Effective date: 2026-04-28 App: CarContractScan (the “App”) Operator: Fractalthink (“we,” “us,” “our”)
This policy explains what information the App collects, how we use it, and who it is shared with. It covers the iOS and Android versions of CarContractScan.
We have written this in plain language. If anything is unclear, email us at support@fractalthink.com.
CarContractScan lets you scan a dealership car-purchase contract with your phone’s camera and get a plain-English summary, key dates, and risk flags before you sign. It is not legal advice — see the Terms of Service for the full disclaimer.
The App is built so we collect as little as possible.
When the App contacts our servers, our servers log:
We do not log the contents of your contracts, your device’s advertising identifier, or any cross-app activity.
Your acceptance of this Privacy Policy and the Terms of Service is recorded in a small file (consent.json) inside the App’s private storage on your device. This file never leaves your device. We do not log or sync your consent server-side. If you uninstall the App, the file is removed with it.
We use the information described above only to:
We do not:
To run the App we share specific data with the following providers. Each is bound by their own privacy practices, linked below.
| Provider | What we send | Why | Their policy |
|---|---|---|---|
| Anthropic | Contract pages, scan ID, locale | To analyze the contract and generate the summary | https://www.anthropic.com/privacy |
| RevenueCat | Anonymous user ID, purchase events | To manage in-app purchases and entitlements | https://www.revenuecat.com/privacy |
| Apple | Standard App Store telemetry, IAP transactions | App distribution and payment processing | https://www.apple.com/legal/privacy/ |
| Google (Firebase App Check) | Anti-abuse attestation tokens | To prove requests come from the genuine App, not a script | https://firebase.google.com/support/privacy |
| Cloudflare | Standard request metadata | To deliver our backend API to your device | https://www.cloudflare.com/privacypolicy/ |
We host our backend on infrastructure we operate ourselves. We do not use third-party analytics SDKs (no Mixpanel, no Amplitude, no Sentry, no Crashlytics).
Because the App does not collect identifying information, we cannot look up “your” data on request — we genuinely do not know which anonymous identifier is yours.
You can:
support@fractalthink.com with questions or concerns.If you are a resident of California, the EU/UK, or another jurisdiction with specific privacy rights (right to know, right to delete, right to portability, etc.), we will honor reasonable requests to the extent we have the data. In most cases we will not — we deliberately do not retain it.
The App is not directed to children under 13 (or the equivalent minimum age in your country). We do not knowingly collect information from children. If you believe a child has used the App, contact us and we will investigate.
We use HTTPS for all network traffic between the App and our backend. Our backend is protected by Firebase App Check (so requests can be cryptographically verified as coming from the genuine App), rate limiting, and a remote killswitch in case of abuse. No system is perfectly secure, but we work to use reasonable safeguards proportionate to the (limited) data we collect.
We may update this policy from time to time. The latest version is always available at https://legal.fractalthink.com/privacy.
When we make a substantive change — for example adding a new third-party service or expanding what we collect — we will bump the version constant in the App and you will be asked to re-accept this policy on next launch. Minor edits (typos, clarifications) will not trigger re-acceptance.
Email: support@fractalthink.com
Operator: Fractalthink
Postal address (registered agent):
Northwest Registered Agent
2501 Chatham Rd. Ste. N
Springfield, IL 62704
This policy is provided in plain language and is not a substitute for advice from an attorney licensed in your jurisdiction.