Last updated: August 3, 2026
The controller for Post Matrix Scan is Philipp Kursawe. For privacy questions or requests, email privacy@dudesoft.dev.
Camera frames and photos selected from your library are processed on your device to detect and decode a Data Matrix code. The app does not upload those images.
If a code cannot be decoded, you can choose to prepare a diagnostic email in Apple Mail. The message can contain the raw matrix-code bytes in hexadecimal form and is sent only after you review and send it. Your selected mail account and mail provider process the message, and the developer receives the sender address shown by Mail and the message contents for support.
When sender identification is available, the app sends the public postal customer number encoded in the matrix code to the Post Matrix Scan server. This number identifies the postal sender/customer represented by the mail code; it is not an identifier assigned to the person scanning the item.
The server returns sender names contributed by the community. If you voluntarily suggest or vote for a sender name, the name and aggregate vote are retained in the shared sender database. Free-text autocomplete searches are sent through our server to the Wikidata API. Wikidata receives the search text from our server, not your App Attest installation key.
We use Apple App Attest to verify genuine app installations and protect the sender database from automated or duplicate voting. The server retains a random installation key identifier, its public verification key, an assertion counter, app environment and bundle information, creation and last-use timestamps, and validation signals supplied by Apple.
After a contribution, a vote marker records that the installation voted for that public postal customer number and when. It is needed to enforce one vote per app installation. The installation key is not an advertising identifier, is not tied to a Post Matrix Scan account, and is not used to follow you across other apps or websites.
The website and API run on Vercel, and persistent sender, attestation, and vote data is stored with Upstash Redis. Apple processes App Attest requests, and Wikimedia Foundation operates Wikidata autocomplete.
Vercel processes network and operational information needed to deliver and protect the service, including IP address, user agent, request time, request path, status, and search parameters. These details are available in Vercel runtime logs for the retention period of the active hosting plan. We do not export them to an analytics service or use them to build usage profiles.
You can request access, correction, or deletion by emailing privacy@dudesoft.dev. Because the app has no user account, include enough context for us to locate the record. We may retain minimized anti-abuse markers where they remain necessary to protect the voting service or comply with legal obligations.
Sender contributions and diagnostic email are optional. You can use the scanner without submitting either. Depending on applicable law, you may have rights to access, rectify, erase, restrict, or object to processing and to complain to your data-protection authority.
Security and service-delivery processing is based on providing the requested feature and our legitimate interest in protecting a reliable, abuse-resistant sender database. We do not sell this information, show ads, or use it for tracking.