Privacy

Skroll sends your words and your brand to AI models to build a deck. You should know exactly which ones, what they get, and what we keep. No hedging below. Where something isn’t built yet, it says so.

What we collect

What you give us: your email and name, the content you put into skrolls, brands you build, files you upload, and any support or feedback messages. What we collect automatically: usage data, and the IP address and browser of each sign-in session. If you sign in with Google, we receive your name, email and profile picture.

Which AI models see your work

Every AI request goes through OpenRouter, which routes it to the lab that runs the model. Those labs are sub-processors, reached through OpenRouter rather than contracted directly.

What it doesModelRun by
Building a deck, and reading a brand from its websiteClaude Sonnet 4.6Anthropic
The chat assistant you talk toGPT-5 miniOpenAI
Editing a deck you already haveGemini 3 FlashGoogle
Labelling images, pulling proof points, naming chatsGemini 2.5 FlashGoogle

What reaches them: your prompt, your chat history for that thread, the deck being built or edited in full, and your brand book: colours, fonts, tone of voice, and any proof points we read from your website. If the assistant searches the web, the query it composes goes to Tavily.

Images are handled differently, and it matters. We don’t upload the file to the model. We hand over its URL, and the provider fetches it from our storage itself. Files you upload live at long, randomly-suffixed links that are not access-controlled: anyone holding the link can open it, and the link does not expire. Treat anything you upload as shareable-by-link rather than private.

What the labs do with it

Nobody trains on your work. We do not train models on your content, and our OpenRouter account is configured to route only to providers that do not train on the inputs they receive. Your prompts and your decks are used for one thing: producing your output.

Not training is not the same as not storing, and we would rather be precise than reassuring. By default the providers do hold your prompt and the deck they generate for a limited period under their standard API terms, typically so they can investigate abuse. Zero data retention is not our default today.

If you need nothing held at all, we can arrange it per organisation. On request we will set your account up for zero data retention with the AI providers, so nothing survives the response, and we can route your requests to EU-hosted providers. To arrange either, email ben@hamburgerlabs.com.

Separately, and on our own infrastructure rather than theirs, we keep a record of AI requests and their responses for debugging and quality. That record contains your prompt and the generated deck, and it lives in our database alongside the rest of your account.

Who else processes your data

WhoWhat forWhat they get
VercelHosting, CDN, file storageRequests, IP addresses, uploaded files, exports
NeonDatabaseYour account, decks, brands, chat history
OpenRouterRoutes every AI requestPrompts, deck content, image URLs
Anthropic, OpenAI, GoogleRun the models, via OpenRouterPrompts, deck content, images
TavilyWeb search, when the assistant researchesSearch queries
Autumn and StripeSubscriptions and paymentName, email, plan. Card details go straight to Stripe
ResendTransactional emailEmail address and message contents
InngestBackground jobsRecord identifiers only, not content
SentryError monitoringError diagnostics, including IP address
Google AnalyticsSite analyticsPage views, cookies, approximate location
Cursor and GitHubTurning bug reports into fixesOnly what a bug report contains (see below)

Most of these are US companies, so using Skroll involves transferring your data outside the UK. We rely on the standard safeguards for those transfers. This list is current as of the date above; ask us at any time and we’ll confirm it.

What happens when you share a skroll

Publishing a skroll makes it genuinely public, not merely unlisted. The page is listed in our sitemap and can be indexed by search engines, so it may show up in search results. Your name and email are not shown on it, but everything in the deck is. Sharing by email will publish a private skroll automatically, so check the contents first. If you unpublish and republish later, the same link is reused.

What a bug report sends

The in-app feedback button attaches an image of the page you were looking at, plus the last 50 request paths and 20 console errors from your session. Request contents and headers are never captured, only the path, status and timing. You can remove the screenshot before sending.

What you send goes to our database, to us by email, and to Cursor, whose coding agent attempts a fix and may open a pull request on our public GitHub repository. Your name and email are not sent to Cursor or published to GitHub, but your message text and the screenshot are sent to Cursor. If your screen is showing something confidential, remove the screenshot or email us instead.

Cookies and analytics

We set a sign-in cookie that lasts seven days, and short-lived cookies to remember interface preferences and what you typed before signing up. Google Analytics and Vercel Analytics run on our public pages and set their own cookies. We do not currently show a cookie banner, so if you would rather not be measured, use your browser’s tracking protection or block those domains. We do not sell your data or run advertising.

How long we keep things

Your account and its content stay while your account is open. Skrolls, brands and uploaded files are deleted permanently the moment you delete them in the app. Billing and tax records are kept six years, as UK law requires.

Being straight with you about the rest: chat history, the AI request records described above, and bug reports are not yet deletable from within the product, and we do not currently run an automated purge. They persist until you ask us to remove them, which brings us to your rights.

Your rights

Under the UK GDPR and the Data Protection Act 2018 you can ask for a copy of your data, correct it, delete it, restrict or object to how we process it, take it elsewhere, and withdraw consent at any time.

There is no self-serve button for account deletion or data export yet. A person does it by hand, within one month, as the law requires. Deleting your account removes your profile, your skrolls, your brands, your uploads, your chat history and your AI request records, and we’ll confirm once it’s gone. To start, email ben@hamburgerlabs.com.

If you’re unhappy with how we’ve handled a request, you can complain to the UK Information Commissioner’s Office.

How we protect it

Your organisation’s data is separated from every other organisation’s at the database level, not just in application code. Passwords and API keys are stored as hashes. We cannot read them, and an API key is shown to you exactly once. Traffic is encrypted in transit.

Changes and contact

If we change what we collect or who processes it, we’ll update this page and its date. Questions, requests, or a copy of our current sub-processor list: ben@hamburgerlabs.com.