← Scrollshelf

Privacy Policy

Effective date: 10 September 2026 · Lumio Studio

1. Who we are and how to contact us

Lumio Studio operates Scrollshelf, including the iOS and Android apps, scrollshelf.xyz and app.scrollshelf.xyz. This Privacy Policy explains how we collect, use, disclose, retain and delete personal information when you use these services.

For privacy questions, access requests or deletion requests, email contact@lumiostudio.co and identify Scrollshelf in your message. For product support, email scrollshelf@lumiostudio.co.

2. Information we collect

Account information: an account identifier and, when provided by your sign-in method, your name, email address and profile image. Firebase Authentication supports the account and sign-in process; Apple or Google may provide the profile information you authorize.

Saved content: links and media you submit, source titles and creator information, thumbnails, transcripts, summaries, key points, tags, shelves, personal notes and edits. We also store processing status, saved dates, note visit counts and related activity needed to operate your library.

Device and service information: app and operating-system versions, device identifiers used by our services, language, notification tokens, IP addresses, timestamps, interactions, error logs and crash diagnostics. Service providers may receive these details when your device connects to their services.

Purchases: subscription status, product identifiers, transaction or purchase-token information, and purchase or renewal events from Apple, Google and Adapty. Payment-card details are handled by the app store; Scrollshelf does not receive your full card details.

Support information: messages and attachments you choose to send us. Please do not send passwords or unnecessary sensitive information.

3. Why we use information

We use information to authenticate you; save, organize, search and synchronize your library; retrieve source content; generate transcripts and summaries; record visits; provide sharing features and notifications; manage subscriptions and restore purchases; answer support requests; diagnose problems; prevent abuse; and improve the service.

Where applicable data-protection law requires a legal basis, we rely on performance of our agreement for requested functionality, legitimate interests for proportionate security and service operation, legal obligations for required records, and consent where required for optional processing. You can withdraw consent for processing that relies on it without affecting earlier lawful processing.

4. AI, transcription and source platforms

Links and relevant source content are processed through Supadata for source metadata and transcription, and Google Cloud / Vertex AI for AI processing such as summaries, organization and embeddings. These providers receive the content needed to perform the requested processing. Source platforms may receive requests to retrieve content and may apply their own privacy policies.

Only submit content you are permitted to use. Avoid submitting confidential information or sensitive personal data you do not want processed by these services. AI output can be incomplete or incorrect; check the original source before relying on it.

Copying context into Claude, Codex, ChatGPT or another assistant is a user-directed action. Scrollshelf does not automatically send your library to those assistants. Information you choose to paste into another service is handled under that service’s terms and privacy policy.

5. Service providers and disclosures

We use Google Firebase and Google Cloud for authentication, database storage, hosting, notifications, processing and crash diagnostics; Supadata for source retrieval and transcription; PostHog for product analytics and session replay; Adapty for subscriptions and purchase analytics; and Vercel for website hosting and delivery. Apple and Google also handle store purchases and their sign-in services.

Providers process information needed for their service. We may also disclose information when legally required, to protect users and the service, or in connection with a business transfer subject to applicable privacy protections. We do not sell personal information for money.

6. Analytics, session replay and browser storage

PostHog records product interactions and may associate them with your account identifier to help us understand usage and diagnose problems. Mobile session replay can record the visible app interface and interactions. Text-entry fields are configured to be masked, but displayed content and images may be visible in recordings. Crash diagnostics may also be associated with your account identifier.

Our websites and providers use cookies or similar browser storage for sign-in, preferences and analytics. Browser controls can restrict or clear storage, although restricting necessary storage can affect sign-in. Contact us to request information about, object to, or request deletion of analytics information associated with your account. Privacy choices available in your app, browser or operating system also apply.

7. Public notes and sharing

Your saved library is not a public directory. If you choose to publish a note, its public summary and the source information shown in the publishing flow become available to anyone with the link. Public pages can be indexed by search engines, appear in our sitemap, and be copied or saved by other people.

Review the content before publishing and do not include another person’s private information without permission. Unpublishing or deleting a public note removes the page from our service, but cannot recall copies already made by recipients or immediately remove search-engine caches. Contact the relevant recipient or search engine where necessary.

8. Retention and deletion

We keep account and library information while it is needed to provide your account and saved-content service, unless you delete it or request deletion. Operational logs, analytics and provider records have separate retention schedules; their duration depends on the purpose, security needs, provider configuration and applicable legal obligations. We do not represent all provider records as being erased instantly when an account is deleted.

In the app, open Settings → Delete account and confirm. The account-deletion process removes your Firebase sign-in identity, owned notes, public-note snapshots, visit records, and the user profile and associated shelves, events and registered devices from our active account database. You can also request deletion without installing the app at scrollshelf.xyz/delete-account, or email contact@lumiostudio.co from the address associated with your account. We may verify ownership before acting.

Email deletion requests are handled within 30 days after identity verification, subject to applicable legal requirements. Requests can include provider-held analytics or subscription-profile information. Some records may be retained where required for legal, tax, fraud-prevention or dispute purposes; access is restricted and retention is limited to that purpose. Backups and third-party records may persist until their retention period expires.

Deleting your Scrollshelf account does not cancel an Apple or Google subscription. Cancel separately in your store subscription settings. The stores retain their own purchase records under their policies.

9. Security and international processing

We use authentication, access controls and encrypted connections to protect information. No internet service or storage system is completely secure. Protect your sign-in account and tell us promptly if you suspect unauthorized access.

Our providers operate internationally, so your information may be processed outside your country, including in the United States and other provider locations. Where required, transfers must be supported by applicable legal safeguards, such as approved contractual protections. Contact us for information about safeguards relevant to your data.

10. Your privacy rights

Depending on your location, you may have rights to access, correct, delete or receive a copy of your information; restrict or object to processing; withdraw consent; or complain to your local data-protection authority. Applicable rights may arise under laws such as the GDPR, UK GDPR, Türkiye’s KVKK or relevant US state privacy laws.

Send requests to contact@lumiostudio.co. We may request proportionate information to verify identity, but do not ask you to send a password. We respond within the period required by applicable law and explain any lawful exception. We do not discriminate against you for exercising applicable privacy rights.

11. Children and policy changes

Scrollshelf is not directed to children under 13. If you believe a child has provided personal information without appropriate authorization, contact us so we can investigate and take appropriate action. Additional parental-consent requirements may apply in your country.

We may update this policy as the service or legal requirements change. The effective date appears above. We will provide additional notice or request consent when required for a material change.

Contact Lumio Studio about this document