← Scraply

Privacy Policy

Effective date: August 1, 2026  ·  Last updated: August 2026

Contents

  1. Introduction
  2. Definitions
  3. Information We Collect
  4. How We Use Your Information
  5. Legal Basis for Processing
  6. Security Measures
  7. Disclosure of Information
  8. Data Retention
  9. Your Rights
  10. Managing Account Access
  11. International Data Transfers
  12. Children's Privacy
  13. Changes to This Policy
  14. Grievance Officer
  15. Governing Law
  16. Contact Us

1. Introduction

This Privacy Policy ("Policy") describes how the developer of the Scraply Android application (the "Developer," "we," "us," or "our") collects, uses, discloses, and safeguards information in connection with the Scraply application (the "Service"). This Policy is incorporated by reference into, and forms part of, our Terms of Service.

By downloading, installing, or using the Service, you acknowledge that you have read and understood this Policy. If you do not agree with its terms, you must not use the Service.

2. Definitions

"User," "you," "your"The individual who downloads, installs, or uses the Service.
"Personal Data"Any information relating to an identified or identifiable natural person, as described in Section 3.
"Content"Photographs, text, folder metadata, and any other material a User creates or uploads within the Service.
"Processing"Any operation performed on Personal Data, including collection, storage, use, or disclosure.
"Data Fiduciary" / "Data Principal"As defined under India's Digital Personal Data Protection Act, 2023 ("DPDP Act"). The Developer acts as the Data Fiduciary; the User is the Data Principal.
"Sub-processor"A third-party service provider engaged by the Developer to Process Personal Data on their behalf, as identified in Section 7.

3. Information We Collect

3.1 Account information

When you authenticate using Google Sign-In, the Developer receives, with your consent, the following Personal Data from Google: your name, email address, profile photograph (where available), and a unique account identifier. The Developer does not receive your Google account password or any Google account data beyond what is listed here.

3.2 Content

The Service allows you to create Content, consisting of photographs, written entries, and associated organizational metadata (folder names, dates, and visual tags). Content is subject to the security measures described in Section 6.

3.3 Account records

The Developer maintains a limited account record for each User, consisting of: (a) an internal account identifier; (b) an onboarding-completion flag; and (c) a Content encryption key, as further described in Section 6. This record does not include any Content.

3.4 Device permissions

The Service requests access to the device's photo library for the sole purpose of allowing the User to select photographs for inclusion in Content. This access is not used for any other purpose.

3.5 Categories of data not collected

The Developer does not collect precise or approximate location data, contacts, call logs, SMS messages, or data from other applications installed on the User's device. The Service does not incorporate advertising or analytics software development kits, and does not generate advertising identifiers.

4. How We Use Your Information

The Developer Processes Personal Data solely for the following purposes:

The Developer does not use Personal Data for advertising, does not construct behavioral or interest profiles, and does not sell, rent, license, or otherwise trade Personal Data to any third party.

5. Legal Basis for Processing

Where applicable law requires a legal basis for Processing, the Developer relies on: (a) your consent, given at sign-in and revocable at any time as described in Section 10; and (b) the necessity of Processing to perform the Service you have requested (i.e., to provide account authentication and backup functionality).

6. Security Measures

Content is encrypted on the User's device using AES-256-GCM prior to transmission. The encryption key applied to a User's Content is:

Encrypted Content is stored in a restricted, application-specific directory within the User's own Google Drive account (the appDataFolder), which is not visible through the standard Google Drive interface and is not accessible to other applications. The Developer does not operate a server on which unencrypted Content is stored, and does not possess the technical capability to access Content in intelligible form.

No method of electronic storage or transmission is entirely secure. While the Developer implements the measures described above, they cannot guarantee absolute security.

7. Disclosure of Information

The Developer engages the following Sub-processors in connection with the Service:

Sub-processorFunction
Google LLCAuthentication (Google Sign-In) and storage of encrypted Content backups within the User's own Google Drive account.
Supabase, Inc.Storage of the account record described in Section 3.3.

The Developer does not disclose Personal Data to any party other than the Sub-processors identified above, except: (a) where required to comply with applicable law, regulation, legal process, or governmental request; (b) to protect the rights, property, or safety of the Developer, their Users, or the public; or (c) in connection with a merger, acquisition, or sale of assets, subject to continued protection of Personal Data under materially equivalent terms. The Developer does not sell Personal Data.

8. Data Retention

Content is retained within the User's own Google Drive account for as long as the User maintains the Service installed and the associated Google account active, or until deleted by the User through Google Drive or through the Service's deletion controls. The account record described in Section 3.3 is retained for the duration of the account's active status and is deleted upon a verified deletion request under Section 9.

9. Your Rights

Subject to applicable law, and irrespective of your jurisdiction, you may exercise the following rights by contacting the Developer as described in Section 16:

The Developer will respond to verified requests within thirty (30) days, or such shorter period as required by applicable law.

10. Managing Account Access

You may revoke the Service's access to your Google account at any time, independently of the Service, through your Google Account settings at myaccount.google.com → Security → Third-party apps with account access. Revocation takes effect immediately with respect to future Processing; Content previously stored in your Google Drive's application-specific directory remains there until separately deleted by you.

11. International Data Transfers

The Developer's Sub-processors (see Section 7, "Disclosure of Information") may Process Personal Data on servers located outside your country of residence, including in the United States. Where such transfers occur, the Developer relies on the respective Sub-processor's own compliance mechanisms (including standard contractual clauses and equivalent safeguards) for cross-border transfer of Personal Data.

12. Children's Privacy

The Service is not directed to, and is not intended for use by, individuals under eighteen (18) years of age. The Developer does not knowingly collect Personal Data from children. If the Developer becomes aware that they have collected Personal Data from a child, they will take reasonable steps to delete such data promptly.

13. Changes to This Policy

The Developer may amend this Policy from time to time to reflect changes in the Service or in applicable law. Material amendments will be reflected by an updated "Last updated" date at the top of this page. Continued use of the Service following any amendment constitutes acceptance of the amended Policy.

14. Grievance Officer

In accordance with the DPDP Act and applicable rules under the Information Technology Act, 2000, the following individual serves as Grievance Officer for matters concerning this Policy:

Developer of Scraply
Email: tinkerboxstudio11@gmail.com

The Grievance Officer will acknowledge grievances and endeavor to resolve them within the timeframe prescribed by applicable law.

15. Governing Law

This Policy is governed by the laws of India, including the Digital Personal Data Protection Act, 2023 and the Information Technology Act, 2000, together with the rules framed thereunder. Where applicable to Users located outside India, the Developer endeavors, on a best-efforts basis, to afford rights materially consistent with those set out in the General Data Protection Regulation (EU/EEA) and the California Consumer Privacy Act, without thereby submitting to the jurisdiction of those frameworks.

16. Contact Us

Questions regarding this Policy, or requests concerning the rights described in Section 9, may be directed to: tinkerboxstudio11@gmail.com

This Policy is provided to describe the Developer's data practices and does not constitute legal advice. Users seeking legal advice regarding their rights should consult a qualified professional.