Privacy Policy
What The Scribble Thing collects, why we need it, and when it goes away.
1. Scope and operator
This Privacy Policy explains how Boring Stuff Club (“we,” “us,” or “our”) handles information when you use The Scribble Thing and related pages (the “Service”). Questions and privacy requests may be sent to inquiry@boringstuff.club.
2. Information we collect
Content and generation data
We collect artwork you upload, optional drawing-order instructions, generation settings, intermediate processing files, AI analysis and animation plans, generated preview and final videos, and technical information about the upload such as file type, dimensions, and size.
Session and security data
We create a random anonymous visitor identifier and session identifier. We use signed cookies to recognize your browser and authorize access to a session. Agent API sessions use a per-session bearer capability instead of an account. We also create a rotating, pseudonymous hash of an IP address for rate limiting, abuse prevention, and aggregate measurement. We do not use that hash to recover your original IP address.
Usage and device data
We collect events such as page views, uploads, generation stages and timing, feature choices, preview activity, downloads, unlock activity, feedback, browser/device information, and errors. For Agent API requests, we also record a sanitized client name, optional client version and marketplace label, and a one-way hash of an optional installation identifier. We do not retain the raw installation identifier or idempotency key. We also record first-touch campaign labels supplied in links, such as source, medium, campaign, and content labels, plus the referring website's hostname. We do not retain the referring page's path or query string. Google Analytics may also collect a client identifier, session statistics, approximate location, and browser or device information through first-party cookies on the public homepage.
Contact and purchase data
If you contact us, we collect your name, email address, message, and related feature or session identifier. When you buy an unlock through Buy Me a Coffee, we receive purchase details needed to validate the transaction and issue a code. We retain pseudonymous hashes of the transaction reference and buyer email, purchase item, amount, currency, delivery status, refund status, and code record. To deliver contact notifications, Resend receives your name, email address, message, and related feature or session reference. For unlock emails, Resend receives the buyer email address and unlock code.
3. How we use information
We use information to:
- receive, analyze, and transform submitted content into animations;
- provide and secure session links, downloads, and unlocks;
- send purchased unlock codes and respond to contact messages;
- prevent abuse, enforce limits, troubleshoot failures, and protect the Service;
- measure reliability, performance, conversion, and feature usefulness; and
- comply with legal obligations and resolve disputes.
We do not use submitted artwork or instructions to train our own AI model. Authorized personnel may review limited session material when reasonably necessary to investigate a support request, security issue, abuse report, or generation failure during the 24-hour session window.
4. AI processing
To generate an animation, we send the uploaded image and your drawing-order instructions to OpenRouter and the selected model provider. Those providers process the content to return an analysis or drawing plan. Provider handling, location, and retention may vary according to the model and provider selected at the time. Do not submit sensitive personal information.
5. Service providers and disclosures
We disclose information only as needed to operate the Service, complete a transaction, comply with law, protect rights and safety, or complete a business transfer. Current provider categories include:
- Google Cloud and Firebase for application hosting, storage, databases, task processing, logging, and delivery;
- OpenRouter and downstream AI model providers for image and instruction analysis;
- Google Analytics for public-site usage measurement;
- Buy Me a Coffee for checkout and purchase webhooks; and
- Resend for transactional email delivery.
We do not sell personal information. We do not use Service information for targeted advertising, and we have disabled Google Signals and advertising-personalization signals in our Google Analytics configuration.
6. Cookies and similar technology
We use a signed scribe_visitor cookie to maintain a pseudonymous visitor identifier, a signed scribe_first_touch cookie for first-touch campaign attribution for up to 90 days, and a signed scribe_session cookie to authorize a browser to access a session. These are used for functionality, security, abuse prevention, and aggregate product measurement.
On the public homepage, Google Analytics may set first-party cookies such as _ga to distinguish visitors and sessions. You can block or delete cookies through your browser. Blocking functional cookies may prevent a private session link from continuing to work in that browser.
7. Retention
- Session content: uploaded artwork, instructions, intermediate files, AI plans, and generated videos are kept for up to 24 hours, unless deletion is required sooner. Using “Delete my session” removes the session content from our active Service earlier.
- Pseudonymous product telemetry: retained for up to 24 months.
- Contact submissions: retained for up to 24 months.
- Purchase, refund, code-delivery, and related accounting records: generally retained for up to seven years where needed for tax, accounting, fraud prevention, dispute resolution, or legal compliance.
- Operational logs and provider-held data: retained under our security configuration and the applicable provider’s retention practices, and may remain for a limited period after deletion from the active Service.
Deletion may be delayed where we must preserve information for security investigations, disputes, legal holds, or other legal obligations.
8. Security and session links
We use measures intended to protect information, including private storage, signed access tokens, restricted service identities, encrypted network transport, upload validation, and access limits. No system is completely secure.
A personal session URL or Agent API bearer capability acts like a password: anyone with it may be able to access the session. Do not share it with anyone you do not intend to give access.
9. Your choices and requests
You can delete an active session from its session page and can block or delete browser cookies. You may also contact us to ask to access, correct, or delete personal information associated with you, or to appeal a request decision. We may need information to verify the request and may retain records where an exception or legal obligation applies.
Residents of California and other jurisdictions may have additional rights, such as rights to know, access, correct, delete, limit certain uses, opt out of sale or sharing, and receive non-discriminatory treatment. Because we do not sell personal information or use it for targeted advertising, we do not provide a sale or targeted-advertising opt-out.
10. Children
The Service is general-audience and is not directed to children under 13. We do not knowingly collect personal information from a child under 13. If you believe a child has submitted personal information, contact us so we can investigate and delete it as appropriate.
11. International processing
We and our providers may process information in the United States and other countries whose data-protection laws may differ from those where you live. Where required, providers use contractual and other safeguards for international transfers.
12. Changes and contact
We may update this Policy as the Service and our practices change. The effective date and version above identify the current Policy. Material changes will be posted here and apply prospectively.
For questions or privacy requests, email inquiry@boringstuff.club.