Last updated: August 2026
How Scrinium collects, uses, and protects your information — in plain language.
Scrinium is designed around the principle that your notes are private. This policy explains what we collect, why, and how it is handled. The short version: we cannot read your notes, and we do not sell or share your personal information.
Account information: your email address, an SRP verifier (used for password-authenticated login; it is not your password and cannot be reversed into one), and your account tier. Vault data: encrypted blobs — your account/vault keys (encrypted with a key derived from your password) and your encrypted note bodies and titles. We never receive plaintext notes, titles, tags, or search queries.
Your email is used to identify your account, send a verification code, and communicate about the Service. Your encrypted vault and notes are stored solely to sync them back to your devices. We do not use your content for advertising, training models, or any purpose other than providing the Service.
We use Resend to send transactional email (verification codes and account notices). Resend receives only your email address and message content; it never receives your notes or password.
When payment processing is enabled, subscription payments are handled by Stripe. Stripe receives payment details and billing information; we do not store your full card number. Stripe processes that data under its own privacy policy.
Encrypted data is stored on Cloudflare (Workers, D1, and R2) and is transferred over TLS. We do not sell, rent, or share your personal information with third parties for their own marketing.
We use only aggregate, privacy-respecting analytics (for example, request counts and uptime) to operate the Service. We do not use advertising trackers and we do not fingerprint you across the web. We never instrument note content.
Your encrypted vault and notes are retained while your account is active. Deleted notes are soft-deleted and may be retained for a limited period to support sync. You may request account deletion by contacting us; because data is encrypted, deletion is performed on the encrypted blobs we hold.
We encrypt your data end-to-end (XChaCha20-Poly1305) and authenticate logins with SRP so your password never reaches our servers. No security system is perfect; we use industry-standard practices but cannot guarantee absolute security.
You may access, export, and delete your data at any time, subject to the limits of zero-knowledge encryption (we cannot export plaintext — you can, from your unlocked device). Depending on your jurisdiction you may have additional rights (for example, under GDPR or CCPA); contact us to exercise them.
We will update this page when our practices change. Questions: contact us at [email protected].