BC Scanner

BC Scanner Privacy Policy

Last updated: 27 September 2026. This policy covers BC Scanner, package gr.lumigo.bcscanner, and the related website. Android version 1.1.5 introduces the device-gallery photo flow described below. Users who still have version 1.1.4 or another earlier version may retain its older local photo behavior until they update. The current server no longer adds photographs to cloud contact storage, including photographs submitted by an older app. Historical copies are handled separately as explained below.

Who we are

BC Scanner is operated by LUMIGO E.E. (Lumigo App), Konstantinouploeos 129, 104 47 Athens, Greece. Our privacy contact is info@lumigo.gr.

We are responsible for account administration, service security and our own operational records. When a business uses BC Scanner to manage its contacts, that business decides which people to record and why. We provide storage and processing of those records on its instructions. Having a business card or scanning it does not, by itself, establish consent to marketing.

What we process

InformationPurpose
Account ID, display name, role, protected access-code verification data and session informationSigning in, account management, access controls and synchronisation. The current Android release uses a provisioned access code.
Names, companies, positions, phone numbers, email addresses, websites, addresses and additional contact fieldsReading, saving, organising, searching and editing business contacts. The records may describe other people.
Card photographs and recognised textExtracting information. In the updated app, photographs are temporary scan input and a device-gallery copy; saved contact records contain the extracted text. Earlier versions also stored cloud photos.
Notes, dictated text, categories and record historyKeeping the context of a contact and changes to saved information.
Your own digital-card detailsKeeping your card available on your devices and creating its QR code or downloadable vCard.
Request/session information, security counters, scan fingerprints, timestamps and usage costsOperating the service, preventing abuse and enforcing or reconciling the scan budget. A fingerprint is a hash of an image, not the image itself; it is not described as anonymous.
Deletion request, account identifier, protected receipt information, status and timestampsVerifying and handling a request, recording its outcome and preventing deleted data from being accidentally restored.
Local settings and device copiesLanguage/theme preferences, local work and restoring the relevant app state.

New saved contact data synchronises automatically to your account. There is no cloud-sync opt-out for a newly saved text record. Contact history and photographs previously saved by earlier versions can remain; replacing a field is not the same as deleting all earlier versions. Legacy trial data is not silently uploaded by the current migration flow.

We do not read the phone's whole address book. Adding a contact to the phone opens the system contact form for your confirmation. The reviewed Android release has no advertising or advertising-ID integration, and purchases are disabled.

Photographs and AI reading

When you request AI reading, the app sends the selected card image through our HTTPS service to OpenAI for extraction. Your typed or dictated note text is not included in this card-reading request. You can check and correct the results before saving.

In the updated Android app, a successful scan saves a copy to the phone's gallery. On older supported devices, the system asks you to choose where to save the image instead. If saving fails or is cancelled, you can retry without repeating AI reading, or explicitly continue without saving the photo. The image remains temporary while you finish that step. The updated app does not add a photo to its saved contact records or new cloud photo storage. On the desktop website, an uploaded image is used for reading; the site does not automatically download another copy.

Contact PDFs and new contact backups created by the updated app contain data rather than card photographs, including when an older contact is exported. Existing photos saved by earlier versions are not silently deleted by this change. A gallery copy is controlled by your device and its photo-backup settings; it may be uploaded by a separate gallery backup service you enabled. This app cannot promise that your gallery is never backed up elsewhere.

The request uses store:false, which disables storage of the response as a retrievable API response. This does not remove standard abuse-monitoring retention. OpenAI's standard API rules retain abuse-monitoring information for up to 30 days, with longer retention where required by law or reasonably needed to protect people or services; certain flagged images may be retained for safety review. Its API data is not used for model training by default unless the customer opts in. We do not promise Zero Data Retention. OpenAI API data controls, response storage.

Camera, images, QR and voice notes

The camera operates when you choose capture or QR scanning. Gallery selection uses the system file picker. QR decoding takes place locally; contact data you subsequently save follows the normal synchronisation flow. An external website contained in a QR code opens only when you choose to open it.

If you choose dictation on Android, BC Scanner opens the device's external speech-recognition activity and receives the resulting text. It does not receive an audio file, upload audio to its own service or maintain its own voice-recording archive. The recognition service can use online processing under its own terms and settings; on-device-only recognition is not guaranteed. You can type a note instead. Android speech recognition.

Providers, exports and international processing

Cloudflare operates our hosting, account/contact databases and historical saved-photo storage. OpenAI processes images for requested card extraction. Their standard data-processing terms govern customer data processed on our instructions and provide contractual safeguards for relevant international transfers. Processing may take place outside Greece and the EEA; we do not claim EU-only storage. Cloudflare terms, section 6.1, Cloudflare DPA, OpenAI DPA.

Your chosen speech recognizer, gallery backup service, file destination and apps used to open exported files apply their own terms. When you export a PDF, spreadsheet, backup, vCard or QR image, or display your QR code, the recipients you choose can receive the included information. Our account deletion cannot recall those copies, gallery photographs or entries already added to the phone's contacts.

On the desktop website, the newsletter editor reads your account contacts to prepare recipient selections and a message draft. Its sender is not connected and the Send button is disabled. Editor text and selected images are not sent to a delivery provider; HTML export creates a file on your device. This desktop tool is not part of the current Android application.

Why processing is permitted

We process account and service information to provide the service you request, including performance of our contract where applicable. We protect accounts, enforce usage limits and resolve service faults on the basis of our legitimate interests in running a secure, reliable service, balanced against individuals' rights. Where a legal duty requires particular records or a response to a request, processing is based on that duty. If a feature requires consent, we obtain it before that processing and allow withdrawal.

For a business customer's contact records, the business determines its own lawful purpose and basis; our processing on its instructions does not automatically give it permission to market to every contact. We do not make decisions with legal or similarly significant effects about a person solely from the AI extraction of their business card.

Retention

Contact data is kept for your use until you request deletion. Associated notes, categories, history and your digital card follow the account-deletion scope. An edit or sign-out does not erase the server history. The updated service does not create new stored cloud photos; historical cloud photos from earlier versions remain until handled under the deletion process. Device-gallery copies and old local backups must be managed on the device or with the chosen backup provider.

Sessions can renew with activity for up to 30 days from activity. Expired entries are cleared during later login housekeeping; that is not a 30-day expiry for contact content. Sign-in security buckets expire after 15 minutes and are removed during subsequent housekeeping.

Cloudflare D1's standard recovery window on our current Free plan is 7 days. Deleted database information may therefore remain recoverable in that window. On a recovery, deletion requests must be reapplied before restored information returns to use. This window does not describe a separately exported backup. D1 recovery.

Historical R2 images require deletion or an applicable lifecycle rule; editing a card does not automatically expire every old image. R2 deletion through the storage API removes the stored object from subsequent reads, but it does not recall an independent exported or cached copy. We do not describe storage redundancy as a user-restorable backup. R2 deletion and consistency.

Where standard Workers Logs are enabled on the Free plan, their normal retention is 3 days. This is not a universal retention promise for every Cloudflare security record or separately exported log. Operational records are used for service diagnostics and security, not advertising. Workers Logs.

Scan-budget records are retained while necessary to enforce the active budget and settle associated charges or disputes. The existing pilot ledger is not keyed by account, so an individual account deletion cannot reliably select its earlier image fingerprints. These records are handled separately from card photos and contact records. Minimal deletion/request evidence, including account identifier, protected receipt reference, status and timestamps, is retained while needed to prevent accidental restoration, finish the request or resolve a related legal dispute. These operational records have no automatic expiry; handling a request includes considering whether retained records are still necessary. Records subject to an actual legal obligation or hold are restricted to that purpose; they are not kept as a substitute for the deleted contact collection.

OpenAI and the device's separate recognition service apply the provider retention described above. We do not promise that deleting a BC Scanner account instantly erases all independent provider or offline-device copies.

Requesting deletion and exercising rights

You can submit a request at BC Scanner account deletion and check its status there. For help, loss of access or another privacy request, contact info@lumigo.gr. Requests are handled by the responsible person at LUMIGO. For email requests, use the subject BC Scanner — delete my account, and include an account identifier or associated email address if available. Do not send your access code or request receipt by email. If the account has no email address, explain how you received access so we can verify ownership proportionately. You do not need to reinstall the app to email us.

Submitting a request does not immediately or automatically erase data or close the account. LUMIGO reviews the request and verifies ownership before authorising deletion. Once deletion processing begins, account access and new writes are blocked so that active data can be removed safely. Its scope includes the account, contacts, notes, categories, history, historical stored account photographs and your digital card. A received or pending request is not a confirmation of completed erasure. Status is available on the request page; we do not promise an automatic confirmation email. We explain any retained records or limitations when handling the request.

Under applicable law, you may request access, correction, erasure, restriction or portability, object to processing based on legitimate interests, and withdraw consent where it is used. We respond without undue delay and normally within one month of receiving a rights request. Where the law permits an extension for complexity or number of requests, we explain it within the initial month. This is a response obligation, not a claim that every backup or provider copy is instantly erased. EDPB rights guidance.

You may complain to the competent supervisory authority, including the Hellenic Data Protection Authority. If a business customer is responsible for the contact record concerned, we help route the request to it and support the appropriate action.

Security and policy updates

We use HTTPS for service communication, account-scoped access controls, protected credential/session verification and sign-in throttling. Android session persistence uses the platform keystore protection. These measures do not mean every local export is encrypted or that the service is end-to-end encrypted.

BC Scanner is intended for business users aged 18 or over. We date material changes to this policy and update the corresponding disclosures when the service changes. Contact info@lumigo.gr with questions.