1. Scope
This policy covers ArbiScan for Crypto on iPhone, iPad and Android, provided by DCMA Technology Limited. Both platforms use the same scanner service; differences in payments, secure storage and privacy controls are explained below.
2. On-device information
Bookmarks, preferences, analytics choices and cached scans are stored on your device. A device credential used for subscription verification is stored in the iOS Keychain on iPhone and iPad, or in Android Keystore-backed encrypted storage on Android. No ArbiScan account or exchange login credentials are required, and the scanner does not place trades.
3. Market-data requests
Loading scans or symbol history sends requests to the ArbiScan service. The service receives network information such as your IP address and requested scan or symbol to serve data, limit abuse and diagnose failures. Our current API service is hosted on Amazon Web Services in Singapore. Subscription verification sends the device credential to our service to determine access. An unbundled token icon may be requested from CoinAll, which receives that network request. External links are handled by the selected service under its own privacy practices.
4. Subscriptions
Apple processes App Store payments on iOS; Google processes Google Play payments on Android. RevenueCat helps verify purchases, renewals, restoration and refunds on both platforms. A random device customer identifier and purchase records determine access. The app’s purchase flow does not give us your payment-card details. Apple, Google and RevenueCat maintain their own transaction records. Restore purchases uses the Apple Account or Google Account that made the purchase in the corresponding store. Store subscriptions are managed separately.
See the Apple privacy policy, Google privacy policy and RevenueCat privacy policy for their practices.
5. Optional analytics
Analytics is off until you allow it. Google Analytics for Firebase then receives screen visits, feature interactions, app and device information, an app-instance identifier and network information; automatic usage and purchase events may also be collected. Custom events exclude search text, saved opportunity identifiers, exchange credentials and the RevenueCat customer identifier. Analytics advertising personalization and advertising-identifier collection are disabled. Settings → Privacy & terms lets you turn analytics off, stopping future collection and resetting analytics data on the device; this does not delete information already received by Google.
6. Advertising and permissions
The free version uses Google AdMob banner ads. The SDK may process network and device information, identifiers, ad interactions and diagnostics. The app requests non-personalized ads and uses Google’s regional consent flow. Non-personalized ads still involve data processing. On both platforms, revisit regional consent choices in Settings → Ad privacy choices. On iOS, tracking permission can be changed in iOS Settings. On Android, advertising privacy controls are available in Android Settings; Android does not use Apple’s tracking-permission prompt. Pro removes banner ads. Refusing tracking permission does not remove free scanner access.
7. Retention and requests
Local bookmarks and preferences can be removed by deleting the app. iOS may retain Keychain credentials after deletion. On Android, uninstalling removes the encrypted device credential, and a reinstall may require restoring purchases. Deleting the app does not cancel a subscription; manage it in the store where you purchased it.
Our API’s Nginx access and error logs are configured for daily rotation with up to 14 rotated log files retained in addition to the current files. This is the rotation setting for those logs, not a deletion deadline for all service data. Other operational logs use the host’s logging and storage limits. Subscription and transaction records maintained by Apple, Google and RevenueCat follow their retention practices and applicable requirements. Turning analytics off or deleting the app does not automatically erase records held by those providers.
For requests about access to or deletion of data associated with your use of ArbiScan, email support@dcma.app. Describe the request and whether you use iOS or Android. Because the app has no ArbiScan account, we may need additional information to identify associated records and verify a request. We cannot identify all server records from a deleted app alone or promise deletion of records independently retained by your app store or other providers.
8. Contact
Email support@dcma.app for privacy questions. Do not send passwords, payment-card details or exchange API keys.