Inkwell — PDF Reader & Scanner

Privacy Policy

Effective date: 21 August 2026 · Version 3.0

This policy explains what the Inkwell Android app does with your information. It describes the app as it is actually built. If we change what the app collects, we change this policy in the same release.

1. Who we are

Inkwell is published by:

TACTIX ADS LP
85 Great Portland Street
London W1W 7LT
United Kingdom
tech@tactixadslp.com

For the purposes of the UK GDPR and the EU GDPR, TACTIX ADS LP is the controller of the limited analytics data described in section 4 and of the advertising described in section 5. We have not appointed a Data Protection Officer, because we are not required to. Write to the address or email above for anything covered by this policy.

2. The short version

3. What stays on your device

Everything in this section is stored only in the app's private storage on your phone, or in files you choose to save. None of it is transmitted to us or to anyone else.

WhatWhere it livesWhy it exists
The PDF files you open, edit, create or save Wherever you chose to keep them, through Android's own file picker They are your files
Page images rendered for display, printing or OCR In memory, discarded when you leave the screen Drawing pages on screen
Photos taken with the camera for document scanning The app's temporary cache folder, then written into the PDF you save Turning a photo of a page into a scan
Text produced by OCR On screen, until you copy, share or leave Making a scanned document searchable
Your saved signature The app's private storage So you do not have to redraw it every time
Your reading position and the last document you opened The app's private storage The "Continue reading" row
The list of PDFs found on your device Read live from Android each time; not uploaded The library screen
Your Ink balance, daily streak, chest and reward counters The app's private storage The in-app rewards system
Your answer to the statistics question The app's private storage So you are not asked twice, and so the switch in Settings can show what is actually happening
Whether you have been offered the first-run tour The app's private storage So the invitation is offered once and never again — Settings keeps a manual way to start the tour for anyone who wants it back
Your answers in Google's ad consent form The app's private storage, written there by Google's consent SDK It is the authoritative record of what you allowed, purpose by purpose. Google's ad SDK reads it directly — see section 5
Which advertising group your installation is in The app's private storage So the group never changes for you — see section 5
Folder permissions you grant Held by Android, not by us So the library can find your PDFs without All Files Access

A few specifics worth stating plainly:

Text recognition (OCR) runs on your device. Inkwell uses the bundled ML Kit text recognition model, which ships inside the app. It does not upload page images to a server, it does not need an internet connection, and it works on a device with no Google Play services installed at all. We tested exactly that on a bare Android image with Google services removed.

Document scanning runs on your device. The camera preview, the page corners you position by hand, perspective correction and image processing are all local. Captured photos are written to the app's own cache folder and are used to build the PDF you save. They are never uploaded.

Your signature stays on your device. It is stored in the app's private storage, and it is only ever drawn into the PDF you are signing.

The app has no backup to the cloud. Android's automatic app-data backup is switched off for Inkwell, so your saved signature, reading position and Ink balance are not copied to your Google Drive.

When you use Copy, Share or Print, you are handing that content to another app or service that you chose. What happens to it after that is governed by that app's or service's own privacy policy, not this one.

4. What is collected and sent off your device

Two components in the app send anything over the network, and there are only two. Google Analytics for Firebase, which is what the rest of this section is about, and the Google Mobile Ads SDK, which requests the ads described in section 5. Nothing else in the app makes a network request at all.

The statistics are switched off when you install the app — the published build ships with collection disabled, so nothing is sent before the app has worked out whether it may.

What happens next depends on where you are:

Either way, you can change the statistics whenever you like. The app's Settings screen — the gear icon in the top bar of both the Library and the Tools screen — has a switch for exactly this, and it works in every country. It covers the statistics and only the statistics: it does not turn the ads off anywhere, and the wording underneath it says so rather than letting the switch imply otherwise. Where Google's consent form is offered, the same screen carries a separate Manage ad privacy entry that reopens it. Section 11 has the steps.

The region rule covers the UK and the 30 countries of the EEA, and also the Crown Dependencies, Gibraltar, and the EU territories that carry their own country code — 42 in all. The app works out where you are from your SIM's country and the country of the mobile network you are connected to, falling back to your device's region setting when there is no SIM at all. It does not use your location and never asks for the location permission; deciding whether to ask for consent is not worth a location prompt. That method is rough, and it is built to err towards asking: a device it cannot place is asked rather than assumed.

Your own answer always outranks that rule, in both directions and permanently. If you decline in Berlin and later move somewhere we would not have had to ask, you stay declined; if you allow, you stay allowed until you say otherwise.

4.1 What Firebase collects

The usage events we send are limited to the following, and they are all we send:

Alongside these, we send small numeric or short text values such as an amount of Ink, a streak length, or the name of a feature. The only long-lived flag we set is the advertising group one described above; there is no paid-upgrade flag, because there is nothing to buy yet and the code that would set one is never reached.

An ad request is separate, and it does not go to Firebase. When the app asks for an ad, that request goes from your device to Google's advertising servers, and it is the one thing here we cannot itemise for you: what the ad SDK puts in it is Google's, not ours, and Google describes it at the link in section 8. What we can tell you is the part we are answerable for. It carries your advertising ID, which is new in this release and is the thing that makes a personalized ad possible (sections 5 and 7). It carries your IP address, because that is how any request over the internet finds its way back to you, and Google works your approximate location out from it, the same way it does for the statistics above. In the UK and the EEA it also carries the record of what you allowed in the consent form, so that Google serves within it. Beyond that identifier we add nothing of our own — no profile we built, no interests, nothing about which documents you have opened.

4.2 What is deliberately not collected

One item left this list in version 3. Until version 2 the list began "No advertising ID — even though the app now shows ads", and called it the strongest claim in this document. It is not a claim we can make any more. Section 7 says what changed and why.

4.3 Why

To understand whether people can find and use the app's features, to see which features are worth improving, to find the places where people get stuck, to measure whether the app is growing, and to know what the advertising earns. Aggregate counts, not individual profiles: we do not attempt to identify anyone, and we hold no information that would let us do so.

The app contains no crash-reporting tool, so we do not receive stack traces, logs or any other diagnostic data from your device.

5. Advertising

Inkwell is free, and the ads are what pay for it. This section is where they are, where they are not, and what decides which ones you get.

They come from Google. The app contains Google's Mobile Ads SDK (AdMob), which is the second of the two components in section 4 that reach the network — and the only one you can see.

WhereWhat appearsAnd when it does not
Coming back to the app A full-screen ad when you return to Inkwell after leaving it running Never on your first-ever session. Never the first time the app comes to the foreground after it starts — only on a later return to one already running. Never within four minutes of the last one. Never when another app has handed Inkwell a document to open. Never when you are coming back from something Inkwell sent you to — a file picker, the share sheet, the print dialog, or a link
The Library screen A banner strip anchored at the bottom, above the navigation bar and never over your list of documents. It replaces itself with another ad roughly every 45 seconds, which is the SDK's interval and not ours —
The Tools screen The same kind of banner strip, in the same place —
Closing a document A full-screen ad when you leave a document and go back to the library Never when that document was opened from another app — you came to read one file, and we are not going to charge you an ad on the way out. Never in the first 30 seconds of a session, and never within three minutes of the last full-screen ad
Watching for a reward A video you start yourself, in exchange for something in the rewards system — Ink, a doubled chest, a streak freeze, or unlocking a tool run Never unless you tap the button that asks for it

No ad is ever placed on the page you are reading. The document view carries no placement of its own — no banner, no strip, nothing over the page, nothing when you turn one. The two banner strips are on the Library and the Tools screen and nowhere else. That is deliberate: reading is the thing you installed the app for.

One case does come between you and a document, and it belongs here rather than in a footnote: leave the app running with a document open, then make a plain return to the foreground — the home button, then back — and the full-screen ad in the first row above is shown on the way back in. That is the return being interrupted rather than the reading, and it is the only time an ad appears over a document.

One further placement is built and switched off: a full-screen ad after a tool finishes, at the end of a merge, a split or an OCR run. It exists in the code and it is disabled in this release. If we turn it on, this policy will say so in the release that does it.

The ads may be personalized. This changed in version 3 of this policy, and it changed against you. Until version 2 every ad was non-personalized, for everyone, in every country. That is no longer true. The app now reads your device's advertising ID and sends it to Google with the ad request, and Google may use it to choose an ad that fits a profile built from it. Section 7 says what we withdrew in order to do that. The rest of this section says what governs it.

What personalization means here. Your advertising ID is a stable identifier your phone gives to apps that ask for it. It follows you from app to app, and it is what an advertising profile is built on — the apps you use, the ads you have been shown, and what you did after them. A personalized ad is one chosen out of that profile. A non-personalized ad is chosen from the country the request came from and the app it will appear in, and from nothing else. The profile is Google's; we do not build one, hold one, or see one.

Who serves them. Google. The ad request goes to Google's advertising business, which runs the auction and decides what to serve. Google is the only ad tech provider involved. We run AdMob directly, with no mediation, so the request is never passed to another advertising network to fill, and no other network receives your advertising ID from us.

What governs it, and where.

If you decline. You still see ads — they are what pays for the app — but they are non-personalized, or limited to whichever of the framework's purposes you did allow. Nothing else changes: every feature works exactly the same either way.

You can change your answer. Where the law requires that form to be reopenable, the app's Settings screen carries a Manage ad privacy entry that reopens it, and your new answers replace the old ones. Where the form is not shown, that entry is not shown either, because a menu item that opened nothing would be worse than no menu item. Section 11 has the route that works in every country, including the one that is not ours to give or withhold.

About one install in seven never sees an ad at all. 15% of installations are put, on first launch, into a group that is shown no advertising ever: decided by a coin flip, recorded once, and never revisited. On those devices the ad SDK is not merely told to stay quiet — it is never loaded at all. It is a control group, and it is the only way we can find out whether the ads cost us more in people leaving than they bring in. You cannot ask to be put in it, we cannot tell you which group you are in, and it costs us 15% of the advertising, permanently. We mention it because it is unusual and because it is true.

A paid upgrade would remove them. The app already contains the switch that turns off every placement above for a paid user. There is nothing to buy yet — see section 4.2.

6. Lawful basis for processing

Under the UK GDPR and the EU GDPR we rely on the following:

WhatLawful basis
Everything the app does on your device — reading, scanning, OCR, signing, editing, storing your reading position, the Ink economy Performance of a contract (UK/EU GDPR Art. 6(1)(b)) — it is the service you installed the app to receive. In practice this data never reaches us, so we are not processing it as a controller in any meaningful sense.
Usage analytics via Firebase (section 4), where we asked you and you agreed Consent (Art. 6(1)(a)) — this is the basis for everyone who was shown the dialog described in section 4 and chose Allow, and for anyone who has switched the statistics on in Settings. You can withdraw it at any time with the same switch (sections 10 and 11). Withdrawing stops the collection from that moment; it does not make what was already collected unlawful.
Usage analytics via Firebase (section 4), where we did not have to ask Legitimate interests (Art. 6(1)(f)) — our interest in understanding how the app is used so we can maintain and improve it. This is the basis outside the countries in section 4, for users who have not been asked and have not changed the setting. We have weighed it against your interests: the data is pseudonymous, we do not build profiles from it, and we do not combine it with anything that identifies you. It does include what each ad impression was worth, which is how we tell whether the advertising is working at all. What version 2 said here and version 3 cannot is that none of it could reach the advertising: your advertising ID is now read (section 5), and where it is attached to what the app sends, Google is able to join the two. Section 5 is where that is governed. You can object at any time (section 10), and the switch in Settings gives that objection effect immediately (section 11).
Advertising (section 5), where we asked you and you agreed Consent (Art. 6(1)(a)) — and since version 3 there is one consent for the ads, not two: Google's certified consent form (section 5). In the countries listed in section 4 it decides both whether ads run at all and whether the ones that do are personalized, purpose by purpose. It is fail-closed, so until you have answered it no ad is requested. Personalized advertising in those countries rests on that form and on nothing else — there is no legitimate-interests fallback for it. Our own dialog is not part of this row: since version 3 it asks about the statistics only and has no effect on advertising anywhere. Withdraw through Manage ad privacy, which reopens the form (sections 10 and 11).
Advertising (section 5), where we did not have to ask Legitimate interests (Art. 6(1)(f)) — our interest in being paid for an app we give away, and yours in it existing and staying free. This is the basis outside the countries in section 4, and since version 3 it covers the personalization as well as the serving. We have weighed it against your interests, and it came out closer than it did before: your advertising ID is now read and sent to Google, and an ad chosen out of a profile is the whole point of doing it. Against that — we build and hold no profile of you, nothing an ad request carries is joined to anything else we hold, the identifier goes to Google and to no one else, and Android's own settings let you reset or delete it at any time, which works in every country (section 11). What it costs you is the ads and the identifier that helps choose them, which is the price of the app. You can object at any time (section 10) — and you should know before you do that the app has no in-app switch for the ads outside those countries, and no Manage ad privacy entry either, because there is no form behind it there. The statistics switch does not touch them either; since version 3 it stops the statistics and nothing else, in every country. The device-level control is the one that works.
Daily reminder notifications Consent (Art. 6(1)(a)) — Android asks you before the app can send notifications, and you can withdraw it at any time in Android's settings.
Camera access for scanning Consent (Art. 6(1)(a)) — Android asks you before the app can use the camera, and you can withdraw it at any time in Android's settings. Camera access is optional; every other feature works without it.

The two analytics rows are the same processing under two different bases, and so are the two advertising rows. Which one applies to you is not a choice we make about you after the fact. The app decides it at launch, from the country signals in section 4, and an answer you have given always beats that decision — so a user who turns the switch off is off everywhere, and a user who said yes is on the consent basis even in a country where we could have relied on legitimate interests instead. We would rather hold the stronger of the two than the more convenient one.

One thing about the advertising rows is worth spelling out rather than leaving to be worked out. The legitimate-interests row for advertising applies only outside the countries in section 4 — which is to say, only where we were not required to ask. Inside them, the ads run on your consent or they do not run, and they are personalized on your consent or they are not personalized.

7. Permissions the app asks for

PermissionUsed forOptional?
CAMERA Photographing pages for the document scanner Yes — the app installs and works fully without it, including on devices with no camera
POST_NOTIFICATIONS Daily streak and chest reminders. Requested the first time you open the Rewards screen, not at launch Yes
READ_EXTERNAL_STORAGE (Android 12 and below only) Finding PDF files to list in your library Yes — you can open files through Android's file picker instead
INTERNET, ACCESS_NETWORK_STATE, WAKE_LOCK, BIND_GET_INSTALL_REFERRER_SERVICE Added by the Firebase Analytics component so it can send usage statistics, and read the Google Play install referrer described in section 4.1. The ad SDK uses the same network access Granted automatically at install by Android; no prompt
AD_ID Reading your device's advertising ID, so that the ads can be personalized as described in section 5. New in this release, and the only advertising permission in the app. Added by both the Google Mobile Ads SDK and Firebase Analytics Granted automatically at install by Android; no prompt. Android's own settings let you reset the identifier or delete it — section 11
RECEIVE_BOOT_COMPLETED, FOREGROUND_SERVICE Needed by Android's WorkManager library, which is what schedules the daily reminder above so it survives a restart. The app runs no foreground service of its own Granted automatically at install by Android; no prompt

Android also lists one permission that Inkwell defines for itself, which no other app can hold. It exists so an internal message inside the app cannot be read from outside it, and it gives the app access to nothing about you.

Inkwell deliberately does not request All Files Access (MANAGE_EXTERNAL_STORAGE). It reads only the documents it created itself and the folders you explicitly grant it through Android's own folder picker.

Two components in the app ask for advertising permissions of their own. Firebase Analytics asks for three; the Google Mobile Ads SDK asks for those same three and a fourth. One of the four is now in the app. The other three are still removed when the app is built:

The check that reads the finished app file still runs, and it still refuses the release unless the permission list is exactly what this section says it is — eleven permissions expected, these three forbidden. Any of the three reappearing would fail it, just as the one we let back in disappearing would. If you want to see the list rather than take our word for it, Google Play shows every permission an app declares, under About this app → App permissions → See more.

A promise this policy made, and is now withdrawing. Version 2 of this section ended by pointing at a prediction version 1 had got wrong: advertising had arrived and the advertising-ID permissions had not come back. It said that keeping them out cost us real money — an ad served without that identifier is worth less to an advertiser than one served with it — and that this was "a price we would rather go on paying". We are not paying it any more. This release puts AD_ID back into the app so that the ads can be personalized, because the difference is what the app earns. That is the entire reason. There is no benefit to you in it, and we are not going to invent one. One permission is enough to make the promise false, and we are not going to hide behind the three we kept out.

What replaces the promise is weaker than the promise, and we would rather say that than dress it up. In the UK and the EEA nothing is personalized unless you allow it in the form described in section 5, and that form can be reopened. Everywhere — including where we do not ask — Android's own settings let you reset the advertising ID or delete it outright, which cuts the profile off at its source and is not ours to withhold (section 11). The other three advertising permissions are still stripped, so nothing here reaches Android's interest-inference system or the Privacy Sandbox at all. That is the compensation on offer. It is not the same thing as not reading the identifier at all, and this section is not going to pretend otherwise.

8. Third parties and international transfers

The only third party that receives any data from the app is Google. It receives it in two different capacities, and the difference is worth stating rather than blurring.

For the analytics, Google acts as our processor, under Google's Firebase Data Processing and Security Terms: it holds that data on our instructions and for our purposes.

For the advertising, "processor" is not an honest description and we are not going to use it. An ad request goes to Google's own advertising business, which decides what to serve and uses what it receives — including your advertising ID — for its own purposes as well as ours: running the auction, choosing a personalized ad where section 5 allows one, measuring and reporting on the ads, and preventing fraud. For that part Google acts as a controller in its own right, not merely on our instructions.

Google is the only ad tech provider. We run AdMob directly and have configured no mediation, so the request is never handed to another advertising network to fill, and no other network receives your advertising ID from us. In the UK and the EEA the consent form in section 5 runs on the IAB Transparency and Consent Framework, and the vendor it asks you about is Google.

Google processes and stores this data on servers in the United States and in other countries where Google or its sub-processors operate. Where data is transferred out of the United Kingdom or the European Economic Area, the transfer relies on the safeguards built into Google's data processing terms, which incorporate the UK International Data Transfer Addendum and the EU Standard Contractual Clauses.

What we still do not do. We do not sell your data. We do not share it with data brokers. We do not pass it to anyone other than Google, and we do not give Google anything beyond the two purposes above. Two claims that stood in earlier versions of this policy no longer stand. Version 1 said we do not share data with advertising networks; that went when Google became one we send to. Version 2 replaced it with something narrower — that no advertising ID goes with the ad request — and version 3 has taken that too. Your advertising ID goes with it. What is left is smaller and still checkable: it goes to Google and to nobody else, and we build no profile of you ourselves.

9. How long data is kept

On your device: for as long as you keep the app installed, or until you clear the app's data. Uninstalling Inkwell removes everything the app stored on your phone — your signature, reading position, Ink balance, your answer to the statistics question, and the record of your answers in Google's consent form. Documents you saved yourself are your files and stay where you saved them; uninstalling does not delete them.

Analytics data: held by Google Analytics under the retention window we set in the Google Analytics console. The maximum Google offers for event-level data is 14 months, after which Google deletes it. Aggregated reports — counts and trends that no longer identify any device — are kept for as long as we run the app.

A copy we hold ourselves. Since 19 August 2026 the raw event rows are also exported once a day out of Google Analytics into BigQuery — still a Google service, but into a dataset under our own account, in the EU region. The export is configured to exclude advertising identifiers. In version 2 that setting had nothing to exclude; since version 3 it does, and the rows we hold still carry only the app instance ID. It runs on the free tier, where rows are deleted automatically 60 days after they arrive. The export arrived in version 2 of this policy, and it is the first copy of this data that we hold rather than only read in a dashboard. Section 10 says what that changes about your rights, and — more to the point — what it does not.

10. Your rights

If you are in the United Kingdom or the European Economic Area, you have the right to:

Objecting and withdrawing both take one tap, and both work. The law requires that withdrawing consent be as easy as giving it. Here it is easier: consent was given in a dialog, and it is withdrawn with a switch in Settings, one tap from either of the app's two main screens. That same switch is how an objection under legitimate interests takes effect, since the two amount to the same thing in practice — stop collecting. Collection stops immediately, the app remembers the answer across updates and restarts, and nothing turns it back on, including travelling to a country where we would not have had to ask you in the first place. That switch covers the statistics and only the statistics: it does not stop the ads in any country, and section 11 says so plainly rather than letting a switch imply otherwise. Withdrawing your ad consent is a separate action on a separate record — Manage ad privacy, on the same screen, reopens Google's form wherever that form exists.

An honest note on how far we can help. We hold no name, email address or account for you. The only identifier on the data we hold is the app instance ID that Firebase generates for your installation — and the app never shows it to you. There is no screen it appears on and no practical way to look it up on your phone. Your advertising ID is a second identifier from this release (section 5), and unlike the first one you can read it in Android's own settings — but it goes to Google's advertising business and not into the rows we hold, so it will not help you find your data here either. For what Google holds against it, Google's own controls apply, and the surest lever is in section 11: reset the identifier, or delete it.

So the honest answer is this: if you write to us about your data, we will almost certainly not be able to find it, because you cannot tell us which of it is yours. We would rather say that than invent a procedure that does not work, or ask you for something that would not identify you either. Where a controller genuinely cannot identify a person from what it holds, the law does not require it to obtain extra information purely in order to do so — and we will tell you that plainly rather than guess at a match and delete somebody else's data.

What you can do without us, which is more effective than anything we could do for you: the switch in Settings stops any further collection the moment you turn it off. Going further, clearing the app's data or uninstalling Inkwell resets the app instance ID, and the old one is never reissued.

None of that deletes what was already collected. That sits under the old identifier until the retention windows in section 9 run out. One sentence that used to stand here is no longer true, and replacing it quietly would be the wrong way to handle that. Version 1 said this data stays as far out of our reach as it is out of yours — that we cannot look it up either. Since the BigQuery export described in section 9, we can: we hold the raw rows and we can query them. What has not changed is the part your request actually turns on. The only identifier on those rows is the app instance ID, the app never shows it to you, and you cannot read it off your phone — so we can now see all of it and still identify none of it as yours. The answer to a request about your own data is the same as it was; the reason for it is narrower than it was. Not that the data is beyond our reach, but that you are not findable in it. What the levers above do is stop anything more being added, and, in the case of clearing the data, break the link to your device so that nothing collected afterwards is joined to any of it. Section 11 has the steps.

You also have the right to complain to a supervisory authority. In the UK that is the Information Commissioner's Office:

If you are in the EEA, you may complain to your national data protection authority. We would rather you contacted us first at tech@tactixadslp.com, but you are not required to.

11. How to opt out or delete your data

Turn the statistics off inside the app. This is the direct route, and it is the one to use. Open Settings — the gear icon in the top bar of either the Library or the Tools screen — and turn off the switch at the top. It is labelled Anonymous usage statistics, in every country. That is the whole procedure. It takes effect immediately, it is remembered across updates and restarts, and it holds wherever you are: an answer you have given always outranks the region rule in section 4. The same switch turns it back on if you change your mind.

What that switch does about the ads: nothing. Not in any country. In version 2 it stopped the ads as well in the countries where we had asked you first; since version 3 it does not, anywhere, because our question is no longer a question about the ads at all (section 4). The wording underneath it describes the statistics only, because a switch that claimed to stop ads it does not stop would be the worse dishonesty. The three routes below are the ones that reach the advertising. If you think the app has placed you in the wrong country — you live in the UK or the EEA and were never shown Google's form — write to us and say so: that is a fault in the country detection described in section 4, and it is worth fixing for everyone it affects and not only for you.

What the switch does not do anywhere is delete what was already collected. It stops the collection; it does not reach back into it. Section 10 explains why we cannot do that part for you.

The three ways to control the advertising. They are different levers, they reach different things, and only the last of them works everywhere.

  1. Google's consent form, in the UK and the EEA. It is shown before any ad is requested, and it is where the advertising is allowed or refused, purpose by purpose. Until it is answered, no ad runs at all. Decline the personalization and you still see ads, but non-personalized ones, or ones limited to whatever you did allow.
  2. Settings → Manage ad privacy, where it is offered. In the countries where the law requires that form to be reopenable, the app's Settings screen has an entry that reopens it, and your new answers replace the old ones. Everywhere else the entry is not shown, because there would be no form behind it.
  3. Android's own advertising ID controls, in every country. Android Settings → Privacy → Ads (the exact path varies by manufacturer) lets you reset the advertising ID, which starts the profile again from nothing, or delete it altogether, after which apps that ask for it get nothing — Inkwell's ad requests then carry no identifier, and the ads you are shown are non-personalized. This one is not ours to give or withhold, it does not depend on where you live, and it is the strongest of the three.

Reset the app instance ID, and clear what is on your phone. Android Settings → Apps → Inkwell → Storage and cache → Clear storage (older versions call it Storage → Clear data; the exact path varies by manufacturer). This does two things at once: it deletes the app's local storage — signature, reading position, and Ink balance — without removing any of your documents, and it resets the app instance ID, so nothing collected from then on is joined to anything collected before. It is the closest thing to a reset switch the app has.

One caveat, because leaving it out would be dishonest: clearing the app's data also clears both of your answers — the one about the statistics and the one you gave Google's form — since both are stored on your phone like everything else. Outside the countries in section 4 that means the statistics start again under section 6's legitimate-interests basis the next time you open the app, and so do the ads. Inside them you are asked both questions again, and until you answer, nothing is collected and no ad is requested. So if you want the statistics off and to stay off, use the switch — and if you clear the data as well, set the switch again afterwards.

Uninstall. Removing the app stops all analytics collection and all advertising permanently, and deletes everything the app stored locally. Documents you saved yourself stay where you saved them.

Turn off notifications. Android Settings → Apps → Inkwell → Notifications, or turn off just the "Reminders" channel.

Ask us. Email tech@tactixadslp.com. Please read the honest note in section 10 first: we have no identifier you can quote at us, so on a request about your own analytics data the likely answer is that we cannot find it. We will still reply, within one month, as the UK GDPR requires — and we will tell you exactly what we could and could not do.

12. Children

Inkwell is not directed at children. It is a document tool intended for adults, our Google Play target-audience declaration is 18 and over, and the app is not part of Google Play's Teacher Approved or Designed for Families programmes.

We do not knowingly collect data from children. We have no way to determine a user's age, because the app has no account and asks for no personal details. If you believe a child has used the app and you want the associated analytics data deleted, email tech@tactixadslp.com — but the limit in section 10 applies here too, and we would rather say so now than promise something we cannot deliver: we have no way to pick one device's data out of the rest. Turning the statistics off in Settings stops any further collection at once, and clearing the app's data or uninstalling it (section 11) severs the link as well. That is the remedy that actually works.

13. Security

The practical protection here is architectural rather than procedural: your documents, your signature and your recognised text are never transmitted, so there is no copy of them for us to lose. Local data sits in the app's private storage, which Android isolates from other apps, and Android's automatic cloud backup is switched off for this app. Analytics data in transit is encrypted by the Firebase SDK, and once it reaches Google it is held under Google's own security terms. It carries no name, no email address and no account, and the copy we hold ourselves carries no advertising ID either (section 9) — there is simply not much in it to lose. The advertising ID that does leave your device goes to Google with the ad request, over the ad SDK's own encrypted connection.

No system is completely secure, and we make no guarantee beyond describing what the app actually does.

14. Changes to this policy

If we change what the app collects, we will update this policy and change the effective date at the top. The current version is always at the URL published on our Google Play listing.

Material changes — a new SDK that collects something new, advertising, in-app purchases — will be described here before or at the same time as the release that introduces them, not afterwards. Two of these versions are that:

The version number at the top is a whole number on purpose. The app records which version of this policy was on screen when you answered our question, and compares it with the version the installed release carries — so there is no such thing as version 3.1. If you are in one of the countries in section 4 and you answered the version 2 question, what you answered was a question about the statistics and the ads together. Version 3's question is about the statistics alone, so your old answer is not an answer to it. The app asks you again, and collects nothing until you reply.

Google's consent form is not versioned by this policy. It is a separate record with its own lifecycle: Google's SDK decides when it must be shown or shown again, it is put to you before the first ad in the countries that require it, and clearing the app's data clears it along with everything else (section 11).

15. Contact

TACTIX ADS LP
85 Great Portland Street, London W1W 7LT, United Kingdom
tech@tactixadslp.com