Privacy Policy


Last Updated: August 2026

Our data processing is GDPR compliant and follows German data protection standards. This statement transparently describes what data we collect and how we protect it.

Data Controller:

Dominik Tirschler
dominik.tirschler@scrylab.de
https://scrylab.de

What Data We Collect

License Data

When activating a license, the following data is stored on our servers:

DataPurposeRetention
Email addressLicense delivery and communication2 years after expiry
Device ID (SHA-256 hash)License binding to prevent sharing2 years after expiry
PlatformLicense validation (linux/windows/macos)2 years after expiry
Subscription statusAccess controlUntil subscription ends

The device ID is a SHA-256 hash of local hardware characteristics and cannot be reversed. It does not directly identify your device or your person.

Users of the free (non-commercial) version do not activate a license key and no data is sent to our servers unless you explicitly opt in to telemetry (see below).

Anonymous Telemetry (Opt-In Only)

By default, ScryLab collects no usage data. On first launch, you are offered a voluntary opt-in for anonymous usage statistics. You can change this at any time in Settings > General > Privacy.

If you opt in, the following anonymous, aggregated data is collected:

DataExamplesPurpose
Daily ID (rolling hash)Changes every midnightDeduplication without tracking
Date2026-05-10Daily aggregation
License tiercommercial / non-commercialFeature analytics
App version0.1.4Compatibility tracking
PlatformlinuxSystem requirements
Event countersapp_start: 2, file_load_mf4: 5, plot: 3Feature usage
Session count2Usage frequency
Total session minutes47Usage depth
Numeric metricstotal_samples_plotted, api_samples_sentPerformance analytics
Crash count0Stability monitoring

The daily ID is derived from a hashed device fingerprint and the date and rotates daily at midnight. Two days from the same device cannot be linked together. Your device ID itself is never transmitted.

Never collected:

  • File contents, signal payloads, or project data
  • File paths or file names
  • IP address (beyond standard server logs, see below)
  • Hostname or directly identifying information

Upload timing: Telemetry is aggregated locally throughout the day. Upload attempts happen at app startup and periodically while the app is running. If an upload fails (for example offline), it is retried on the next attempt.

Withdrawal: Disabling telemetry in Settings > General > Privacy immediately deletes all locally queued telemetry data and stops any further collection and upload.

Anonymous Crash Reports (Opt-In Only)

Separate from usage telemetry, ScryLab offers its own voluntary opt-in for anonymous crash reports. It is disabled by default, offered separately on first launch, and can be changed at any time in Settings > General > Privacy.

If you opt in, a crash produces one anonymous report containing the following data:

DataExamplesPurpose
Daily ID (rolling hash)same as telemetryDeduplication without tracking
Incident IDrandom ID per crashPrevents duplicate submission
Date2026-08-19Daily aggregation
App version / platform / operating system0.2.6 / linux / Linux-x86_64Reproduction
Graphics / driver infoGPU model and driver versionDiagnosing driver-specific crashes
Crash typesegfault / python_exception / qt_fatalClassification
Error signatureHash of error type and call stackGrouping identical crashes
Error message & scrubbed stack tracetechnical error descriptionRoot-cause analysis

Scrubbing: Before saving, your home directory path (replaced with ~) and your username (replaced with <user>) are removed from the message and stack trace. Never included are file contents, signal payloads, or project data. No stable device or installation ID is transmitted; the daily ID rotates daily at midnight like telemetry and cannot be linked across days.

Upload timing: The report is stored locally at crash time and transmitted only on the next launch (the crashing process can no longer send anything itself). After confirmed receipt the local copy is deleted; at most the last 10 reports are kept.

Withdrawal: Disabling crash reports in Settings > General > Privacy immediately deletes all locally pending reports and stops any further upload.

AI Chat (optional)

The built-in AI chat is optional and disabled by default. There are three ways to use it, with very different data flows:

  1. Your own API key: You provide the key of an AI provider of your choice. Your inputs then go directly from your device to that provider — nothing is sent to our servers, and no account is required.
  2. MCP: Connecting an external AI client. Our servers are not involved.
  3. Hosted AI chat (ScryLab gateway): Only in this mode does data pass through our servers.

When using the hosted AI chat, we process:

DataPurposeRetention
Email address (on verification)Linking your credit potUntil deletion on request
Credit / payment entriesBilling of AI credit10 years (statutory retention, §147 AO)
Verification code (temporary)Email confirmation via device flowDeleted automatically after expiry
Usage log (model, tokens, cost, IP address)Billing, abuse prevention12 months
Anonymous device hash (free trial only)One-time starter credit, abuse prevention

Content: The actual chat inputs and responses are not stored in our database.

Sharing with AI providers: In the hosted AI chat, your inputs are forwarded to our AI provider to answer them — depending on the chosen model, Anthropic or Mistral AI. Anthropic also processes in the USA; this transfer is safeguarded by the Data Processing Addendum (DPA) with EU Standard Contractual Clauses incorporated into Anthropic’s Commercial Terms. Mistral AI processes within the EU. Your inputs are used solely to answer your request.

Deletion: You can request deletion of your AI account at any time via support@scrylab.de. Billing records are retained for statutory reasons but are separated from your email address (pseudonymized).

The anonymous device hash is derived from its own salt and is deliberately not linkable to the telemetry or crash-report IDs.

Website

Only standard server logs (IP address, browser) for security purposes. No cookies. No tracking.

Data Security

  • Servers in Germany (EU)
  • Encrypted connection (HTTPS / TLS)
  • No sharing with third parties — except the optional hosted AI chat (see above)
  • GDPR retention: telemetry and crash-report data is automatically deleted after 12 months

Your Rights

You can at any time:

  • Request access to your data
  • Request correction of inaccurate data
  • Request deletion of your data (license data is deleted after expiry; telemetry data is anonymous and cannot be assigned back to you)
  • Withdraw telemetry and crash-report consent at any time via Settings > General > Privacy

For questions or requests, contact support@scrylab.de. You can also file a complaint with the data protection authority (BfDI).