Privacy policy
Last updated: 25 July 2026
This policy describes how Scrollify ("we", "us") handles personal data when you use scrollify.io (the "Service").
1. Data we collect
- Account data: email address, password hash (never the raw password), plan, and optional profile fields you provide. If you sign in via Google, we receive your name, email, and Google profile identifier from Google's OAuth service.
- Job data: the public URLs you submit for export, the configuration you choose (preset, format, duration), job status, and the output files we generate. URLs are stored to show your export history and to allow re-queueing.
- Image uploads: product or other photos you upload for Image Auto-Crop and E-Commerce Image Preparation (JPG, PNG, WebP, or ZIP batches), plus the processing options you choose (crop, padding, canvas, format, marketplace preset) and the derived output files we generate. These files may include personal or product imagery you choose to upload.
- Guest demos (no account): if you try a free watermarked scroll export or guest image convert without signing in, we process the public URL or uploaded images you submit, generate a short-lived output file, and store a temporary job record so you can preview, download, or later claim the file into an account. Guest demos are watermarked and time-limited.
- IP address: we collect your IP address (or the address reported by our CDN / reverse proxy) on API requests, including guest demos, authentication, exports, and contact submissions. We use it for security, rate limiting, abuse prevention, and to bind anonymous guest-demo quotas so clearing cookies or changing network identity alone does not reset fair-use limits. We store a one-way hash of the IP for guest-demo quota and event records rather than the raw address in those tables; raw IPs may still appear briefly in technical server logs.
- Session data: an HTTP-only session cookie and a short-lived token issued on login. These are used solely for authentication and expire on logout or after a period of inactivity.
- Guest demo cookie: an HTTP-only
sl_guestcookie that identifies your anonymous demo session in the browser. It does not sign you in. Combined with your IP hash, it enforces per-visitor demo limits. Clearing site cookies starts a new browser identity, but IP-based limits may still apply. - Contact form: name, email address, and message content when you contact us.
- Technical logs: server-side request logs (IP address, timestamp, endpoint) retained for security, abuse prevention, and operational diagnosis.
- Cookie consent: your consent or refusal for optional analytics cookies, stored locally.
2. How we use your data
- Providing the Service: processing export jobs, storing outputs, authenticating sessions, and sending transactional emails (account verification, password reset).
- Guest try-before-signup: running a limited number of watermarked demos, enforcing fair-use quotas (per guest cookie and per IP), offering a short download window, and optionally attributing a later signup to a prior demo session so we can improve onboarding (aggregate metrics only for CMS operators).
- Image preparation: running server-side image processing on uploaded files to crop, normalize canvases, convert formats, and deliver a ZIP download for your batch.
- Security and abuse prevention: rate limiting, IP-level blocking of private-network access attempts, guest-demo quota enforcement, and detection of misuse.
- Service improvement: aggregated, internal analysis of failure patterns to improve export reliability. No individual URL or personal data is shared externally for this purpose.
- Billing: subscription management via our payment processor(s). We do not store full card details on our servers.
- Communication: responding to contact form submissions and sending service notices where necessary.
3. Legal bases (GDPR)
We process your data to perform our contract with you (providing exports, maintaining your account), to pursue legitimate interests (security, fraud prevention, fair-use enforcement for free demos, service improvement), and where required by law. Pre-contractual steps — such as a free guest demo before you create an account — are processed on that basis or on legitimate interests in preventing abuse of free compute. Transactional emails are sent on a contract basis. Optional analytics cookies rely on your consent, which you can withdraw at any time by clearing site data or adjusting your browser settings.
4. Public share links
When you generate a public share link for an export, the linked file becomes accessible to anyone who has the URL. Share links do not expose your account details, email, or any metadata about you. You can stop sharing at any time by removing the share link from your library.
5. Third-party processors
We use third-party services to operate the Service, including payment processors, email delivery providers, and infrastructure providers. These processors handle data only as instructed by us and under appropriate data protection agreements. We do not sell your personal data to third parties.
6. Retention
- Account and job data: retained while your account is active and for a reasonable period afterward to support backups and legal obligations.
- Export files: retained until you delete them or your account is closed; we may apply storage limits with notice.
- Guest demo outputs: anonymous download is typically available for about 1 hour after the demo is ready. Files may be kept on disk for a short reclaim window (typically up to about 72 hours) so you can create a free account and save the export to your library. After that window, files are removed by our normal storage cleanup. Guest quota and event records (hashed guest identity and hashed IP) are retained for the rolling fair-use window (typically 24 hours) and for limited operational / abuse analysis, then deleted or overwritten.
- Image-prep uploads and outputs: original uploads, working files, and batch ZIP outputs for Image Auto-Crop / E-Commerce Image Preparation are stored on our servers for a limited retention window (typically up to 48 hours), then deleted automatically. You may also delete a batch earlier from your library. Guest image converts follow the guest demo retention rules above when used without an account.
- Password reset tokens: single-use, expire after one hour, deleted automatically.
- Session tokens: expire on logout or after the configured inactivity window.
- Guest demo cookie (
sl_guest): persists for up to about 30 days unless you clear cookies earlier. - Contact messages: processed and delivered by email only — no database record is created. Messages are retained in the operator's email inbox only as long as needed to respond. Deletion requests must be submitted by contacting us directly.
- Technical logs (including IP addresses): retained for a limited period for security and operational purposes, then deleted or anonymised.
7. Your rights (EEA / UK)
You have the right to access, correct, or erase your personal data; to restrict or object to processing; and to data portability where applicable. You may also lodge a complaint with your local supervisory authority. To exercise these rights, contact us via the contact form.
Note on contact form submissions: messages sent via the contact form are forwarded by email and are not stored in our application database. A Subject Access Request (SAR) response will include a manual review of the operator's email inbox in addition to any data held in the application. To request deletion of a contact message, please contact us and include the approximate date and subject of the original message.
Note on guest demos: because guest demos are anonymous, we may only be able to locate related records if you provide enough detail (approximate time, demo type, and that you still have the sl_guest cookie or a demo ID). Clearing cookies removes our ability to match your browser identity; hashed IP records may remain until their retention window ends.
8. International transfers
Where we use processors or infrastructure outside your region, we implement appropriate safeguards such as standard contractual clauses where required by applicable law.
9. Children
The Service is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us data, please contact us and we will delete it promptly.
10. Changes to this policy
We may update this policy; the "Last updated" date will change. Continued use after changes constitutes acceptance where permitted by law.
11. Contact
For privacy questions or data requests, use the contact form on the home page.