Legal

Privacy Policy

Scripts are personal. This page explains exactly what Scriptopus collects, why, where it lives, who can see it, and the control you keep over all of it, in plain language.

Last updated: 7 October 2026
Private by default

Your work is visible only to your account, unless you deliberately share it.

Not for sale

We do not sell your data or run ads. Analytics counts visits and screens, never your writing, and Do Not Track switches it off.

No AI training

Your content is processed to answer you, never to train AI models.

You hold the keys

Export everything at any time; deleting your account deletes your data.

This summary is a convenience. The sections below are the policy.

01

Who we are & scope

This policy covers Scriptopus ("we", "us"), meaning the marketing site at scriptopus.com, the app at app.scriptopus.com, and the Scriptopus desktop application. Scriptopus is the data controller for the personal data described here; you can reach us any time at hello@scriptopus.com. Using the Service is also governed by our Terms of Service.

02

What we collect

Account information

Your name, email address, and a hashed password. Passwords are stored only as salted cryptographic hashes, never in plain text. If you sign in with Google, we receive your name, email, and Google account identifier; we never see your Google password.

We also keep two IP addresses on your account: the one you signed up from and the one you most recently signed in from, each with the rough location our host, Cloudflare, attaches to it (city, region and country). Staying signed in counts as signing in, so the second address follows you while you use the app. Each new one replaces the one before it, and we keep no list of earlier addresses. We use them to keep accounts secure, for instance to notice an account being used from somewhere unexpected, and to see roughly where our writers are. Only the Scriptopus team sees them. This rests on our legitimate interest in running a secure service.

Every request from the app says which kind of Scriptopus sent it: the web app on a computer or on a phone, or the Windows or Mac app, along with the browser, the operating system and the app's version. We keep the latest of these on your account, and for each day you use Scriptopus, which kinds you used. It tells us which versions people rely on and where a reported problem happens, so we can fix it there. Only the Scriptopus team sees it, and it rests on the same legitimate interest.

Your content

The material you create or upload: scripts, synopses, treatments, beats, notes, characters, locations, uploaded reference files, generated images and audio, and the messages you exchange with the AI assistant.

Sharing data

When you share something, we store the recipient email addresses you enter, the permission you give each one, and the comments and suggested edits they leave.

Download and waitlist emails

Scriptopus Free is the desktop app on a free account, so getting it starts with creating one, as with the other plans. For a Free account we keep what we keep for any account: your name, email address and sign-in details. Your scripts stay on your computer and are never sent to us. The app asks us only which plan you are on and whether a new version is out, and neither request carries anything you wrote.

Until 23 September 2026 the Free download was mailed to an address given on this site, with an optional box asking for news. We keep those addresses to tell their owners when a new version is out, and send news only to people who ticked the box. If you joined the Windows waitlist before the app came out on 29 September 2026, we keep your address to send the one email saying it is out. Every one of these emails has an unsubscribe link, and writing to hello@scriptopus.com gets the address deleted outright.

For the record: version notices to the old download list rest on our legitimate interest in keeping that app current and safe, and news rests on your consent, which you can withdraw at any time.

Feedback and error reports

Messages you send through the in-app feedback form, and technical error reports (stack traces and the app state around a failure) that help us fix what broke. If you add words to an error report, they are stored alongside it.

In the web app, error reports also go to FaultFixer, the error-tracking service we use. A report holds the error and its stack trace, the page address, your browser and operating system, the version of the app, and a short trail of what happened just before: requests that failed, messages the app logged, and which controls were clicked or typed in (by their place on the page, never what you typed). It does not hold the text of your scripts. If you write to us from the form that opens after an error, your words go with that report. The web app sends these reports whatever storage you chose. The installed desktop app sends its error reports to our own servers only, and in Offline storage it sends none.

Service data

Operational records needed to run the Service: timestamps of activity, usage counters for rate-limited features, and standard server logs. We run no advertising trackers and build no profiles for sale or targeting.

Activity measures

If your scripts sync to our cloud, the app also keeps a daily tally for your account: how long it was open, how long it was on screen and in use, how long you spent writing, and how many edits, clicks, key presses, scrolls and screens that came to. Your AI requests are counted from the record each one already leaves. These are numbers and nothing else. They never include what you typed, which script or page you had open, or what was on the screen.

We use them to see how the product is used and whether a change helped. They are kept with your account, because that is the question they answer: who finds their way around and who gets stuck. The tally is separate from the analytics below and does not depend on Do Not Track. Writers on Local only or Offline storage, or on the Free plan, are left out of it entirely.

Analytics

We use Google Analytics to count visits: how many people come, roughly where from, on what kind of device, and which pages and screens they open, so we can find the place people give up. Its advertising features and Google signals are switched off, and it is not linked to your account. It never reads what you type, and your screen is never recorded. In the app it is told the name of the screen rather than the address in your browser bar, so it never receives a project id or a share or invitation link.

It loads from Google's servers and reports to them directly. It is optional: we honour Do Not Track, and choosing Local only or Offline storage in the app switches it off entirely. Details are on the Cookie Policy page.

03

How we use it

  • To provide the Service: storing and syncing your work, generating exports, keeping backups and version history.
  • To run the AI features you explicitly invoke (see Section 4).
  • To deliver the sharing features: sending invite emails, showing shared surfaces to your recipients, returning their feedback to you.
  • To send transactional email: account confirmation, password resets, share invitations and report deliveries. No marketing lists, no newsletters you didn't ask for.
  • To tell people who downloaded Scriptopus Free that a new version is out, and to send news to those who asked for it (see Download and waitlist emails).
  • To find and fix errors, keep the Service secure, and enforce usage limits and our Terms.
  • To understand how the Service is used, meaning which screens are opened and which controls are clicked but never your writing, so we can improve what confuses people.
  • To see how much each synced account uses the app, from the activity measures: time and counts, never content.
  • To respond when you contact us.

What we never do

We do not sell or rent your data, show you ads, use your content for advertising, or read your scripts out of curiosity. Access to stored content is limited to what operating the Service requires.

04

AI processing

When you use an AI feature, the relevant parts of your project are sent to our AI service providers solely to generate the response you asked for: a chat reply, a report, an image, a read-aloud performance, and for no other purpose.

Not used for training

Your content is not used to train AI models. Not by us, and our provider agreements do not permit them to use it that way either. An AI request is processing, not donation.

AI features run only when you invoke them; nothing in your project is analyzed in the background without an action from you.

05

Where data lives & security

Your work lives in two places: locally on your device (the app is local-first, so you can keep writing offline) and mirrored to our cloud, which runs on Cloudflare infrastructure: databases for structured data, object storage for files, images, audio, and backups.

  • All traffic between your device and our servers is encrypted in transit (HTTPS).
  • Passwords are salted and hashed with an industry-standard algorithm.
  • Sessions use short-lived access tokens with rotating refresh tokens.
  • Every read and write of your projects is checked against your account server-side.

No system is perfectly secure, and we cannot guarantee absolute security, which is one more reason the app gives you one-click exports and full local backups. If we learn of a breach affecting your personal data, we will notify you as required by law.

06

Cookies & local storage

The short version: essential storage, plus analytics — nothing for advertising. The app keeps your session and preferences in your browser's local storage, and one small cookie (sb_auth) tells our websites whether you're signed in so they can show you the right buttons. Google Analytics sets two more: a random id and the time of your last visit, so a returning visitor is not counted as a new one. Neither is linked to your account. The full inventory, and how to clear it, is on the Cookie Policy page.

Analytics is the one thing here that is not strictly necessary, so it comes with an off switch rather than a banner: we honour your browser's Do Not Track setting, and Local only or Offline storage in the app disables it completely.

07

When data is shared

Your data leaves our systems only in these cases:

  • People you choose. Recipients of your share links see what you shared, under the permission you set.
  • Service providers. Infrastructure hosting, AI processing, transactional email delivery, analytics (Google Analytics) and error tracking (FaultFixer, for the web app), each processing data only to provide their service to us, under contract.
  • Legal requirements. If we are compelled by law, or where disclosure is necessary to protect the rights, safety, or property of Scriptopus, our users, or the public.
  • Business transfer. If Scriptopus is acquired or reorganized, data may transfer to the successor, who remains bound by this policy.

08

How long we keep it

  • Your account and content: for as long as your account exists.
  • AI chat history: retained per-script for 90 days on our servers, then removed.
  • Automatic backups: kept on a rolling basis and cycled out as new ones are made.
  • Error reports and feedback: kept as long as needed to fix the issue and improve the Service.
  • Activity measures: for as long as your account exists. Deleting the account deletes them.
  • Sign-in addresses: the sign-up address for as long as your account exists, the latest one until a newer one replaces it. Deleting the account deletes both.
  • Which app you use: the latest until a newer one replaces it, and the kinds used each day for as long as your account exists. Deleting the account deletes them.
  • Download and waitlist addresses: until you unsubscribe or ask us to delete them. An unsubscribed address is kept only so we know not to write to it again.
  • After account deletion: your data is removed from live systems promptly, and clears from rolling backups as they cycle. Copies already delivered to people you shared with are theirs to have seen.

09

Your rights & choices

You do not need to email us for the essentials. They are built into the app:

  • Access & portability: export your screenplay (PDF, FDX, Fountain, Celtx) or an entire project, with everything in it, as a self-contained archive, at any time.
  • Rectification: edit your profile and content directly.
  • Deletion: delete individual projects, or your whole account from account settings.

Depending on where you live, including under Türkiye's KVKK and the EU/UK GDPR, you may also have rights to request access, correction, deletion, restriction, or objection, and to lodge a complaint with your data-protection authority. For any request, write to hello@scriptopus.com and we will respond as the applicable law requires.

10

Children

The Service is not directed to children and requires users to be at least 16. We do not knowingly collect personal data from anyone younger; if you believe a child has created an account, contact us and we will delete it.

11

International transfers

Our infrastructure and service providers operate globally, so your data may be processed in countries other than your own. Where that happens, we rely on our providers' recognized safeguards (such as standard contractual clauses) so that your data receives equivalent protection wherever it is processed.

12

Changes & contact

We may update this policy as the product or the law evolves; the "Last updated" date above will change, and material changes will be communicated in the app or by email. Questions, requests, concerns: hello@scriptopus.com — we are a small team and we read everything.