Is CamScanner Safe in 2026? What the Evidence Shows

The 2019 Android malware finding is real, but it does not prove current builds are infected. A useful 2026 answer must separate that history from current developer-reported disclosures.

There is no responsible one-word answer to “Is CamScanner safe?” Kaspersky documented a malicious component in an Android build in 2019; that historical finding does not establish that the current iPhone or Android app contains malware. Today, the verifiable privacy trade-offs come from CamScanner’s current App Store privacy label and its own privacy policy. Your decision should depend on document sensitivity and which cloud, account, advertising, and collaboration features you enable.

Disclosure: ScanLens competes with CamScanner. This review therefore uses dated primary sources, distinguishes developer disclosures from independent verification, and does not infer present malicious behavior from an old incident. Sources were reviewed on .

What can be verified about CamScanner today?

The current US App Store listing names INTSIG Information Co., Ltd as the developer and describes scanning, OCR, conversion, collaboration, account features, and uploads to external cloud services. It also says documents can remain on the device when users do not choose sharing or cloud workflows. It is therefore not accurate to claim that every scan is automatically uploaded to CamScanner servers.

Apple’s privacy label says the developer may use identifiers and usage data to track users across apps and websites. It also lists contact information, user content, identifiers, usage data, and diagnostics as data that may be collected but not linked to identity, depending on the features used. Apple notes that these answers are supplied by the developer and are not verified by Apple.

CamScanner’s privacy policy, effective January 20, 2026, describes categories of data, purposes, sharing, storage, cross-border transfers, and regional rights. A policy describes processing the company permits itself to perform; it does not prove that every category is collected in every session.

What happened in the 2019 Android incident?

In August 2019, Kaspersky researchers reported a Trojan-Dropper component inside an advertising library bundled with a recent Android version of CamScanner. The component could retrieve additional modules. This was a serious software supply-chain failure involving an Android distribution and third-party advertising code.

That finding is bounded historical evidence. It does not demonstrate that the current iOS app was affected, and it does not demonstrate that current Android releases contain the same component. App-store availability is not an independent security audit, but a seven-year-old incident is not proof of a current infection either.

What the public sources do not prove

  • They do not prove that every document is uploaded when cloud and collaboration features are disabled.
  • They do not identify the physical storage location for every user, region, and feature.
  • They do not prove that a government or another third party accessed a particular user’s scans.
  • They do not provide a current independent network capture of the iPhone app.
  • They do not turn a self-reported privacy label into independent verification of app behavior.

The previous version of this article made broad server-location and government-access claims that its sources did not establish. Those claims have been removed.

A practical privacy test for any scanner app

  1. Document sensitivity: a menu and a passport copy do not carry the same consequence if exposed.
  2. Processing path: determine whether OCR and enhancement happen locally or require a server.
  3. Storage path: check whether files remain local, enter the provider’s cloud, or move to a cloud account you control.
  4. Account and sharing: collaboration links and cross-device sync create additional access paths.
  5. Telemetry: read the platform privacy label for tracking, advertising, analytics, diagnostics, and user content.
  6. Recovery: verify that exported PDF or image files reopen without the original app.

How ScanLens differs — and what it still discloses

ScanLens performs document OCR on the iPhone and does not require a ScanLens account for scanning. Users can export local PDF, JPG, or PNG files and optionally connect third-party cloud storage. Free exports carry a ScanLens watermark; Premium removes it and unlocks additional PDF and cloud features. Check the current privacy policy, plan comparison, and App Store listing.

ScanLens’s App Store privacy label includes developer-reported categories used for analytics, personalization, and app functionality. It would be misleading to describe the product as collecting no analytics or diagnostics. The narrower verified claim is that document recognition runs on-device and no ScanLens account is required for scanning.

So, should you use CamScanner?

For low-sensitivity documents, users who value CamScanner’s cross-platform workflow and collaboration tools may find its disclosed trade-offs acceptable. For identity documents, medical records, tax material, or confidential contracts, use the smallest data path that completes the task: local processing, local export, minimal account dependence, and a backup you control.

The evidence supports caution and informed configuration, not a claim that the current app is malware. For product features see ScanLens vs CamScanner; for the underlying threat model use the document security checklist.

Sources and review method

This is a static-source review, not a penetration test or current packet capture. Recheck the linked sources before making a high-risk decision.

Frequently Asked Questions

Is CamScanner safe to use in 2026?

The public evidence does not support calling the current app malware. Kaspersky documented a malicious component in an Android build in 2019, but that does not prove current releases are infected. Evaluate current privacy trade-offs from the platform label, CamScanner policy, and the features you enable.

Was the iPhone version part of the 2019 finding?

The cited Kaspersky report concerned an Android version and a bundled advertising component. It does not establish that the iPhone version contained the same module.

Does CamScanner upload every scan?

The current App Store description says documents can remain on the device when sharing is not used, while cloud, account, and collaboration features involve additional processing or transmission. Public sources do not support a blanket claim that every scan is automatically uploaded.

What should I use for sensitive documents?

Prefer a workflow with local processing, local export, minimal account dependence, and a backup you control. Verify the current privacy label and test that exported files open outside the scanner app.