Privacy Policy — Scrolld®

How Scrolld OÜ, a company registered in Estonia, processes personal data under the GDPR and the CCPA — the data controller, what is collected, and how to contact us about it.

Effective: March 10, 2026

1. Introduction

Scrolld OÜ, a company registered in Estonia ("we", "us", "our"), operates the scrolld.io platform — an AI-powered data storytelling service. We are committed to protecting your privacy and processing your personal data in compliance with the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and other applicable data protection laws.

2. Data Controller

The data controller for the purposes of GDPR is Scrolld OÜ, Estonia. For privacy-related inquiries, contact us at privacy@scrolld.io.

3. What Data We Collect

3.1 Account Data

You can create an account either with an email address and password, or via Google or GitHub OAuth. Depending on the method you choose, we collect:

  • Email address
  • Password (only for email/password registration) — never stored in plain text; we store a one-way salted cryptographic hash and cannot recover your original password
  • Display name / username, if you set one
  • Profile picture (if provided by your OAuth login provider)
  • Unique user ID
  • Subscription plan and billing status (via Paddle)
  • 3.2 Uploaded Data

    When you upload any safe local file (including CSV, Excel, JSON, XML, documents, or text), we store it temporarily for processing. We do not analyze, mine, or use your uploaded data for any purpose other than generating your requested data story. Your uploaded datasets may contain any type of information — we treat all uploads as confidential.

    3.3 Generated Content

    Story configurations, published stories, and associated metadata (title, theme, publish status) are stored to provide the service.

    3.4 Usage Data

    We collect minimal usage data:

  • Story view counts and like counts (aggregated, not per-user tracking)
  • Server logs (IP address, request timestamps) retained for 30 days for security
  • 3.5 What We Do NOT Collect

  • No cookies for tracking or advertising
  • No third-party analytics (no Google Analytics, no pixel trackers)
  • No device fingerprinting
  • No selling or sharing of data with third parties for marketing
  • 4. How We Use Your Data

  • Provide the service (story generation, publishing) — Contract performance (Art. 6(1)(b))
  • Process payments via Paddle (Merchant of Record) — Contract performance (Art. 6(1)(b))
  • Send transactional emails (receipts, account changes) — Legitimate interest (Art. 6(1)(f))
  • Security monitoring and abuse prevention — Legitimate interest (Art. 6(1)(f))
  • AI analysis of your uploaded data to generate stories — Contract performance (Art. 6(1)(b))
  • 5. Third-Party Processors

    We use the following service providers as applicable to enabled features. International transfers are governed by applicable provider and contractual safeguards:

  • Google/GitHub OAuth — Authentication — Email, avatar, auth tokens — US
  • Apple OAuth — Authentication when Apple sign-in is configured — Email, name, auth tokens — US
  • Microsoft OAuth — Authentication when Microsoft sign-in is configured — Email, profile, auth tokens — US
  • LinkedIn OAuth — Authentication when LinkedIn sign-in is configured — Email, profile, auth tokens — US
  • Paddle — Payments (Merchant of Record) — Email, payment details — UK/EU (PCI DSS Level 1)
  • Anthropic (Claude AI) — Story generation when an Anthropic-backed feature is used — Content submitted to that enabled AI feature — US; transfer safeguards apply
  • Cloudflare — Edge compute, frontend delivery, D1/KV/R2 storage, and enabled Workers AI — Service traffic, account/story data, uploads — Global network; transfer safeguards apply
  • Resend — Transactional email delivery — Email address, message content — US
  • Hive — Content moderation — Text or media submitted for moderation — US
  • PhotoDNA (Microsoft) — Known illegal image matching for content moderation — Image fingerprints — US
  • 6. Data Processing

    When Scrolld OÜ processes personal data contained in customer-uploaded data to provide the service, Scrolld OÜ acts as the processor on the customer's behalf. The sub-processors that may support this processing are listed below.

  • Google/GitHub OAuth — Authentication — Email, avatar, auth tokens — US
  • Apple OAuth — Authentication when Apple sign-in is configured — Email, name, auth tokens — US
  • Microsoft OAuth — Authentication when Microsoft sign-in is configured — Email, profile, auth tokens — US
  • LinkedIn OAuth — Authentication when LinkedIn sign-in is configured — Email, profile, auth tokens — US
  • Paddle — Payments (Merchant of Record) — Email, payment details — UK/EU (PCI DSS Level 1)
  • Anthropic (Claude AI) — Story generation when an Anthropic-backed feature is used — Content submitted to that enabled AI feature — US; transfer safeguards apply
  • Cloudflare — Edge compute, frontend delivery, D1/KV/R2 storage, and enabled Workers AI — Service traffic, account/story data, uploads — Global network; transfer safeguards apply
  • Resend — Transactional email delivery — Email address, message content — US
  • Hive — Content moderation — Text or media submitted for moderation — US
  • PhotoDNA (Microsoft) — Known illegal image matching for content moderation — Image fingerprints — US
  • A signed Data Processing Agreement is available on request: privacy@scrolld.io

    7. Data Retention

  • Account data: Retained until you delete your account
  • Uploaded files: Retained while your story exists; deleted when you delete the story
  • Published stories: Retained until you unpublish or delete
  • Server logs: Automatically purged after 30 days
  • Paddle records: Retained per legal/tax requirements (typically 7 years)
  • 8. Your Rights (GDPR / CCPA)

    You have the right to:

  • Access — Request a copy of all personal data we hold about you
  • Rectification — Correct inaccurate personal data
  • Erasure — Request deletion of your account and all associated data ("right to be forgotten")
  • Portability — Export your stories and data in standard formats (JSON, HTML)
  • Restriction — Request we limit processing of your data
  • Objection — Object to processing based on legitimate interests
  • Withdraw consent — Where processing is based on consent
  • To exercise any of these rights, email legal@scrolld.io. We will respond within 30 days (GDPR) or 45 days (CCPA).

    9. International Transfers

    Your data may be transferred to and processed in the United States. We rely on Standard Contractual Clauses (SCCs) and sub-processor certifications to ensure adequate protection for EU/EEA data subjects.

    10. Security

    We implement industry-standard security measures:

  • All data in transit encrypted via TLS 1.3
  • All data at rest encrypted (AES-256 for storage, database-level encryption)
  • JWT-based authentication with RS256 signature verification
  • HMAC-SHA256 webhook signature verification
  • Request body size limits to prevent abuse
  • SSRF protection on URL imports
  • Input sanitization and XSS prevention on all user content
  • CORS restrictions to authorized origins only
  • 11. Children

    Our service is not directed to children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us immediately.

    12. Changes

    We may update this policy. Material changes will be communicated via email to registered users. The "Effective" date at the top reflects the latest revision.

    Read on Scrolld →


    Scrolld® — Drop your data. Get a story.