LEGAL

Privacy Policy

Effective date: 29 July 2026

Last updated 29 July 2026

This Privacy Policy explains how Ground Leads EOOD (Граунд Лийдс ЕООД), the Bulgarian company that operates ScribeGap ("ScribeGap", "we", "us", "our"), collects, uses, shares, and protects personal data when you use our websites at scribegap.com and app.scribegap.com and related services (the "Service"). We process personal data in accordance with Regulation (EU) 2016/679 (the "GDPR") and applicable Bulgarian data protection law.

By using the Service you acknowledge this Policy. It should be read together with our Terms of Service and Disclaimers.

1. Who we are (Data Controller)

The data controller is Ground Leads EOOD (Граунд Лийдс ЕООД), the company that operates ScribeGap, a single-member limited liability company (EOOD) registered at Nadezhda 2, bl. 238, ent. V, app. 63, 1220 Sofia, Bulgaria, company number (EIK) 207817277, VAT BG207817277. For any privacy question or to exercise your rights, contact us at privacy@scribegap.com.

Note on roles: for account and website data we act as the data controller. For the content you generate and any data you bring into the Service, you are the controller and we act as your processor, handling that data on your behalf and on your instructions to provide the Service.

2. Scope

This Policy covers personal data of website visitors, account holders, and people who contact us. It does not cover third-party websites we link to, which have their own policies.

3. Personal data we collect

3.1 Account and identity data. When you create an account (using an email address and password, or by signing in with Google): your name, email address, and, for third-party sign-in, the account identifier provided by that provider.

3.2 Content and inputs. The topics, prompts, drafts, keywords, and other content you enter or generate in the Service.

3.3 Usage and device data. Log data, actions in the Service, approximate location derived from IP, browser and device information, and support communications.

3.4 Payment data. When you subscribe, payments are handled by Stripe. We receive limited billing information (such as plan, status, and the last digits/brand of your card) but we do not collect or store your full card number; that is handled by Stripe under its terms.

3.5 Google-connected data. If you choose to connect Google, we access certain Google account data on a read-only basis, described in Section 4.

3.6 Cookies and similar technologies. See Section 14. Please do not enter sensitive personal data into the Service (such as health data, government identifiers, or full payment card numbers).

4. Google user data (Google API Services, Limited Use)

This section describes how we access and use data from Google APIs. It is important, and it governs any conflict with the rest of this Policy regarding Google user data.


4.1 What we access. If, and only if, you connect your Google account, we request read-only access using a single scope:

4.2 How we use it. We use this Google data solely to provide the user-facing features you request, for example to surface high-value topics you may be missing and to identify your pages that could be improved. We do not use it for any other purpose.

4.3 Limited Use. ScribeGap's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular:

  • We do not use Google user data for serving advertisements.

  • We do not sell Google user data.

  • We do not transfer Google user data to others except as necessary to provide or improve the user-facing features that access it, to comply with applicable law, or as part of a merger or acquisition with appropriate notice.

  • We do not allow humans to read Google user data unless: we have your consent for specific messages, it is necessary for security purposes (such as investigating abuse), to comply with applicable law, or the data is aggregated and anonymised for internal operations.

  • We do not use Google user data to develop, improve, or train generalised or non-personalised AI and/or machine-learning models.

4.4 Storage and revocation. To maintain your connection we securely store the tokens Google issues. You can disconnect at any time from within the Service or at https://myaccount.google.com/permissions, after which we stop accessing your Google data and delete the associated tokens.

5. AI processing of your content

To generate drafts and channel variations, the inputs you submit are processed by third-party AI providers acting on our behalf, solely to produce your output. We do not use your content, or Google user data, to train AI models, and we do not sell your content or use it for advertising.

6. Purposes and legal bases (GDPR Article 6)

  • To provide, operate, and secure the Service, and to manage your account and Subscription — legal basis: performance of a contract.

  • To process payments and prevent fraud — contract and legitimate interests.

  • To improve and maintain the Service and understand how it is used — legitimate interests, and consent where required (for example non-essential cookies).

  • To communicate with you about the Service, and to send marketing where you have opted in — legitimate interests and/or consent; you can opt out anytime.

  • To comply with legal obligations and to establish, exercise, or defend legal claims — legal obligation and legitimate interests.

7. How we share data (sub-processors and recipients)

We do not sell or rent your personal data. We share it only with:

  • Service providers acting on our behalf ("sub-processors"), under data-protection contracts, including: Supabase (database, authentication, and storage); Vercel (hosting of the app.scribegap.com application); Framer (hosting of the scribegap.com marketing site and its contact / sign-up forms); Anthropic (AI processing of your inputs to generate content); Stripe (payment processing); DataForSEO and ValueSERP (third-party search-volume and search-results data used to score keywords); Google (for the read-only Search Console integration you enable per Section 4, and for our email inbox); and Cloudflare (DNS, content delivery, and email routing).

  • Authorities or others where required by law, or to protect our rights, users, or the Service.

  • A successor entity in a merger, acquisition, or sale of assets, with notice as required.

8. International transfers

Your account and content data is primarily hosted and processed in the United Kingdom (our database and application hosting are in the London region). For transfers of personal data outside the European Economic Area, including to the United Kingdom and to sub-processors in the United States (such as our AI, payment, and search-data providers), we rely on an appropriate safeguard: a European Commission adequacy decision where one applies, or otherwise the Commission's Standard Contractual Clauses.

9. Data retention

We keep personal data only as long as needed for the purposes above:

  • Account and content data: for the life of your account and, unless the law requires otherwise, no longer than 12 months after you close it.

  • Billing and accounting records: retained as required by Bulgarian law. Under the Accountancy Act (Art. 12), accounting records and financial statements, including invoices and documents needed for tax control and audit, must be kept for 10 years, counted from 1 January of the year following the reporting period to which they relate.

  • Marketing data: until you opt out, and then only as needed to honour your choice.

  • Google tokens: until you disconnect or your account is closed.

10. Security

We use appropriate technical and organisational measures to protect personal data, including access controls, encryption in transit, and restricted internal access. No system is perfectly secure; if a breach affects your personal data, we will notify you and the competent authority where the law requires.

11. Your Right

Subject to applicable law, you have the right to: access your data; correct it; delete it ("right to be forgotten"); restrict or object to processing; data portability; and withdraw consent at any time (without affecting prior processing). You also have the right to lodge a complaint with your local supervisory authority. In Bulgaria this is the Commission for Personal Data Protection (Комисия за защита на личните данни, CPDP). To exercise your rights, email privacy@scribegap.com; we respond within one month and may ask you to verify your identity.

12. Children

The Service is not directed to, and may not be used by, anyone under 18. We do not knowingly collect data from children.

13. Changes to this Policy

We may update this Policy. For material changes we will provide notice (for example by email or in-app) at least thirty (30) days before they take effect and update the effective date above.

14. Cookies

We use only strictly necessary cookies required for the Service to function (for example to keep you signed in and to secure the site). For website analytics we use a privacy-friendly, cookieless measurement tool that does not set tracking cookies or profile individual visitors, so we do not rely on your consent for it. If we later introduce non-essential or tracking cookies (for example a switch to a cookie-based analytics provider), we will show a consent banner that lets you accept or reject them and publish a full cookie list at that time.

15. Contact

Privacy questions or requests: privacy@scribegap.com, or by post to Ground Leads EOOD (operator of ScribeGap), Attn: Data Protection, Nadezhda 2, bl. 238, ent. V, app. 63, 1220 Sofia, Bulgaria.

© 2026 ScribeGap. All rights reserved.

© 2026 ScribeGap. All rights reserved.