Privacy Policy

Magnifier: Zoom & Reader

This policy explains how the Magnifier Android application handles local visual content, technical identifiers, trial access, and one-time purchase verification.

Effective date: August 9, 2026 Package: com.magnifier.app
No ads or developer analytics Magnifier contains no advertising SDK and does not operate a developer analytics service.
Visual content stays local Camera images, recognized text, and QR contents are not sent to the Magnifier backend.
Access is verified online A pseudonymous device key and purchase data support the trial and lifetime entitlement.

1. Identity and scope

This Privacy Policy applies to the Android application Magnifier: Zoom & Reader ("Magnifier", "the app"), package com.magnifier.app. It is effective August 9, 2026.

Contact email: 35olia35@gmail.com.

2. What Magnifier does not collect

Magnifier does not send camera frames, frozen images, recognized text, QR contents, speech text, or synthesized audio to the Magnifier backend. The app does not maintain cloud histories of images, text, QR scans, or speech.

Magnifier has no advertising SDK, does not serve ads, and does not operate a developer analytics or cross-app tracking service. It does not ask for a name, email address, phone number, postal address, password, contacts, messages, health data, or precise location.

3. Camera, frozen images, and sharing

Magnifier requests CAMERA permission for live magnification, zoom, torch-assisted viewing, tap-to-focus, frozen frames, text recognition, and QR scanning. Live frames and frozen images are processed locally. A frozen image remains in app memory while in use and is not automatically saved or uploaded.

When you explicitly save an image, it is written to the storage destination provided by Android. When you explicitly share an image, Magnifier creates a temporary local share file and sends it through Android's share sheet to the app you choose. The receiving app or storage provider then handles the image under its own practices.

4. Reader and text to speech

The Reader uses Google ML Kit on the device to recognize text in a frozen image. The app includes recognition support for Latin, Chinese, Japanese, Korean, and Devanagari scripts. Google Play services may download a recognition module when needed.

Recognized text is displayed locally and can be copied only when you choose. Magnifier does not upload recognized text or keep a recognized-text history. On-device language identification helps select an appropriate Android TextToSpeech language or voice.

When you choose Read aloud, Magnifier passes the recognized text to the Android TextToSpeech engine installed or selected on your device. Magnifier does not store speech history or audio. Voice downloads and network behavior depend on the installed TTS engine, which may have its own privacy practices.

5. QR scanner

QR recognition runs locally through Google ML Kit. Magnifier does not send QR payloads to its backend and does not maintain QR history. Links are never opened automatically.

Open, Copy, and Share occur only after your explicit action. Open sends an HTTP or HTTPS URL to an external browser or compatible app. Copy writes the payload to Android's clipboard. Share sends it to the app you select. Those destinations have their own privacy practices.

6. Trial and device identifier

Magnifier provides a seven-day trial and uses a Supabase backend to make the trial resistant to reinstall-based resets, check access at startup, restore verified lifetime access, and limit abuse.

The app reads Android's ANDROID_ID and combines it with an app-specific schema and package name. It immediately applies SHA-256 on the device to create a pseudonymous 64-character device key. The raw ANDROID_ID is not transmitted to or stored by the Magnifier backend. The pseudonymous device key is transmitted over HTTPS to a Supabase Edge Function, which applies a server-secret HMAC before storing a device_hash.

The stored trial record contains an internal record ID, the HMAC-derived device hash, trial start and expiry timestamps, creation and last-seen timestamps, and a trial policy version. It is used only for app functionality, entitlement enforcement, security, fraud prevention, and abuse prevention. It is not used for advertising, behavioral profiling, or cross-app tracking.

7. Anonymous technical access identity

The app has no visible registration, login, profile, or user account screen. It does not ask you for a name, email address, password, phone number, or social sign-in.

To authenticate access checks securely, the app creates a technical anonymous Supabase authentication session. Supabase assigns an anonymous UUID and issues access and refresh tokens. Session tokens and their expiry are stored in private app preferences on the device. This technical identity is not presented as a personal account and is not used to build a profile.

8. Google Play purchase and lifetime access

Magnifier offers one non-consumable, one-time purchase for lifetime access. The Google Play product is magnifier_full_access with purchase option full-access. It is not a subscription.

Google Play handles the payment transaction and payment-card details. Magnifier does not receive or store your card number or payment credentials. After a purchase or restore, the app sends the Google Play purchase token, product ID, and pseudonymous device key to its backend over HTTPS. The backend verifies the purchase with the Google Play Developer API, records the entitlement, and acknowledges eligible purchases.

The backend stores the raw purchase token and a SHA-256 token hash; package, product, and purchase-option identifiers; purchase and acknowledgement state; purchase completion, first-verification, last-verification, acknowledgement, creation, and possible revocation timestamps; test-purchase status; and, when Google supplies them, order ID and region code. A linked lifetime-entitlement record stores internal trial-device and purchase IDs, product ID, grant and verification timestamps, creation time, and any revocation time. Purchase tokens are not written to Android logs.

9. Google ML Kit technical data

Google states that ML Kit input data and outputs are processed on the device. For Magnifier, the user content involved includes camera images, recognized text, and QR contents. That user content is separate from the technical metrics described here.

Google states that ML Kit Android SDKs collect technical information for diagnostics and usage analytics, including device and application information, per-installation or device identifiers depending on the feature, performance metrics, API configuration, input and output sizes, feature versions, event types, and error codes. The language-identification feature also collects identified languages. Google reports that this technical data is encrypted in transit and is not transferred by ML Kit to third parties.

10. Local data

Private app storage may contain the selected OCR script, camera-permission prompt state, anonymous Supabase session tokens, a verified trial snapshot, and a verified lifetime entitlement snapshot. These local access snapshots contain status and relevant verification timestamps, not camera or recognized-text content.

Temporary shared-image files are kept in app cache and are subject to best-effort cleanup. Images you explicitly save remain in device storage until you delete them.

11. Data recipients and service providers

  • Supabase: anonymous authentication, Edge Functions, trial records, purchase verification records, and lifetime entitlements.
  • Google Play and Google Play Billing: product display, purchase processing, purchase state, and restoration.
  • Google Play Developer API: server-side purchase verification and acknowledgement.
  • Google ML Kit and Google Play services modules: on-device OCR, QR recognition, language identification, model delivery, and technical metrics.
  • Android TextToSpeech: read-aloud processing through the engine selected on the device.
  • Browsers, storage providers, clipboard, and sharing apps: only when you explicitly open, save, copy, or share content.

Supabase and Google process applicable data to provide services to Magnifier. Their own legal notices also govern their processing.

12. Data retention and deletion

Local data

Clearing Magnifier's app data or uninstalling the app removes private preferences, sessions, cached access snapshots, and app cache from that installation. You must delete user-saved images from device storage yourself. Data sent to another app remains subject to that app's controls.

Trial records

The backend retains the pseudonymous device hash and trial timestamps so the fixed trial can remain enforceable after reinstall and so abuse can be prevented. Uninstalling the app does not delete this server record. No automatic deletion period is currently promised for these records.

Purchase and entitlement records

Purchase-verification and lifetime-entitlement records are retained as needed to verify, restore, secure, and administer lifetime access; detect duplicate or fraudulent use; and document purchase state and revocation. No automatic deletion period is currently promised for these records.

Magnifier does not provide a personal account or an in-app account-deletion control. The current pseudonymous design does not provide the developer with a reliable way to locate a particular server record from a person's name or email address. Contact the developer with privacy questions, but do not send purchase tokens or other secrets by email.

13. Permissions

CAMERA: live magnification, frozen frames, OCR, and QR scanning.

INTERNET: anonymous Supabase authentication, trial and entitlement checks, purchase verification, Google Play Billing, ML model delivery, and applicable third-party technical metrics. It is not used to upload camera images, recognized text, QR payloads, or speech content to the Magnifier backend.

14. Security

Backend communications use HTTPS. Sensitive Google Play credentials, the Supabase service-role credential, and the device-hash HMAC secret are server-side and are not embedded as privileged credentials in the Android app. Purchase legitimacy is verified server-side before lifetime access is recorded. Database tables use row-level security and are not directly readable or writable by anonymous app clients.

Magnifier minimizes content collection and avoids logging raw purchase tokens on Android. However, no storage, transmission, or security method can be guaranteed absolutely secure.

15. Official service information

16. Children

Magnifier is a general-purpose utility and is not designed to solicit personal information from children. The developer does not knowingly use the app to collect names, contact details, visual content, or recognized text from children.

17. Policy changes and contact

This policy may be updated when Magnifier's functionality, dependencies, or legal requirements change. The effective date will be updated when the policy changes.

Questions about this Privacy Policy can be sent to:

35olia35@gmail.com