Privacy Policy
Who we are
FreeFax is a mobile application operated by Joel Foster (d/b/a “FreeFax”, “we”, “us”). FreeFax lets you scan documents with your iPhone — or upload them from Photos or Files — and send them as fax transmissions to USA and Canadian destinations. This Privacy Policy explains what data we collect, how we use it, who we share it with, and your rights.
If you have questions: joelsfoster+freefax@gmail.com.
What we collect
Account data
- By default, FreeFax operates anonymously. We assign your device a random, opaque identifier (a UUID) the first time you launch the app and use it to track your credit balance and fax history. We do not collect your name, email, or any account information unless you choose to sign in with Apple.
- If you sign in with Apple, we additionally store your Apple user identifier (opaque) and the email address Apple returns to us. Apple supports “hide my email” and we respect that.
Usage data (required for core function)
- The fax destination phone numbers you enter.
- The content of documents you send as faxes — the page images we transmit to your fax carrier. These come from documents you scan with the in-app camera or that you explicitly choose to upload from your Photos library or the Files app (including multi-page PDFs, which we rasterize one-page-per-image on your device before transmission).
- Number of pages sent and the success/failure status of each transmission.
- Timestamps for account creation, sign-in, and fax sends.
- Apple Push Notification Service (APNs) device tokens, used solely to deliver fax-status push notifications (delivered or failed) to your device. Tokens are removed when you delete your account or when Apple invalidates them.
- Per-fax Live Activity push tokens. When you start a fax, iOS generates a short-lived push token bound to the Dynamic Island / lock-screen status pill for that single send. We use it only to update or dismiss that one pill from our server. The token is deleted automatically when the fax record reaches a terminal state, when iOS invalidates it, or at the latest within 8 hours.
Commerce data
- Apple in-app purchase transaction receipts. Apple may share a transaction identifier, product identifier, quantity, and purchase date with us. We do not receive credit card numbers.
- A count of credits you hold and a ledger of how you earned or spent them.
Ad data
- When you watch a rewarded video, Google AdMob processes the ad request on our behalf. AdMob collects device identifiers, ad-interaction events, and coarse geographic signals in accordance with Google’s privacy practices. If you granted App Tracking Transparency permission, AdMob may associate this with your Identifier for Advertisers (IDFA). If you did not, AdMob uses a non-tracking advertising identifier.
- We only receive the reward grant (i.e. “this user completed an ad, grant 1 credit”) from AdMob via Server-Side Verification, keyed to your FreeFax user identifier.
Diagnostic data
- When the app crashes or the server returns an error, we capture an error report via Sentry. This may include a stack trace, device model, OS version, and your FreeFax user identifier and email so we can debug your specific issue. We do not send Sentry your fax content or fax destination numbers.
What we do NOT collect
- We do not collect your precise location.
- We do not read or scan your photos, files, or contacts outside of items you explicitly hand to us via the system Photos picker or the Files picker (and even then, only the items you select — iOS scopes our access to those specific items).
- We do not sell your data to anyone for any purpose.
How we use your data
- To identify your device anonymously and, if you opt in, authenticate you via Sign in with Apple.
- To transmit the faxes you ask us to send, via our fax carrier (Telnyx).
- To maintain your credit balance and a history of your fax transmissions.
- To verify your in-app purchases with Apple.
- To serve you rewarded ads and grant the corresponding credits.
- To update and dismiss the per-fax status pill on your lock screen and Dynamic Island via APNs.
- To diagnose bugs and improve the app.
- To comply with our legal obligations (including the USA Telephone Consumer Protection Act and federal junk-fax rules, and the Canadian Radio-television and Telecommunications Commission’s Unsolicited Telecommunications Rules).
Who we share it with
We share the minimum data necessary with the following processors:
| Processor | What we share | Purpose |
|---|---|---|
| Apple | IAP receipts, transaction identifiers | In-app purchase verification |
| Google (AdMob) | Ad request context, reward confirmation tokens, your FreeFax user id | Serving rewarded ads and verifying reward |
| Apple (APNs) | Device push tokens, per-fax Live Activity push tokens, and notification payloads | Delivering fax-status push notifications and updating the Dynamic Island / lock-screen status pill |
| Telnyx | Your fax document image and the destination phone number | Transmitting the fax |
| Vercel | All API traffic (hosting) and temporary fax-image storage (Vercel Blob) | Infrastructure |
| Neon | Database contents | Postgres database hosting |
| Sentry | Error reports, user id, email | Crash / error monitoring |
We do not sell your data, rent your data, or share it for targeted advertising outside of the rewarded-video flow described above.
How long we keep it
- Fax document images: uploaded to temporary storage, deleted on transmission success or failure, or by a daily cleanup job within 48 hours — whichever comes first.
- Fax transmission records: kept while your account exists so you can review your send history.
- Account records: kept while your account exists. When you delete your account (see below), all records associated with you are deleted within 30 days.
- Error reports: retained by Sentry for 90 days.
Your rights
- Access: the app exposes your data via the send history tab and the account menu.
- Delete: tap “delete my account” in the account menu. This is a hard delete; your account, fax history, credit balance, and error reports tied to your user id are purged.
- Request a copy: email joelsfoster+freefax@gmail.com and we will produce a copy of your data within 30 days.
- Canadian users (PIPEDA): under Canada’s Personal Information Protection and Electronic Documents Act you have the right to access the personal information we hold about you, to request correction of inaccuracies, and to withdraw consent for our processing (subject to legal and contractual restrictions). Contact us at joelsfoster+freefax@gmail.com and we will respond within 30 days. We do not transfer Canadian personal information outside Canada beyond what is shown in the “Who we share it with” table above — our processors (Apple, Google, Telnyx, Vercel, Neon, Sentry) operate primarily from the USA, and your data may be processed there.
- California (CCPA) / EEA (GDPR) users: you have additional rights to know, correct, delete, and port your data. Contact us and we will comply within the timelines the law requires. We do not discriminate against users for exercising these rights.
Children
FreeFax is not directed to children under 13 and we do not knowingly collect data from anyone under 13. If you believe we have, email us and we will delete it.
Security
Data in transit is encrypted with TLS. Fax document images are stored with unguessable URLs and deleted promptly. Session tokens are signed JWTs. No system is perfectly secure; we promise reasonable care, not perfection.
Changes
We may update this policy. The “Last updated” date at the top reflects the most recent change. Material changes will be surfaced in-app.