Privacy Policy
Effective September 26, 2026
This policy explains how Scribase handles personal data we control — account, billing, and website data — including what we collect, why, the legal bases, how long we keep it, who we share it with, and your rights. Personal data you store inside your projects is governed by our Data Processing Agreement.
1. Scope of this policy
This Privacy Policy explains how Scribase ("we", "us", or "our") handles personal data for which we act as the controller — the personal data we collect to operate our business, provide accounts, take payment, and run our website and documentation. It applies to visitors to our website and to people who create and administer Scribase accounts.
It does NOT govern the data you place inside your Scribase projects. When you store or process personal data of your own end users through the Service — in your database, storage, authentication, or functions — you are the controller of that data and we are your processor. That relationship is governed by our Data Processing Agreement at https://scribase.com/legal/dpa, not by this policy.
2. Personal data we collect
Account data
When you register, we collect the information needed to create and secure your account, such as your name, email address, authentication identifiers, and organization or team details.
Billing data
To take payment for paid plans we collect billing contact details and process payments through Creem (creem.io), our payment processor and merchant of record. We do not see or store card numbers; Creem handles them. We retain records of invoices and transactions as required for accounting and tax.
Usage and device data
When you use the console, CLI, control API, or website, we collect operational data such as log entries, IP address, browser and device information, feature usage, and diagnostic events. We use this to secure the Service, prevent abuse, debug problems, and understand which features are used.
Communications
When you contact support, report a vulnerability, or otherwise communicate with us, we keep the content of those communications and our responses so we can help you and keep a record.
3. How and why we use personal data
We use the personal data described above for the following purposes:
- To provide, maintain, and secure the Service and your account.
- To process payments, send invoices, and manage subscriptions.
- To respond to support requests and communicate about the Service, including service, security, and legal notices.
- To detect, prevent, and investigate fraud, abuse, and security incidents.
- To understand and improve how the Service and website are used, including reliability and performance.
- To comply with legal obligations and to establish, exercise, or defend legal claims.
We do not sell your personal data. We do not use the contents of your Customer Data to train models or for advertising.
4. Legal bases (EEA/UK)
Where the GDPR or UK GDPR applies, we rely on the following legal bases: performance of a contract (to provide the Service and account you asked for); legitimate interests (to secure and improve the Service and prevent abuse, balanced against your rights); compliance with a legal obligation (such as tax and accounting); and consent where required (for example, certain optional communications or non-essential cookies), which you may withdraw at any time.
7. International data transfers
We and our sub-processors may process personal data in countries other than where you are located. Where we transfer personal data across borders in a way that triggers legal safeguards, we rely on recognized transfer mechanisms — such as the European Commission’s Standard Contractual Clauses and the UK Addendum — together with appropriate technical and organizational measures.
8. Data retention
We keep personal data for as long as your account is active and for as long as needed to provide the Service. After your account is closed we delete or anonymize account and usage data in the ordinary course, except where we must retain certain records — such as invoices — to meet legal, tax, or accounting obligations, or to resolve disputes and enforce agreements. Retention and deletion of Customer Data inside your projects is governed by the Data Processing Agreement.
9. Security
We protect personal data with technical and organizational measures appropriate to the risk, including encryption in transit and at rest, least-privilege access, auditable operations, and verified recovery. You can read more about our security posture at https://scribase.com/security. No system is perfectly secure, but we work continuously to keep your data safe and to respond quickly if something goes wrong.
10. Your rights
Depending on where you live, you may have rights over your personal data, including the right to access, correct, delete, or port it, to object to or restrict certain processing, and to withdraw consent. Residents of California and similar jurisdictions have additional rights, including the right to know what personal information we collect and the right not to be discriminated against for exercising their rights.
To exercise any of these rights, contact us at support@scribase.com. We will verify your request and respond within the time required by applicable law. You also have the right to lodge a complaint with your local data-protection authority, though we hope you will contact us first so we can help.
11. Children
The Service is intended for businesses and developers and is not directed to children. We do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact us and we will delete it.
12. Changes and contact
We may update this policy from time to time. When we make a material change, we will update the effective date and, where appropriate, notify you through the Service. Your continued use after an update takes effect constitutes acceptance of the revised policy.
For any privacy question or request, contact us at support@scribase.com.