scribase
Legal

Privacy Policy

Effective September 26, 2026

This policy explains how Scribase handles personal data we control — account, billing, and website data — including what we collect, why, the legal bases, how long we keep it, who we share it with, and your rights. Personal data you store inside your projects is governed by our Data Processing Agreement.

1. Scope of this policy

This Privacy Policy explains how Scribase ("we", "us", or "our") handles personal data for which we act as the controller — the personal data we collect to operate our business, provide accounts, take payment, and run our website and documentation. It applies to visitors to our website and to people who create and administer Scribase accounts.

It does NOT govern the data you place inside your Scribase projects. When you store or process personal data of your own end users through the Service — in your database, storage, authentication, or functions — you are the controller of that data and we are your processor. That relationship is governed by our Data Processing Agreement at https://scribase.com/legal/dpa, not by this policy.

2. Personal data we collect

Account data

When you register, we collect the information needed to create and secure your account, such as your name, email address, authentication identifiers, and organization or team details.

Billing data

To take payment for paid plans we collect billing contact details and process payments through Creem (creem.io), our payment processor and merchant of record. We do not see or store card numbers; Creem handles them. We retain records of invoices and transactions as required for accounting and tax.

Usage and device data

When you use the console, CLI, control API, or website, we collect operational data such as log entries, IP address, browser and device information, feature usage, and diagnostic events. We use this to secure the Service, prevent abuse, debug problems, and understand which features are used.

Communications

When you contact support, report a vulnerability, or otherwise communicate with us, we keep the content of those communications and our responses so we can help you and keep a record.

3. How and why we use personal data

We use the personal data described above for the following purposes:

  • To provide, maintain, and secure the Service and your account.
  • To process payments, send invoices, and manage subscriptions.
  • To respond to support requests and communicate about the Service, including service, security, and legal notices.
  • To detect, prevent, and investigate fraud, abuse, and security incidents.
  • To understand and improve how the Service and website are used, including reliability and performance.
  • To comply with legal obligations and to establish, exercise, or defend legal claims.

We do not sell your personal data. We do not use the contents of your Customer Data to train models or for advertising.

5. Cookies and analytics

Our website and console use cookies and similar technologies that are strictly necessary to sign you in and keep the site working, and, where you consent, a limited set of analytics to understand aggregate usage. You can control non-essential cookies through your browser settings or any consent controls we present. Disabling strictly necessary cookies may prevent parts of the Service from working.

6. How we share personal data

We share personal data only as needed to run the Service and our business:

  • Sub-processors and service providers — infrastructure, payment processing, communications, and analytics providers that process data on our behalf under contract and only on our instructions.
  • Legal and safety — where required by law, legal process, or to protect the rights, property, or safety of Scribase, our customers, or the public.
  • Business transfers — in connection with a merger, acquisition, financing, or sale of assets, subject to the protections in this policy.

A current list of the sub-processors we use to provide the Service, and how to subscribe to change notices, is available on request and referenced in the Data Processing Agreement at https://scribase.com/legal/dpa.

7. International data transfers

We and our sub-processors may process personal data in countries other than where you are located. Where we transfer personal data across borders in a way that triggers legal safeguards, we rely on recognized transfer mechanisms — such as the European Commission’s Standard Contractual Clauses and the UK Addendum — together with appropriate technical and organizational measures.

8. Data retention

We keep personal data for as long as your account is active and for as long as needed to provide the Service. After your account is closed we delete or anonymize account and usage data in the ordinary course, except where we must retain certain records — such as invoices — to meet legal, tax, or accounting obligations, or to resolve disputes and enforce agreements. Retention and deletion of Customer Data inside your projects is governed by the Data Processing Agreement.

9. Security

We protect personal data with technical and organizational measures appropriate to the risk, including encryption in transit and at rest, least-privilege access, auditable operations, and verified recovery. You can read more about our security posture at https://scribase.com/security. No system is perfectly secure, but we work continuously to keep your data safe and to respond quickly if something goes wrong.

10. Your rights

Depending on where you live, you may have rights over your personal data, including the right to access, correct, delete, or port it, to object to or restrict certain processing, and to withdraw consent. Residents of California and similar jurisdictions have additional rights, including the right to know what personal information we collect and the right not to be discriminated against for exercising their rights.

To exercise any of these rights, contact us at support@scribase.com. We will verify your request and respond within the time required by applicable law. You also have the right to lodge a complaint with your local data-protection authority, though we hope you will contact us first so we can help.

11. Children

The Service is intended for businesses and developers and is not directed to children. We do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact us and we will delete it.

12. Changes and contact

We may update this policy from time to time. When we make a material change, we will update the effective date and, where appropriate, notify you through the Service. Your continued use after an update takes effect constitutes acceptance of the revised policy.

For any privacy question or request, contact us at support@scribase.com.