legal
privacy
effective 28 July 2026
scrollport lets an AI agent discover a capability, pay for it from one prepaid balance, and run it. This page describes what that involves handling, and — just as importantly — what it does not.
What we store
- Your account. Email and a provider identifier from Google sign-in. We do not store a password, because we never issue one.
- Your wallet. An append-only ledger of top-ups, holds, charges and refunds. Entries are never edited or deleted — a correction is a new compensating entry. That is a design constraint for correctness, and it means your billing history is complete by construction.
- Your runs. For each call: which capability, the input you sent, the result, the estimated and final cost, and timing. This is the audit trail that answers “what did my agent do, and what did it spend” — the question the dashboard exists to answer.
- Artifacts. Files a run produces (audio, images, datasets), in object storage, reachable only through expiring signed links.
- API keys. Hashed, never stored in readable form. We cannot recover a key for you; we can only issue a new one.
What we never store
- Provider credentials. When you connect HubSpot, Notion or any other account, the OAuth tokens are held by our authentication provider, Nango. Our own code receives a connection reference — an integration id and a connection id — and never the token itself. There is no field in our database that could hold one.
- Card details. Payments run through Stripe's hosted checkout. Card numbers never reach our servers.
- Passwords. Authentication is Google sign-in and hashed API keys.
Run inputs and results
To run a capability we must send your input to the provider that performs it — a search query goes to the search provider, text to be spoken goes to the voice provider. That is the service, not a secondary use of your data. Each provider handles what it receives under its own policy.
We keep inputs and results so the usage log can show them back to you and so a failed run can be explained. We do not use them to train models, and we do not sell them.
Who else sees data
Only the parties needed to deliver a call you asked for: the capability provider for that run, plus our infrastructure — hosting, the database, payments, and the provider authentication layer described above. We do not sell personal data or share it for advertising.
Keeping and deleting
Run records and ledger entries are kept while your account is open. Artifacts expire on their own schedule and are swept afterwards.
You can ask us to delete your account and its data, and we will — with one honest exception: records we are required to keep for tax and accounting, which are financial transaction records, not run contents. Disconnecting a provider revokes the connection at Nango, so any token we never held stops working.
Where data is held
Our database and storage run in the European Union. Capability providers operate in their own regions, so running a capability may send your input outside the EU — which is inherent to calling that provider at all.
Your rights
Depending on where you live you may have the right to access, correct, export or delete your personal data, and to object to certain processing. Ask and we will act on it. If you are in the EU or UK you may also complain to your data protection authority.
Contact
Questions, requests, or anything on this page that looks wrong: privacy@scrollport.com.
Changes
If this policy changes substantively we will update the effective date above and, for anything that materially affects you, say so directly rather than relying on you to re-read this page.