Privacy Policy
Last modified: May 7, 2026
1. Introduction
Welcome to Merasus. This Privacy Policy explains how we collect, use, and protect your information when you use our applications and services ("Services").
When we say "Merasus," "our," "we," or "us," we're talking about Merasus. This policy applies to all of our applications unless specified otherwise.
Our commitment: We believe in minimal data collection. We only collect what's absolutely necessary to provide our Services.
2. Information We Collect
The information we collect varies by application. See the application-specific sections below for details.
Information Stored Locally on Your Device
Most of our applications store data locally on your device only. This data never leaves your device and includes:
- Your preferences and settings
- Content you add or manage (playlists, URLs, favorites, scan results)
- Usage history and progress (watch history, scan progress)
We cannot access this data. It stays on your device.
Information You Provide Voluntarily
When you contact us for support, you may provide:
- Your email address
- Information about your issue
Purchase and Subscription Information
If you subscribe to an optional premium plan (such as Merasus ID Premium), the transaction is processed by Apple App Store or Google Play Store. For subscription state management, we use Adapty, a third-party subscription platform. Through Adapty and the app stores we receive:
- Confirmation that a subscription was started, renewed, or cancelled
- The product identifier (e.g., weekly, monthly, or yearly plan)
- Subscription status (active, trial, expired, or cancelled)
- A randomly generated subscriber identifier, used only to link subscription state to your account
We do not receive your payment details (credit card, billing address, etc.). All payment processing is handled entirely by Apple or Google. Adapty's privacy policy is available at https://adapty.io/privacy/.
Merasus ID Account (Optional, for Participating Apps)
Some of our applications offer an optional account called Merasus ID. A Merasus ID lets you sync your subscription state across devices and across participating Merasus applications. Creating or using a Merasus ID is entirely optional; our applications can be used without one.
When you choose to sign in to a Merasus ID, we collect and process:
- Your email address (entered by you, or provided by Apple Sign In or Google Sign In). Apple's private relay email is supported.
- A display name (optional; entered by you or provided by your sign-in provider)
- A profile photo (optional; only if you upload one or one is provided by your sign-in provider)
- A randomly generated user identifier
- Authentication tokens, stored in encrypted storage on your device (not retained on our servers)
- Your subscription state (tier, product identifier, renewal or expiry dates)
Merasus ID data is stored on our servers at id.merasus.com. It is used to authenticate your account across devices, to preserve your subscription entitlement across participating Merasus applications, and to respond to support requests. It is not used for advertising, profiling, or sharing with third parties for their own purposes.
Participating apps as of May 2026: PaperNest, Wipest. AREZTV does not currently use Merasus ID.
Account deletion: You can delete your Merasus ID from within the app at any time (Settings > Account > Delete Account). Upon deletion, your personal information (email, display name, profile photo, user identifier) is anonymized on our servers. Transaction and subscription records may be retained as required by tax or accounting law.
Advertising Identifiers (Participating Apps Only)
Some of our applications run paid advertising campaigns to acquire new subscribers. To measure whether those campaigns convert into actual subscriptions (without which campaign spend cannot be attributed), the apps that run these campaigns send anonymous purchase and trial-start events to Firebase Analytics (Google LLC) and the Meta SDK (Meta Platforms, Inc.). These events include:
- Your device's advertising identifier: GAID on Android (collected by default, resettable in your device settings); IDFA on iOS (collected only if you grant permission via Apple's App Tracking Transparency prompt; otherwise not collected).
- An anonymous transaction identifier provided by Adapty (used to deduplicate the event so the same purchase is not counted twice). It does not contain your name, email, or other personal information.
- The product identifier and the local currency amount of the subscription.
We do not send your name, email address, document content, photos, or any in-app behavior to Firebase or Meta. We only send the two events listed above (purchase and trial start). The apps do not display advertisements inside the app itself.
Participating apps as of May 2026: PaperNest. Wipest and AREZTV do not currently send advertising or analytics events. This section will be updated if and when that changes for any of those apps.
How to opt out:
- iOS: Settings > Privacy & Security > Tracking > toggle the participating app off (or choose "Ask App Not to Track" the next time the app asks). When tracking is off, the app does not access your IDFA and does not send events to Meta. Firebase still receives anonymous events without an advertising identifier.
- Android: Settings > Privacy > Ads > "Delete advertising ID" or "Reset advertising ID". Resetting issues a new GAID; deleting it stops sharing entirely.
3. Application-Specific Information
AREZTV - Media Player
| Data Type |
Collected? |
Details |
| Personal Information |
No |
We don't collect names, emails, or any personal data |
| Analytics |
No |
No analytics or tracking SDKs |
| Advertising |
No |
No ads, no ad tracking |
| Location |
No |
We don't access your location |
| Your Content (URLs, playlists) |
Local Only |
Stored on your device, never sent to us |
| Preferences & History |
Local Only |
Stored on your device, never sent to us |
| Device Identifiers |
Server |
Used for phone-to-TV remote pairing only. Encrypted and deleted when you unpair. |
| Session Tokens |
Server |
Stored on our relay server for reconnection. Deleted when you unpair. |
Summary: AREZTV stores most data locally on your device. The streaming URLs you enter connect directly from your device to those services.
Remote Control Feature (Phone-to-TV)
When you use the remote control feature to pair your phone with a TV:
- What we collect: Randomly generated device identifiers (UUIDs) and session tokens
- Why: To enable communication between your phone and TV
- Security: All data is encrypted with AES-256-GCM and transmitted over TLS
- Retention: Data is automatically deleted when you unpair devices or disconnect
- Sharing: Not shared with any third parties
Advertising and Analytics SDKs (AREZTV)
- AREZTV does not integrate any advertising SDK, attribution SDK, or behavioral analytics SDK.
- No advertising identifier (IDFA, GAID) is collected, accessed, or transmitted by the app.
- If this changes in the future, this section and the table above will be updated, and the app will request your permission where required by Apple's App Tracking Transparency framework.
PaperNest - Document Manager
| Data Type |
Collected? |
Details |
| Personal Information |
Optional |
Only if you choose to create a Merasus ID. No personal information is collected if you use PaperNest without signing in. |
| Behavioral Analytics |
No |
No in-app behavioral analytics. We do not track which screens you visit, which features you use, or how long you spend in the app. Adapty is used only to manage subscription state (not to track in-app behavior). |
| Conversion Analytics (Subscription Events Only) |
Limited |
Two events only, fired on a successful purchase or trial start: purchase and start_trial. Each event includes the local price, currency, product identifier, and an anonymous Adapty transaction ID for deduplication. Sent to Firebase Analytics (Google) and the Meta SDK. See "Advertising and Analytics SDKs" below for full details. |
| Advertising (In-App) |
No |
PaperNest does not display advertisements inside the app. |
| Ad Campaign Attribution |
Limited |
Used only to measure whether subscriptions originated from a paid advertising campaign so the campaign can be optimized or stopped. On Android we collect the GAID; on iOS we collect the IDFA only if you grant permission via Apple's App Tracking Transparency prompt. No advertising profile is built about you. |
| Location |
No |
We don't access your location |
| Camera & Photo Library |
Local Only |
Used for document scanning and import; images stay on your device |
| Documents, Scans & OCR Text |
Local Only |
Stored on your device, never sent to us |
| AI Processing (Classification, Tags, Chat) |
Local Only |
Runs entirely on your device using a downloaded AI model; no document content is sent anywhere |
| AI Model Downloads |
Download Only |
Model files (400 MB - 1.2 GB) downloaded from third-party repositories when you enable AI features; no data uploaded |
| Biometric Data |
No |
Handled by your device's OS; we never access or store biometric data |
| Document Conversion |
Server (temporary) |
When you choose to convert a file, it is sent to our server for processing and immediately deleted after conversion |
| Cloud Sync (iCloud Drive / Google Drive) |
Your Cloud Account |
If enabled, documents are synced to your own iCloud Drive or Google Drive account. We do not store your documents on our servers. |
| Google Account (Email, Name) - for Google Drive sync |
Local Only |
Used for Google Drive sign-in. Your email and display name are stored locally on your device for display purposes only and are not sent to our servers. |
| Merasus ID (Email, Display Name, User ID) |
Optional, Server |
Only if you create a Merasus ID. Stored on our server at id.merasus.com. Deletable in-app at any time. See Section 2 for details. |
| Profile Photo (via Merasus ID) |
Optional, Server |
Only if you upload a profile photo or one is provided by your sign-in provider. Deletable in-app. |
| Subscription Status |
Optional, Server |
Only if you subscribe to Merasus ID Premium. Managed via Adapty and linked to your Merasus ID if signed in. |
| Preferences & Settings |
Local Only |
Stored on your device, never sent to us |
Summary: PaperNest stores all your documents, scans, and OCR text locally on your device. No files are ever sent to our servers without your explicit action. If you enable cloud sync, your documents are stored in your own iCloud Drive or Google Drive account. The only server communication involving your file content is document format conversion, which requires your explicit action. Creating a Merasus ID is optional and is only needed if you want to sync your subscription across devices or other Merasus apps.
Camera and Photo Library (PaperNest)
- Camera: Used only when you choose to scan a document. Photos are processed and stored locally on your device.
- Photo Library: Accessed only when you choose to import images. Selected photos are copied into the app's local storage.
- No images or photos are ever sent to our servers or any third party.
On-Device AI Features
- Processing: Document classification, tagging, OCR correction, and chat run entirely on your device. No document content is ever sent to any server for AI processing.
- Model Downloads: When you enable AI features, a model file (approximately 400 MB to 1.2 GB) is downloaded from third-party repositories (such as Hugging Face). Only the model file is downloaded; no personal data or document content is uploaded.
- Device Information: Your device's available memory (RAM) is read locally to recommend an appropriate model size. This information is not transmitted anywhere.
- You can disable or remove AI features at any time from the app settings.
Biometric Authentication
- Biometric authentication (Face ID, Touch ID, fingerprint) is handled entirely by your device's operating system.
- We never access, store, or transmit your biometric data.
- This feature is optional and can be enabled or disabled in settings.
Document Conversion
- What: Only the file you select is sent to our secure server for format conversion.
- How: The file is processed and converted on our server.
- Retention: The file is immediately deleted from our server after conversion is complete. No copies are retained.
- No content is logged, stored, or analyzed.
Cloud Sync (iCloud Drive / Google Drive)
- What: If you enable cloud sync, your documents and metadata are uploaded to your own iCloud Drive or Google Drive account.
- Where: Documents are stored in your personal cloud storage account, not on our servers. We do not have access to your cloud storage.
- Google Sign-In: If you use Google Drive sync, we use Google Sign-In to authenticate your account. Your email address and display name are stored locally on your device for display purposes. Your Google access token is stored securely on your device using encrypted storage and is used only for Google Drive API calls.
- Control: You can enable or disable cloud sync at any time from the app settings. Disabling sync does not delete files already in your cloud storage.
Advertising and Analytics SDKs (PaperNest)
PaperNest integrates two third-party SDKs to measure whether paid subscription campaigns convert into actual subscriptions. These SDKs do not show ads inside the app and do not track your in-app behavior.
- Firebase Analytics (Google LLC): Receives two events,
purchase and start_trial, fired only when a successful subscription transaction completes. Each event includes the local price amount, currency code, product identifier, and an anonymous Adapty transaction identifier used for deduplication. On Android, the event also includes your Google Advertising ID (GAID). Firebase does not receive screen views, taps, document content, or any other in-app events.
- Meta SDK / Facebook App Events (Meta Platforms, Inc.): Receives the same two events,
Purchase and StartTrial, with the same parameters. On iOS, your IDFA is included only if you grant permission via Apple's App Tracking Transparency prompt; if you choose "Ask App Not to Track", the SDK is configured not to access the IDFA and not to send events to Meta. Firebase still receives the anonymous event without your IDFA. On Android, your GAID is included.
- What is never sent: document content, OCR text, AI-generated tags or summaries, scan thumbnails, file names, your name, your email address, or your in-app navigation. The two attribution events are the only data the app sends to Firebase or Meta.
- Adapty transaction ID: a randomly generated, anonymous identifier used by Adapty's subscription platform. We use it as the deduplication key (
transaction_id for Firebase, fb_order_id for Meta) so that the same purchase is not counted twice across the client SDK, the Adapty server-to-server integration, or webhook replays. It does not identify you personally.
- App Tracking Transparency (iOS): The first time you reach the end of onboarding, iOS displays a system prompt asking whether you want to allow PaperNest to track you across other apps and websites. We only request this permission so the Meta SDK can use your IDFA for ad campaign attribution. If you decline, the app continues to work normally and you will still be able to subscribe; only the ad-attribution accuracy on iOS is reduced.
- Privacy policies of these SDKs: Firebase, https://firebase.google.com/support/privacy; Meta, https://www.facebook.com/about/privacy.
- Opt-out: see "How to opt out" under Section 2, "Advertising Identifiers", for the device-level controls that disable advertising identifier sharing.
Wipest - Photo Gallery Cleaner
| Data Type |
Collected? |
Details |
| Personal Information |
Optional |
Only if you choose to create a Merasus ID. No personal information is collected if you use Wipest without signing in. |
| Analytics |
No |
No behavioral analytics or tracking SDKs. Adapty is used only to manage subscription state (not to track in-app behavior). |
| Advertising |
No |
No ads, no ad tracking |
| Location |
No |
We don't access your location. EXIF location data embedded in your photos is read locally on your device only and is never transmitted. |
| Photo Library |
Local Only |
Read access to display your photos; write access to delete photos you choose to remove |
| Photo Analysis (Blur Detection, Similarity) |
Local Only |
Runs entirely on your device; no photos or analysis results are sent anywhere |
| Preferences, Settings, Scan Progress & Statistics |
Local Only |
Stored in a local database on your device, never sent to us |
| iCloud Backup of Local Database (iOS only) |
Your iCloud Account |
Optional. A copy of the app's local database (scan results, preferences) is periodically saved to your own private iCloud container so it can be restored after reinstall. We do not have access to this data. |
| Merasus ID (Email, Display Name, User ID) |
Optional, Server |
Only if you create a Merasus ID. Stored on our server at id.merasus.com. Deletable in-app at any time. See Section 2 for details. |
| Profile Photo (via Merasus ID) |
Optional, Server |
Only if you upload a profile photo or one is provided by your sign-in provider. Deletable in-app. |
| Subscription Status |
Optional, Server |
Only if you subscribe to Merasus ID Premium. Managed via Adapty and linked to your Merasus ID if signed in. |
| Cross-Promotion Content (Promo Cards) |
Server (read-only) |
The app fetches small promotional cards about other Merasus apps from our server. We receive only your device's IP address and basic request metadata (app version, platform, language) as part of this fetch. Premium subscribers do not see these cards and the app does not contact our server for them. |
Summary: Wipest processes all your photos, analysis results, and gallery data entirely on your device. No photos or analysis results are ever sent to our servers. Creating a Merasus ID is optional and is only needed if you want to subscribe to premium or sync your subscription across devices and other Merasus apps.
Photo Library Access
- Read access: Used to display your photos and videos so you can review and organize them.
- Write access: Used only to delete photos and videos that you explicitly choose to remove by swiping left. Deletion requires your confirmation before any photos are permanently removed.
- No photos are ever uploaded, transmitted, or shared with us or any third party.
On-Device Photo Analysis
- Blur detection: Uses a Laplacian algorithm to identify potentially blurry photos. This runs entirely on your device.
- Similar photo detection: Uses perceptual hashing (dHash) to find visually similar photos. This runs entirely on your device.
- Analysis results (scores and hashes) are stored in a local database on your device and are never transmitted anywhere.
- No machine learning models are downloaded. All algorithms are built into the app.
iCloud Backup of Local Database (iOS only)
- What: A snapshot of the app's local database (scan results, reviewed photo IDs, preferences, statistics) is periodically copied to your own private iCloud container so that your scan progress can be restored after reinstall.
- Where: The backup is stored in your personal iCloud account, in an app-private container. We do not have access to it.
- What's not included: Your photos and videos themselves are never copied or backed up by Wipest. Only the app's own local metadata is backed up.
- Control: If you disable iCloud or sign out of your Apple ID, the backup is no longer updated. The feature is iOS-only; Android does not use iCloud.
Notifications (Local Only)
- Wipest uses local on-device notifications for streak reminders and weekly summaries.
- These notifications are scheduled and triggered entirely on your device. No notification data is sent to any remote server.
- You can disable notifications at any time from the app's settings or your device settings.
Cross-Promotion Cards (Promo Cards)
- Wipest occasionally shows small cards introducing other Merasus apps in the swipe deck. The content of these cards (titles, descriptions, images) is served from our server at id.merasus.com so that we can update it without requiring an app update.
- When the app fetches these cards, our server receives standard request metadata (IP address, app version, platform, language). The fetch contains no photos, no analysis data, and no personal information.
- Whether each card has been shown, tapped, or dismissed is recorded only in the local database on your device. This information is not transmitted to our servers.
- Active premium subscribers do not see these cards, and the app does not fetch promo content for them.
Feedback (Voluntary)
- If you choose to send feedback through the app, only the information you enter (email, message) is sent to our server.
- This is entirely optional. The app functions fully without sending any feedback.
Advertising and Analytics SDKs (Wipest)
- Wipest does not currently integrate any advertising SDK, attribution SDK, or behavioral analytics SDK.
- No advertising identifier (IDFA, GAID) is collected, accessed, or transmitted by the app.
- If we add subscription-conversion attribution to Wipest in the future (the same two-event setup used in PaperNest, limited to
purchase and start_trial), this section and the table above will be updated. On iOS, the app will request your permission via Apple's App Tracking Transparency framework before any IDFA is accessed.
4. How We Use Your Information
We use the limited information we have to:
- Provide and maintain our Services
- Authenticate optional Merasus ID accounts and preserve your subscription state across devices and participating apps
- Respond to your support requests
- Process in-app purchases and subscriptions through the app stores and our subscription platform provider
- Measure whether our paid subscription advertising campaigns convert into actual subscriptions, in the participating apps listed under Section 2 ("Advertising Identifiers"), so we can stop campaigns that do not work and improve the ones that do. This is limited to two events (
purchase and start_trial) and the device's advertising identifier. See Section 2 and the relevant application-specific section for the full scope.
- Comply with legal obligations, including tax and accounting requirements
We do not use your information for:
- Showing advertisements inside our applications
- Selling your data to third parties
- Building behavioral or interest-based advertising profiles about you
- Tracking which screens you visit, which features you use, or how long you spend in our apps
- Training artificial intelligence models
5. Third-Party Services
Our applications may connect to third-party services that you configure:
- Media URLs: When you enter a media URL, your device connects directly to that service. We have no control over those services.
- Chromecast/DLNA: If you cast content, your device communicates directly with your casting device on your local network.
- Apple App Store / Google Play Store: In-app purchases and subscriptions are processed entirely by Apple or Google. We do not handle your payment information.
- Adapty (subscription management): We use Adapty to manage subscription state, validate store receipts, and receive renewal, trial, and cancellation webhooks. Adapty receives transaction events and subscriber identifiers. Adapty does not receive your documents or any file content from our apps. Adapty's privacy policy: https://adapty.io/privacy/
- Apple Sign In: If you sign in to a Merasus ID with Apple, Apple returns a user identifier and, if you choose, a private relay email to our authentication server at id.merasus.com.
- Google Sign-In: Used in PaperNest for Google Drive authentication and, separately, as a Merasus ID sign-in option. For Google Drive sync, your email and display name are stored locally on your device. For Merasus ID sign-in, your email and display name are also stored on our authentication server at id.merasus.com.
- iCloud Drive / Google Drive (cloud sync): If you enable cloud sync in PaperNest, your documents are stored in your own cloud account. We do not access or control your cloud storage.
- Firebase Analytics (Google LLC), participating apps only: Used in apps that run paid advertising campaigns (currently PaperNest) to receive subscription conversion events. Receives the two events
purchase and start_trial with the local price, currency, product identifier, anonymous Adapty transaction ID, and on Android the GAID. Does not receive in-app behavioral events. Privacy policy: https://firebase.google.com/support/privacy.
- Meta SDK / Facebook App Events (Meta Platforms, Inc.), participating apps only: Used in apps that run paid advertising campaigns (currently PaperNest) to receive subscription conversion events. Receives the same two events with the same parameters. On iOS, your IDFA is included only if you grant permission via Apple's App Tracking Transparency prompt; if you decline, the SDK is configured not to access the IDFA and not to send events to Meta. Privacy policy: https://www.facebook.com/about/privacy.
Please review the privacy policies of any third-party services you use with our applications.
6. Data Security
Since we store data locally on your device:
- Your data is protected by your device's security (PIN, biometrics, encryption)
- We cannot access your data remotely
- If you uninstall the app, local data is deleted
For application-specific server features, see the Application-Specific Information section.
7. Data Retention
- Local data: Stored until you delete it or uninstall the app
- Support emails: Retained for up to 2 years, then deleted
- Merasus ID account data: Retained until you delete your account. Upon deletion, personal information (email, display name, profile photo, user identifier) is anonymized on our servers.
- Purchase and subscription records: Retained as required by law (typically 5-7 years for tax and accounting purposes), even after account deletion. These records are kept in a form that does not require personally identifiable information beyond what tax authorities require.
- App-specific server data: See Application-Specific Information for details
8. Your Rights
You have the right to:
- Access: View your data. Local data is already on your device. If you have a Merasus ID, you can view your account information in-app (Settings > Account).
- Delete: Clear app data or uninstall to delete local data. If you have a Merasus ID, you can delete your account at any time from within the app (Settings > Account > Delete Account). Account deletion anonymizes your personal information on our servers.
- Portability: Export your data where the app provides this feature
- Object: Contact us if you have concerns about data processing
- Opt out of advertising identifier sharing:
- iOS: Settings > Privacy & Security > Tracking > toggle the participating app off. You can also choose "Ask App Not to Track" the next time the app's tracking prompt appears. When tracking is off, the app does not access your IDFA and does not send events to Meta; Firebase still receives anonymous events without an advertising identifier.
- Android: Settings > Privacy > Ads > "Delete advertising ID" or "Reset advertising ID". Resetting issues a new GAID; deleting it stops sharing entirely.
To exercise these rights or ask questions, contact us at [email protected].
9. Children's Privacy
Our Services are not intended for children under 13. We do not knowingly collect information from children under 13. If you believe a child has provided us with personal information, please contact us.
10. International Users
Merasus is based in Turkey. If you use our Services from outside Turkey, please note that any information you provide may be transferred to and processed in Turkey, where data protection laws may differ from your country.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by:
- Updating the "Last modified" date
- In-app notification for major changes
Your continued use of our Services after changes constitutes acceptance of the updated policy.
12. Contact Us
If you have questions about this Privacy Policy, please contact us:
Email: [email protected]
Website: https://merasus.com