Privacy Policy
What we collect, what we deliberately don’t, and who else touches it.
Last updated July 25, 2026
1. Overview
This Privacy Policy explains what personal data Scraphe collects when you use the Service, why, who else processes it on our behalf, and how you can exercise your rights over it. It applies regardless of whether you’ve made a purchase — browsing the library and creating a free account already involve some data collection under GDPR, KVKK, and similar laws.
2. What we collect
- Your email address, via Google OAuth through our authentication provider;
- Your credit balance and credit ledger;
- Generation metadata — token counts and status for each generation — never your raw project source;
- Subscription and billing state, via Creem, our payment processor;
- We don’t run a product-analytics tool today, so no analytics events are collected.
3. What we explicitly do not collect
- Passwords, in our own systems — you can sign in with Google, with GitHub, or with an email address and password. On the password path, the password is held only by our authentication provider (Supabase), as a salted hash — never in our own database, never in plaintext, and never visible to us. On the Google and GitHub paths no password exists at all;
- Payment card data — Creem, our Merchant of Record, holds this, not us;
- Your own AI-provider API keys — none exist; we run our own keys for every model tier;
- Your project source beyond a single request — the project context you paste in is used to produce that one generation and is not persisted afterward.
4. We never train on your data
This is a binding commitment, not a marketing line: we do not use your project content or prompts to train any AI model. We do not train models, we do not fine-tune on your work, and we do not sell or share it for anyone else to train on.
To produce your result in real time, your brief and any project context you provide are sent to our AI provider, wiro.ai, which runs the models we route to. It is named in the sub-processor table below, along with exactly what it receives. Your project’s source files are never uploaded — they are read in your own browser, and only the small derived profile is transmitted.
We want to be precise about the limit of what we can promise on a third party’s behalf: our own no-training commitment above is unconditional, but wiro.ai’s handling of what it receives is governed by its own terms, and we have not yet confirmed its retention and training policy in writing. We are not going to imply a contractual guarantee we have not obtained. When we have it, this section will say so plainly and name the terms.
5. How we use it
We use what we collect to operate the Service — running your generations, billing you through Creem, keeping your account secure, and responding to support requests. We do not run a product-analytics tool today, so there is no usage profiling behind this. We do not sell your personal data, and we do not use it for advertising.
6. Sub-processors
Every third party that processes personal data on our behalf, what it does, and what it touches:
| Sub-processor | Purpose | Data touched | Cross-border note |
|---|---|---|---|
| Supabase | Authentication (including transactional email, e.g. password-reset links), Postgres database, and file storage for generated assets | Email address, password-reset link content, credit ledger, generation metadata and stored output, subscription state | Project region eu-west-1. Whether a separate vendor backs Supabase's outbound email at the SMTP/dashboard level isn't verifiable from our own integration, so we neither assert nor rule that out. |
| Render | Application hosting | Request logs, session cookies in transit | Standard SaaS hosting; publishes its own DPA/SCCs. Replaced Vercel as our host on 29 July 2026. |
| wiro.ai | Runs the AI model behind every design generation, adaptation and revision | Your brief, any project context you choose to provide (framework, colours, fonts, component names, and the product description you enter), and the generated code returned to you | This is the provider that sees what you write. Your project's source files are never uploaded — they are read in your own browser and only the small derived profile is sent. |
| Fal.ai | AI image generation | Image-generation prompts, output images | US-based platform; standard AI-vendor DPA posture. |
| Creem | Payments — our Merchant of Record | Name, email, payment method (held by Creem, not us), billing address for tax | Creem is the data controller for payment-transaction data it directly collects. Currently configured against Creem's test environment, so no real payment data has been processed. |
Additional AI model hosts are planned for higher-quality tiers, and we may add a product-analytics tool later. None of them receives any data today, so none is listed above — this table is updated before any new provider processes anything.
7. International data transfers
Most of our sub-processors are US-based and operate under a standard AI/SaaS-vendor DPA posture; we verify each provider’s published DPA and SCC terms at drafting time rather than assume them. Creem is the data controller for the payment-transaction data it directly collects, as our Merchant of Record.
8. Türkiye (KVKK) note
Turkish law (KVKK, Law No. 6698) applies to us as a data controller because the founder/entity behind Scraphe is based in Türkiye, regardless of where a given user is located. KVKK’s principles are close to GDPR’s but are a separate compliance regime, not automatically satisfied by GDPR compliance alone.
9. Your rights
Under GDPR and KVKK you can ask to access, correct, export, or delete your personal data, and to object to certain processing. We respond to a verified request within 30 days — the GDPR norm, which matches KVKK’s own statutory window: Law No. 6698, Article 13(2), gives you a response within 30 days, free of charge. To make a request, email privacy@scraphe.com.
10. Retention & deletion
You can delete your account yourself, in-app — Settings → Account or Settings → Privacy both offer a Delete account control, behind an explicit confirmation step. Once you confirm, your account row and your generation rows are deleted outright — not a soft-delete. Credit-ledger rows are not deleted; because that ledger is our financial audit trail, we anonymise them instead, severing the link to your identity while the credit amounts and timestamps themselves remain. Deleted data can still be recovered from database backups for up to seven days afterward, the length of our database provider’s point-in-time-recovery window, before it ages out everywhere. We keep subscription records only as long as bookkeeping law requires.
11. No special-category data
We don’t collect health, biometric, political, or other special-category data, and we intend to keep it that way — doing so would trigger stricter rules under both GDPR and KVKK that the Service isn’t built to satisfy today.
13. Age requirement
The Service is not directed at anyone under 18, matching the eligibility rule in our Terms of Service. We do not knowingly collect personal data from anyone under 18.
14. Changes to this policy
We may update this policy as the Service or our sub-processors change. Material changes update the “Last updated” date above.
15. Contact
Privacy questions and rights requests go to privacy@scraphe.com — a monitored mailbox for exactly this purpose.