ScaFix
ScaFix privacy notice
Updated 30 August 2026
This Privacy Policy explains what information ScaFix may process when you use the app or visit scafix.app and the choices available to you.
Web app, account, project storage and payments
Account, Pro access and web projects
When you use the web app while signed in, Firebase Authentication and Cloud Firestore process your account identifier, sign-in information, project content, measurements, settings, web parts inventory and entitlement state. Your account, paid access and signed-in projects, including their measurements and settings, sync between web and iOS when you use the same ScaFix account. The web parts inventory does not sync to iOS. Google processes this information on ScaFix’s behalf.
Web analytics and marketing
Google Analytics loads only after you consent to Analytics. It measures page views and ScaFix actions such as demo start, signup start, checkout start and App Store clicks; for signed-in users it may receive the opaque Firebase user ID, but not a name or email address. Meta Pixel loads only after you consent to Marketing and measures page views and the same actions together with browser and device data, IP address, page URL, and Meta cookies or identifiers. The web app does not load TikTok or Snap pixels or advertising SDKs. After Marketing consent, the first valid UTM values and the click identifiers fbclid, ttclid, gclid, gbraid or wbraid are kept temporarily in the tab’s session storage under scafix.firstPartyAttribution.v1; other parameters are ignored. If you start a web purchase, the campaign values are stored only as Stripe Checkout Session metadata and are not copied to the recurring subscription. Withdrawing consent stops new measurement calls; third-party cookies may remain until deleted or expired. Project content, measurements, images and payment-card data are not sent to Google Analytics or Meta through this integration.
Measurement of completed purchases
If Marketing was allowed when Stripe Checkout started, ScaFix may send Meta a Purchase event after a server-confirmed purchase, containing purchase value, currency and a stable Stripe identifier, a SHA-256-hashed email address, and any Meta identifiers _fbp/_fbc. Plaintext email is not sent, and the event is not sent without this consent.
If Analytics was allowed when Stripe Checkout started, ScaFix may send Google Analytics 4 a Purchase event after a server-confirmed purchase, containing the purchase value excluding tax, currency, the Checkout Session ID as transaction ID, the opaque Firebase user ID, and the Google Analytics client and session cookies. Advertising use and ad personalization remain denied, and the event is not sent without this consent.
For a signed-in user, ScaFix stores the current Analytics and Marketing choices, a random revision, and the update time in Firebase. When Checkout starts, the revision and only the consented identifiers needed for purchase measurement—the Google Analytics client/session cookies and/or Meta _fbp/_fbc—may be copied to Stripe Checkout Session metadata. This metadata may remain on an abandoned Checkout Session. It is used only to verify current consent when the webhook arrives and measure a confirmed purchase; it is not copied to the recurring subscription. Changing either choice rotates the revision, so an older session cannot authorize a new event. No project data or payment-card data is stored in this measurement metadata.
Stripe Checkout metadata also records which optional categories were granted when Checkout started.
Payments and entitlement
Web subscriptions are processed by Stripe. Stripe receives the billing and payment information needed to complete and manage the purchase; ScaFix does not store complete payment-card numbers. App Store purchases remain processed by Apple. ScaFix processes provider, customer, subscription and transaction identifiers and subscription status to attach either purchase to the same signed-in ScaFix account.
Your choices
You can delete web projects and your ScaFix account. Manage or cancel active subscriptions with the payment provider before deletion; deleting the account does not automatically end either a Stripe or App Store subscription. Purchase and subscription history may be retained without the account link where needed for accounting, security and legal records. Contact support@scafix.app for access to or deletion of other server records.
Payment before account creation
You can start and pay for a web subscription before creating or signing in to a ScaFix account. To let you claim the purchase, ScaFix stores a necessary random claim secret in an HttpOnly cookie and a server claim record containing Stripe references, the selected subscription tier, a masked email address and a SHA-256 hash of the email address. The server record also contains a hash of the network address for abuse prevention and, where you consented, applicable campaign and measurement data. ScaFix does not store complete payment-card data.
In production, the purchase can be claimed for 30 days. A paid purchase that is not claimed within that window is automatically cancelled and refunded.
Necessary account, security and service emails are separate from optional email marketing. Only with your explicit consent does ScaFix store your email address, language, verification status, consent time and consent-text version in a separate Firebase marketing list. You can withdraw consent at any time in Settings. Withdrawal or account deletion removes your list entry.
Microsoft Clarity: heatmaps and session recordings
Analytics also includes Microsoft Clarity: clicks, scrolling and session recordings on public pages, with masked content.
Clarity loads only after a new Analytics consent showing this notice. Form content is masked; account, project, editor, upload and payment-return pages are not recorded. We do not send Firebase user IDs. Clarity processes usage and device data and may set pseudonymous session cookies. Advertising consent for Clarity stays denied. You can withdraw consent in privacy settings. Recordings are not screen videos of your private drawings.
Vercel analytics and performance
When you consent to Analytics, ScaFix also uses Vercel Web Analytics and Speed Insights. They process anonymous, aggregated page views and technical performance measurements such as page or route, referrer, approximate country, browser, device, operating system, network type and Core Web Vitals. The services do not use cookies or link the data to your Firebase user. They do not provide recordings or playback of user sessions (session replay). Web Analytics derives an anonymous hash from the incoming request and may use it to group page views into a short-lived session and calculate aggregate measures such as bounce rate. The hash and session link are reset or discarded within 24 hours and are not used to track visitors across days, websites or apps. Concrete project identifiers, project content, measurements, file names, images and payment information are not sent. Collection stops when you withdraw Analytics consent.
Details for the iPhone app and related services
Data controller
Ole Emil Frikstad Urstad (ScaFix). Contact: support@scafix.app.
Owner-only operational notifications and App Store events
Only the verified ScaFix owner account can choose to enable private push notifications about new account registrations, trials, purchases and trial conversions. Regular users are not registered for these notifications and are not shown this notification-permission request.
When the owner enables notifications, ScaFix and Firebase Cloud Messaging process a Firebase Installation ID (FID), its association with the device’s Apple Push Notification service (APNs) token, and related registration data to route and deliver the notifications. Turning the feature off removes the device from ScaFix’s recipient list and unregisters it from FCM.
For a purchase made from a Firebase-authenticated app session, ScaFix may issue a stable, randomly generated appAccountToken, link it on the server to the Firebase user ID (UID), and pass the token to StoreKit. This lets ScaFix associate relevant purchase and subscription events with the account. The token is not a payment credential and contains no payment information.
ScaFix receives and verifies signed App Store Server Notifications v2 from Apple and processes relevant purchase and subscription event data, such as notification and event type, transaction and original-transaction identifiers, product identifier, environment, signed date and appAccountToken. This processing is used to detect events including a new subscription, a free trial and its paid conversion, prevent duplicate handling, and create an owner alert where applicable. Apple handles the payment.
The push-notification text states only the type of operational event. It does not contain the customer’s name, email address, Firebase UID, appAccountToken, transaction identifiers, payment or card details, receipt contents, project content, measurements or images. These operational-notification data are not used for advertising.
What we collect
1) Account and sign-in
If you choose to sign in, ScaFix uses Firebase Authentication for Apple, Google and email sign-in. This may include a user ID, email, display name and sign-in method. For Google sign-in, Google Sign-In may also process an account identifier, name, email and technical sign-in data.
2) Usage analytics
Usage analytics is on by default. Firebase Analytics receives app opens, session and lifecycle data, number of projects, scaffold systems used, and other feature usage.
Firebase Analytics may also receive purchase and subscription events, such as product ID and status, but never payment-card information.
When both optional usage analytics and ad measurement are enabled, Firebase Analytics purchase and subscription events may be linked to or imported into Google Ads for attribution, conversion measurement and ad optimization. Payment-card data, Firebase Authentication/Firestore account data and project content are not transferred to Google Ads.
Usage analytics can be turned off at any time in Settings → Privacy. This does not affect app functionality.
Advertising measurement and tracking
ScaFix processes information to provide the app and uses Firebase for usage analytics that can be turned off in Settings. On first use, Apple’s ATT prompt is the only advertising-measurement choice. Meta and TikTok start direct tracking only when you choose Allow. AppsFlyer can use Apple’s privacy-preserving measurement without IDFA/IDFV only if you later enable advertising measurement in Settings. Snapchat is measured only through AppsFlyer; the app has no direct Snap SDK.
When advertising measurement remains enabled in ScaFix and ATT permission is granted, Meta Platforms Ireland Limited, TikTok Technology Limited and AppsFlyer Ltd. may receive install, app-open, session or retention data, technical app and device information, an approximate IP-based location, installation ID/IDFV and IDFA.
When ad measurement is active, one purchase event may be sent to AppsFlyer for each eligible, verified, paid production charge — initial purchase or renewal — with product ID, actual price, currency, quantity and StoreKit transaction/order ID. Payment-card data, receipt contents and bank details are never shared. AppsFlyer may forward configured postbacks to Meta, TikTok and Snap. Meta and TikTok receive no purchase events directly from the app, and the app has no direct Snap SDK.
If ATT is denied or restricted, direct tracking and IDFA/IDFV are off. AppsFlyer’s privacy-preserving SKAdNetwork/AdAttributionKit can be used only if you later enable advertising measurement in Settings; no device-level data is then shared with advertising partners.
TikTok Enhanced Data Postback and automatic purchase tracking are disabled. We never send project content, measurements, scans, images, names, email addresses or phone numbers to the advertising partners. Apple may send privacy-preserving SKAdNetwork/AdAttributionKit postback copies to AppsFlyer. These Apple postbacks do not contain IDFA or contact information.
5) Meta ad measurement and tracking
Meta SDK tracking applies only to an App Store version of ScaFix that includes the SDK. No Meta SDK tracking occurs before such a version has been published and installed. When a version containing the SDK is used, tracking starts and continues only while you grant permission through Apple’s App Tracking Transparency (ATT) prompt and advertising measurement remains enabled in ScaFix under Settings → Privacy.
- Meta may receive information about installs and app activations, device and app identifiers (including IDFA where available), IP address, and technical app and device data.
- Meta may also receive SDK-generated session and lifecycle data, including activation and deactivation, session duration, time between sessions, and interruptions when the app moves between foreground and background.
- Meta may use the information for attribution, reporting and ad improvement, and link it with data from other apps, websites or services.
- Automatic logging of other app events is disabled. Meta’s activation measurement nevertheless records the activation and deactivation events and session data described above. Projects, measurements, images, names and email addresses are not sent to Meta through this integration.
ScaFix works without this permission. You can change your choice later in iOS Settings for ScaFix.
What data is not used for
- No third-party ads are shown in the app
- No sale of project or usage data
Projects, PDF import, camera and account logo
Drafts you create while signed out are stored only locally in that browser or on the device. When you are signed in, projects, wall measurements, project settings and your account logo are stored and synchronized through Firebase Cloud Firestore and Cloud Storage so the content is available on the web and iPhone. The imported source PDF itself is processed in memory and is not uploaded; derived project geometry that you save in the project may be synchronized like other project data. Camera, photo and LiDAR access is used only when you start a feature that requires it. An uploaded account logo is stored in the cloud until you replace it or delete the account.
Sharing and processors
Firebase (Google Ireland Limited), including Cloud Firestore and Cloud Storage, processes account data, synchronized projects, wall measurements, project settings and account logos, as well as server-verified subscription and transaction data, operational notifications, optional usage analytics, and technical security/SDK data on our behalf. Apple processes purchases, App Store Server Notifications, APNs delivery and App Attest certifications.
For security, Firebase App Check uses Apple App Attest. Firebase processes cryptographic attestation and assertion objects, short-lived App Check tokens, and basic app and technical information to verify that requests come from an authentic ScaFix installation and protect Firebase and ScaFix backend services against abuse. On signed-in backend requests, the App Check token is sent with the Firebase authentication token. ScaFix does not store App Check tokens or attestation material in its own application database, and these data are not used for advertising.
AppsFlyer Ltd. may process privacy-preserving Apple measurement data when advertising measurement is enabled and device data when both advertising measurement remains enabled in ScaFix and ATT is allowed. Meta Platforms Ireland Limited and TikTok Technology Limited process direct advertising-measurement data only under the same two conditions. Snap Inc. may receive campaign postbacks through AppsFlyer; the app contains no Snap SDK.
Firebase usage analytics, project content and ScaFix account data are not shared with Meta, TikTok, AppsFlyer or Snap.
Apple, Google and the advertising-measurement providers may process data outside the EEA under valid transfer mechanisms, including the European Commission’s Standard Contractual Clauses (SCCs) where applicable.
Your choices and deletion
You can change analytics consent under Settings → Privacy. Advertising measurement can be turned off in ScaFix under Settings → Privacy; in an app version that includes the Meta SDK, Meta tracking can also be declined in Apple’s prompt and changed later in iOS Settings for ScaFix. You can delete your sign-in account directly in the app under Settings → Account → Delete Account. Local app data, synchronized cloud projects, project settings and account-logo/branding data are then deleted. Contact support@scafix.app to request access to or deletion of any other server records associated with you.
Changes
For material changes, we will update the date at the top of this page.
AppsFlyer OneLink · 2026-09-08
With Marketing consent, the App Store button uses AppsFlyer OneLink to measure the path from an ad to the app. AppsFlyer receives campaign/ad identifiers, a Meta click identifier when present, and connection/device information when you click. Matching later installs or purchases depends on iOS consent and available signals; a click is not a purchase. Without consent, the button goes directly to Apple.
