Privacy Policy
Last updated: June 2026
Scrab Tools is built privacy-first. This policy explains, in detail, what personal data we collect, why we collect it, how long we keep it, who we share it with, and the rights you have under the GDPR, UK GDPR, CCPA/CPRA and similar laws. It applies to www.scrabtools.site and the Scrab Tools API.
1. Who we are (data controller)
Scrab Tools ("we", "us", "our") operates the website at www.scrabtools.site and is the data controller for the personal data described in this policy.
For any privacy question or to exercise your rights, contact us through the Contact page or at the email address published there. If you are in the EEA/UK and are not satisfied with our response, you may also lodge a complaint with your local data protection authority.
2. Our privacy-first model
Most Scrab Tools tools run entirely in your browser. For these client-side tools (the majority of our image, text, CSV, and developer utilities), your files and text are processed locally on your device and are never uploaded to or seen by our servers.
A smaller set of tools require server-side processing — for example certain PDF operations and all AI tools. For these, the data you submit is transmitted to our backend over an encrypted (TLS/HTTPS) connection, processed, and then deleted according to the retention schedule in section 6.
Each tool page tells you whether it 'Runs in your browser' or uses 'Secure server processing', so you always know before you act.
3. Personal data we collect
Account data (only if you create an account): your email address, optional display name, and a password that is stored only as a salted, hashed value (scrypt) — never in plain text. If you sign in with Google, we receive your email, name, profile picture URL, and Google account identifier.
Authentication data: short-lived access tokens (held in memory in your browser) and a rotating refresh token stored in a secure, HttpOnly cookie. A one-time passcode (OTP) may be emailed to you to verify your address.
Uploaded content (transient): for server-side and AI tools, the files or text you submit, retained only until automatic deletion (see section 6).
Usage and security data: tool-usage records (which tool ran, success/failure, duration), request metadata (IP address, user agent, request IDs), and audit logs, used to operate, secure, and improve the service.
Consent records: your cookie choices stored together with a timestamp, IP address, derived country, and browser, as evidence of consent required by law.
Communications: any information you include when you contact us.
4. How we use your data and our legal bases
To provide the tools you request — legal basis: performance of a contract / your request.
To create and secure your account, verify your email via OTP, and keep you signed in — performance of a contract.
To protect the service against abuse, fraud, and attacks (rate limiting, reCAPTCHA, audit logs) — legitimate interests, and legal obligation where applicable.
To analyze aggregated, anonymized usage so we can improve the product — legitimate interests, or consent where analytics cookies are used.
To comply with legal obligations and respond to lawful requests — legal obligation.
We do not use your uploaded content to train AI models, and we do not sell your personal data.
5. AI tools and third-party processing
When you use an AI tool (e.g. Document Summary, OCR, Content Generator, Image/PDF analysis), the text, image, or document you submit is sent to our AI subprocessor (Anthropic) solely to generate your result, and returned to you.
We instruct our AI subprocessor not to use submitted content to train their models. We recommend you avoid submitting highly sensitive personal data to AI tools where it is not necessary.
6. Data retention and automatic deletion
Server-processed files are deleted automatically: within 1 hour for guests and within 24 hours for signed-in users. You can also delete saved files sooner from your dashboard.
Tool-usage and audit logs are retained for a limited period for security and analytics, then deleted or anonymized.
Account data is retained while your account is active and deleted (or anonymized) after you close your account, except where we must retain limited records to meet legal obligations.
7. Cookies and similar technologies
We use strictly necessary cookies for security and session management (for example a secure refresh-token cookie and an anonymous guest identifier), and — only with your consent — optional analytics or marketing cookies. See our Cookie Policy for the full breakdown and how to change your choices.
8. Subprocessors we rely on
We use carefully selected service providers who process data on our behalf under appropriate agreements: hosting and content delivery (e.g. Vercel for the web app, Render for the API), database (e.g. Neon/PostgreSQL), optional object storage (e.g. Cloudflare R2 / S3-compatible storage), transactional email (your configured SMTP/email provider) for OTP and notifications, AI processing (Anthropic), and bot/abuse protection (Google reCAPTCHA).
These providers may process data in countries outside your own; where required we rely on appropriate safeguards such as Standard Contractual Clauses.
9. International transfers
Your data may be processed in countries other than where you live. Where personal data is transferred outside the EEA/UK, we use lawful transfer mechanisms (such as adequacy decisions or Standard Contractual Clauses) to protect it.
10. Security
We apply industry-standard safeguards: TLS encryption in transit, hashed passwords (scrypt), HttpOnly/Secure cookies, strict security headers and Content-Security-Policy, CORS allow-listing, rate limiting, and audit logging. No method of transmission or storage is 100% secure, but we work continuously to protect your data.
11. Children's privacy
Scrab Tools is not directed to children under 16 (or the age required by your jurisdiction). We do not knowingly collect their personal data; if you believe a child has provided us data, contact us and we will delete it.
12. Your rights
Depending on where you live, you may have the right to access, correct, delete, restrict, or object to the processing of your personal data, to data portability, and to withdraw consent at any time. California residents have rights to know, delete, correct, and opt out of 'sale'/'sharing' (we do not sell or share personal data for cross-context behavioral advertising).
To exercise any right, contact us via the Contact page. We will verify your identity and respond within the timeframe required by law. You will not be discriminated against for exercising your rights.
13. Changes to this policy
We may update this policy as the service evolves. We will revise the 'Last updated' date above and, for material changes, provide a more prominent notice.
14. Contact
For any privacy question or request, please use the Contact page. We aim to respond promptly.