LEGAL
Privacy Policy
Effective date: 8 September 2026
Last updated 8 September 2026
This Privacy Policy explains how Ground Leads EOOD (Граунд Лийдс ЕООД), the Bulgarian company that operates ScribeGap ("ScribeGap", "we", "us", "our"), collects, uses, shares, and protects personal data when you use our websites at scribegap.com and app.scribegap.com and related services (the "Service"). We process personal data in accordance with Regulation (EU) 2016/679 (the "GDPR") and applicable Bulgarian data protection law.
By using the Service you acknowledge this Policy. It should be read together with our Terms of Service and Disclaimers.
1. Who we are (Data Controller)
The data controller is Ground Leads EOOD (Граунд Лийдс ЕООД), the company that operates ScribeGap, a single-member limited liability company (EOOD) registered at Nadezhda 2, bl. 238, ent. V, app. 63, 1220 Sofia, Bulgaria, company number (EIK) 207817277, VAT BG207817277. For any privacy question or to exercise your rights, contact us at privacy@scribegap.com.
Note on roles: for account and website data we act as the data controller. For the content you generate and any data you bring into the Service, you are the controller and we act as your processor, handling that data on your behalf and on your instructions to provide the Service.
2. Scope
This Policy covers personal data of website visitors, account holders, and people who contact us. It does not cover third-party websites we link to, which have their own policies.
3. Personal data we collect
3.1 Account and identity data. When you create an account (using an email address and password, or by signing in with Google): your name, email address, and, for third-party sign-in, the account identifier provided by that provider.
3.2 Content and inputs. The topics, prompts, drafts, keywords, and other content you enter or generate in the Service.
3.3 Usage and device data. Log data, actions in the Service, approximate location derived from IP, browser and device information, and support communications. If you consent to advertising cookies on our marketing website, this also includes the visit information described in Section 14, which is shared with Meta.
3.4 Payment data. When you subscribe, payments are handled by Stripe. We receive limited billing information (such as plan, status, and the last digits/brand of your card) but we do not collect or store your full card number; that is handled by Stripe under its terms.
3.5 Google-connected data. If you choose to connect Google, we access certain Google account data on a read-only basis, described in Section 4.
3.6 Data we read from your own website. To work out what your site is about, the Service reads your website in two ways. Where your Search Console history is too thin for us to tell what you write about, we fetch your home page and use its text. When you ask the Service to suggest links between your own articles, we read your robots.txt and your sitemap to list the pages you have published, and we send a small number of requests to the few pages we finally recommend, to check they are still reachable. In both cases what we read is material you have already published publicly. Section 5 explains where it goes.
3.7 Images you upload. If you use Resize My Image, the photograph you choose is opened, cropped and re-saved entirely inside your own browser. It is never uploaded to us, never sent to any third party, and never stored anywhere. We receive nothing but the record that you used the feature.
3.8 Cookies and similar technologies. See Section 14. Please do not enter sensitive personal data into the Service (such as health data, government identifiers, or full payment card numbers).
4. Google user data (Google API Services, Limited Use)
This section describes how we access and use data from Google APIs. It is important, and it governs any conflict with the rest of this Policy regarding Google user data.
4.1 What we access. If, and only if, you connect your Google account, we request read-only access using a single scope:
Google Search Console, read-only (https://www.googleapis.com/auth/webmasters.readonly) We do not request write access, and we do not access Google Analytics or any other Google data. We cannot post, change, or delete anything in your Google account.
4.2 How we use it. We use this Google data solely to provide the user-facing features you request: to surface high-value topics you may be missing, to identify your existing pages that could be improved, and to show you how your published articles are performing in search over time. To group the search queries your site already appears for into readable topics, those queries are sent to our AI provider (Anthropic), acting on our behalf and solely to produce that grouping for you. They are not used to train any model. We do not use Google data for any other purpose.
4.3 Limited Use. ScribeGap's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular:
We do not use Google user data for serving advertisements.
We do not sell Google user data.
We do not transfer Google user data to others except as necessary to provide or improve the user-facing features that access it, to comply with applicable law, or as part of a merger or acquisition with appropriate notice.
We do not allow humans to read Google user data unless: we have your consent for specific messages, it is necessary for security purposes (such as investigating abuse), to comply with applicable law, or the data is aggregated and anonymised for internal operations.
We do not use Google user data to develop, improve, or train generalised or non-personalised AI and/or machine-learning models.
4.4 Storage and revocation. To maintain your connection we securely store the tokens Google issues. You can disconnect at any time from within the Service or at https://myaccount.google.com/permissions, after which we stop accessing your Google data and delete the associated tokens.
5. AI processing of your content
To produce your drafts and the outputs derived from them, the content you submit or generate — and, where Sections 3.6 and 4.2 apply, the text of your home page, the list of page addresses in your sitemap, and the search queries your site appears for — is processed by third-party AI providers acting on our behalf, solely to produce your output. These providers process it under their API terms and do not use it to train their general-purpose models.
Not everything the Service makes involves AI, and the difference is worth stating plainly. AI cover images are produced by a third-party AI image model from a short text description of your topic and brand, never from your logo and never from personal data. Quick Covers, social carousels and Pinterest pins are drawn in your own browser from your logo, your colours and your fonts, with no AI image model involved at all. Resize My Image never leaves your browser, as described in Section 3.7.
We do not use your content, or Google user data, to train AI models, and we do not sell your content or use it for advertising.
6. Purposes and legal bases (GDPR Article 6)
To provide, operate, and secure the Service, and to manage your account and Subscription — legal basis: performance of a contract.
To process payments and prevent fraud — contract and legitimate interests.
To improve and maintain the Service and understand how it is used — legitimate interests, and consent where required (for example non-essential cookies).
To measure whether our advertising works, and to show our advertisements to people who have visited our marketing website — legal basis: your consent, which you can withdraw at any time.
To communicate with you about the Service, and to send marketing where you have opted in — legitimate interests and/or consent; you can opt out anytime.
To comply with legal obligations and to establish, exercise, or defend legal claims — legal obligation and legitimate interests.
7. How we share data (sub-processors and recipients)
We do not sell or rent your personal data. We share it only with:
Service providers acting on our behalf ("sub-processors"), under data-protection contracts, including: Supabase (database, authentication, and storage); Vercel (hosting of the app.scribegap.com application); Framer (hosting of the scribegap.com marketing site and its contact / sign-up forms); Anthropic (AI processing of your content to generate written text, to group your Search Console queries into topics, to judge which of your published pages relate to a draft, and to write the text description used to create cover images); OpenAI (AI generation of cover images from a text description of your topic and brand); Stripe (payment processing); DataForSEO and ValueSERP (third-party search-volume and search-results data used to score keywords); Google (for the read-only Search Console integration you enable per Section 4, and for our email inbox); and Cloudflare (DNS, content delivery, and email routing).
Meta Platforms Ireland Limited, but only if you consent to advertising cookies on scribegap.com. Meta is not acting solely on our instructions: it receives the information described in Section 14 and uses it as a controller in its own right under its own data policy. We and Meta are jointly responsible for collecting that information on our website and sending it to Meta. You can withdraw consent at any time, after which nothing further is sent.
Authorities or others where required by law, or to protect our rights, users, or the Service.
A successor entity in a merger, acquisition, or sale of assets, with notice as required.
8. International transfers
Your account and content data is primarily hosted and processed in the United Kingdom (our database and application hosting are in the London region). For transfers of personal data outside the European Economic Area, including to the United Kingdom and to sub-processors and recipients in the United States (such as our AI, payment, search-data and advertising providers), we rely on an appropriate safeguard: a European Commission adequacy decision where one applies, or otherwise the Commission's Standard Contractual Clauses.
9. Data retention
We keep personal data only as long as needed for the purposes above:
Account and content data: for the life of your account and, unless the law requires otherwise, no longer than 12 months after you close it.
Billing and accounting records: retained as required by Bulgarian law. Under the Accountancy Act (Art. 12), accounting records and financial statements, including invoices and documents needed for tax control and audit, must be kept for 10 years, counted from 1 January of the year following the reporting period to which they relate.
Marketing data: until you opt out, and then only as needed to honour your choice.
Google tokens: until you disconnect or your account is closed.
Search metrics we cache: search volume and competition describe Google rather than any particular customer, so we cache them once and reuse them for up to 30 days. That cache is keyed only by the keyword and the market. It holds no customer identifier, and none of your own site data, keyword lists or drafts.
Your own keyword results: cached against your website for up to 7 days, so that reopening the app does not repeat a search you have already paid for.
Generated and uploaded images: not stored at all. Covers, carousels, pins and resized images exist only in your browser until you download them or close the tab.
10. Security
We use appropriate technical and organisational measures to protect personal data, including access controls, encryption in transit, and restricted internal access. No system is perfectly secure; if a breach affects your personal data, we will notify you and the competent authority where the law requires.
11. Your Right
Subject to applicable law, you have the right to: access your data; correct it; delete it ("right to be forgotten"); restrict or object to processing; data portability; and withdraw consent at any time (without affecting prior processing). You also have the right to lodge a complaint with your local supervisory authority. In Bulgaria this is the Commission for Personal Data Protection (Комисия за защита на личните данни, CPDP). To exercise your rights, email privacy@scribegap.com; we respond within one month and may ask you to verify your identity.
12. Children
The Service is not directed to, and may not be used by, anyone under 18. We do not knowingly collect data from children.
13. Changes to this Policy
We may update this Policy. For material changes we will provide notice (for example by email or in-app) at least thirty (30) days before they take effect and update the effective date above.
14. Cookies, Browser storage, and Advertising Technologies
Strictly necessary. We use a small number of cookies and browser storage entries required for the Service to function, for example to keep you signed in, to secure the site, and to remember your cookie choice. These do not require your consent.
Website analytics. For website analytics we use a privacy-friendly, cookieless measurement tool that sets no tracking cookies and does not profile individual visitors, so we do not rely on your consent for it.
Advertising measurement, with your consent only. On our marketing website at scribegap.com we use the Meta pixel, a measurement tool provided by Meta Platforms Ireland Limited, to understand which of our advertisements lead people to sign up, and to show our advertisements to people who have already visited the site. It stores cookies in your browser and sends Meta information about your visit, including the pages you viewed, whether you clicked through to sign up, your IP address, your browser and device, and any Meta identifiers already stored in your browser. Meta may combine that with information it already holds about you.
We do not load the Meta pixel until you accept advertising cookies. If you reject them, or close the banner without choosing, it is not loaded and Meta receives nothing about your visit.
When you start a trial. If you accepted advertising cookies and then start a free trial, our server tells Meta that a trial began. We send the advertising identifiers already stored in your browser by the pixel, and a scrambled (hashed) version of your email address, so that we can tell whether our advertising is working. We do not send your name, your website, anything from your Google Search Console connection, or any content you have created. If you did not accept advertising cookies, we send nothing at all.
Where it is not used. The Meta pixel does not run anywhere on app.scribegap.com. No data from your Google Search Console connection, and none of the content you create in the Service, is ever sent to Meta or used for advertising.
What we store on your device:
Sign-in session, set by ScribeGap. Keeps you signed in to app.scribegap.com. Strictly necessary. Lasts until you sign out or the session expires.
Cookie choice, set by ScribeGap. Records whether you accepted or rejected advertising cookies, and which version of this notice you answered. Strictly necessary. Stored until you clear it.
_fbp, set by Meta on scribegap.com. Identifies your browser so Meta can measure our advertising. Advertising, consent required. Expires after about 90 days.
_fbc, set by Meta on scribegap.com. Records which advertisement you clicked before arriving. Advertising, consent required. Expires after about 90 days.
Changing your mind. The banner on your first visit lets you accept or reject advertising cookies, with both choices equally available. You can change your answer at any time using the Cookie settings link in the footer of scribegap.com. Rejecting costs you nothing: no part of the Service depends on advertising cookies. Clearing your browser storage for scribegap.com also clears your recorded choice, and the banner will ask again.
15. Contact
Privacy questions or requests: privacy@scribegap.com, or by post to Ground Leads EOOD (operator of ScribeGap), Attn: Data Protection, Nadezhda 2, bl. 238, ent. V, app. 63, 1220 Sofia, Bulgaria.
