Scraphe

Privacy Policy

What we collect, what we deliberately don’t, and who else touches it.

Last updated July 25, 2026

1. Overview

This Privacy Policy explains what personal data Scraphe collects when you use the Service, why, who else processes it on our behalf, and how you can exercise your rights over it. It applies regardless of whether you’ve made a purchase — browsing the library and creating a free account already involve some data collection under GDPR, KVKK, and similar laws.

Placeholder — operating entity. As with the Terms of Service, the data controller named in the final published version of this policy must be the actual contracting party (the founder or the entity once formed, per the business-operations plan §1), not “Scraphe” as a bare trade name.

2. What we collect

  • Your email address, via Google OAuth through our authentication provider;
  • Your credit balance and credit ledger;
  • Generation metadata — token counts and status for each generation — never your raw project source;
  • Subscription and billing state, via Creem, our payment processor;
  • We don’t run a product-analytics tool today, so no analytics events are collected.

3. What we explicitly do not collect

  • Passwords, in our own systems — you can sign in with Google, with GitHub, or with an email address and password. On the password path, the password is held only by our authentication provider (Supabase), as a salted hash — never in our own database, never in plaintext, and never visible to us. On the Google and GitHub paths no password exists at all;
  • Payment card data — Creem, our Merchant of Record, holds this, not us;
  • Your own AI-provider API keys — none exist; we run our own keys for every model tier;
  • Your project source beyond a single request — the project context you paste in is used to produce that one generation and is not persisted afterward.

4. We never train on your data

This is a binding commitment, not a marketing line: we do not use your project content or prompts to train any AI model. We do not train models, we do not fine-tune on your work, and we do not sell or share it for anyone else to train on.

To produce your result in real time, your brief and any project context you provide are sent to our AI provider, wiro.ai, which runs the models we route to. It is named in the sub-processor table below, along with exactly what it receives. Your project’s source files are never uploaded — they are read in your own browser, and only the small derived profile is transmitted.

We want to be precise about the limit of what we can promise on a third party’s behalf: our own no-training commitment above is unconditional, but wiro.ai’s handling of what it receives is governed by its own terms, and we have not yet confirmed its retention and training policy in writing. We are not going to imply a contractual guarantee we have not obtained. When we have it, this section will say so plainly and name the terms.

5. How we use it

We use what we collect to operate the Service — running your generations, billing you through Creem, keeping your account secure, and responding to support requests. We do not run a product-analytics tool today, so there is no usage profiling behind this. We do not sell your personal data, and we do not use it for advertising.

6. Sub-processors

Every third party that processes personal data on our behalf, what it does, and what it touches:

Every third-party sub-processor that touches personal data, what it does, and what it touches
Sub-processorPurposeData touchedCross-border note
SupabaseAuthentication (including transactional email, e.g. password-reset links), Postgres database, and file storage for generated assetsEmail address, password-reset link content, credit ledger, generation metadata and stored output, subscription stateProject region eu-west-1. Whether a separate vendor backs Supabase's outbound email at the SMTP/dashboard level isn't verifiable from our own integration, so we neither assert nor rule that out.
RenderApplication hostingRequest logs, session cookies in transitStandard SaaS hosting; publishes its own DPA/SCCs. Replaced Vercel as our host on 29 July 2026.
wiro.aiRuns the AI model behind every design generation, adaptation and revisionYour brief, any project context you choose to provide (framework, colours, fonts, component names, and the product description you enter), and the generated code returned to youThis is the provider that sees what you write. Your project's source files are never uploaded — they are read in your own browser and only the small derived profile is sent.
Fal.aiAI image generationImage-generation prompts, output imagesUS-based platform; standard AI-vendor DPA posture.
CreemPayments — our Merchant of RecordName, email, payment method (held by Creem, not us), billing address for taxCreem is the data controller for payment-transaction data it directly collects. Currently configured against Creem's test environment, so no real payment data has been processed.

Additional AI model hosts are planned for higher-quality tiers, and we may add a product-analytics tool later. None of them receives any data today, so none is listed above — this table is updated before any new provider processes anything.

7. International data transfers

Most of our sub-processors are US-based and operate under a standard AI/SaaS-vendor DPA posture; we verify each provider’s published DPA and SCC terms at drafting time rather than assume them. Creem is the data controller for the payment-transaction data it directly collects, as our Merchant of Record.

Placeholder — Supabase project region. Which region our primary datastore runs in (EU vs. US) hasn’t been picked yet, and it determines whether an EU-adequacy or SCC story is even needed for the data described in this policy (doc 16 §1.2, §10 item 2).

8. Türkiye (KVKK) note

Turkish law (KVKK, Law No. 6698) applies to us as a data controller because the founder/entity behind Scraphe is based in Türkiye, regardless of where a given user is located. KVKK’s principles are close to GDPR’s but are a separate compliance regime, not automatically satisfied by GDPR compliance alone.

Placeholder — two open counsel questions. Whether Scraphe must register in KVKK’s VERBİS data-controller registry (Türkiye has a small-business/limited-processing exemption whose applicability here needs a lawyer’s read), and whether this policy needs a Turkish-language version for KVKK’s transparency requirement, are both unresolved (doc 16 §1.2, §10 items 3–4).

9. Your rights

Under GDPR and KVKK you can ask to access, correct, export, or delete your personal data, and to object to certain processing. We respond to a verified request within 30 days — the GDPR norm, which matches KVKK’s own statutory window: Law No. 6698, Article 13(2), gives you a response within 30 days, free of charge. To make a request, email privacy@scraphe.com.

10. Retention & deletion

You can delete your account yourself, in-app — Settings → Account or Settings → Privacy both offer a Delete account control, behind an explicit confirmation step. Once you confirm, your account row and your generation rows are deleted outright — not a soft-delete. Credit-ledger rows are not deleted; because that ledger is our financial audit trail, we anonymise them instead, severing the link to your identity while the credit amounts and timestamps themselves remain. Deleted data can still be recovered from database backups for up to seven days afterward, the length of our database provider’s point-in-time-recovery window, before it ages out everywhere. We keep subscription records only as long as bookkeeping law requires.

Placeholder — bookkeeping retention period. The exact statutory retention period for subscription/financial records depends on which jurisdiction our business entity is formed in — not yet decided (doc 16 §1.2, §7).

11. No special-category data

We don’t collect health, biometric, political, or other special-category data, and we intend to keep it that way — doing so would trigger stricter rules under both GDPR and KVKK that the Service isn’t built to satisfy today.

12. Cookies

We use two cookies, both strictly necessary: a session cookie that keeps you signed in, and a short-lived marker written only while you complete a password reset. Neither is used to track you. Full detail, including the marker’s lifetime and scope, is in our Cookie Policy.

13. Age requirement

The Service is not directed at anyone under 18, matching the eligibility rule in our Terms of Service. We do not knowingly collect personal data from anyone under 18.

14. Changes to this policy

We may update this policy as the Service or our sub-processors change. Material changes update the “Last updated” date above.

15. Contact

Privacy questions and rights requests go to privacy@scraphe.com — a monitored mailbox for exactly this purpose.