Scanner Privacy Policy
Last updated: May 2026
This policy applies exclusively to the G-Loop Scanner mobile app (com.gstoragescanner) distributed via Google Play Store. For the desktop software and website, see the general Privacy Policy.
1. Introduction
G-Loop Scanner is an Android mobile application that companions the G-Loop desktop software, developed and operated by MEGADV di Andrea Tedesco, with registered office at Piazza dei Mille 18, 88049 Soveria Mannelli (CZ), Italy (hereinafter “we”, “us”, “our”). MEGADV di Andrea Tedesco is the data controller pursuant to Art. 4(7) GDPR. Google Play package identifier: com.gstoragescanner.
The Scanner is a B2B tool that lets users manage filament spools, spare parts, and consumables for 3D printing by scanning barcodes/QR codes and synchronizing data with the user's computer on the same local network. The app does not create any user account internally and does not require login credentials. For any questions about this policy, contact us at info@g-loop.it.
2. Data We Collect
We follow the principle of data minimization (GDPR Art. 5(1)(c)). Data collected by the app is limited to the four categories listed below, and nothing else:
2.1 Pseudonymized Device Identifier
A 16-character hexadecimal hash generated locally from the Android device's unique identifier (getUniqueId()). The original value never leaves the device: only the hash is transmitted. The hash is non-reversible and is used solely to correlate multiple reports from the same device (e.g. group recurring crashes). It is not linked to any real identifying information.
2.2 Diagnostics and Crash Logs
When the app encounters an unhandled error, the following are automatically sent to our server (g-loop.it/api/feedback.php): the JavaScript stack trace of the error, the device brand and model, the Android version, the app version, and the pseudonymized identifier. Stack traces may include internal source file paths and app function names. No payment data, passwords, scanned content, or other personal data are included.
2.3 Voluntarily Submitted Feedback
When you choose to fill in the feedback form from the profile panel, we receive: a rating (1-5 stars), an optional free-text message you wrote, the pseudonymized identifier, system information, and app version. Submission is always user-initiated: no feedback is ever transmitted unless you tap the “Send” button.
2.4 Local Communication via QR Code
When you pair with the computer by scanning the QR code generated by the desktop software, the app connects to the desktop strictly within the local network (RFC 1918 private IP ranges: 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16, plus 127.0.0.0/8 and 169.254.0.0/16). All inventory data (product codes, quantities, loans, team roles) travels directly from phone to user's own computer: it never transits our servers and does not constitute data collection by us. For local network compatibility, this communication uses unencrypted HTTP within the private network; traffic to the Internet (sections 2.1-2.3) is always HTTPS/TLS.
3. What We Do NOT Collect
For clarity towards you and Google Play reviewers, we explicitly state that the G-Loop Scanner app does NOT collect:
- Email address, name, surname, or phone number (the app never asks for these)
- Your device's IP address: our servers do not store the IP in the feedback database (verified at code level)
- Geographic location (neither GPS, nor network, nor IP-based)
- Contents of contacts, calendar, messages, email, or call history
- Photos, videos, or files other than the scanned barcodes — camera images are processed only locally and never leave the device
- Payment, financial, or credit card data
- Web browsing history or usage of other apps
- Advertising identifiers (Android Advertising ID, IDFA) — the app contains no advertising, third-party analytics, or tracking SDKs
4. Purpose of Processing and Legal Basis
We process the data listed in section 2 exclusively for the following purposes, pursuant to Articles 6(1)(b) and 6(1)(f) GDPR:
- Service delivery: enabling the companion app and local communication with the desktop software — legal basis: performance of a contract, Art. 6(1)(b)
- Diagnostics and bug fixing: identifying and solving issues by analyzing received stack traces — legal basis: legitimate interest, Art. 6(1)(f)
- Product improvement: evaluating user feedback to plan new features and fix usability issues — legal basis: legitimate interest, Art. 6(1)(f)
- Update availability check (only in versions distributed outside the Google Play Store; in the Play Store version updates are handled exclusively by Google and the update-check endpoint is disabled)
5. Data Retention
Diagnostics data and feedback are retained in our MySQL database (servers hosted in Italy, provider Aruba S.p.A.) until one of the following occurs:
- You request deletion (see section 10 — Data Deletion)
- The data is no longer necessary for the above purposes (typically within 24 months of submission for bug logs, 36 months for aggregated feedback)
- A legal obligation to delete arises
We do not apply a fixed automatic expiration: retention is evaluated case-by-case based on residual diagnostic value. Deletion requests are fulfilled within 30 days as required by Art. 12(3) GDPR.
6. Data Security
We implement the following technical and organizational measures:
- All app communications towards our servers occur exclusively via HTTPS/TLS 1.2+
- The device identifier is pseudonymized on the device before any transmission (non-reversible hash)
- The pairing QR code uses a single-use token valid for 5 minutes, and the app accepts connections only towards RFC 1918 private IP addresses
- Servers apply rate limiting to prevent abuse (max 5 crash reports/device/day and 10 feedback/IP)
- Logs sent to the server are automatically filtered to remove any credentials, API tokens, passwords, or suspicious strings accidentally included
- Physical servers are located in the European Union (Italy); database access is restricted to the controller and protected by strong authentication
7. Android Permissions Requested
The app declares the following permissions in its Android manifest (verifiable in the device's system settings):
INTERNET— for local communication with the computer (private LAN) and sending feedback to our serversCAMERA— exclusively for reading barcodes/QR codes; images are never saved nor transmittedVIBRATE— to provide tactile feedback when a valid code is scanned
The Google Play Store version does NOT declare the REQUEST_INSTALL_PACKAGES permission (present only in side-distributed builds outside the Play Store, where it is needed for automatic APK updates).
8. Demo Mode — Zero Cloud Traffic
The app includes a Demo Mode that can be activated from the profile panel before pairing with the computer. When Demo Mode is active:
- All traffic to our servers is blocked at code level (gating verified in
api.ts,crashReporter.tsandFeedbackModal.tsx— first instruction of every request) - The app uses an entirely in-memory sample dataset (10 items, 5 team members, 3 loans)
- No device data is transmitted, not even the pseudonymized identifier. Demo Mode is designed to allow full app evaluation (including by Google Play reviewers) without any network connection or credentials
9. Your Rights
As a data subject, in compliance with Articles 15-22 GDPR, you have the right to:
- Access: obtain confirmation of processing and a copy of your data (Art. 15)
- Rectification: request correction of inaccurate data (Art. 16)
- Erasure: request deletion — “right to be forgotten” (Art. 17) — see section 10
- Restriction: request restriction of processing (Art. 18)
- Portability: receive your data in a structured, machine-readable format (Art. 20)
- Objection: object to processing based on legitimate interest (Art. 21)
- Complaint: lodge a complaint with the Italian Data Protection Authority (www.garanteprivacy.it)
To exercise any of these rights, write to info@g-loop.it including, if possible, the device identifier or the username associated with the pairing, so that we can locate your data.
10. Data Deletion — How to Request It
The G-Loop Scanner app (com.gstoragescanner), distributed by MEGADV di Andrea Tedesco, allows you to request complete deletion of data associated with your device at any time, in compliance with Art. 17 GDPR and Google Play requirements.
Procedure to request deletion
- Open the G-Loop Scanner app on your Android device and tap the user icon at the top right. Note the device identifier (if displayed) or, alternatively, the username used for pairing with the desktop computer.
- Send an email to info@g-loop.it with the subject line “Scanner Data Deletion Request”, indicating the device identifier (if available) or a brief description of usage (e.g. “I used the Scanner between X and Y from my Samsung Galaxy”).
- The data controller verifies the request and proceeds to fully delete the associated data within 30 days of receipt, in compliance with Art. 12(3) GDPR.
- You receive written confirmation of the deletion at the email address from which the request originated.
Data that gets deleted
- All crash log records associated with the device identifier (stack traces, brand/model, Android version, app version)
- All feedback (ratings + comments) submitted from your device
- The pseudonymized device identifier and all its occurrences in our databases
Data that is NOT in our systems (because it is not collected)
- Email address linked to the app — the app never asks for an email address
- IP address — not stored in the feedback database (verified at code level)
- Location, contacts, photos, or other personal data (see section 3)
Timeline: deletion is completed within 30 days of the request. Any system backups containing already-deleted data are overwritten in the standard rotation cycle (max 30 additional days). After fulfillment, no data of yours is retained by MEGADV for any purpose.
Email for deletion requests: info@g-loop.it — suggested subject: Scanner Data Deletion Request
11. International Transfers, Minors, and Changes
International transfers: our servers are hosted exclusively within the European Union (Italy, Aruba S.p.A., Arezzo data center). We do not transfer your data outside the European Economic Area.
Minors: the G-Loop Scanner app is a B2B tool intended for an audience over 18 years old and is not directed at children under 16. We do not knowingly collect data from minors.
Changes: this policy may be updated in case of regulatory or product changes. The current version is always available at this URL. Material changes will be flagged via in-app banner.
12. Contact
Data controller: MEGADV di Andrea Tedesco, registered office Piazza dei Mille 18, 88049 Soveria Mannelli (CZ), Italy. Tax code and VAT number available on request.
App: G-Loop Scanner (com.gstoragescanner)
Email: info@g-loop.it
Website: www.g-loop.it
General Privacy Policy (desktop + website): g-loop.it/privacy.php