How ScaFix handles data
Last updated: 27 July 2026
This Privacy Policy explains what information ScaFix may process when you use the app or visit scafix.app and the choices available to you.
Data controller
Ole Emil Frikstad Urstad (ScaFix). Contact: support@scafix.app.
Website analytics on scafix.app
Google Analytics is OFF by default on scafix.app and is enabled only if you expressly allow analytics. The Google tag is not loaded, and no analytics requests or analytics cookies are sent before you consent.
When you consent, Google Analytics may process the page visited, page title, referrer and campaign parameters, approximate country or region, browser and device type, and events such as clicks through to the App Store. Google may then set the first-party _ga and _ga_* cookies to distinguish visits and sessions.
Google Ireland Limited processes this information on our behalf. Event data is retained for up to 14 months. Google Signals and advertising personalisation are disabled. Google may process data outside the EEA using lawful transfer mechanisms. Learn more in Google’s Privacy Policy.
You may decline without affecting the website’s functions, and you may change or withdraw consent at any time using the permanent “Privacy settings” button. Your choice is stored locally in the browser under scafix.analyticsConsent.v1 only to remember the setting; this necessary storage is not used for tracking. After consent, the first landing page, campaign parameters and any advertising click identifiers are stored temporarily in session storage under scafix.websiteAttribution.v1 so that an App Store click on a later page can be attributed to the same visit. This session data is removed when the tab is closed or consent is withdrawn.
Marketing on scafix.app
Meta Pixel, TikTok Pixel and Snap Pixel are OFF by default on scafix.app. They load only after you expressly allow “Marketing” in the privacy settings.
After consent, the providers may process the page visited, destination, campaign parameters, approximate region, browser and device data, IP address, provider-specific identifiers and cookies, and clicks through to the App Store. Names, email addresses, phone numbers, project content, measurements and images are not sent through this website integration.
The data is used for campaign attribution, reach measurement, audience building and ad optimisation. Meta Platforms Ireland Limited, TikTok Technology Limited and Snap Group Limited may process data outside the EEA under their respective transfer mechanisms.
You may reject marketing or withdraw consent at any time using the permanent “Privacy settings” button. Your choice is stored locally under scafix.marketingConsent.v1. Withdrawal stops new calls; third-party cookies already set may remain until deleted or expired by the provider. An App Store click does not confirm an installation.
Owner-only operational notifications and App Store events
Only the verified ScaFix owner account can choose to enable private push notifications about new account registrations, trials, purchases and trial conversions. Regular users are not registered for these notifications and are not shown this notification-permission request.
When the owner enables notifications, ScaFix and Firebase Cloud Messaging process a Firebase Installation ID (FID), its association with the device’s Apple Push Notification service (APNs) token, and related registration data to route and deliver the notifications. Turning the feature off removes the device from ScaFix’s recipient list and unregisters it from FCM.
For a purchase made from a Firebase-authenticated app session, ScaFix may issue a stable, randomly generated appAccountToken, link it on the server to the Firebase user ID (UID), and pass the token to StoreKit. This lets ScaFix associate relevant purchase and subscription events with the account. The token is not a payment credential and contains no payment information.
ScaFix receives and verifies signed App Store Server Notifications v2 from Apple and processes relevant purchase and subscription event data, such as notification and event type, transaction and original-transaction identifiers, product identifier, environment, signed date and appAccountToken. This processing is used to detect events including a new subscription, a free trial and its paid conversion, prevent duplicate handling, and create an owner alert where applicable. Apple handles the payment.
The push-notification text states only the type of operational event. It does not contain the customer’s name, email address, Firebase UID, appAccountToken, transaction identifiers, payment or card details, receipt contents, project content, measurements or images. These operational-notification data are not used for advertising.
What we collect
1) Account and sign-in
If you choose to sign in, ScaFix uses Firebase Authentication for Apple, Google and email sign-in. This may include a user ID, email, display name and sign-in method. For Google sign-in, Google Sign-In may also process an account identifier, name, email and technical sign-in data.
2) Usage analytics
Usage analytics is on by default. Firebase Analytics receives app opens, session and lifecycle data, number of projects, scaffold systems used, and other feature usage.
Firebase Analytics may also receive purchase and subscription events, such as product ID and status, but never payment-card information.
When both optional usage analytics and ad measurement are enabled, Firebase Analytics purchase and subscription events may be linked to or imported into Google Ads for attribution, conversion measurement and ad optimization. Payment-card data, Firebase Authentication/Firestore account data and project content are not transferred to Google Ads.
Usage analytics can be turned off at any time in Settings → Privacy. This does not affect app functionality.
3) Subscriptions and purchases
Payments and subscriptions are handled by Apple through the App Store. ScaFix does not receive card details or full payment information, but reads subscription status through StoreKit. Deleting your ScaFix account does not cancel an active App Store subscription; you must manage or cancel the subscription separately in the App Store.
4) Projects, measurements and images
Project data is primarily stored locally on your device. ScaFix does not upload project content by default. Camera, photo and LiDAR access is used only when you start features that require it.
Advertising measurement and tracking
ScaFix processes information to provide the app and uses Firebase for usage analytics that can be turned off in Settings. On first use, Apple’s ATT prompt is the only advertising-measurement choice. Meta and TikTok start direct tracking only when you choose Allow. AppsFlyer can use Apple’s privacy-preserving measurement without IDFA/IDFV only if you later enable advertising measurement in Settings. Snapchat is measured only through AppsFlyer; the app has no direct Snap SDK.
When advertising measurement remains enabled in ScaFix and ATT permission is granted, Meta Platforms Ireland Limited, TikTok Technology Limited and AppsFlyer Ltd. may receive install, app-open, session or retention data, technical app and device information, an approximate IP-based location, installation ID/IDFV and IDFA.
When ad measurement is active, one purchase event may be sent to AppsFlyer for each eligible, verified, paid production charge — initial purchase or renewal — with product ID, actual price, currency, quantity and StoreKit transaction/order ID. Payment-card data, receipt contents and bank details are never shared. AppsFlyer may forward configured postbacks to Meta, TikTok and Snap. Meta and TikTok receive no purchase events directly from the app, and the app has no direct Snap SDK.
If ATT is denied or restricted, direct tracking and IDFA/IDFV are off. AppsFlyer’s privacy-preserving SKAdNetwork/AdAttributionKit can be used only if you later enable advertising measurement in Settings; no device-level data is then shared with advertising partners.
TikTok Enhanced Data Postback and automatic purchase tracking are disabled. We never send project content, measurements, scans, images, names, email addresses or phone numbers to the advertising partners. Apple may send privacy-preserving SKAdNetwork/AdAttributionKit postback copies to AppsFlyer. These Apple postbacks do not contain IDFA or contact information.
5) Meta ad measurement and tracking
Meta SDK tracking applies only to an App Store version of ScaFix that includes the SDK. No Meta SDK tracking occurs before such a version has been published and installed. When a version containing the SDK is used, tracking starts and continues only while you grant permission through Apple’s App Tracking Transparency (ATT) prompt and advertising measurement remains enabled in ScaFix under Settings → Privacy.
- Meta may receive information about installs and app activations, device and app identifiers (including IDFA where available), IP address, and technical app and device data.
- Meta may also receive SDK-generated session and lifecycle data, including activation and deactivation, session duration, time between sessions, and interruptions when the app moves between foreground and background.
- Meta may use the information for attribution, reporting and ad improvement, and link it with data from other apps, websites or services.
- Automatic logging of other app events is disabled. Meta’s activation measurement nevertheless records the activation and deactivation events and session data described above. Projects, measurements, images, names and email addresses are not sent to Meta through this integration.
ScaFix works without this permission. You can change your choice later in iOS Settings for ScaFix.
What data is not used for
- No third-party ads are shown in the app
- No sale of project or usage data
Sharing and processors
Firebase (Google Ireland Limited) processes account data, server-verified subscription and transaction data, operational notifications, optional usage analytics, and technical security/SDK data on our behalf. Apple processes purchases, App Store Server Notifications, APNs delivery and App Attest certifications.
For security, Firebase App Check uses Apple App Attest. Firebase processes cryptographic attestation and assertion objects, short-lived App Check tokens, and basic app and technical information to verify that requests come from an authentic ScaFix installation and protect Firebase and ScaFix backend services against abuse. On signed-in backend requests, the App Check token is sent with the Firebase authentication token. ScaFix does not store App Check tokens or attestation material in its own application database, and these data are not used for advertising.
AppsFlyer Ltd. may process privacy-preserving Apple measurement data when advertising measurement is enabled and device data when both advertising measurement remains enabled in ScaFix and ATT is allowed. Meta Platforms Ireland Limited and TikTok Technology Limited process direct advertising-measurement data only under the same two conditions. Snap Inc. may receive campaign postbacks through AppsFlyer; the app contains no Snap SDK.
Firebase usage analytics, project content and ScaFix account data are not shared with Meta, TikTok, AppsFlyer or Snap.
Apple, Google and the advertising-measurement providers may process data outside the EEA under valid transfer mechanisms, including the European Commission’s Standard Contractual Clauses (SCCs) where applicable.
Your choices and deletion
You can change analytics consent under Settings → Privacy. Advertising measurement can be turned off in ScaFix under Settings → Privacy; in an app version that includes the Meta SDK, Meta tracking can also be declined in Apple’s prompt and changed later in iOS Settings for ScaFix. You can delete your sign-in account directly in the app under Settings → Account → Delete Account, and local projects and other local app data are deleted at the same time. Contact support@scafix.app to request access to or deletion of any other server records associated with you.
Changes
For material changes, we will update the date at the top of this page.