Privacy Policy

Privacy Policy

How the PDF Viewer app handles your information.

Applies to PDF Viewer for Android 1.2.8 (versionCode 11, com.octopus.pdf.viewer) · Last updated: September 29, 2026

1. Overview

This Privacy Policy describes how PDF Viewer ("the app", "we", "our", or "us") handles your information when you use our Android application. Optional access is controlled through the app and Android permission or file-selection screens; this policy explains that access and does not replace those choices.

PDF Viewer is a document reader and PDF annotation tool. It has no user account, no sign-in, and no server of ours that stores your documents. Your files are opened, rendered and edited on your device.

The app is supported by advertising. It also uses a small number of third-party SDKs for advertising, ad attribution and crash/notification services, which are described in detail in Section 5.

2. Information You Provide

No account or sign-in is required, and the app does not ask for account or payment information to use its document tools. If you contact us by email, we receive your email address, message and any attachments you choose to send, and use them to respond to your request.

The document tools do not upload these files, annotations or images to a server of ours. If you deliberately share a file with another app, a cloud provider or our support email, that recipient receives the content you choose to send.

3. On-Device Processing

All document handling happens on your device:

Office previews load their renderer from bundled app assets and read local document copies. The preview pipeline does not use an online conversion service. Documents may contain external links or resources; opening or loading external content can contact the relevant website or provider, whose data practices apply.

Optional background screenshot reminders

To enable screenshot reminders, you select your phone's actual screenshot folder using Android's system folder picker and grant read access. Common locations include DCIM/Screenshots and Pictures/Screenshots; the correct location depends on your phone. Android grants access to that directory and its contents, including future files, rather than to your entire photo library.

When the feature is enabled and notifications are allowed, the app runs a foreground service with an ongoing notification. It observes changes and periodically checks the selected directory for newly saved screenshot images, including while PDF Viewer is in the background. It reads image content to show a local preview and records the image name, content URI and capture or file timestamp in a local database. The app does not record your screen, take screenshots for you, or upload screenshot images or this index as part of monitoring.

Only the selected directory is monitored. Existing images are used as a starting baseline rather than generating new alerts, and screenshots identified as taken while PDF Viewer is visible are excluded. Detection can take several seconds and can be interrupted by Android or manufacturer battery restrictions. Opening a screenshot notification lets you view that image and choose to convert it to PDF.

Screenshot notifications may display a file name or image preview on the notification shade or lock screen, depending on your device settings. You can disable Screenshot reminders in the app's Settings, choose a different Screenshot folder, or change notification visibility in Android settings. Disabling monitoring stops the service; it does not delete screenshots, existing index entries or previously granted directory access.

4. Collection and Sharing

Document reading, editing, conversion and screenshot monitoring process your files locally. These features do not upload document contents, signatures or screenshot images to an app-operated backend, and we do not sell or rent those contents. Local processing still involves accessing and storing the information needed for the features, as described in Sections 3 and 8. Support emails and files you intentionally share are separate from these local operations.

However, the app does include third-party SDKs for advertising, ad attribution and app stability. These SDKs operate independently of your documents and may collect limited device and usage data over the internet, such as:

The app does not intentionally pass document contents, signatures or screenshot images to advertising or attribution SDKs. Diagnostic reports can contain exception messages and technical context, which may include a file name or path if it appears in an error. We do not claim that third-party SDKs are isolated from the app by separate Android file permissions.

We use provider dashboards to review advertising and attribution reports and diagnose problems. These can include aggregate statistics as well as individual crash details and installation or session identifiers; they are not necessarily anonymous. We use this information to operate the app, measure advertising and fix defects.

5. Third-Party Services

The app integrates the following third-party services. Their privacy policies and applicable service terms explain their data practices and their roles in processing data. We remain responsible for our use and configuration of these services.

Advertising

Ad attribution and measurement

Stability and messaging (Google Firebase)

Document scanning

Document rendering library

6. Permissions

PDF Viewer uses the permissions and user-granted access below. Some Android permissions are granted automatically; runtime permissions and special access are controlled separately by Android.

PermissionWhy the app requests it
Internet
(INTERNET)
Required by the advertising, attribution and Firebase SDKs to load ads and configuration and to send crash reports. The app itself does not upload your documents.
Network state
(ACCESS_NETWORK_STATE)
Lets the advertising SDKs detect connectivity so they do not fail or retry pointlessly when the device is offline.
Notifications
(POST_NOTIFICATIONS)
Shows the app's own notifications: new-screenshot cards for the optional screenshot feature, document reminders, and messages sent through Firebase Cloud Messaging. You can decline or revoke this and still use all document features.
Selected images and screenshot directory
(Android system photo/file picker and folder picker)
Image to PDF and ID Card receive images you select through system pickers. Background screenshot reminders require a separate, persistent read grant to the local screenshot directory you select. Monitoring reads newly saved images in that directory and stores local metadata as described in Section 3.
All-files access
(MANAGE_EXTERNAL_STORAGE)
Used, if you grant it in Android special-access settings, to discover and manage supported PDF and Office documents in shared storage, subject to Android restrictions. Screenshot monitoring does not use or require this permission; it uses the separately selected directory. Document and image system pickers do not require this broad access.
Files and media on older Android
(READ_EXTERNAL_STORAGE up to Android 12L, WRITE_EXTERNAL_STORAGE up to Android 10)
Same document access and saving on devices that do not support the newer storage permission model.
Run after restart
(RECEIVE_BOOT_COMPLETED)
Restores scheduled local reminders after a restart or app update. Directory selection and screenshot settings are retained, but you may need to reopen PDF Viewer to restart screenshot monitoring after a reboot, force-stop or system termination.
Background service
(FOREGROUND_SERVICE, FOREGROUND_SERVICE_SPECIAL_USE)
Runs optional screenshot monitoring with an ongoing notification. It listens for directory changes and periodically checks only the selected directory for new images. Turn off Screenshot reminders in the app settings to stop it. A foreground service does not guarantee uninterrupted operation if Android or the device manufacturer restricts the app.

Permissions added automatically by the included SDKs

The advertising, attribution and messaging libraries listed in Section 5 declare a number of further permissions in the app's manifest. These support SDK and notification functions; they do not replace the document or directory access described above:

PermissionWhat it is for
Advertising ID
(com.google.android.gms.permission.AD_ID)
Allows the advertising and attribution SDKs to read your resettable Google Advertising ID, as described in Sections 4, 5 and 7.
Privacy Sandbox ad services
(ACCESS_ADSERVICES_AD_ID, ACCESS_ADSERVICES_ATTRIBUTION, ACCESS_ADSERVICES_TOPICS)
Lets the Google Mobile Ads SDK use Android's Privacy Sandbox ad APIs for ad measurement, attribution and interest-based advertising without cross-app identifiers.
Wake lock
(WAKE_LOCK)
Used by the messaging and advertising libraries to complete delivery and measurement work when the screen is off.
Receive cloud messages
(com.google.android.c2dm.permission.RECEIVE)
Allows delivery through Firebase Cloud Messaging. Messages are sent using the Firebase project and its authorized senders, and Google operates the delivery infrastructure.
Vibrate
(VIBRATE)
Used for notification alerts, including the screenshot cards and reminders described above.
Wi-Fi and install-referrer service state
(ACCESS_WIFI_STATE, com.android.vending.CHECK_LICENSE, BIND_GET_INSTALL_REFERRER_SERVICE)
Used by the advertising, measurement and attribution SDKs to determine connection type and to read the Google Play install referrer described in Section 5.

The app does not request access to your location, the camera, microphone, contacts, calendar, SMS, call logs, health data or biometric data. Scanning is handled by the Google Play services scanner component described in Section 5, and image import uses system pickers. Separately, enabling screenshot monitoring grants ongoing access to the chosen directory, including new images saved there; all-files access, if enabled for document management, is broader still.

Manage runtime permissions and notifications in Android Settings → Apps → PDF Viewer. Manage all-files access under Android’s Special app access settings. Directory grants are separate from photo permissions. You can stop monitoring or change its selected directory in the app; these actions do not revoke earlier directory grants. Clearing app storage or uninstalling removes the app’s saved directory grants. Turning off screenshot monitoring leaves the document tools available.

7. Advertising, Analytics and Your Choices

The app is free and displays advertising. Ads are served by Google AdMob and, through mediation, by the partner networks listed in Section 5. To serve and measure ads, these partners may collect the advertising identifier, IP address, device and app data, and ad interaction data described in Section 4, and may use cookies or similar technologies.

Partner policies explain how they process advertising data. You can manage advertising identifiers and supported personalization controls on your device:

Advertising-ID and personalization controls do not necessarily stop ads, contextual advertising, diagnostics or fraud-prevention processing. Some tool flows use rewarded ads. Choosing not to use a tool does not by itself disable the app’s other SDKs.

The app does not integrate the Google Analytics for Firebase SDK as a separate analytics product. Advertising and attribution SDKs still perform their own measurement, and Firebase Crashlytics and ML Kit process the diagnostic or usage data described above. Disabling screenshot monitoring or denying notifications does not disable advertising, attribution or crash reporting.

8. Data Stored on Your Device

The app keeps the following information locally, primarily in its Android app-specific storage:

The app sets allowBackup="false" to disable Android cloud backup. On some devices, this does not prevent manufacturer-managed device-to-device transfer; the app’s current transfer rules do not exclude all private files. Review your device’s backup and migration settings. Files you save in shared storage or deliberately export may also be included in backups operated by other apps or providers.

9. Retention and Deletion

Local documents, settings and screenshot records remain until you delete them, clear app storage or uninstall, subject to cache cleanup by the app or Android:

SDK data has retention periods separate from your local files. Google describes a 90-day retention period for Crashlytics crash traces and associated identifiers before beginning removal; other services follow their published policies and applicable configurations. Deleting local app data does not automatically erase provider-held records. Contact us for requests relating to data processed on our behalf; we will use available provider controls or explain any identification limits and direct you to the appropriate provider. Support correspondence is kept for handling the request, related follow-up and any applicable legal obligations, and can be included in a deletion request.

10. Your Rights and Choices

Depending on where you live, you may have rights to access, correct, delete, restrict or object to the processing of your personal data, to data portability, and to withdraw consent (for example under the GDPR, the UK GDPR, the CCPA/CPRA, or similar laws).

No app account is required, but support correspondence and SDK reports can still contain personal data. Available controls depend on the type of information and the relevant service:

We do not sell your personal information for money. Sharing device identifiers with advertising partners for interest-based advertising may be considered a "sale" or "sharing" under some laws; you can opt out as described above.

11. Security

App-private copies use Android’s application storage protections. Original files in shared storage and deliberately shared or exported files have the access controls of their storage location or recipient. Google Mobile Ads and Firebase document encryption in transit; other providers describe their safeguards in the linked policies.

No method of storage or transmission is completely secure, and no app can guarantee absolute security. You should keep your device protected with a screen lock, and be aware that files you explicitly share or export leave the app's private storage and are then governed by wherever you send them.

12. Children's Privacy

The app is a general-audience productivity tool. It is not directed to children, and we do not knowingly collect personal information from children. The app does not ask for a name, email or any account and does not provide public profiles or a social feed. Files can still be shared with another app when you choose to do so.

Because the app is supported by advertising, it is not intended for children under the age of digital consent in your country. If you are a parent or guardian and believe a child has used the app and provided information to a third-party SDK, please contact us at the address in Section 14 and we will help you exercise the available controls, including device-level ad personalization opt-outs.

13. International Transfers and Changes to This Policy

The third-party providers listed in Section 5 are international companies and may process the technical data described above on servers outside your country, including in the United States, under the safeguards described in their own privacy policies.

We may update this Privacy Policy from time to time, for example when features or SDKs change. The revised version will be posted on this page with a new "Last updated" date at the top. Material changes will also be noted in the app's store listing or in the app itself.

14. Contact Us

If you have any questions or concerns about this Privacy Policy or about how the app handles your information, please contact us: