Privacy Policy
Last Updated: August 2026
Our data processing is GDPR compliant and follows German data protection standards. This statement transparently describes what data we collect and how we protect it.
Data Controller:
Dominik Tirschler
dominik.tirschler@scrylab.de
https://scrylab.de
What Data We Collect
License Data
When activating a license, the following data is stored on our servers:
| Data | Purpose | Retention |
|---|---|---|
| Email address | License delivery and communication | 2 years after expiry |
| Device ID (SHA-256 hash) | License binding to prevent sharing | 2 years after expiry |
| Platform | License validation (linux/windows/macos) | 2 years after expiry |
| Subscription status | Access control | Until subscription ends |
The device ID is a SHA-256 hash of local hardware characteristics and cannot be reversed. It does not directly identify your device or your person.
Users of the free (non-commercial) version do not activate a license key and no data is sent to our servers unless you explicitly opt in to telemetry (see below).
Anonymous Telemetry (Opt-In Only)
By default, ScryLab collects no usage data. On first launch, you are offered a voluntary opt-in for anonymous usage statistics. You can change this at any time in Settings > General > Privacy.
If you opt in, the following anonymous, aggregated data is collected:
| Data | Examples | Purpose |
|---|---|---|
| Daily ID (rolling hash) | Changes every midnight | Deduplication without tracking |
| Date | 2026-05-10 | Daily aggregation |
| License tier | commercial / non-commercial | Feature analytics |
| App version | 0.1.4 | Compatibility tracking |
| Platform | linux | System requirements |
| Event counters | app_start: 2, file_load_mf4: 5, plot: 3 | Feature usage |
| Session count | 2 | Usage frequency |
| Total session minutes | 47 | Usage depth |
| Numeric metrics | total_samples_plotted, api_samples_sent | Performance analytics |
| Crash count | 0 | Stability monitoring |
The daily ID is derived from a hashed device fingerprint and the date and rotates daily at midnight. Two days from the same device cannot be linked together. Your device ID itself is never transmitted.
Never collected:
- File contents, signal payloads, or project data
- File paths or file names
- IP address (beyond standard server logs, see below)
- Hostname or directly identifying information
Upload timing: Telemetry is aggregated locally throughout the day. Upload attempts happen at app startup and periodically while the app is running. If an upload fails (for example offline), it is retried on the next attempt.
Withdrawal: Disabling telemetry in Settings > General > Privacy immediately deletes all locally queued telemetry data and stops any further collection and upload.
Anonymous Crash Reports (Opt-In Only)
Separate from usage telemetry, ScryLab offers its own voluntary opt-in for anonymous crash reports. It is disabled by default, offered separately on first launch, and can be changed at any time in Settings > General > Privacy.
If you opt in, a crash produces one anonymous report containing the following data:
| Data | Examples | Purpose |
|---|---|---|
| Daily ID (rolling hash) | same as telemetry | Deduplication without tracking |
| Incident ID | random ID per crash | Prevents duplicate submission |
| Date | 2026-08-19 | Daily aggregation |
| App version / platform / operating system | 0.2.6 / linux / Linux-x86_64 | Reproduction |
| Graphics / driver info | GPU model and driver version | Diagnosing driver-specific crashes |
| Crash type | segfault / python_exception / qt_fatal | Classification |
| Error signature | Hash of error type and call stack | Grouping identical crashes |
| Error message & scrubbed stack trace | technical error description | Root-cause analysis |
Scrubbing: Before saving, your home directory path (replaced with ~) and your username (replaced with <user>) are removed from the message and stack trace. Never included are file contents, signal payloads, or project data. No stable device or installation ID is transmitted; the daily ID rotates daily at midnight like telemetry and cannot be linked across days.
Upload timing: The report is stored locally at crash time and transmitted only on the next launch (the crashing process can no longer send anything itself). After confirmed receipt the local copy is deleted; at most the last 10 reports are kept.
Withdrawal: Disabling crash reports in Settings > General > Privacy immediately deletes all locally pending reports and stops any further upload.
AI Chat (optional)
The built-in AI chat is optional and disabled by default. There are three ways to use it, with very different data flows:
- Your own API key: You provide the key of an AI provider of your choice. Your inputs then go directly from your device to that provider — nothing is sent to our servers, and no account is required.
- MCP: Connecting an external AI client. Our servers are not involved.
- Hosted AI chat (ScryLab gateway): Only in this mode does data pass through our servers.
When using the hosted AI chat, we process:
| Data | Purpose | Retention |
|---|---|---|
| Email address (on verification) | Linking your credit pot | Until deletion on request |
| Credit / payment entries | Billing of AI credit | 10 years (statutory retention, §147 AO) |
| Verification code (temporary) | Email confirmation via device flow | Deleted automatically after expiry |
| Usage log (model, tokens, cost, IP address) | Billing, abuse prevention | 12 months |
| Anonymous device hash (free trial only) | One-time starter credit, abuse prevention | — |
Content: The actual chat inputs and responses are not stored in our database.
Sharing with AI providers: In the hosted AI chat, your inputs are forwarded to our AI provider to answer them — depending on the chosen model, Anthropic or Mistral AI. Anthropic also processes in the USA; this transfer is safeguarded by the Data Processing Addendum (DPA) with EU Standard Contractual Clauses incorporated into Anthropic’s Commercial Terms. Mistral AI processes within the EU. Your inputs are used solely to answer your request.
Deletion: You can request deletion of your AI account at any time via support@scrylab.de. Billing records are retained for statutory reasons but are separated from your email address (pseudonymized).
The anonymous device hash is derived from its own salt and is deliberately not linkable to the telemetry or crash-report IDs.
Website
Only standard server logs (IP address, browser) for security purposes. No cookies. No tracking.
Data Security
- Servers in Germany (EU)
- Encrypted connection (HTTPS / TLS)
- No sharing with third parties — except the optional hosted AI chat (see above)
- GDPR retention: telemetry and crash-report data is automatically deleted after 12 months
Your Rights
You can at any time:
- Request access to your data
- Request correction of inaccurate data
- Request deletion of your data (license data is deleted after expiry; telemetry data is anonymous and cannot be assigned back to you)
- Withdraw telemetry and crash-report consent at any time via Settings > General > Privacy
For questions or requests, contact support@scrylab.de. You can also file a complaint with the data protection authority (BfDI).