Policies

Policies

Privacy Policy

How we gather and handle information for Scribbles and its associated services.

Who We Are

Scribbles is provided by Vincent Ritter Consulting. This policy explains what information we collect, why we collect it, and how we handle it when you use scribbles.page and related services.

Account Information

When you create and use an account, we store information needed to provide the Service, which may include:

  • Email address, password (hashed), and optional profile details such as a display name or avatar.
  • Passkeys and session data used for sign-in.
  • Blog content you create (posts, pages, media, themes, settings, custom domains, and related metadata).
  • Billing status and subscription identifiers from our payment providers (not your full card number).
  • API keys and access tokens you create, stored securely and used only to authenticate your integrations.
  • Transactional email related to your account (for example confirmation, password reset, invitations, backups, and billing notices).

At signup we may use spam-prevention checks (including Bento) to reduce abusive registrations. That processing is limited to signup abuse prevention.

Service Monitoring

For service monitoring and debugging, we use Sentry.ioopen in new window in production. When an application error is reported, we aim to minimize personal data; identifiers such as a customer or user ID may be included solely for debugging.

Our server logs are automatically filtered to remove sensitive data and are permanently deleted after 7 days. Server logs may contain IP addresses; we do not access logs except for debugging or security.

Payment Processing

New paid checkouts are processed by Stripeopen in new window. Some existing lifetime or legacy orders were processed by Lemon Squeezyopen in new window. Please refer to their privacy policies (Stripe, Lemon Squeezy) for how they handle payment data. We do not store full credit card numbers on our servers.

Analytics

We use Tinylyticsopen in new window for privacy-focused analytics on our marketing site when you are logged out. Tinylytics is designed to avoid cookies and user-identifiable tracking for that use.

Blog owners may optionally enable Scribbles Analytics on a public blog. When enabled, pageview data for that blog (such as path, referrer, user agent, country, IP address for geo resolution, and a hashed visitor identifier) is forwarded to Tinylytics so the blog owner can see aggregate visitor stats and optional kudos. Owner pageviews and non-public pages are excluded where practical.

Blog owners may also choose to load their own analytics or widgets (for example Tinylytics, Plausible, or Cloudflare Web Analytics). Those tools are controlled by the blog owner and governed by the third party's privacy policy.

We use essential cookies only: a session cookie to keep you signed in while browsing, and an optional "remember me" cookie if you choose that option at sign-in. These cookies are for authentication and are not used for advertising. Some preferences in the admin interface may also be stored in your browser's local storage.

Security Measures

We implement security measures to protect against unauthorized access, alteration, or misuse of your information. Data in transit is secured with TLS/SSL. Sensitive fields such as API keys and certain blog secrets are encrypted at rest where applicable. Media and backups are stored with our hosting and object-storage providers.

We use Cloudflareopen in new window for DDoS protection and edge security. Traffic may pass through Cloudflare's network; their privacy policy applies to that processing.

Third-Party Data Handling

We do not sell your personal data. We share data with third parties only as needed to operate the Service — for example payment processors, error monitoring, email delivery, spam prevention at signup, CDN/edge security, analytics providers described above, and storage/hosting providers.

If you enable third-party embeds on your blog (such as comments, contact forms, newsletters, testimonials, or status widgets), those services may collect information from your visitors under their own policies. That collection is between you, your visitors, and the third party.

Your Choices

You can update account details, export blog content, revoke API tokens, disable blog analytics, and delete your account from the product settings. Account deletion removes your user record and associated blogs and posts from the live Service, subject to residual copies in backups or logs that expire on their normal schedule. Contact us if you need help exercising these choices.

Contact

If you have questions about this privacy policy, please contact us at [email protected].

Last updated: July 2026