Legal
Privacy Policy
How we use personal data alongside our zero-upload file architecture and minimized workflow records.
Service operator
- Legal name
- Anurodh Acharya
- Trading name
- Scrub Metadata
- Address
- 88 Kirti Marg, Teentolia, Morang, Nepal
- Country of establishment
- NP
This operator supplies ScrubMetadata and acts as controller for its own account, website, security, billing support and contact processing. Customer processing follows documented customer instructions when this operator acts as processor. Legal responsibilities follow the actual processing activity, not merely the contract label.
Paddle is the merchant of record for the purchase and handles payment and applicable transaction taxes.
Our Privacy Commitment
Scrub Metadata is built on the principle that raw file processing stays local. We cannot access, view, or store your files during supported local processing because the file bytes stay within your browser.
This DPA applies only to processing where ScrubMetadata acts on documented customer instructions as a processor. ScrubMetadata may act as a controller for separate account administration, security, billing-support, website, and direct-contact processing described in the Privacy Policy. The role follows the actual purpose and activity, not just the name of a data field.
Zero-Upload File Architecture
Your files are processed in your browser using client-side algorithms. This prevents ScrubMetadata from receiving raw file contents during supported local processing.
Zero-Upload File Architecture
How It Works
Raw file data that stays outside ScrubMetadata infrastructure
Professional supports browser and local folder processing. Approved customer-controlled cloud integrations are not part of the current Professional offer. ScrubMetadata can receive minimized workflow evidence such as counts, categories, status, timestamps, and evidence hashes, but not raw file data through these supported processing paths. Support correspondence is separate: do not send raw customer files or raw metadata to support.
Platform data we process
Zero-upload describes the raw-file processing boundary, not an absence of platform personal data. ScrubMetadata processes minimized account, authentication, security, device-trust, consent, billing, operational, error-monitoring, audit, compliance-evidence, and support data for the purposes described in the canonical public data-category register. It does not use visitor analytics, advertising pixels, retargeting cookies, or cross-site behavioral profiling.
Account and organization data
- Data
- Name, email address, company, professional role and profile link submitted with an application, application status, technical submission information including IP address, user-agent and referrer, account state, subscription entitlement, and saved service preferences.
- Purpose
- Assess application eligibility, prevent abuse, create and administer the account, provide the contracted service, and maintain organization isolation. Application review may include the professional profile you submit.
- When
- Processed when you apply, including before approval, or when you create or use an authenticated account. Submitted information is provided by you; any consulted public professional profile is a separate source.
- Retention criteria
- Application records can exist without an account; account closure does not itself establish their deletion. Completed applications need a decision or withdrawal trigger and pending applications need an inactivity trigger, with justified abuse-prevention exceptions. Account records follow the separate offboarding, legal-hold, backup and provider process. For the controlled trial, return and deletion are operator-managed on request, with a proposed 30-day operational target for active stores, subject to documented holds and exceptions. Provider copies are retained per provider terms; expiry not verified. This is not a statutory deadline or a claim of automatic deletion.
- Minimization
- Only fields needed for account, organization, entitlement, and access administration are used.
Authentication, security, and device-trust data
- Data
- IP address or minimized network summary, user-agent, browser and operating-system summary, device name, cryptographic device-fingerprint or proof hashes, session state, login events, and security-risk signals.
- Purpose
- Deliver magic-link authentication, authorize trusted devices, prevent abuse, investigate security events, and protect accounts and organizations.
- When
- Processed when authentication, device authorization, rate limiting, or security controls run; this is not advertising or cross-site profiling.
- Retention criteria
- Sign-in magic links are valid for 15 minutes and approved onboarding tokens for 48 hours. Browser session, CSRF and device lifetimes are listed in the shared storage table. These validity periods are not deletion deadlines for security logs, device history or incident evidence; those records require separate retention and deletion rules.
- Minimization
- Exports and ordinary reports use redacted or summarized network and device evidence; raw file data is excluded.
Consent and privacy-preference evidence
- Data
- Consent choice, purpose, notice version, timestamp, withdrawal state and consent identifier stored in this browser. The separately tier-gated server capture paths store pseudonymized subject references and record IP address and user-agent as null.
- Purpose
- Remember privacy choices and record local choice or withdrawal events. Where the separate organization consent register is enabled, support its audit evidence.
- When
- Professional does not synchronize this browser preference to the organization consent register. Optional browser error monitoring remains off unless consented. Separate security and request logs can contain network information.
- Retention criteria
- The browser preference has no automatic expiry; local consent and processing logs keep the latest 50 entries. Clearing site storage removes them. Separately enabled server records need their own retention, legal-hold and deletion schedule.
- Minimization
- The record excludes raw file data and stores bounded consent evidence rather than browsing-content history.
Billing, subscription, and entitlement data
- Data
- Billing contact, customer and transaction references, plan, subscription state, invoice or refund status, tax evidence, and webhook reconciliation state. Payment-card data is handled by Paddle, not ScrubMetadata.
- Purpose
- Provide checkout, billing, entitlement, invoicing, tax handling, refunds, and financial reconciliation.
- When
- Processed when a customer starts or manages a paid subscription or billing event.
- Retention criteria
- Retained for subscription administration and applicable financial, dispute, tax, and legal-record periods; provider-side retention is handled separately.
- Minimization
- ScrubMetadata stores provider references and bounded billing state, not payment-card details.
Service usage and operational-control data
- Data
- Feature or API action, timestamp, usage and quota counters, rate-limit state, request correlation identifier, workflow status, and bounded performance or availability signals. Application abuse prevention sends IP-address identifiers and hourly allowed or blocked request counts to Upstash.
- Purpose
- Operate the service, enforce purchased limits, coordinate idempotent work, diagnose failures, measure availability, and prevent abuse.
- When
- Generated when service functions or operational controls run; no visitor advertising profile is created.
- Retention criteria
- Short-lived counters expire by design; other operational records follow the configured audit, reliability, billing, or incident retention rule.
- Minimization
- Raw file bytes, raw metadata values, full filenames, and local paths are excluded from operational telemetry and ordinary exports.
Privacy-filtered error and reliability data
- Data
- Error type, scrubbed message and stack context, bounded request context, internal account identifier where set, release and environment identifiers, and privacy-filtered browser or server diagnostics. Filtered diagnostics are not necessarily anonymous.
- Purpose
- Detect, diagnose, and resolve security, availability, and software reliability failures.
- When
- Server-side operational monitoring is separate from browser consent. Optional browser monitoring stays off unless the user consents and is disabled when this browser sends Global Privacy Control. Session replay and browser performance tracing are disabled in the current configuration.
- Retention criteria
- Retained only for the configured diagnostic, security, and incident-response period and the enabled provider plan.
- Minimization
- Credentials, message bodies, raw files, raw metadata values, full filenames, local paths, and local certification events are removed or dropped before provider delivery.
Compliance workflow and audit evidence
- Data
- Organization-scoped tasks, subject and requester names and email addresses, request descriptions and case narratives, decisions, statuses, deadlines, approvals, counts, categories, redacted evidence, evidence hashes, export manifests, and audit events entered or generated in the compliance workflows.
- Purpose
- Operate DSAR, DPIA, RoPA, incident, processor, approval, reporting, and accountability workflows requested by the customer.
- When
- Processed when an authorized user records or generates compliance-workflow evidence.
- Retention criteria
- Customer instructions and the applicable organization policy govern workflow retention. Completing or hiding a DSAR case does not erase its narratives or underlying records. Archiving an audit record does not delete it. The final case, archive and residual-copy deletion schedule must be established before publication.
- Minimization
- Raw file data remains outside the platform boundary; reports and exports apply record-specific redaction and manifest rules.
Communications and support data
- Data
- Recipient and sender address, message content and any attachments supplied to a contact mailbox, support or privacy enquiry, delivery state, suppression preference, and related audit reference.
- Purpose
- Deliver magic links, security notices, requested compliance communications, service support, and opted-in messages.
- When
- Processed when a user requests or triggers a communication or contacts a published support channel.
- Retention criteria
- Retained for delivery reconciliation, support, security, legal-claim, and suppression periods applicable to the communication.
- Minimization
- Do not send raw customer files or raw metadata to support. Application-generated messages exclude them; unsolicited mailbox attachments require separate handling and do not inherit the local-processing boundary.
Register public-platform-data-category-v1; last technical source review 2026-09-05. The register records current technical purposes, categories, minimization, retention criteria, and provider paths. Owner and privacy or legal review must confirm the final controller-processor roles, lawful basis, retention periods, transfer safeguards, and notice approval. This register does not determine legal compliance.
European Privacy Rights
Why we use personal data
Application review, account administration and requested support
Our legitimate interests under Article 6(1)(f) in assessing suitability for the Professional service, administering a business relationship and helping its authorized users. Where you contract personally, Article 6(1)(b) instead covers processing necessary for that contract or steps you request before it.
We review the professional information you submit and any public professional profile you provide. Required identity and organization information is needed to assess the application and provide protected access. Optional monitoring or marketing consent is not a condition of access.
Authentication, abuse prevention and service reliability
Our legitimate interests under Article 6(1)(f) in protecting accounts, enforcing access and purchased limits, investigating faults and preventing misuse.
These controls use necessary technical identifiers and bounded operational records, not advertising profiles. Browser storage must separately satisfy applicable storage and consent rules; a GDPR interest does not by itself authorize optional tracking.
Subscription administration and handling billing disputes
Article 6(1)(b) where needed for your own contract, or Article 6(1)(f) to administer the organization's purchase, reconcile entitlement and handle claims. A separate legal obligation is relied on only for records the applicable law requires us to keep.
Paddle determines the purposes and legal grounds for its independent payment and tax activities. Its obligations do not create an unlimited retention basis for our own records.
Optional browser error monitoring and promotional communications
Your separate consent under Article 6(1)(a) for the optional purpose you select.
You can refuse or withdraw without losing the core service. Withdrawal stops future optional collection or messages; it does not itself erase records already received. Minimal refusal or suppression evidence is used to respect your choice, not to continue marketing.
Responding to requests about data we control
Article 6(1)(c) where needed to meet applicable GDPR rights and accountability duties; Article 6(1)(f) for a requested enquiry that does not invoke such a duty.
We seek identity information only where reasonably necessary. Requests about your organization's workflow records are referred to that controller and handled on its instructions.
These grounds describe our controller activities where the GDPR applies. They are not the customer's grounds for workflow or sensitive-data processing. For legitimate interests, we assess necessity, reasonable expectations and the effect on people, limit the data and access, and consider objections through the privacy contact. A new purpose or materially different use requires a fresh assessment and appropriate notice.
Your GDPR Rights
For requests governed by GDPR, we respond without undue delay and within one month of receipt. Where the law permits an extension of up to two further months for complexity or the number of requests, we explain the reason within the first month. We request additional identity information only where reasonably needed. If the data is controlled by your organization, we assist that controller with the request rather than decide its purpose for it.
Contact Information
Privacy Questions
Data Subject Requests
Security Concerns
These are the canonical published contact routes. DNS, mailbox or alias routing, monitored ownership, receipt, response-time, PGP, and vulnerability-reward claims remain owner and provider runtime evidence gates.
Cookie Policy
Essential Cookies and Optional Error Monitoring
We use minimal essential cookies and local storage required for authentication, security, and remembering privacy choices. Visitor analytics, advertising cookies, and retargeting pixels are not used. Optional browser error monitoring is off unless you consent.
| Name | Purpose | Lifetime | Storage |
|---|---|---|---|
| next-auth.session-token / __Secure-next-auth.session-token | Sign-in session | Up to 30 days; renewed during continued authenticated use | Cookie |
| next-auth.csrf-token / __Host-next-auth.csrf-token | Authentication request protection where the authentication library sets it | Browser session | Cookie |
| csrf-token | Protect application requests against cross-site request forgery | One hour from issue or refresh | Cookie |
| device-authorized | Remember authorized-device state | Up to 24 hours | Cookie |
| gdpr-consent | Privacy choices, notice version, timestamp and consent session identifier | No automatic time expiry in the current implementation; replaced on a new choice or removed when site data is cleared | Local storage |
| gdpr-consent-log / soc2-processing-log | Local consent and privacy-setting activity history; the storage name does not claim SOC 2 certification | Latest 50 entries in each log; no automatic time expiry. Removed when site data is cleared | Local storage |
What We Don't Use
Cookie Choices
Our minimal cookie usage is designed around privacy-by-default principles. Essential cookies are necessary for the service to function, while optional browser error monitoring remains consent-based and can be rejected or withdrawn.
Cookie Management
You can manage cookies through your browser settings:
Third-Party Service Providers
While supported file processing stays within the browser, local folder, or approved customer-controlled boundary, we use the following source-integrated service providers for essential platform operations:
Payment Processing - Paddle
Purpose: Subscription checkout, billing, invoicing, and tax handling as merchant of record
Data Shared: Billing contact and transaction details needed for checkout and subscription administration. Paddle, not ScrubMetadata, receives and processes payment-card data.
Operational Boundary: Paddle acts as an independent controller for its merchant-of-record activities. The applicable Paddle contracting entity depends on the buyer location. Paddle determines its own retention; deleting a ScrubMetadata account does not erase Paddle records or remove ScrubMetadata service obligations.
Evidence Status: Source-integrated; runtime and legal evidence open
Privacy Policy: www.paddle.com
Application Hosting - Vercel
Purpose: Hosting the web application and serverless request handlers
Data Shared: Account and application request traffic, including technical request information needed to serve the application. Customer file bytes and raw extracted metadata values are excluded from the supported browser-local processing path.
Operational Boundary: Application Functions are configured in iad1, a United States region, also recorded in the 4 September 2026 production deployment receipt. This is not an EU-only hosting claim or a complete inventory of CDN, logs, support, backup or other provider locations. Transfer safeguards and account-specific contractual assurance still require evidence.
Evidence Status: Source-integrated; runtime and legal evidence open
Privacy Policy: vercel.com
Relational Database - Neon PostgreSQL
Purpose: Account, organization, subscription, audit, and privacy-safe compliance workflow records
Data Shared: User and organization account data plus minimized compliance records. Customer file bytes, local paths, raw filenames, and raw extracted metadata values are excluded from the supported browser-local processing path.
Operational Boundary: The production database project was observed in AWS us-east-1, United States, on 5 September 2026. Its configured restore history is six hours. That is not a complete backup-deletion guarantee or a statement about all provider access locations. The account contract and transfer safeguards remain to be established.
Evidence Status: Source-integrated; runtime and legal evidence open
Privacy Policy: neon.com
Cache and Abuse Prevention - Upstash Redis
Purpose: Distributed rate limits, session-related controls, and bounded operational coordination
Data Shared: IP-address identifiers and hourly allowed or blocked request counts for application abuse prevention, plus other minimized identifiers, counters and control state for reliable operation. No customer file content or raw metadata values.
Operational Boundary: Security-critical paths fail closed when their required distributed control is unavailable. The rate-limit window does not establish analytics retention. Actual analytics retention, residency and transfer safeguards remain account-specific evidence requirements.
Evidence Status: Source-integrated; runtime and legal evidence open
Privacy Policy: upstash.com
Email and Magic-Link Delivery - Resend
Purpose: Transactional email, account-security messages, compliance alerts, and opted-in communications
Data Shared: Recipient email address, bounded message content, and delivery status needed to send and reconcile the message.
Operational Boundary: The verified scrubmetadata.com sending domain was observed in us-east-1, United States, on 5 September 2026, with open and click tracking disabled. Resend publishes a 30-day retention period for email content, metadata, delivery events, logs and metrics on Free, Pro and Scale. This does not delete copies in our application, recipient mailboxes or Zoho Mail, or establish complete provider backup erasure. The sending region does not establish every storage or support location. Zoho Mail separately handles contact mailbox replies. Marketing and newsletter messages require explicit opt-in and remain suppressible.
Evidence Status: Source-integrated; runtime and legal evidence open
Privacy Policy: resend.com
Contact Mailbox Hosting - Zoho Mail
Purpose: Receiving and replying to privacy, security, support, billing, and legal enquiries sent to the published ScrubMetadata contact addresses
Data Shared: Sender and recipient addresses, message content, attachments, and delivery metadata supplied by the person who contacts ScrubMetadata. Customers must not send raw files or raw metadata through these contact channels.
Operational Boundary: Zoho Mail hosts the monitored contact mailbox and aliases. Processing location, retention, transfer mechanism, DPA, incident-contact, and change-notice facts remain owner, legal, and provider evidence gates.
Evidence Status: Source-integrated; runtime and legal evidence open
Privacy Policy: www.zoho.com
Privacy-Filtered Error Monitoring - Sentry
Purpose: Application error diagnosis and security/availability alerting
Data Shared: Privacy-filtered technical error context and an internal account identifier where set. This is not necessarily anonymous. Customer file bytes, local paths, raw filenames, raw metadata values, authorization credentials, and message bodies are excluded.
Operational Boundary: Monitoring is governed by the application redaction boundary. Provider enablement and production monitoring evidence remain separate release gates.
Evidence Status: Source-integrated; runtime and legal evidence open
Privacy Policy: sentry.io
DNS and Bot Protection - Cloudflare
Purpose: DNS, network protection, and configured Turnstile bot checks on public intake surfaces
Data Shared: Technical network and challenge information, including IP address, TLS fingerprint, user-agent, site key and associated origin for Turnstile; no customer file content or raw metadata values.
Operational Boundary: Cloudflare is not an interactive authentication provider. Its Turnstile notice distinguishes processing on the website operator's behalf for bot protection from its independent controller processing to improve bot detection. Exact enabled services, locations, and transfer safeguards remain owner/legal/provider evidence gates.
Evidence Status: Source-integrated; runtime and legal evidence open
Privacy Policy: www.cloudflare.com
Interactive authentication: Resend-delivered one-time email magic link. NextAuth is used internally as the database-session facade and is not a third-party OAuth identity provider.
Evidence boundary: Published provider terms establish the contract routes described here, not acceptance by our production accounts. Account coverage, locations, transfer mechanisms, DPAs, SCCs and assurance reports require current owner, legal, and provider evidence. A separate signature is needed only where the governing agreement requires one; incorporation does not fill missing parties or transfer annexes.
Last technical source review: 2026-09-05.
Important: The supported local processing path excludes original file bytes, raw extracted metadata, raw filenames, and local paths from these providers. This does not cover attachments someone sends to a contact mailbox. Do not send raw customer files or metadata to support.
Data Retention Policy
How Long We Keep Your Data
Raw files processed locally
Supported raw-file processing stays on your device. Local buffers, downloads and browser storage are controlled by the application, browser and operating system. We do not promise immediate physical erasure from device memory. Support attachments are a separate data path.
Account Information: Active account and reviewed offboarding
Email, name, and profile information are retained while the account is active. Exit is operator-managed on request. The proposed operational timeframe for deletion from active customer-directed stores is 30 days after the service ends and an authorized instruction is recorded; this is not a statutory deadline. Completion is confirmed in a dated record covering return, deletion, retention exceptions, providers and backups.
Operational records
Short-lived counters expire under their configured controls. Other billing, security and diagnostic records have different retention needs. The final schedule must identify each period or determinable criterion and its starting event; no uniform 13-month deletion guarantee is made.
Audit Logs: retention policy
Security and compliance audit logs (login attempts, API access) follow documented retention and applicable regulatory obligations. Specific preservation exceptions are assessed under their recorded legal basis.
Paddle payment records
Paddle determines retention for its own payment and financial records under its privacy notice and applicable obligations. This may continue after your ScrubMetadata subscription ends.
Support correspondence and backups
Provider-held support, archive and backup records are retained per provider terms; where an expiry has not been verified, the confirmation identifies it as “expiry not verified.” No fixed provider-erasure deadline is promised. Archiving is not deletion. A retention exception must identify a continuing purpose or legal obligation and an endpoint or review criterion.
Data Minimization
Raw-file processing is minimized by architecture and compliance records are designed to use hashes, counts and redacted summaries; complete field-by-field coverage remains under verification. Retention and deletion workflows are policy-governed; complete execution, lawful-preservation and legal-hold evidence remain open.
Data Protection Contact
For any questions about how we handle your data, privacy concerns, or to exercise your rights under GDPR/CCPA:
Privacy Contact
Email: privacy@scrubmetadata.com
General Support: support@scrubmetadata.com
Routing evidence: These are the canonical published contact routes. DNS, mailbox or alias routing, monitored ownership, receipt, response-time, PGP, and vulnerability-reward claims remain owner and provider runtime evidence gates.
Representative boundary: The privacy contact is an operational enquiry channel, not a statement that an EU or UK statutory representative has been appointed. Representative applicability, identity, postal address, and publication remain an owner and legal gate.
For EU Residents
If you are located in the European Union and have concerns about how we handle your data, you have the right to lodge a complaint with your local data protection authority (supervisory authority).
Children's Privacy
This is a professional service for authorized adult users, not a service directed to children.
We do not knowingly collect, use, or disclose personal information from children under 13 years of age. If you are under 13, please do not use this Service or provide any information to us.
If we learn that we have collected personal information from a child under 13 without parental consent, we will delete that information as quickly as possible. If you believe we might have information from or about a child under 13, please contact us immediately at privacy@scrubmetadata.com.
Note for Parents: If you are a parent or guardian and you are aware that your child has provided us with personal information, please contact us so that we can take necessary action.
California Privacy Rights (CCPA / CPRA)
Where the California Consumer Privacy Act, as amended, applies to the processing, California residents have the rights below. Applicability depends on the activity and legal thresholds, not simply access to this website.
Right to Know
Request categories and specific pieces of personal information, including information beyond 12 months where the law provides
Right to Delete
Request deletion of your personal information, subject to certain exceptions
Right to Opt Out of Sale or Sharing
Opt out of sale or sharing where applicable. The absence of a sale does not by itself establish the absence of sharing for cross-context behavioral advertising
Right to Non-Discrimination
We will not discriminate against you for exercising any of your CCPA rights
Right to Correct
Request correction of inaccurate personal information
Right to Limit Use of Sensitive Information
Limit uses and disclosures of sensitive personal information where this right applies
How to Exercise Your Rights
To exercise any of these rights, please email us at privacy@scrubmetadata.com with any description that lets us understand your request. A particular subject line is not required. An authorized agent may act where the law permits.
Access, correction and deletion requests may require proportionate identity verification and normally receive a response within 45 days, with a further 45 days where permitted and explained. Sale or sharing opt-outs do not require that verification and follow their separate, shorter legal timetable. We do not use the access-request timetable to delay an opt-out.
Shine the Light Law
California Civil Code Section 1798.83 permits California residents to request certain information about disclosure of personal information to third parties for direct marketing purposes. We do not share personal information with third parties for their direct marketing purposes.
Privacy by Design Principles
These source-reviewed foundations support Article 25 work. Runtime effectiveness, controller context, owner review and legal compliance remain separately assessed.
Purpose and lawfulness
Purpose, legal-basis and consent workflows record accountable evidence; applicability and legal validity remain controller-reviewed.
Transparency
Public and customer notice controls use versioned, evidence-scoped publication records; owner approval and delivery evidence remain separate gates.
Data minimization
Raw-file processing is minimized by architecture and compliance records are designed to use hashes, counts and redacted summaries; complete field-by-field coverage remains under verification.
Storage limitation
Retention and deletion workflows are policy-governed; complete execution, lawful-preservation and legal-hold evidence remain open.
Integrity and confidentiality
Role, step-up, device, four-eyes and audit controls exist; exact per-action enforcement requires signed current-source replay.
Accountability and data-subject rights
DSAR workflows support accountable intake and lifecycle evidence; identity, fulfillment, delivery and legal exceptions remain separately gated.
Evidence status: source reviewed runtime evidence incomplete. Legal compliance: not determined.