Skip to main content

Privacy Policy

Last updated: March 14, 2026

1. Data Controller

The Data Controller for this website is:

Scribora AI

Contact: [email protected]

For any questions about this Privacy Policy or to exercise your data protection rights, contact us at the email address above.

2. Data Protection Officer

Given the nature and scale of our data processing activities, a Data Protection Officer (DPO) has not been formally appointed as it is not required under Art. 37 GDPR. However, for any data protection inquiries you can contact us at [email protected]. We will appoint a DPO if our processing activities require one in the future.

3. Information We Collect

3.1 Account Data

When you create an account, we collect your name and email address via our authentication provider (Clerk). We also store your subscription tier, credit balance, and account preferences.

3.2 Project & Content Data

When you use our service, we collect and store: project titles and settings, scraped content from sources you specify (e.g. Reddit), knowledge base entries, AI-generated outlines and chapters, and AI-generated images. This data is necessary to provide the content generation service.

3.3 Billing Data

Payment information is processed by Paddle, our Merchant of Record. We store only your Paddle customer ID and subscription ID. We never store credit card numbers, bank details, or other financial information on our servers.

3.4 Usage & Analytics Data

We collect usage metrics such as chapters generated, word counts, and credit consumption to provide platform analytics and improve our service. We do not use third-party behavioral tracking tools on the Scribora.ai platform itself.

4. Web Scraping & Third-Party Content

Scribora collects publicly available content from third-party platforms (including Reddit, Hacker News, and StackExchange) based on topics you specify. This scraping is performed to build a knowledge base for your content generation projects.

  • Legal basis: Legitimate interest (Art. 6(1)(f)) in providing the research and content generation service you requested, balanced against the fact that the scraped content is already publicly available.
  • Data collected: Post titles, body text, author usernames, scores, and source URLs from public posts and comments.
  • Retention: Scraped content is stored for the duration of your project and deleted when you delete the project or your account.
  • No personal profiling: We do not use scraped data to build profiles of third-party users. Scraped content is used solely as reference material for AI-powered content generation.

5. Legal Basis for Processing (GDPR Art. 6)

We process your data based on:

  • Contract performance (Art. 6(1)(b)): Account creation, content generation, subscription management, and customer support.
  • Legitimate interest (Art. 6(1)(f)): Platform security, fraud prevention, service improvement, usage analytics, and web scraping of publicly available content.
  • Legal obligation (Art. 6(1)(c)): Tax and accounting records, regulatory compliance.
  • Consent (Art. 6(1)(a)): Marketing communications and optional cookies. You can withdraw consent at any time.

6. How We Use Your Information

  • Providing and maintaining the content generation service
  • Processing your AI content requests via third-party LLM providers
  • Scraping publicly available content from platforms you specify for research purposes
  • Managing your account and subscription
  • Processing payments and refunds (via Paddle)
  • Providing customer support
  • Improving our platform based on aggregated usage data
  • Complying with legal obligations

7. Third-Party Services & Sub-Processors

We share your data with the following third-party services, strictly for the purposes described:

ServicePurposeData Shared
ClerkAuthenticationEmail, name, login credentials
Anthropic (Claude)AI content generationProject data, prompts, scraped content
OpenAI (GPT-4, DALL-E)AI content & image generationProject data, prompts, image requests
PaddlePayment processing (Merchant of Record)Email, billing info, transaction data
Cloudflare (R2)File storageUploaded images, generated landing pages
Fly.ioHosting infrastructureAll platform data (encrypted at rest)
UpstashTask queue (Redis)Temporary job metadata

For a full list including data locations and transfer safeguards, see our Sub-Processors page.

8. International Data Transfers

Some of our sub-processors (Anthropic, OpenAI, Cloudflare, Fly.io) are based in the United States. When your data is transferred outside the European Economic Area (EEA), we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission, or reliance on the EU-US Data Privacy Framework where applicable.

9. AI-Generated Content Disclosure

Scribora uses artificial intelligence (Anthropic Claude, OpenAI GPT-4) to generate content. Your project data, including scraped sources and notes, is sent to these AI providers for processing. These providers process data according to their respective API terms and do not use API inputs for model training. However, we cannot guarantee the complete accuracy, originality, or suitability of AI-generated content. You are responsible for reviewing all generated content before use or publication.

10. Data Retention

  • Account data: Retained for the duration of your account, plus 30 days after deletion.
  • Project data: Retained until you delete the project or your account.
  • Billing records: Retained for 10 years as required by tax and accounting law.
  • Usage analytics: Retained in aggregated form for up to 26 months.
  • Audit logs: Retained for 3 years for security and compliance purposes, then automatically deleted.
  • Support communications: Retained for 3 years after resolution.

11. Your Rights (GDPR)

Under the General Data Protection Regulation, you have the following rights:

  • Access (Art. 15): Request a copy of all personal data we hold about you.
  • Rectification (Art. 16): Request correction of inaccurate data.
  • Erasure (Art. 17): Request deletion of your personal data (“right to be forgotten”).
  • Restriction (Art. 18): Request limitation of processing.
  • Data Portability (Art. 20): Receive your data in a structured, machine-readable format.
  • Objection (Art. 21): Object to processing based on legitimate interest.
  • Withdraw Consent: Withdraw any previously given consent at any time, without affecting the lawfulness of processing before withdrawal.

To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.

12. Right to Complain

If you believe your data protection rights have been violated, you have the right to lodge a complaint with a supervisory authority. As our establishment is in Italy, our lead supervisory authority is the Garante per la protezione dei dati personali (Piazza Venezia 11, 00187 Roma, Italy). EU residents may also lodge a complaint with their local Data Protection Authority.

13. Automated Decision-Making

We do not use your personal data for automated decision-making or profiling that produces legal effects or similarly significantly affects you. The AI content generation feature is a tool you control and does not make decisions about you.

14. Cookies

We use essential cookies for authentication and platform functionality. For details about all cookies we use, please see our Cookie Policy.

15. Children's Privacy

Scribora is not intended for use by individuals under 16 years of age. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.

16. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes via email or through the platform at least 15 days before they take effect. Continued use after changes constitutes acceptance of the updated policy.

17. Contact Us

For privacy-related inquiries: [email protected]

For general support: [email protected]