Privacy policy
Version 1.0. Last updated on 2026-07-20.
We value privacy on the internet, therefore we ensure that your information remains private and under your control. This Privacy Policy describes how we handle your data.
By using Scrooje and its features, you acknowledge and consent to the processing of your data as described in this Privacy Policy. This policy covers:
- Details on the data we collect.
- Our use of your data.
Legal framework
Scrooje operated by Scrooje Software Limited (“We”, “Us” “Our”) is based in Hong Kong SAR. Therefore, the company is governed by Hong Kong laws and regulations, including Personal Data Privacy Ordinance (PDPO).
Despite being a Hong Kong based entity, we are committed to maintain global data protection standards. As such, we align our policy with international privacy principles, including what is covered by General Data Protection Regulation (GDPR) in Europe.
Data collected from you and how we use it
The fundamental principle of our policy is to collect as little information as possible, focusing only on what’s required for operation of the service. Our analytical metrics are derived only from the information used by the application to run the service.
Data provided by you:
- Username: Required to create and log into your account. The username is encrypted at the field level in our database and is not shared with anyone.
- Email: You have an option to specify an email address in your user account for communication and password reset purposes. The email address is encrypted at the field level in our database - decrypted by our application only when needed to contact you. We may share this email address with our third party service providers to provide the Service.
- Communication with Scrooje: When contacting our support, the information is not encrypted. If you wish to encrypt your messages, you could use our OpenPGP public key to encrypt your message and include your public key.
Data collected automatically:
- Website visits: We use Cloudflare Web Analytics on our website to understand visitor behaviour, including page load performance and general usage patterns. This service operates in cookieless mode and does not track individual users or use persistent identifiers. Cloudflare collects anonymized metrics such as page views, referrers, and performance data. This data collection is limited to the public-facing website and is not active inside the web application.
- Human verification: To prevent use of bots, we use Cloudflare Turnstile for the password reset process. Turnstile may collect signals such as IP address and browser characteristics to verify you’re human; this data is handled under Cloudflare’s own privacy practices and is not stored in our database.
- Application activity: We encrypt your data on your device before sending it to our servers. Our server stores metadata like date and time of the last upload or the last authentication. We cannot read the contents of your data. This metadata is used internally for debugging, capacity planning and analytics.
- IP Address Collection: IP addresses may appear briefly in temporary rate-limiting logs for unauthenticated requests (sign in, sign up, password reset) and are not written to our database. Cloudflare may independently log or retain IP addresses under its own policies to prevent abuse and spam.
The financial data you enter into the web app is client-side encrypted with keys that belong only to you. We have no technical means to decrypt your financial data. Under normal operation, neither we nor any third party can read this data.
Data sub-processors
To provide our services we engage with various data sub-processors. These subprocessors are used for their specific functions and do not store data beyond what is necessary. Our sub-processors include:
- Amazon Web Services (AWS): Hosts our cloud servers and stores client-side encrypted financial data.
- Neon: Hosts our cloud database, which stores authentication credentials, accounting book information, metadata about client-side encrypted data, and product analytics.
- Cloudflare: Protects from DDoS and abuse, collects IP addresses as part of this service, and provides anonymized website analytics via Cloudflare Web Analytics. Cloudflare privacy policy can be found at https://www.cloudflare.com/privacypolicy/
- Fastmail: Provides email service. May include user email and communication details.
- AC PM, LLC (Postmark): Provides transactional email service for account notifications, email verification, and password resets. Includes user email.
- Stripe: Processes subscription payments. Collects payment details such as payment card details, billing address, and any email, phone number or name provided at checkout. Stripe privacy policy can be found at: https://stripe.com/privacy/
Support communications are retained for 3 years. Encrypted backups are retained for 28 days. Server metadata (login and upload timestamps) is retained for 30 days before being purged.
Due to the sensitive nature of the data stored in the database, we encrypt all fields that may pose a risk after a database leak, meaning we follow a policy whereas even the cloud database provider does not have access to the sensitive information.
Subscriptions and payments
Scrooje offers optional subscription plans. Payment processing is handled entirely by Stripe. We pass only an internal user ID to Stripe to link your account to a Stripe customer. Any email address, name, or billing address you provide during checkout is entered directly with Stripe and may differ from the email associated with your Scrooje account.
We store subscription-related metadata in our own database, including your subscription plan, price ID, and the mapping between your Stripe customer ID and your user ID. We do not directly store your payment details, billing address, or checkout email in our systems.
Your rights
You have the right to access, correct, or request erasure of your data. The best way to erase your data is by deleting your user account through the web application; account data is fully erased within 28 days. To request access to or correction of your data, contact us at mail@scroo.je.
If you have an active or past subscription, deleting your Scrooje account does not automatically erase billing data held by Stripe (such as payment details, billing address, or checkout email), as this data is controlled by Stripe under its own retention and legal obligations. To request erasure of that data, you’ll need to contact Stripe directly.
If you notice a violation of your privacy rights, you have the right to file a complaint with the appropriate authority. We will look into that and resolve issues accordingly based on our privacy policy and applicable laws.
Disclosure
We may be required by law to disclose information about our users. This may include your username and email, and metadata about encrypted data you uploaded to our system, such as object size and version numbers. Despite the minimal data disclosed, we are committed to ensuring that such requests are legal and fully comply with laws and regulations.
We have not been compelled by any legal process to compromise this encryption, and have no mechanism in place to do so as a matter of course.
Personal data of children
We do not knowingly collect or solicit Personal Data from children under 18 years of age (or the minimum age required by applicable local law, where higher). If you are a child under the age of 18, please do not attempt to register for or otherwise use Scrooje or send us any Personal Data. If we learn we have collected personal data from a child under 18 years of age, we will delete that information as quickly as possible. If you believe that a child under 18 years of age may have provided personal data to us, please contact us at mail@scroo.je.
Modifications
We reserve the right to modify the Privacy Policy. Where you have provided an email address, we will notify you of material changes. We recommend reviewing this policy periodically. Continued use of the service after changes take effect constitutes acceptance of the revised policy.
Client-side encrypted, always.