Privacy Policy
Last Updated: July 2026
1. Introduction
Scripta.ai ("Scripta," "we," "our," or "us"), operated by Living Circuits Technologies, is committed to protecting the privacy and personal data of our users. This Privacy Policy describes what information we collect, how we use it, how we protect it, and your rights in relation to it — including your rights under the Malaysian Personal Data Protection Act (PDPA) and applicable international data protection standards.
By using the Scripta platform, you agree to the collection and use of information as described in this Privacy Policy.
2. Information We Collect
Scripta adheres to data minimization principles. We collect only what is necessary to operate and improve the platform.
2.1 Account Information
When you register for a Scripta account, we collect your email address. No additional personal information is required for account creation or core platform functionality.
2.2 Payment & Billing Metadata
All payment processing is handled by our PCI-DSS compliant partner, Stripe. Scripta does not collect, store, or process your credit card numbers, CVVs, or expiration dates. We retain only the metadata supplied by Stripe that is necessary to manage your subscription — specifically your Stripe customer identifier and subscription status.
2.3 Document Processing Data
Documents uploaded to Scripta are stored in secure temporary environments and processed automatically via our AI pipeline. Upon delivery of the generated output, the original source documents and all processing fragments are permanently and systematically deleted from our servers. Scripta does not retain, archive, or index user documents beyond the active processing session. No human review of uploaded content is performed.
2.4 Usage Analytics
We collect anonymized usage data to monitor platform performance and stability, including processing volumes, error rates, and feature usage patterns. This data is aggregated and cannot be mapped back to individual users.
2.5 Technical Data
For security and operational monitoring purposes, our servers automatically capture standard technical parameters including masked IP addresses, browser type, operating system, and access timestamps. This data is used solely for platform security and is routinely purged.
3. Affiliate & Banking Data
Users who participate in the Scripta Affiliate Program provide additional information necessary for commission payout processing.
3.1 Data Collected
- Full name (as registered with the banking institution)
- Bank name
- Bank account number
- Country
- Preferred payout currency
3.2 Purpose
Banking details are collected exclusively for the purpose of processing affiliate commission payments and satisfying applicable financial reporting requirements. This data is not used for any other purpose.
3.3 Storage & Security
Affiliate banking details are encrypted at rest within our secure database infrastructure. Access is restricted to essential financial operations and automated payout processing systems. This data is never shared with third parties beyond the financial institutions executing the payout transfer.
3.4 Retention
Banking details are retained for the duration of an active affiliate account. Upon termination of affiliate status or account deletion, banking details are permanently removed from our systems within 30 days, except where financial or tax regulations require longer retention.
4. Referral Tracking
When a visitor arrives at Scripta through an affiliate referral link, the referral code is stored locally in the visitor's browser using localStorage. This code is submitted to our systems upon successful account registration to attribute the referral to the appropriate Affiliate Agent.
Referral codes stored in localStorage expire after 30 days. Scripta does not use advertising cookies or third-party tracking cookies for referral attribution or any other purpose.
5. How We Use Your Information
Information collected by Scripta is used solely for the following purposes:
- Operating, maintaining, and improving the Scripta platform.
- Processing documents and delivering AI-generated outputs.
- Managing user accounts and subscription status.
- Processing affiliate commission payments.
- Monitoring platform security and preventing fraudulent activity.
- Communicating with users regarding their accounts, subscriptions, or support requests.
- Complying with applicable legal obligations.
Scripta does not sell, rent, or trade user data to third parties for marketing or advertising purposes under any circumstances.
6. Third-Party Service Providers
Scripta relies on the following trusted third-party providers. Data transmission to these partners is governed by Data Processing Agreements (DPAs):
- Application Hosting & Database: Vercel and Supabase — for platform hosting, encrypted storage, and database management.
- Payment Processing: Stripe — for subscription billing and payment management. Scripta is completely isolated from PCI-DSS scope through Stripe's hosted payment infrastructure.
- AI Processing: OpenAI — for document summarization. Documents are transmitted to OpenAI via API under zero-data-retention (ZDR) terms. OpenAI does not store or use data sent through our API to train public AI models. This protection is particularly relevant for legal, medical, and academic documents processed on our platform.
- Email Communications: Resend — for transactional email delivery including account verification and billing notifications.
7. Data Security
Scripta implements industry-standard technical and organizational safeguards to protect user data against unauthorized access, disclosure, alteration, or destruction. All network communication is enforced via TLS encryption. Database access is controlled through strict access policies and regularly reviewed.
While we maintain high standards of data protection, no cloud system can guarantee absolute security. In the event of a data breach that materially affects your personal information, we will notify affected users within the timelines required by applicable law.
8. Cookies & Local Storage
Scripta uses minimal client-side storage:
- localStorage: Used for session management, anonymous user identification, and temporary referral code storage. No personally identifiable information is stored beyond what is necessary for platform functionality.
- Cookies: Scripta does not use advertising cookies, cross-site tracking cookies, or third-party analytics cookies.
9. Data Retention
- Account data is retained for the duration of your active account and for a reasonable period thereafter as required by applicable law.
- Document data — uploaded documents and generated summaries are permanently deleted upon completion of processing.
- Subscription data is retained for the period required to comply with financial and legal obligations.
- Affiliate banking data is retained for the duration of active affiliate status and deleted within 30 days of account termination, subject to applicable tax retention requirements.
10. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- The right to access the personal data we hold about you.
- The right to request correction of inaccurate data.
- The right to request deletion of your personal data, subject to legal retention requirements.
- The right to data portability — you may request an export of your account metadata or affiliate statement.
- The right to withdraw consent where processing is based on consent.
To exercise any of these rights, please contact us through the contact form on the Scripta website.
11. Children's Privacy
Scripta is not directed at individuals under the age of 18. We do not knowingly collect personal data from minors. If we become aware that a minor has registered without verifiable parental consent, we will take steps to delete the account and associated data promptly.
12. Amendments
Scripta reserves the right to update this Privacy Policy from time to time. Material changes will be communicated via email or prominent notice on the platform with a minimum of 14 days' advance notice. Your continued use of Scripta following the effective date of any update constitutes acceptance of the revised Privacy Policy.
13. Contact
For privacy-related inquiries, data requests, or concerns regarding this Privacy Policy, please contact us through the contact form available on the Scripta website.