PDF Scan Goat

Privacy

Your data.

Controller

The publisher responsible for PDF Scan GOAT and this website is:
Kai-Uwe Laag
c/o Familie Edenhofner
Stingesbachstraße 18
41462 Neuss
Germany
Email: datenschutz@goatapplications.dev. Updated: 13 September 2026.

Documents and recognition stay on your device

Camera captures, imported photos and PDFs, thumbnails, recognized text, document analysis, signatures and other edits are processed on your iPhone or iPad and stored in the app container. Documents are not uploaded to our servers or an AI provider for this processing. No GOAT account is required. The app includes no advertising, advertising identifiers or proprietary audience analytics.

Permissions and settings

The camera requires your iOS permission. You select files and images for import. The optional biometric lock uses Apple device authentication; we receive no Face ID or Touch ID data. The app also stores settings, organizational details, local Premium entitlement information and local review-request counters. These counters are not transmitted to us.

Retention, trash and backups

Documents remain locally until permanently deleted or until you remove the app and its data. Moving a document to trash is not permanent deletion. Failed export copies are removed; the app cleans up its temporary exports older than 24 hours at the next app launch. There is no proprietary cloud sync. Depending on system settings, app data may be included in Apple device backups. Deleting content in the app does not automatically delete backups or previously exported copies. Keep separate backups of important files.

Export, copying and redaction

Sharing or copying deliberately passes content to iOS, the clipboard or a destination app. Their providers’ rules also apply; cross-device clipboard and cloud destinations depend on your settings. Redaction sanitizes the exported copy, not the editable original retained locally. Check the output, file name and remaining content before sharing.

Apple purchases, reviews and diagnostics

Apple handles App Store downloads, product queries, Premium purchases, restoration and entitlement verification. The app receives no payment details. Review requests use Apple’s system dialog. The app has no proprietary tracking or crash-analysis SDK. Depending on your settings, Apple may process diagnostic and TestFlight data and make it available to developers. See Apple’s privacy information.

Website and hosting

Cloudflare serves and protects this website, processing technical connection data such as IP address, requested URL, timestamp, browser and error information. The website embeds no advertising or visitor-analytics scripts, external fonts or contact forms. We set no marketing cookies. Technical logs support delivery, troubleshooting and security, not user profiling. They are needed only for those purposes; service-side retention also depends on the Cloudflare service and its settings.

Email support

When you contact us, we process your sender address, message and information you voluntarily provide to handle the request. Cloudflare Email Routing forwards messages to a Gmail inbox; Cloudflare and Google process communication data. Include your device, operating-system and app version and describe the issue. Do not send passwords, payment details or confidential documents; use anonymized or fictional examples. Messages are retained while necessary for handling requests, follow-up or legal claims, subject to statutory retention duties. Personal content no longer needed is then deleted.

Purposes and legal bases

Where we process personal data, contract-related enquiries are handled for contract performance or pre-contractual steps (GDPR Article 6(1)(b)). General support, secure website delivery and fault prevention rely on legitimate interests in reliable services and communication (Article 6(1)(f)). Processing required by law relies on Article 6(1)(c). Where separate consent is required, Article 6(1)(a) applies and consent may be withdrawn for the future. Device permissions are not blanket consent to additional processing.

Recipients and international processing

Cloudflare and Google may process data for hosting and email alongside the publisher; Apple services and destinations you select are separate. Processing may occur outside the European Economic Area, including in the United States. Providers describe their applicable transfer mechanisms, such as adequacy decisions and standard contractual clauses, in their information: Cloudflare and Google. Contact our privacy address for information about safeguards used for our processing.

Your rights

Subject to the GDPR, you may request access, correction, deletion, restriction or portability. You may object to processing based on legitimate interests for reasons relating to your particular situation. You may complain to a supervisory authority, particularly where you reside; in North Rhine-Westphalia this is LDI NRW. Contact datenschutz@goatapplications.dev. We have no remote access to documents stored solely on your device.

Voluntary information and automated decisions

You do not have to send us documents or support messages. Necessary connection data is required to deliver the website, and without contact details we may be unable to answer an enquiry. We do not conduct automated decision-making with legal or similarly significant effects or related profiling. OCR and analysis provide suggestions to review, not binding assessments.

← Back to the homepage