways, and neither sends your documents to our servers. It can hand a document to the platform print system — AirPrint on iOS and the Android print framework — or send it directly to a network printer on your local Wi-Fi. To find nearby printers, the app searches your local network (on iOS, it asks for local network access first). Direct printing sends the document, a job name based on the document’s name, and the name “Printer Pilot” straight from your device to the printer. Printers you save are stored on your device. We do not see what you print.
Cloud Integrations and Backup
If you connect Google Drive, we request access to the files you explicitly choose to import or export, and we store the email address of the connected Google account along with access tokens encrypted at rest. We do not browse, index, or store your full Drive library. You can disconnect at any time from Settings → Cloud Storage, which revokes our access at Google and deletes the stored connection.
iCloud backup uses your device’s own iCloud Drive container. Those files go directly from your device to Apple and are governed by Apple’s privacy policy.
Subscriptions and Payments
Subscriptions are sold and processed by Apple and Google. We never receive or store your payment card details or billing address. To confirm your subscription we send the transaction identifier or purchase token from your device to Apple or Google for verification, and we store that identifier along with your plan, renewal status, and expiry date. Apple and Google may also notify our servers when a subscription renews, is cancelled, or is refunded.
A subscription can be used on up to five devices. Restoring a purchase on another device links that device’s account to the subscription, and the linked accounts share one pool of AI credits.
Data Stored on Your Device
Your documents, their extracted text and AI output, your preferences, saved printers, signatures and stamps, and the contents of the document vault, expenses, reminders, flashcards, and the list of your signature requests are stored locally on your device. The device account secret and connection tokens are held in the iOS Keychain or Android Keystore.
Uninstalling the app removes this local data, with one exception: on iOS, the Keychain keeps the device account secret, so reinstalling the app on the same iPhone reconnects you to the same account.
Service Providers
We share data only with providers that process it on our behalf to run the Service. We may also disclose information where required by law, to enforce our Terms, or to protect the rights and safety of our users.
Our current providers are:
- Google Cloud — application hosting, databases, and logging.
- Google (Gemini) — content sent for AI features.
- OpenAI — content sent for AI features, and document passages for embeddings.
- DeepInfra — content sent for AI features.
- Google Drive — the files you explicitly import or export.
- Apple and Google Play — subscription verification and subscription status notices.
- Expo — push notification delivery.
- Sentry — crash and error diagnostics.
- Google Analytics for Firebase — app usage analytics, unless you turn it off.
- Microsoft Clarity — masked session replays of the app, unless you turn usage analytics off, and visit analytics for our website.
- Resend — delivery of support messages, AI response reports, and signature request emails.
- Cloudflare (cdnjs) — delivers the PDF viewer used on the signing page.
- Vercel — hosting for our website.
Data Retention
- Documents, extracted text, AI summaries, chat history, and document passages are kept until you delete the document or chat session, or until your account is deleted.
- Signature requests, including their PDFs and signature records, are kept until your account is deleted.
- Your device account, profile, and subscription records are kept until your account is deleted.
- Usage analytics events are retained by Google Analytics for up to 14 months.
- Session recordings are retained by Microsoft Clarity for 30 days, and aggregated usage data for up to 13 months.
- Crash reports are retained by Sentry according to its standard retention period.
- Support messages and AI response reports are kept in our support mailbox for as long as needed to handle them.
- IP-based rate-limiting records and server logs are kept for as long as needed to protect the service from abuse.
Your Rights and Choices
Depending on where you live, you may have the right to access, correct, export, or delete your personal information, to object to or restrict certain processing, and to lodge a complaint with your local data protection authority. To exercise any of these rights, email support@printerpilot.app. We will respond within 30 days.
Within the app you can:
- Change or remove your name and email address from Settings → Your Profile.
- See what is stored for your device, and delete it, from Settings → Your Data.
- Enable or disable AI features from Settings → AI and Privacy.
- Turn usage analytics and session replays on or off from Settings → AI and Privacy.
- Manage notification preferences from Settings → Notifications and in your device settings.
- Delete individual documents at any time from your library.
- Disconnect cloud providers from Settings → Cloud Storage.
Deleting Your Account
You can delete your account and its data from inside the app: open Settings → Your Data and tap Delete My Data. Deletion is immediate and cannot be undone. It removes your account and everything stored with it on our servers — documents, extracted text, AI output, chats, signature requests, profile details, device records, push tokens, cloud connections, and subscription records. The app then starts again with a new, empty device account.
If you no longer have the app, you can ask us to delete your account by email instead. Full details of what is deleted, what is kept, and how to request deletion without the app are on our account deletion page.
Security
We use encryption in transit (HTTPS) for all communication between the app and our servers. Device account secrets and passwords are stored only as one-way hashes, cloud provider access tokens are encrypted at rest, and secrets on your device are held in the platform secure keychain. Direct printing to a printer on your local network uses the printer’s own protocol, which most printers do not encrypt. No system is completely secure; contact us if you suspect unauthorized access to your account.
Children
Printer Pilot is not directed to children under 13 (or the equivalent minimum age in your region). We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, contact us so we can remove it.
International Data Transfers
Your information may be processed in countries other than your own, including the United States. Where personal data is transferred out of your region, we rely on the safeguards offered by our service providers, including standard contractual clauses where applicable.
Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes we will update the effective date above and, where appropriate, notify you in the app. Your continued use of Printer Pilot after an update means you accept the revised policy.
Contact Us
If you have questions about this Privacy Policy or how your data is handled, email support@printerpilot.app or use Settings → Help & Support in the app.