Privacy Policy
Your data isn't the product. There is no product — just the news. Scrollan doesn't ask you to sign up, doesn't track you, and doesn't sell or share personal information. This policy covers both the Scrollan iOS app and the scrollan.app website.
The short version
We don't collect personal profiles, we ship no advertising or analytics identifiers, and there are no accounts. The app sends us only what is technically required to serve you: the ID of an article you want summarized or read aloud, your language code, your ZIP prefix if you enable local news, and — if you turn on notifications — an anonymous Apple push token. The website stores exactly one thing in your browser: your light/dark theme choice.
1. Who we are
Scrollan ("we", "us") is an independent news service published by Berkay Dinçer, based in New Jersey, United States. Privacy contact: privacy@scrollan.app.
2. What we don't do
- No tracking. Our iOS privacy manifest sets
NSPrivacyTracking = false. No IDFA, no fingerprinting, no data-broker linkage. - No accounts. No sign-up, sign-in, social login or email collection anywhere in the Service.
- No analytics SDKs. No Firebase, Mixpanel, Segment, Amplitude, Meta SDK, AppsFlyer or similar — in the app or on the website.
- No ads. We show no advertising and share nothing with ad networks.
- No selling or sharing. We do not sell personal information and do not share it for cross-context behavioral advertising.
3. The iOS app: what stays on your device
These preferences live exclusively in iOS UserDefaults on your phone and never reach our servers (unless you back your device up to iCloud — Apple's setting, not ours): your selected language; your ZIP code for the local feed; your saved articles; and first-launch flags. Delete the app or tap Start over in Profile and they're gone.
4. The iOS app: what we receive
When you request AI output
Tapping an article's AI brief or audio playback sends our backend the article ID, your language code, and the same anonymous API key shipped with every install. We do not log IPs for analytics; short-lived rate-limit counters keyed by IP protect the service from abuse and age out automatically within minutes.
When you enable the local feed
Your ZIP code is used on-device to select a metro region; requests then reference that region's public news sources. Your ZIP itself stays on the phone.
When you enable notifications (optional)
If you allow push notifications, iOS gives us an anonymous Apple Push Notification token for your device. We store that token — and nothing else — to deliver breaking-news alerts (currently capped at three per day). The token identifies a device install, not a person; it is deleted automatically when Apple reports it invalid (for example after you uninstall) and you can revoke it any time in iOS Settings → Notifications → Scrollan.
5. The website (scrollan.app)
- Theme preference. Your light/dark choice is kept in your browser's localStorage and never transmitted to us. See the Cookie Policy — we set no tracking cookies.
- Server logs. Our hosting provider (Vercel) processes standard request data (IP address, user agent) transiently to deliver pages and prevent abuse, as any web server does.
- Rate limiting. Requests that trigger AI generation are protected by the same short-lived, auto-expiring IP counters as the app.
- Third-party images. Some article images load from the original publisher's CDN, which receives the standard image request from your browser.
6. Our processors
We use a small number of infrastructure providers, each receiving only what the function requires and none receiving a personal profile: Supabase (backend and database), Vercel (website hosting), OpenAI (article text is sent for summarization/translation — article text only, never anything about you), ElevenLabs (article text for audio narration), and Apple (push notification delivery).
7. Retention
Rate-limit counters expire within minutes. Push tokens are kept while valid and pruned when Apple reports them dead. Everything else about your usage was never collected in the first place.
8. Your rights (California, EU/UK and elsewhere)
Because we hold essentially no personal data, most rights requests are satisfied by design: there is no profile to access, port or delete. California residents' CCPA/CPRA rights and EU/UK GDPR rights — and exactly how to exercise each one — are laid out on our Privacy Choices page. To make any request: privacy@scrollan.app. We respond within 45 days.
9. Children
The Service is general-audience news and is not directed to children under 13. We do not knowingly collect personal information from anyone, children included.
10. Security
Traffic to our backend and website is encrypted in transit (TLS). Backend access is restricted, and public database access is limited by row-level security to published content only.
11. Changes
We'll post any changes here with an updated date. Material changes will be flagged prominently on the site.
12. Contact
privacy@scrollan.app — Scrollan, New Jersey, United States.