Privacy Policy
1. Who we are
This policy covers the ScrollGist browser extension and the scrollgist.app service that powers its default mode. The data controller is Clarity4Us Dijital Çözümler ve Danışmanlık Anonim Şirketi, registered in Istanbul, Türkiye ("we", "us") — see the contact page for full company details. Questions: privacy@scrollgist.app.
2. What the extension accesses
ScrollGist only acts on the pages it supports — Instagram, Facebook, and Twitter/X — and only when you actively open its panel and start a transcription or analysis. On those pages it may access:
- Video audio of the video you are viewing, to produce a transcript.
- Post text (the caption/body), when you choose to analyze it.
- The current post's URL, used only as a local cache key on your device.
The extension does not read your messages, your feed at large, your account credentials, your contacts, or your browsing history, and it does nothing on other websites.
3. Two modes, two data flows
3a. ScrollGist mode (default)
Content is sent from your browser to our API (api.scrollgist.app, running on
Cloudflare), which forwards it to an AI provider and returns the result.
| Data | Path | Retention |
|---|---|---|
| Recorded video audio / post text / transcripts being analyzed | Your browser → our API → AI provider (currently Groq) → back to you | Zero. Transit only — never written to disk, never logged, discarded the moment your result is returned |
| Anonymous device token (a random identifier generated by the extension), usage counters, plan/entitlement status | Stored by our API | Kept while you use the service; deleted on request |
| A salted, one-way hash of your IP address (abuse prevention). Raw IP addresses are never stored. | Stored by our API | Kept while you use the service |
The device token is random and is not linked to your name, email, or social accounts. We cannot tell who you are from it, and we cannot see which posts you visit — only how many credits it has used.
3b. Bring-your-own-key mode (advanced, optional)
If you enter your own API key in Settings, requests go directly from your browser to the provider you chose — OpenAI, Google (Gemini), Groq, Mistral, Anthropic, or OpenRouter — authenticated with your key. Nothing touches ScrollGist servers. Data sent this way is handled under that provider's own privacy policy.
4. What is stored on your device
| Data | Where | Lifetime |
|---|---|---|
| Preferences (language, mode), the anonymous device token, and — in BYOK mode — your API keys | Your browser's local extension storage, on your device only | Until you change them or uninstall |
| Transcripts and analyses you generate (cached per post so revisiting is instant) | Your browser's session storage, on your device only | Cleared automatically when you close the browser |
BYOK API keys are never sent anywhere except, as credentials, to the provider they belong to.
5. Payments
Paid plans are sold by Paddle, our merchant of record. Paddle collects your email and payment details under its own privacy policy; we never see your card number. We receive from Paddle only what is needed to activate your plan (a customer/subscription reference linked to your device token).
6. What we never collect
No analytics, no crash or usage telemetry, no advertising identifiers, no behavioral tracking, no selling or sharing of data — in either mode. We cannot see which posts you watch or what their content was.
7. Sub-processors
- Cloudflare — hosting and network infrastructure for our API and this website.
- Groq — AI transcription and analysis in ScrollGist mode.
- Paddle — payments, invoicing, and tax as merchant of record.
8. Why the extension asks for each permission
activeTab/tabCapture— to capture the audio of the video in the tab you are viewing, only after you click the toolbar button.sidePanel— to show the panel where results appear.storage— to keep preferences (and, in BYOK mode, your keys) on your device.tabs— to know the current post's URL for the local per-post cache.clipboardWrite— to let you copy results.- Host access to
instagram.com,facebook.com,twitter.com,x.com— to read the post you are viewing; toapi.scrollgist.app— for ScrollGist mode; and to the specific AI provider domains — for BYOK mode. No broad "all sites" access is requested.
9. Your rights and deleting your data
- On your device: uninstalling the extension deletes all of its local and session storage, including any keys.
- On our servers: email privacy@scrollgist.app to have your device token and its counters deleted. Since the token is anonymous, include it (shown in the extension's Settings) so we can find the record.
- Payment data: managed through Paddle under its policy; billing-related requests can also be sent to us and we will coordinate.
Depending on where you live (including under GDPR and Turkey's KVKK), you may have rights of access, correction, deletion, and objection. For content we process in transit there is nothing to access or delete — it is not retained. For the counters described above, contact us.
10. Children
ScrollGist is not directed at children under 13 (or the equivalent minimum age in your jurisdiction), and we do not knowingly collect personal data from children.
11. Changes
If our data practices change, we will update this policy and its effective date before the change ships. Material changes will also be noted in the extension's release notes.
12. Contact
privacy@scrollgist.app — or support@scrollgist.app for general support.