How Scrolld OÜ, a company registered in Estonia, processes personal data under the GDPR and the CCPA — the data controller, what is collected, and how to contact us about it.
Effective: March 10, 2026
1. Introduction
Scrolld OÜ, a company registered in Estonia ("we", "us", "our"), operates the scrolld.io platform — an AI-powered data storytelling service. We are committed to protecting your privacy and processing your personal data in compliance with the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and other applicable data protection laws.
2. Data Controller
The data controller for the purposes of GDPR is Scrolld OÜ, Estonia. For privacy-related inquiries, contact us at privacy@scrolld.io.
3. What Data We Collect
3.1 Account Data
You can create an account either with an email address and password, or via Google or GitHub OAuth. Depending on the method you choose, we collect:
Email address
Password (only for email/password registration) — never stored in plain text; we store a one-way salted cryptographic hash and cannot recover your original password
Display name / username, if you set one
Profile picture (if provided by your OAuth login provider)
Unique user ID
Subscription plan and billing status (via Paddle)
3.2 Uploaded Data
When you upload any safe local file (including CSV, Excel, JSON, XML, documents, or text), we store it temporarily for processing. We do not analyze, mine, or use your uploaded data for any purpose other than generating your requested data story. Your uploaded datasets may contain any type of information — we treat all uploads as confidential.
3.3 Generated Content
Story configurations, published stories, and associated metadata (title, theme, publish status) are stored to provide the service.
3.4 Usage Data
We collect minimal usage data:
Story view counts and like counts (aggregated, not per-user tracking)
Server logs (IP address, request timestamps) retained for 30 days for security
3.5 What We Do NOT Collect
No cookies for tracking or advertising
No third-party analytics (no Google Analytics, no pixel trackers)
No device fingerprinting
No selling or sharing of data with third parties for marketing
4. How We Use Your Data
Provide the service (story generation, publishing) — Contract performance (Art. 6(1)(b))
Process payments via Paddle (Merchant of Record) — Contract performance (Art. 6(1)(b))
Send transactional emails (receipts, account changes) — Legitimate interest (Art. 6(1)(f))
Security monitoring and abuse prevention — Legitimate interest (Art. 6(1)(f))
AI analysis of your uploaded data to generate stories — Contract performance (Art. 6(1)(b))
5. Third-Party Processors
We use the following service providers as applicable to enabled features. International transfers are governed by applicable provider and contractual safeguards:
Google/GitHub OAuth — Authentication — Email, avatar, auth tokens — US
Apple OAuth — Authentication when Apple sign-in is configured — Email, name, auth tokens — US
Microsoft OAuth — Authentication when Microsoft sign-in is configured — Email, profile, auth tokens — US
LinkedIn OAuth — Authentication when LinkedIn sign-in is configured — Email, profile, auth tokens — US
Paddle — Payments (Merchant of Record) — Email, payment details — UK/EU (PCI DSS Level 1)
Anthropic (Claude AI) — Story generation when an Anthropic-backed feature is used — Content submitted to that enabled AI feature — US; transfer safeguards apply
Cloudflare — Edge compute, frontend delivery, D1/KV/R2 storage, and enabled Workers AI — Service traffic, account/story data, uploads — Global network; transfer safeguards apply
Resend — Transactional email delivery — Email address, message content — US
Hive — Content moderation — Text or media submitted for moderation — US
PhotoDNA (Microsoft) — Known illegal image matching for content moderation — Image fingerprints — US
6. Data Processing
When Scrolld OÜ processes personal data contained in customer-uploaded data to provide the service, Scrolld OÜ acts as the processor on the customer's behalf. The sub-processors that may support this processing are listed below.
Google/GitHub OAuth — Authentication — Email, avatar, auth tokens — US
Apple OAuth — Authentication when Apple sign-in is configured — Email, name, auth tokens — US
Microsoft OAuth — Authentication when Microsoft sign-in is configured — Email, profile, auth tokens — US
LinkedIn OAuth — Authentication when LinkedIn sign-in is configured — Email, profile, auth tokens — US
Paddle — Payments (Merchant of Record) — Email, payment details — UK/EU (PCI DSS Level 1)
Anthropic (Claude AI) — Story generation when an Anthropic-backed feature is used — Content submitted to that enabled AI feature — US; transfer safeguards apply
Cloudflare — Edge compute, frontend delivery, D1/KV/R2 storage, and enabled Workers AI — Service traffic, account/story data, uploads — Global network; transfer safeguards apply
Resend — Transactional email delivery — Email address, message content — US
Hive — Content moderation — Text or media submitted for moderation — US
PhotoDNA (Microsoft) — Known illegal image matching for content moderation — Image fingerprints — US
A signed Data Processing Agreement is available on request: privacy@scrolld.io
7. Data Retention
Account data: Retained until you delete your account
Uploaded files: Retained while your story exists; deleted when you delete the story
Published stories: Retained until you unpublish or delete
Server logs: Automatically purged after 30 days
Paddle records: Retained per legal/tax requirements (typically 7 years)
8. Your Rights (GDPR / CCPA)
You have the right to:
Access — Request a copy of all personal data we hold about you
Rectification — Correct inaccurate personal data
Erasure — Request deletion of your account and all associated data ("right to be forgotten")
Portability — Export your stories and data in standard formats (JSON, HTML)
Restriction — Request we limit processing of your data
Objection — Object to processing based on legitimate interests
Withdraw consent — Where processing is based on consent
To exercise any of these rights, email legal@scrolld.io. We will respond within 30 days (GDPR) or 45 days (CCPA).
9. International Transfers
Your data may be transferred to and processed in the United States. We rely on Standard Contractual Clauses (SCCs) and sub-processor certifications to ensure adequate protection for EU/EEA data subjects.
10. Security
We implement industry-standard security measures:
All data in transit encrypted via TLS 1.3
All data at rest encrypted (AES-256 for storage, database-level encryption)
JWT-based authentication with RS256 signature verification
HMAC-SHA256 webhook signature verification
Request body size limits to prevent abuse
SSRF protection on URL imports
Input sanitization and XSS prevention on all user content
CORS restrictions to authorized origins only
11. Children
Our service is not directed to children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us immediately.
12. Changes
We may update this policy. Material changes will be communicated via email to registered users. The "Effective" date at the top reflects the latest revision.