Privacy Notice
1. Introduction
Welcome to Scrivla ("we," "our," or "us"), accessible at scrivla.com. We provide a web-based tool that lets authors write, import, and convert book manuscripts into EPUB and PDF formats for publishing or print.
This Privacy Notice explains what personal data we collect, how we use it, and your rights regarding that data. By using Scrivla, you agree to the practices described in this notice.
2. Who We Are
Scrivla is the data controller for personal data processed through our platform. If you have questions about this notice or your data, you can contact us at:
Email: privacy@scrivla.com
Website: scrivla.com
3. Data We Collect
3.1 Account & Contact Information
When you register for an account, we collect:
- Your name and email address
- A password (stored in hashed form — we never see it in plain text)
- Account preferences and settings
3.2 Subscription & Billing Information
If you upgrade to a Pro subscription, we collect:
- Your subscription plan and billing period
- Payment method details — note that we do not store your card number or full payment credentials on our servers. Payments are processed by a third-party payment processor (such as PayPal). Only a transaction reference and status are retained by us.
3.3 User-Generated Content
You may upload or create manuscript content on Scrivla. This content is private to your account and is not shared with or visible to other users unless you explicitly choose to export or publish it yourself. We process this content solely to provide you with the service.
3.4 Usage & Analytics Data
We collect information about how you interact with the platform, including:
- Pages visited, features used, and time spent
- Browser type, device type, and operating system
- IP address and approximate geographic region
- Error logs and performance data
This data helps us improve Scrivla and diagnose technical issues. Where possible, we aggregate or anonymise this data.
3.5 Cookies & Similar Technologies
We use cookies and similar tracking technologies to keep you logged in, remember your preferences, and understand how the service is used. You may control cookie preferences through your browser settings, though disabling certain cookies may affect functionality.
3.6 OpenRouter API Key & AI Features
If you use AI-assisted writing features, you provide and manage your own OpenRouter API key:
- Your responsibility: You create and manage your OpenRouter account and API key directly with OpenRouter. We do not create or provision keys for you.
- How we store it: Your API key is encrypted using AES-256-CBC encryption and stored securely on our servers. We never transmit your key to any third party.
- How we use it: When you generate AI content, your scene beat, character notes, and codex entries are sent to OpenRouter to generate prose. Your key is used only to authenticate requests to OpenRouter's API.
- Your billing: You maintain direct billing with OpenRouter for all API usage. Scrivla does not charge per-generation or add markup to OpenRouter's costs. You are responsible for managing your OpenRouter account balance and usage.
- Data retention: OpenRouter may retain logs of requests per their privacy policy. Scrivla does not retain your AI generation history beyond temporary caching.
4. Legal Basis for Processing
For users in the European Economic Area (EEA) and United Kingdom, we process personal data under the following legal bases:
- Contract: to provide the service you signed up for, including account management and content conversion.
- Legitimate interests: to improve our service, maintain security, and prevent fraud.
- Consent: for optional analytics or marketing communications. You may withdraw consent at any time.
- Legal obligation: when required by applicable law.
5. How We Use Your Data
We use your data to:
- Create and manage your account
- Deliver and improve the manuscript conversion service
- Process subscription payments
- Send transactional emails (e.g. password reset, billing receipts)
- Respond to support requests
- Analyse usage trends and improve platform performance
- Comply with legal obligations and protect against fraudulent activity
We do not sell your personal data to third parties. We do not use your manuscript content for training AI models or any purpose beyond delivering the service.
6. Data Sharing & Third Parties
We share data only as necessary:
- Payment processors (e.g. PayPal): to complete subscription transactions. Their use of your data is governed by their own privacy policies.
- Hosting and infrastructure providers: who store and process data on our behalf under data processing agreements.
- Analytics providers: who may receive anonymised or aggregated usage data.
- Legal authorities: if required by law or to protect the rights and safety of Scrivla or its users.
All third-party service providers are contractually required to handle your data securely and in accordance with applicable law.
7. International Data Transfers
Scrivla serves users globally. Your data may be transferred to and stored in countries outside your own, including countries that may have different data protection laws. Where required, we implement appropriate safeguards such as Standard Contractual Clauses (SCCs) for transfers from the EEA.
8. Data Retention
We retain your personal data for as long as your account is active or as necessary to provide the service. If you delete your account:
- Your account and profile data will be deleted within 30 days.
- Your manuscript content will be permanently deleted from our servers within 30 days.
- Billing records may be retained for up to 7 years as required for tax and accounting purposes.
9. Your Privacy Rights
Depending on your location, you may have the following rights:
- Access: request a copy of the personal data we hold about you.
- Correction: request correction of inaccurate or incomplete data.
- Deletion: request deletion of your personal data ("right to be forgotten").
- Portability: request your data in a structured, machine-readable format.
- Restriction: request that we restrict processing of your data.
- Objection: object to processing based on legitimate interests.
- Withdraw consent: at any time, for consent-based processing.
To exercise any of these rights, contact us at privacy@scrivla.com. We will respond within 30 days. If you are in the EEA or UK and believe we have not addressed your concern, you have the right to lodge a complaint with your local data protection authority.
10. Security
We implement appropriate technical and organisational measures to protect your data, including encrypted connections (HTTPS), hashed passwords, and access controls. However, no system is completely secure. We encourage you to use a strong, unique password and to keep your account credentials confidential.
11. Children's Privacy
Scrivla is not directed at children under the age of 16. We do not knowingly collect personal data from children. If we become aware that a child under 16 has provided us with personal data, we will delete it promptly. If you believe a child has registered, please contact us at privacy@scrivla.com.
12. Changes to This Notice
We may update this Privacy Notice from time to time. When we make material changes, we will notify you by email or by posting a prominent notice on the platform. The "Last Updated" date at the top of this page reflects the most recent revision. Your continued use of Scrivla after changes take effect constitutes acceptance of the updated notice.
13. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Notice or your data, please contact us: