Privacy Policy
Last updated: August 2026
1. What we collect
When you create a Scriva account, we collect:
- Your email and password (handled by our authentication provider, Supabase — we never see or store your password in plain text).
- Profile details you provide: name, agency, phone, website, tagline, brand voice, brand color, and logo.
- Property listing details you enter: address, price, features, neighborhood, notes, and any photos you upload.
- Usage data: how many pieces of content you have generated, so we can enforce trial and plan limits.
If you publish a listing's shareable landing page, we also collect information submitted by visitors through that page's contact form (name, email or phone, and their message), and basic visit data (which link — QR, social, or direct — brought them there). That data belongs to you as the listing owner; visitors are not Scriva account holders.
2. How we use it
- To generate your content package, your listing details — including any photos you upload, which we analyze to help write photo-specific captions and pick a cover image — are sent to a third-party AI provider (Anthropic) for processing. Under our agreement with them, they do not use this data to train their models.
- To send you account-related emails (welcome, trial status, payment issues, lead notifications) through our email provider, Resend.
- To process your subscription payment through our payment processor, Creem — Scriva never receives or stores your full card number.
- To enforce fair-use limits on generations and uploads, and to prevent abuse of the free trial.
Our legal basis for these uses is: performing our contract with you (running the service you signed up for), our legitimate interest in keeping the product secure and fairly used (fraud prevention, quota enforcement), and legal obligations we have to keep certain billing records (see "Data retention and deletion" below).
3. Who we share it with
We don't sell your data, and we don't share it with data brokers or advertisers. We share the minimum necessary with the vendors that make the product work: Supabase (database, authentication, file storage), Anthropic (AI content generation and photo analysis), Creem (billing — Creem acts as the merchant of record for your subscription, see the Terms of Service), Resend (transactional email), and Vercel (hosting — every request to Scriva passes through their infrastructure — and aggregate, cookieless traffic analytics for our own pages). Each handles data under their own privacy terms as our data processors, and none of them are authorized to use your data for their own purposes beyond providing that service to us. We may also disclose data if required by law, subpoena, or to protect the rights, safety, or property of Scriva, our users, or the public.
4. International data transfers
Scriva is used by agents in many countries, but our vendors process and store data primarily in the United States (and other countries where they operate infrastructure). If you're located outside the US — including in the EU, UK, or elsewhere with data protection laws — using Scriva means your data is transferred to and processed in those countries. Where required, we rely on the safeguards our vendors provide for these transfers (such as their own Standard Contractual Clauses or equivalent mechanisms); we don't independently verify each vendor's transfer mechanism beyond what their own privacy terms represent.
5. Cookies
We use one essential cookie to keep you signed in. We don't use advertising or cross-site tracking cookies. Anonymous visitors to a shareable listing page or to our marketing site are not tracked individually — we log aggregate visit counts, not identities. Our traffic analytics (Vercel Web Analytics) set no cookies and build no cross-site profile: they record the page visited, the referring site, and coarse device and country information, with no identifier that persists across visits.
6. Security
We use industry-standard measures to protect your data: all traffic to Scriva is encrypted in transit (HTTPS/TLS), data at rest is stored with our infrastructure providers' own encryption (Supabase, Vercel), access to production data is restricted to what's needed to operate the service, and database-level access rules (row-level security) keep each agent's listings and leads visible only to them. No method of transmission or storage is 100% secure, so we can't guarantee absolute security — but we work to keep these protections current. If a breach affecting your personal data occurs, we'll notify affected users and any authorities required by applicable law without undue delay.
7. Data retention and deletion
We keep your account data for as long as your account is active. To request deletion of your account and associated data, contact us at the address below — we don't yet have a self-service delete-account button, so this is handled manually today. When we delete your account, we permanently delete your profile, property listings, generated content, uploaded photos, leads, and page-view history from our production database; this cascades automatically once the underlying account record is removed. Some of that data may persist briefly in routine infrastructure backups before those backups themselves are purged. We retain minimal billing records (e.g., that a payment occurred, not full card details — those live with Creem) for as long as required by tax and accounting law, even after account deletion.
8. Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal data, to object to or restrict certain processing, and to lodge a complaint with your local data protection authority. Most requests can be handled directly in Settings (profile, language, billing); for anything else, including account deletion, contact us and we'll take care of it. We don't charge a fee for reasonable requests and we'll respond within the time required by applicable law (or, absent a specific legal deadline, within 30 days).
9. Children
Scriva is a professional tool for real estate agents. It is not directed at, and we do not knowingly collect data from, anyone under 18. If we learn a minor has provided us personal data, we'll delete it.
10. Changes to this policy
If this policy changes in a meaningful way, we'll update the date at the top of this page and, where appropriate, notify you by email.
11. Contact
Questions about this policy or your data, including deletion or access requests: hello@scriva.dev