ExactKB – Privacy Policy

Effective 14 September 2026 · Applies to the ExactKB Android app (ro.creativdigital.exactkb)

The short version. ExactKB compresses photos entirely on your phone. We do not upload your photos; sharing sends them to the app you choose. The free version shows ads. Usage analytics follows regional consent unless you choose otherwise in Settings. Crash reporting is on by default with an opt-out. When enabled, these services include technical identifiers and device information. You can buy “Remove ads” once; Google Play handles the payment and we never see your payment details. No account is needed and none is created.

1. Who we are

ExactKB is published by Creativ Digital Agency S.R.L., a company registered in Romania (CUI 50033098, J40/9081/2024), Str. Dacia nr. 133, Sector 2, Bucharest. We are the data controller for the processing described here. Contact: office@creativdigital.ro.

2. Your photos stay on your device

When you choose or take a photo, ExactKB reads it, compresses it and writes the result on your phone. This happens on the device’s own processor. Compression does not upload images or thumbnails. The app has no server for photos. If you share a result, the chosen app receives the file and its name.

3. Permissions

PermissionWhy
Camera (via the system camera app)Only when you tap “Take a photo”. ExactKB does not access the camera itself; the system camera app returns one picture.
PhotosThrough the Android photo picker: the app can only read the photo you select.
Storage (Android 8–9 only)To save the compressed copy to your gallery when you tap “Save”.
InternetUsed only by the advertising, analytics, crash-reporting and Google Play billing components described below. Compression works offline.

4. Data we collect and why

We do not ask for your name, e-mail address or any account. The data below is collected through Google services integrated in the app.

4.1 Usage analytics (Google Analytics for Firebase)

Analytics helps us understand feature usage and improve ExactKB. By default, it is enabled outside the EEA when UMP reports IABTCF_gdprApplies=0. Where UMP reports that GDPR applies (1), including the EEA, it is enabled only if purpose 1 (storage/access of information on a device) in IABTCF_PurposeConsents is consented to. Refusal or missing consent keeps it off. If the regional signal is unavailable, analytics remains off until resolved. We reevaluate at startup and after the UMP or “Ad consent options” form closes.

Settings → Share usage data lets you explicitly opt in or out. This manual choice is saved and takes precedence over the automatic UMP-based analytics decision on later launches and form changes; it does not change your advertising consent. When enabled, we send compression results, size limits, quality, attempts, source size buckets, output bytes, duration, saves, shares and purchase restoration. Firebase also collects an app-instance identifier and technical information such as device model, OS, language and app version. These identifiers are pseudonymous, not anonymous. We do not add photo content or file names. Analytics advertising-ID collection remains disabled.

Turning analytics off stops future collection; switching from enabled to disabled also resets local analytics data. This does not erase previously uploaded data. Server retention follows the project's configured Google Analytics retention settings.

4.2 Crash reports (Firebase Crashlytics)

Firebase Crashlytics is enabled by default in all regions to diagnose crashes and fix bugs. You can opt out at any time using the single Settings → Share crash reports switch; your choice is saved independently of analytics and advertising consent. Reports may include technical stack traces, device and OS information, app version, memory information and an installation identifier. These identifiers may constitute personal data. We do not attach photos. Turning this setting off disables automatic reporting and deletes unsent reports; it does not erase reports already sent. Retention is governed by Firebase Crashlytics' retention policy.

4.3 Advertising (Google AdMob)

The free version shows banners on the home and result screens and, occasionally, a full-screen ad after saving or opening a share destination. Google AdMob may collect advertising IDs, IP addresses, derived coarse location, device information and ad interactions. Google's User Messaging Platform (UMP) handles advertising consent. Advertising consent signals default to denied in the app manifest; app telemetry settings do not override them, leaving updates to UMP and its configured consent-mode integration. Analytics advertising-ID collection remains disabled. Ads are requested only when UMP permits them. Depending on your choices and eligibility, ads may be personalised, non-personalised, limited, or unavailable. Required privacy options are available in Settings → Ad consent options, including after buying “Remove ads”. That purchase hides ads and stops new ad requests, but does not delete previously collected data or disable analytics or crash reporting. UMP may still run to resolve the analytics consent decision.

How Google uses this data: policies.google.com/technologies/partner-sites.

4.4 Purchases (Google Play Billing)

“Remove ads” is a one-time purchase processed entirely by Google Play. We receive only a purchase token and its status so the app can hide ads and restore the purchase on reinstall. We never see your payment method or billing address.

5. Who receives data

ServiceProviderDataPolicy
Google Analytics for FirebaseGoogle Ireland Ltd.Usage events, app-instance ID, device infoFirebase privacy
Firebase CrashlyticsGoogle Ireland Ltd.Crash reports, device infoFirebase privacy
Google AdMob / User Messaging PlatformGoogle Ireland Ltd.Advertising ID, IP, device info, consent choicesGoogle privacy
Google Play BillingGoogle Ireland Ltd.Purchase token and statusGoogle privacy

Google may transfer data outside the EEA under the EU–US Data Privacy Framework and Standard Contractual Clauses. We do not sell personal data.

6. Your choices

7. Your rights (GDPR)

You have rights to access, rectify or erase personal data, restrict or object to processing, and data portability, as applicable. Technical identifiers may not let us identify your records from your name alone. Contact office@creativdigital.ro about exercising your rights. You may also lodge a complaint with the Romanian supervisory authority, ANSPDCP (dataprotection.ro), or your local authority.

8. Children

ExactKB is not directed at children under 16. If you believe a child has provided personal data through the app, please contact us.

9. Security

Photo processing stays on the device. Data sent to Google services uses TLS. Compressed files are kept in private app storage until you save or share them. Sharing grants the receiving app access to the selected file. Android cloud backup is disabled for ExactKB.

10. Changes

We will update this page when the app’s data practices change and update the effective date above. Significant changes will also be noted in the app’s store listing.