Privacy
As of October 2026. The German version of this page is legally binding.
In short
The website scriptloom.net sets no cookies, uses no analytics or tracking services and embeds no third-party content. Fonts and images are loaded from this server. The Scriptloom app sends no usage or telemetry data. For a Scriptloom account we store only what signing in and security need (see “Scriptloom account”).
Controller
RivenVox Studios, Welserstraße 3, 87463 Dietmannsried, Germany, email: contact@scriptloom.net
Providing the website
When you visit, your browser sends technically necessary data to the server, in particular your IP address, date and time and the requested file. They are processed to deliver the website and the app downloads and to keep the service secure. The legal basis is Art. 6 (1) (f) GDPR. No access logs are kept. In case of technical errors the server may store a message that includes the IP address; these error logs are limited in size and continuously overwritten.
The website runs on a rented server of a hosting provider, which processes this data on our behalf.
The Scriptloom app
Scriptloom works on your computer. Your projects are stored locally only; the app transmits neither content nor usage or crash data. Future team features that send data to a server will come with their own notice and are only active after you explicitly sign in.
Scriptloom account
You can create an account at api.scriptloom.net. The account server and its database run on the same rented server as the website. For it we process:
Account data: name, email address and whether it is confirmed, your password only as an irreversible hash, and when the account was created and changed. If you sign in with Google, the ID of your Google account is added.
Signed-in devices: for each sign-in we store a session key, the IP address, the browser and system identifier (user agent) and when the device was last active. Your account page shows these devices and lets you sign them out.
Two-factor sign-in: if you turn it on, we store the key for your authenticator app and your backup codes, both encrypted.
Purpose and legal basis: we process this data to provide your account (Art. 6 (1) (b) GDPR). The device list, IP addresses and the limit on sign-in attempts also protect your account against misuse (Art. 6 (1) (f) GDPR). For this limit the server keeps IP addresses in memory for at most ten minutes.
Retention: we keep account data until you delete your account. A session ends when you sign out or do not use the device for 30 days; the server deletes expired sessions within an hour. Links to confirm, reset and delete are valid for at most 24 hours, “Trust this device” for 30 days; after that they are deleted too. Before updates the server backs up its database; these backups stay on the server and are deleted after 30 days.
Cookies: api.scriptloom.net only sets cookies that are technically necessary for signing in: the session cookie (up to 30 days), one for the second sign-in step (10 minutes), if you wish one for trusted devices (30 days) and, during a sign-in with Google, one that secures this process. They need no consent (§ 25 (2) no. 2 TDDDG). There are no cookies for analytics or advertising.
Emails: we send confirmation, reset and deletion emails through Resend (Plus Five Five, Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA) as a processor. Resend receives your email address and the content of the email; sending runs through servers in the EU (Ireland). Resend is certified under the EU-US Data Privacy Framework (Art. 45 GDPR); the data processing agreement also contains standard contractual clauses.
Sign in with Google: if you choose “Sign in with Google”, your browser takes you to Google (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland). After you sign in there, Google sends us your name, your email address, whether it is confirmed and the ID of your Google account. We never learn your Google password, and we store neither Google's access tokens nor your profile picture. Google learns that you sign in to Scriptloom; for this, Google's privacy policy applies. The legal basis is Art. 6 (1) (b) GDPR.
Export and deletion: on your account page you can download your account data as a file (Art. 15 and 20 GDPR) and delete your account (Art. 17 GDPR). Deleting removes the account's data at once; open links expire within 24 hours at the latest, and the backups made before updates keep the data until they are deleted after 30 days.
Contact by email
If you write to us, we process your details to answer your request (Art. 6 (1) (b) or (f) GDPR) and delete them once they are no longer needed, unless legal retention periods apply.
Your rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object (Art. 21). You can also lodge a complaint with a data protection supervisory authority (Art. 77 GDPR).