Privacy
Last updated 29 August 2026
This explains what Scritch does with personal data on this website and in the operator console. How the recovery agent handles the data your own application sends is set out under “What leaves the browser” on the home page and in the data processing terms for your workspace.
Who we are
Scritch is operated by Senne Bels (Okapi Works), based in Belgium, the data controller for the processing described here. For any privacy request, email privacy@scritch.xyz.
What we collect
Your account. Your email, your workspace name, and a hash of your password, so you can sign in and we can run your workspace.
Analytics, cookieless by default. We use PostHog to record which pages you view, where you arrived from, your device and browser type, and a coarse location derived from your IP address, to learn which pages actually help. By default this is cookieless: no cookie, no cross-site tracking, and no persistent identifier. You can object at any time by choosing Decline in the banner, which turns analytics off. If you accept a cookie instead, we additionally recognise a returning visit, and you can withdraw that whenever you like.
Incident data your app sends. Field states and rule codes, never the values a person typed unless you allowlist a specific path, and the end user’s device platform only with their own consent. It is encrypted at rest, kept for the period you set in your workspace, and then cleared.
Why we are allowed to
A legitimate interest in improving the site with cookieless analytics, which you can object to at any time, and your consent for the cookie that recognises a returning visit, which you can take back. Performance of our contract with you for your account and the service itself. A legitimate interest in keeping the service secure and free of abuse.
Who else processes it
PostHog handles analytics and processes it in the United States; that transfer rests on your consent and PostHog’s own data protection terms. Neon stores the service data and Vercel hosts the application. We do not sell personal data, and we do not share it beyond the processors that run the service.
How long we keep it
Account data for as long as your account exists. Analytics for PostHog’s retention period. Incident data for the retention you set in your workspace, after which the report, transcript and event detail are cleared.
Your rights
You can ask to access, correct, erase, restrict, or port your data, and object to processing based on legitimate interest. You can withdraw analytics consent whenever you like from the cookie banner or the “Manage cookies” link. Email us to exercise any of these. You also have the right to complain to the Belgian Data Protection Authority at gegevensbeschermingsautoriteit.be.
Changes
We will post any change here and update the date at the top.