Scrapalot LogoScrapalot

Privacy Policy

Last updated: September 25, 2026

1. Who we are

Scrapalot AI ("Scrapalot", "we") provides an AI research assistant for your documents, available at scrapalot.app and as desktop and Android applications. This policy describes what data we process and why. The controller of that data — the person responsible for it under the GDPR — is Šimun Šunjić, Siget 18D, 10020 Zagreb, Croatia, OIB 85146524773. Contact: hello@mail.scrapalot.app.

2. Data we collect

Account data: email address, optional name and profile picture — entered at registration or provided by Google when you choose Google Sign-In (we receive your basic Google profile: email, name, picture; we never receive your Google password). Your content: documents, notes, and chat messages you upload or create — stored so the service can work for you. Technical data: standard server logs (IP address, timestamps, requests) kept for security and debugging, and usage counters (e.g. monthly token usage) used to enforce plan quotas.

3. How we use it

Only to provide the service you asked for: signing you in, storing and searching your library, producing the answers you request, and enforcing plan limits. Some of your content leaves our servers, and only to run a feature you used — your question and the passages that match it go to the AI model that writes the answer, a page image goes to a vision model when a scan has to be read, your recording goes to a speech provider when you talk to Scrapalot, and a search term goes to a search engine when you switch web search on. Section 5 names every recipient and says what it receives. We do not sell your data, we do not use your documents to train models, and the providers we use do not train on them either.

4. Storage and retention

Data is stored on our servers in the European Union (Hetzner, Germany). A weekly backup of the whole system — database and uploaded files — is kept off-site with Cloudflare (R2) so the service can be restored after a failure. Your content remains yours and stays available until you delete it in the app, or request account deletion (see How to delete your account); deleting your account removes your personal data and content from active systems, and the backup copy ages out as backups rotate. Server logs rotate automatically.

5. Who receives what

These are the companies that can see part of your data, and what each one gets. Everything below happens only when the feature it belongs to is used; nothing on this list receives your whole library.
  • The AI model that answers you — your question, the recent messages in that chat, and the passages retrieved from your documents. By default that is our own model provider, DeepSeek (operated in China), with OpenRouter (United States) as the standby. If you configure your own provider and key in settings, your content goes there instead — and if you run a local model, the answer is produced on your own machine.
  • Deciding where to search — the same question, plus the names and a few sample titles of your collections, may go to a decision-model provider (TypeSafe, United States) and to the model above, to choose which collections and which search method fit.
  • Reading scanned pages — page images from a document that has no machine-readable text go to NVIDIA (United States) for optical character recognition.
  • Voice — what you say goes to Groq (United States) to be transcribed; the text that is read back to you goes to Microsoft, which produces the speech.
  • Web search, when you turn it on — your search terms go to DuckDuckGo and the engines it queries on its behalf, and the pages found are fetched by us, or by a scraping service if one is configured for the instance.
  • Research and book lookups — titles, authors and search terms go to the catalogues you are searching: arXiv, Crossref, Semantic Scholar, OpenAlex, PubMed, doi.org, Open Library, the Internet Archive, Project Gutenberg and Anna's Archive.
  • Questions about medicines — the medicine names in your question go to openFDA, the U.S. Food and Drug Administration's public label and adverse-event service.
  • Sources you connect yourself — Google Drive, Dropbox, OneDrive and SharePoint, Notion, Confluence, Slack and Zotero receive the requests needed to read what you asked to import, and only after you connect them.
  • Tool servers you add — if you configure an MCP server, whatever a tool call to it contains goes to that server. You choose it, so you choose what it sees.
  • Account, billing and messages — Stripe (payments; we never see your full card number), Mailgun in the EU (the email we send you), Google (only if you use Google Sign-In), and Google Firebase (to deliver a push notification to your device).
  • Running the service — Hetzner (Germany) hosts it and Cloudflare (R2) holds the weekly backup described in section 4.
Several of these providers are outside the European Union, including in the United States and, for the default answering model, in China. Where the European Commission has issued an adequacy decision we rely on it, and otherwise on its standard contractual clauses. You can avoid a transfer you do not want by choosing a different provider — or a local model — in settings, and by leaving web search, voice and the connectors switched off. We never share your library with other users unless you use a sharing feature yourself.

6. Your rights

You can manage and delete individual documents and notes at any time from within the app. To access, correct, export, or delete your account and all associated data, email hello@mail.scrapalot.app (see How to delete your account). EU/EEA users have the rights provided by the GDPR, including the right to lodge a complaint with a supervisory authority.

7. Children

Scrapalot is not directed at children under 13 and we do not knowingly collect data from them.

8. Changes

We will post any changes to this policy on this page and update the date below. Material changes will be announced in the app.