Privacy Policy

How we protect and handle your personal information


1. Introduction

BG Mobile Apps Pty Ltd operates the Scrya platform via www.scrya.com and associated mobile applications. This policy explains how the company protects personal information under the Australian Privacy Principles (Privacy Act 1988) and applicable privacy laws. It applies to service usage and should be read alongside the Terms of Use.

2. Information We Collect

Personal information categories include:

  • Account information (name, email, password, username)
  • Contact information (phone, address)
  • Location data (approximate device location used for security, diagnostics, or regional functionality)
  • Content and data you provide through the platform
  • Usage data and service interactions
  • Device information and identifiers

Note: Declining to provide certain information may limit service access.

3. How We Collect Information

Collection methods include:

  • Direct collection during account creation or service use
  • Automatic collection during service use
  • Cookies and similar technologies
  • Third-party services via Single Sign-On

4. How We Use Your Information

Uses include:

  • Providing and improving our platform services
  • Processing and organizing your data
  • Analyzing and improving service performance
  • Service communications
  • Security and integrity protection
  • Legal compliance
  • Technical debugging and fixes
We do not use your data to train or develop general-purpose AI or machine learning models.

5. Location Data

Scrya may access approximate or device-level location information for the following reasons:

  • To improve security, fraud prevention, and account verification
  • To optimise app performance and diagnose technical issues across regions
  • To support features that depend on regional settings (time zone, language)

Scrya does not use precise GPS tracking, does not collect real-time location, and does not share location data with any external parties. All location information is handled securely and used strictly for service functionality and compliance purposes.

6. Browser Extension Architecture & Data Handling

The Scrya browser extension for grok.com is deliberately designed so that your creative work, API keys, generated media, and AI chat conversations never need to pass through Scrya's servers. This section describes, concretely, what the extension does with your data:

API keys stay on your device

When you add an xAI / Grok API key (or any LLM provider credential — OpenAI, Anthropic, Ollama, etc.) in the extension's settings, it is stored only in your browser's local extension storage. Keys are never transmitted to Scrya servers. The provider records we do sync to our Supabase backend for convenience across browsers have the apiKey field explicitly stripped before upload.

Generated media goes to your own storage

Videos and images that Grok Imagine generates for you are captured in your browser and uploaded directly to your own Cloudflare R2 bucket via presigned URLs. Scrya does not host, mirror, or retain your generated content. Our presigning Edge Function exists only to keep S3-style credentials off the client; it never sees the files themselves.

AI chat is browser-to-provider

When you chat with Victoria or any custom chatbot, the messages travel directly from your browser to whichever LLM provider you have configured (Ollama on localhost, LM Studio, OpenAI, Anthropic, Grok, etc.). Scrya does not proxy, log, or read these conversations. Conversation history is stored locally in the browser's extension storage.

AI persona generation uses your own LLM

When you tap "Generate persona", or import a character from an indexed movie, the request goes to your configured LLM provider — not to a Scrya endpoint. You pay the (often zero) cost; we don't see the input or the output.

What we DO sync to Supabase

For convenience across browsers and team workspaces, the following non-sensitive metadata is synced to the Scrya backend:

  • Account profile (email, display name, team memberships)
  • Saved prompt-pack subscriptions and category preferences
  • Chatbot definitions you create (name, persona text, avatar URL — not conversation messages)
  • Lists and tag assignments for your captured media (metadata only — the media files stay in your own R2 bucket)
  • Public challenge entries that you explicitly submit

What we DO NOT collect

  • LLM API keys (stripped before any sync)
  • AI chat conversation contents
  • Generated video or image files
  • Browsing history outside grok.com
  • Precise location data

7. Data Sharing and Disclosure

Information disclosure without consent occurs only when:

  • Required or authorized by law
  • Necessary for service provision
  • Required to protect rights or property
  • Necessary to prevent immediate harm

Data may be shared with trusted service providers under confidentiality obligations.

8. Data Security

Protective measures include:

  • Data encryption (in transit and at rest)
  • Secure access controls and authentication
  • Regular security assessments
  • Employee training and confidentiality agreements

9. Your Privacy Rights

Australian Users

  • Right to access and correct personal information
  • Right to complain to the Office of the Australian Information Commissioner

California Residents

  • Right to know collected, used, shared, or sold information
  • Right to delete personal information held by businesses
  • Right to opt-out of information sales
  • Right to non-discrimination when exercising rights

EEA Users

  • Right to access and portability
  • Right to rectification
  • Right to erasure ("right to be forgotten")
  • Right to restrict processing
  • Right to object to processing
  • Right to withdraw consent

Exercise rights by contacting us via the Contact Us section below.

10. International Data Transfers

The company operates globally with data transfers to different jurisdictions. For EEA users, safeguards are provided via Standard Contractual Clauses and adequacy decisions. For US users, we comply with state-specific laws (CCPA/CPRA). All transfers include appropriate technical and organizational measures.

11. Cookies and Tracking Technologies

We use cookies and similar technologies to enhance user experience, analyze site traffic, and personalize content. Users can manage cookie preferences through their browser settings.

12. Data Retention

We retain personal information for as long as necessary to provide our services and fulfill the purposes outlined in this policy. When data is no longer needed, we securely delete or anonymize it.

13. Children's Privacy

Our services are not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If we become aware of such collection, we will take steps to delete the information.

14. Region-Specific Disclosures

California Privacy Notice: CCPA/CPRA-specific rights are available upon request.

EU/UK Privacy Notice: GDPR rights and protections are available upon request.

Other Jurisdictions: Contact the company for local privacy rights information.

15. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify users of any material changes by posting the new policy on our website and updating the "Last Updated" date.

16. Contact Us

For questions about this Privacy Policy or to exercise your privacy rights, please contact us at:

Email: [email protected]