privacy
scrollport lets an AI agent discover a capability, pay for it from one prepaid balance, and run it. This page describes what that involves handling, and — just as importantly — what it does not.
What we store
- Your account. Email and a provider identifier from Google sign-in. We do not store a password, because we never issue one.
- Your wallet. An append-only ledger of top-ups, holds, charges and refunds. Entries are never edited or deleted — a correction is a new compensating entry. That is a design constraint for correctness, and it means your billing history is complete by construction.
- Your runs. For each call: which capability, the input you sent, the result, the estimated and final cost, and timing. This is the audit trail that answers “what did my agent do, and what did it spend” — the question the dashboard exists to answer.
- Artifacts. Files a run produces (audio, images, datasets), in object storage, reachable only through expiring signed links.
- API keys. Hashed, never stored in readable form. We cannot recover a key for you; we can only issue a new one.
- Support requests. If you use our support form, we send your name, reply email, subject and message to our support inbox through Resend. After Resend accepts the message, our database removes that content and keeps only a one-way sender key used to limit abuse.
What we never store
- Provider credentials. When you connect HubSpot, Notion or any other account, the OAuth tokens are held by our authentication provider, Nango. Our own code receives a connection reference — an integration id and a connection id — and never the token itself. There is no field in our database that could hold one.
- Card details. Payments run through Stripe's hosted checkout. Card numbers never reach our servers.
- Passwords. Authentication is Google sign-in and hashed API keys.
Run inputs and results
To run a capability we must send your input to the provider that performs it — a search query goes to the search provider, text to be spoken goes to the voice provider. That is the service, not a secondary use of your data. Each provider handles what it receives under its own policy.
We keep inputs and results so the usage log can show them back to you and so a failed run can be explained. We do not use them to train models, and we do not sell them.
Google Workspace data
If you connect Gmail, Scrollport may process message and thread content, attachments, headers, labels, identifiers and mailbox metadata needed for the Gmail tool you explicitly run. Gmail tools may read and manage messages and labels, create or replace drafts, send a draft to its addressed recipients, and move messages or threads to and from Gmail trash. Scrollport does not expose permanent Gmail deletion or mailbox administration.
If you connect Google Drive, Scrollport may process file and shared-drive metadata, file contents, links and collaboration data needed for the tool you explicitly run. This includes Drive files and folders, Google Docs, Sheets, Slides and Forms, and Drive comments and replies. Tools may create, edit, upload, download, export, copy, rename, move, trash and restore files, and may read Forms responses. Scrollport does not expose permanent Drive deletion, permission changes, ownership transfers or end-user Forms response submission.
If you connect Google Calendar and Tasks, Scrollport may process calendar-list and event data, free/busy availability, task-list and task data needed for the tool you explicitly run. Tools may create and edit events, add a Google Meet conference, and create, edit or delete tasks and task lists. Google Tasks deletion is permanent and cannot be undone. Scrollport does not expose calendar, calendar-list or sharing-policy deletion or mutation.
We use Google Workspace data only to execute the tool you or your authorised agent requested, return its result and retain the user-visible run history described above. We do not use Google Workspace data for advertising or credit decisions, sell it, train or improve general-purpose AI or machine-learning models with it, or use it to build an independent profile of you. We do not create, retain, sell or transfer aggregated or anonymised datasets derived from Google Workspace data. Access stays within the connected workspace and the tool authority you grant to each agent. An email send is externally visible and cannot be undone; document and spreadsheet updates can replace or remove content.
Raw Google Workspace run inputs, results and provider error content are retained for no more than 30 days. Private Google artifacts are retained for no more than 7 days. We then irreversibly redact the raw run content and delete expired artifact bytes while retaining only non-content execution, authority, security and financial audit metadata where needed. We do not turn Google content used as catalog test evidence into a permanent copy.
Google OAuth tokens are encrypted, stored and refreshed by Nango rather than our application. Requested Google data passes through Nango (OAuth token management), Railway (application hosting), Google Cloud Model Armor (security screening) and Supabase (EU database and private artifact storage) only as needed to protect and deliver the requested tool and retain its run. External network traffic uses HTTPS, and Google Workspace data and credentials retained by our infrastructure providers are encrypted at rest.
Connected-app inputs and textual results, including supported document and image artifacts, cross a fail-closed Google Cloud Model Armor prompt-injection check before they can be returned to an agent. Suspicious content is blocked. Unsupported opaque binary artifacts stay private behind expiring links and are explicitly labelled as untrusted; instructions extracted from them do not carry user authority.
Scrollport personnel do not routinely read Google Workspace data. Human access is restricted to a specific user's affirmative consent, a necessary security or abuse investigation, or legal compliance. Disconnecting an app revokes its grant and the retention limits above continue to age out prior run content. Final workspace closure immediately redacts eligible Google run content and expires its artifacts for physical deletion; a request to delete your account follows that controlled closure process.
Scrollport's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Who else sees data
Only the parties needed to deliver a call you asked for: the capability provider for that run, plus our infrastructure — hosting, the database, payments, and the provider authentication layer described above. We do not sell personal data or share it for advertising.
Product analytics
By default, we use PostHog's EU service for bounded browser statistics such as page class and app-connection intent. A random first-party browser identifier is stored for up to 30 days so repeat visits can be counted consistently. It is not connected to an identified profile and does not enable session recording. You can turn browser analytics off and remove its stored identifier below. Committed server milestones such as agent connection, first tool use and top-up are also reported for operational analytics.
If you allow detailed analytics, browser events can join an identified profile after sign-in. Identified profiles use the public USR, WSP and AGT support references; a known account email labels the human profile, and an agent profile may name its human owner. We do not include run inputs or results, raw URLs, search queries or prompts in our analytics events. With the same permission, session recordings show page content and field values, including names, emails, searches and any prompts or results displayed on screen. Passwords, API keys, access-granting links and payment details are protected from recording. Browser console logs, network headers and bodies, and cross-origin frames are not recorded. You can return to anonymous analytics or turn browser analytics off at any time.
Keeping and deleting
Non-Google run records and ledger entries are kept while your account is open. Google Workspace content follows the shorter 30-day run-content and 7-day artifact limits above. Artifact links stop working at expiry and private bytes are then deleted by a scheduled sweep. Uploaded files and generated non-Google files stay in your workspace until you delete them or close the workspace. Each workspace has 1 GB of file storage; expiring download links do not delete the underlying files. Closure makes files unavailable immediately and schedules deletion of the stored bytes.
You can ask us to delete your account and its data. Controlled closure immediately redacts eligible Google Workspace run content and expires its artifacts, while records we are required to keep for tax, accounting, authority, security and abuse prevention remain without the raw Google content. Disconnecting a provider revokes the connection at Nango, so any token we never held stops working.
Support messages remain in our support inbox only while needed to reply, resolve the request, prevent abuse or meet legal obligations. The API outbox copy is redacted as soon as the email provider accepts it.
Where data is held
Our database and storage run in the European Union. Capability providers operate in their own regions, so running a capability may send your input outside the EU — which is inherent to calling that provider at all.
Your rights
Depending on where you live you may have the right to access, correct, export or delete your personal data, and to object to certain processing. Ask and we will act on it. If you are in the EU or UK you may also complain to your data protection authority.
Contact
Questions, requests, or anything on this page that looks wrong: privacy@scrollport.com.
Changes
If this policy changes in a way that materially affects you, we will say so directly rather than relying on you to re-read this page.