<!-- source: https://picania.com/privacy -->

# Picania privacy policy

Last updated 2026-09-23. This page changes when what the app sends changes; the date above moves with it.

## The short version

- Picania has no account, no sign-in and no ads. Without Picania Plus the developer receives nothing from the app itself. With Plus, Picania's server passes scans to Gemini and counts credits; it keeps neither the photos nor the answers. Google Play gives developers aggregate install and crash statistics under Google's own terms.

- Your photos, results, history, sales and settings are stored on your phone. The table below lists what leaves it. Photos, text and your notes leave only after something you do: a scan, a tap or a share. A few things are automatic: Google's ML Kit diagnostics, a daily check of the Gemini model list and prices while you use your own key, a check with Google Play on your phone for a Picania Plus purchase each time the app opens or comes back to the screen (with the purchase token sent to Picania's server only if you have or recently had one), a retry of a scan you started that could not finish once the connection returns, and a catalogue lookup of a book or music barcode the phone reads in a photo you scan.

- Cloud identification sends a checked copy of your photo to Google's Gemini API, either under your own API key or through Picania Plus. Without Plus, nothing goes to Gemini until you add a key.

- Before a photo is uploaded, the phone blurs personal text it can read, pixelates faces (except on a Cards mode grid, where cards carry printed faces; on a phone without Gemini Nano, a photo with a detected face is not uploaded at all, except a small face on a Cards mode grid), and strips location metadata. That check is best effort, not a guarantee.

- When the app uses Google's ML Kit libraries, they may send Google diagnostics about themselves (device model, app version, timings, a per-install identifier). No photo and no text goes with them.

## What stays on your phone

Photos you scan (the checked copy is what the app keeps), item names, values and verdicts, your scan history, sales and shortlists, your notes and corrections, your settings, and your Gemini API key (encrypted with a key held in the Android Keystore, so it is not stored in plain text). The app's own data opts out of Android backup, so none of it is copied to Google's cloud backup; a phone-to-phone transfer when you set up a new device may copy it (your key's encrypted copy cannot be read on the new phone). Photos taken with Picania's own camera are also saved to your gallery under Pictures/Picania as ordinary, unblurred photos; a gallery backup such as Google Photos treats them like any other photo. A gallery photo you import is never modified. To delete: Settings → Stored scans → Clear all removes every saved scan and result, including the scans made for a sale (the sale keeps its listing and notes but loses those photos); your key, subscription token and settings stay until you uninstall; a scan not yet finished is removed from its own row in Manage Items once it is no longer running. Deleting a sale removes its files and the scans made for it; a scan the sale reused from your ordinary history stays there. Uninstalling the app removes its own data; the Pictures/Picania photos stay in your gallery until you delete them there.

## What leaves your phone, and when

When | What is sent | To whom

You analyze a photo (camera, gallery, a sale photo) with a Gemini key added | A copy of the photo after the on-device check (personal text pixelated best effort, faces pixelated outside Cards mode, location metadata stripped because the copy is re-encoded); the text the phone read from it with personal text removed best effort; a barcode if one was read, with the catalogue's title and author line; for a sale photo, the listing's caption. An Inspect sends the checked close-up and may send the checked photo of the item's cover. In Cards mode: higher-resolution crops of each card cell, faces not pixelated because cards carry printed faces. | Google's Gemini API, under your key. Google's Gemini API terms apply to what you send. On the unpaid tier Google may use your content to improve its products and human reviewers may read it after it is disconnected from your key; on a paid tier it is not used to improve products and is logged for a limited time for abuse monitoring.

You scan with Picania Plus | The same request as with your own key | Picania's server, then Google's Gemini API under Picania's paid account. Google's paid-tier terms say prompts and responses are not used to improve its products and are logged for a limited time for abuse monitoring. The function keeps nothing from the scan; its logs hold the model, the token, item and credit counts, Gemini error codes and a short prefix of the hashed record id, alongside Google Cloud's standard request log (IP address, time, user agent) kept for Google Cloud's default log retention.

The app opens or comes back to the screen while you have (or recently had) a Picania Plus purchase, and with every Plus scan | Your Google Play purchase token, and an attestation from Google Play Integrity that the request comes from the genuine app | Picania's server, which checks the token with Google Play

Your first Plus scan or subscription check, then as needed while you subscribe | A Firebase installation id and a Firebase messaging registration made through Google Play services (app id, app and Android version), and a Play Integrity attestation exchanged for a Firebase App Check token. Later requests to Picania's server carry that registration token and the App Check token in headers; the server does not store them. Nothing of this happens without Plus. | Google (Firebase, Play Integrity, Google Play services), then Picania's server

"Second opinion on expensive picks" is on and a pick qualifies | A padded crop of that item, cut from the checked photo | Google's Gemini API, under your key or through Picania Plus

You Inspect an item or ask for a second opinion yourself, after typing a name or a note for it | Your typed name and note for that item, as hints, with the photo (prices you typed are removed from the note first) | Google's Gemini API, under your key or through Picania Plus

When the app uses ML Kit (detection, text, barcode and face reading, the on-device AI) | Diagnostics from Google's ML Kit libraries: device model and OS version, the app's package and version, timings and sizes, a per-install identifier that is not meant to identify you. Google says it does not pass this to third parties. There is no switch for it. | Google

You add or test a key, open the model list, and once a day while you use your own key | Your key in a request header, asking for the list of models (Test key asks for the chosen model only) | Google's Gemini API

The phone reads a book (ISBN) or music barcode in a photo you scan (before the photo check, whether or not a key is set) or in an Inspect close-up (after the check) | The barcode digits | Open Library (books), MusicBrainz and Apple's iTunes lookup (music)

At most once a day, while you use your own key | A request for the public price list; no key, photo or content | OpenRouter

You share, retry or refresh an estatesales.net sale link | Requests for the sale page, a thumbnail of each picture it lists, and the full pictures you select | estatesales.net

You tap Search on an item | The item's name, maker and model, or its barcode, as a search query opened in your browser or search app | Google Search

You tap Image search on an item | The item's crop from the checked photo, and its name | Google Lens, or the app you choose

You tap Directions on a sale | The sale's address and, when the listing gives one, its map position | The maps app you choose

You share a sale with someone | A file with the sale's title, dates and hours, address and map position, seller, listing link and description; every analyzed photo of it (the checked copies) with the full results: names, makers, values, the text and barcodes the phone read; and everything you recorded: stars, your own maximum, names and notes you typed, answers, outcomes, prices paid and asked | The person or app you choose

You open this policy, the guide or a sale's listing page | Only the page address you open | Your browser

## Picania Plus and purchases

Picania Plus is a monthly subscription bought in Google Play, with no account and no sign-in. Plus includes 608 AI credits each paid month; Plus Pro includes 2,138. Google Play handles payment.

For each subscription, Picania's server stores:

- a one-way hash of the purchase token as the record id;

- which product it is;

- this month's AI credit count and any in-flight holds;

- the paid-through date and the last verification time; and

- a hash of the latest order id; and

- random ids and times of its most recent AI calls, used to settle each call's credits once.

It stores no name, e-mail, payment details, photo or scan text. The app passes Google Play a hashed random per-install id for Play's fraud checks; the phone never sends it to Picania's server, and although Google Play includes it in the purchase details the server reads, the server does not store it. Picania Plus also uses Google Play Billing's own traffic.

A subscription's record is deleted automatically three months after its last paid period ends. To have it deleted sooner, e-mail [support@picania.com](mailto:support@picania.com) with the order numbers of your Plus payments (they start with GPA., in your Google Play order history; include every plan if you changed plan); the record cannot be tied to you any other way. A subscription started with a promo code has no order number and is deleted only automatically. If the subscription is still active, the app's next check creates a new record with the month's count at zero; to remove it for good, cancel first and ask once the paid month has ended.

Unused credits do not carry over. Cancelling stops the next renewal. A paid month is not refunded by Picania; Google Play's own refund rules still apply.

## What the app does not send

Your location (the app has no location permission; a sale's map position comes from the listing, not from your phone), contacts, the original photo files, your history or settings apart from the records of a sale you choose to share, and your key to anyone but Google. Every request is over HTTPS. Like any connection, each server sees your IP address and ordinary request headers: the catalogues, estatesales.net and OpenRouter see the app's name (Picania/0.1 (com.picania.app)); Gemini sees Android's standard user agent (Android version and device model) and your key.

## Other people's details in your photos

Before upload the phone reads every line of text in the photo, flags lines that look like an address, phone number, e-mail, card number, date of birth or a name on a form or label, pixelates them on the uploaded copy and removes them from the text sent with it. Faces are pixelated, except on a card grid in Cards mode (printed faces). This is a best-effort check, not a guarantee. Do not upload a photo of a document expecting it to be cleaned. Known limits, in full (the repository is private, so this page is the public list; keep it in step with docs/pii-limitations.md rows 1 to 13 and its Cards note):

- The round MaxiCode block on a FedEx or UPS label is not blurred; the tracking barcode and the address block are.

- Only US formats are recognised: US addresses with a state code and ZIP, North American phone numbers, the US social-security shape.

- A person's name is blurred only when the on-device model (Gemini Nano) is available, is asked and answers. It is asked on the wide shot and on Inspect; a Scene angle shot, a barcode-locked Quick Scan and anything in Cards mode never ask it; without Nano, names in free text stay readable. Addresses, phone numbers, e-mails, card numbers and dates of birth do not depend on it.

- A name standing alone, with no street or form field near it, is not treated as a name (it looks like an author on a spine).

- Handwriting is often missed; text too small or too blurred for the phone to read is not blurred.

- A barcode-shaped symbol the phone cannot decode on a shipping label is blurred without being read, so a pattern that only looks like a barcode, or a product's own barcode that failed to decode, can be pixelated too. A barcode elsewhere (a QR code on a business card, a membership card) is not blurred.

- A tracking number the whole-frame pass missed can still reach the text sent with the photo if it carries no tracking word nearby.

- Bank account and routing numbers, seven-digit phone numbers and non-US address formats are out of scope.

- The original photo on the phone is untouched, including the copy Picania's camera saves to Pictures/Picania; only the uploaded copy and the app's own record are pixelated.

- Pixelation replaces the area with large blocks before the image is encoded; it is not a cryptographic erasure.

- A room, a shelf or a collection can still identify someone with every label blurred.

- A business address is blurred like a private one when no business word is near it, and a private address inside a block that looks like a company's is left partly visible.

- In Cards mode the cells are sent at higher resolution with the frame's blur scaled in and a per-line check; a bare name legible only at cell resolution is not blurred.

- An Ultra HDR gallery photo used to carry a small unblurred copy of the scene (its gain map) into the upload; fixed on 2026-09-22. Measured before the fix: none of the affected photos had anything blurred in it.

## Permissions

Camera, for photos you take in the app. Internet and network state, for the requests above. Google Play Billing, for Picania Plus. Also, with no prompt: keeping the phone awake briefly and receiving Firebase messages (both added by Google's Firebase library used for Plus), and connecting to the phone's on-device AI service (AICore). No other permissions that ask you anything.

## Children

Picania is not directed at children and is listed for adults.

## Contact

Lampensoft™, [support@picania.com](mailto:support@picania.com). This policy is for the Picania app for Android, package com.picania.app, published by Lampensoft™.
