Privacy Policy
What we collect, who processes your manuscript, where it goes, and what we will never do with it.
Last updated: 12 August 2026
Please read: this policy is a working draft prepared as a starting point. It has not been reviewed by a qualified lawyer and is not legal advice. Have it checked against the law of your jurisdiction — and your actual business practices — before relying on it.
1. Who is responsible for your data
Scriptreaders International, trading as ScriptReaders, of 37 Adekola Street, Victoria Island, Lagos, Nigeria, is the data controller for the personal data described here.
We are established in Nigeria and process data under the Nigeria Data Protection Act 2023, overseen by the Nigeria Data Protection Commission (NDPC). Because we offer the service to researchers internationally, the data protection law of your own country may also apply — the UK and EU GDPR in particular reach organisations outside their borders that offer services to people inside them. Where that is so, we aim to meet the higher standard rather than the minimum.
For any question about this policy, or to exercise a right under section 9, contact support@scriptreaders.com.
To be completed: confirm with a Nigerian lawyer whether you meet the NDPA threshold for registration with the NDPC as a data controller of major importance, and whether you must appoint a Data Protection Officer.
2. What we collect
Information you give us
- Account details — name, email address, a hashed password, and institution where you provide it. We never store your password itself.
- Manuscripts and scan settings — the files you upload, plus word count, target journal, citation style, first language if you state it, and any instructions.
- Correspondence — enquiries through our contact form and emails you exchange with us.
Information collected automatically
- Server and edge logs — IP address, browser type, pages requested, and timestamps, generated by our hosting and network providers as a normal part of serving the site.
- Session cookies — one for account login, one for administrator login. No advertising or third-party analytics cookies. See the Cookie Policy.
What we do not collect
We do not receive or store card numbers, CVV codes, or banking credentials. Those go directly to Squad. We retain only a transaction reference, amount, currency, and status, so we can reconcile payments and handle refunds.
3. Your manuscripts — the part that matters most
Unpublished research needs stronger protection than ordinary contact data, and an automated service raises questions a human editor does not. Explicitly:
- Your manuscript is not used as training data. It is processed to produce your results and nothing else. This is a contractual commitment from our analysis provider, not an assurance we invented: Anthropic's Commercial Terms of Service state that “Anthropic may not train models on Customer Content from Services”, and everything you upload is Customer Content under those terms.
- It is not published as a sample or shown to other users.
- Files are stored in private object storage, never in a public web directory, and are retrievable only by you or by an authenticated administrator.
- Processing is automated. A human does not read your manuscript unless you ask us to look at something specific.
How long the analysis provider keeps it. Under Anthropic's published API retention policy, the content of a request — your manuscript and the results returned — is not retained by default once the response has been returned. Their documentation states that retained data is never used for model training without express permission, and that only what is technically necessary for a feature to work is kept at all.
Two mechanical details apply to how we call the service, and neither stores your writing: we send a fixed instruction block that is cached briefly to reduce cost, held in memory and deleted when it expires; and we require results in a fixed data shape, of which only that empty shape is cached, for up to 24 hours. Your manuscript is in neither.
The one exception, stated plainly: if a request is flagged by the provider's automated trust-and-safety systems, they may retain the input and output for up to two years, and that applies regardless of any other arrangement. Ordinary academic writing is not the sort of thing those systems look for, but we would rather you knew the ceiling than assumed there was none.
Zero data retention is in place. Requested from the provider on 11 August 2026 and approved on 15 August 2026, it applies to our account: the content of a request is not written to their storage at all, rather than being written and then deleted. This is stronger than the default described above, and it is the arrangement under which every scan runs.
Two things this does not change, both stated above and both still true: the trust-and-safety exception below, which applies regardless of any retention arrangement; and our own storage, which is a separate question answered in the section on how long we keep your manuscript.
A note for whoever maintains this page: do not replace the figures above with the five-year period from Anthropic's consumer retention page. That number covers opt-in model-training data and feedback submissions on Claude Free, Pro, and Max — not the API. Publishing it here would tell researchers their unpublished manuscripts sit in a training pipeline for five years, which is the opposite of what the API terms actually commit to.
4. Why we use your data
- To perform the scan you paid for and return results. Basis: performance of a contract.
- To operate your account and keep your scan history available. Basis: performance of a contract.
- To respond to enquiries. Basis: legitimate interests, or steps preparatory to a contract.
- To keep financial records. Basis: legal obligation.
- To secure and maintain the service. Basis: legitimate interests.
We do not sell your data, do not use it for behavioural advertising, and do not send marketing email unless you have asked us to.
5. Who processes your data
These are every organisation that touches your data, what they do, and where they are:
| Provider | What they do | Where |
|---|---|---|
| Spaceship | Website hosting, application server, and database | United States |
| Google LLC | Email delivery and business correspondence | United States |
| Cloudflare, Inc. | Manuscript storage (R2) and the scanning engine (Workers) | United States, with global edge processing |
| Anthropic PBC | The language analysis that produces your scan results Commercial API terms state that submitted content is not used to train models. Verify against the current agreement before relying on this. | United States |
| Self-hosted LanguageTool | Spelling, punctuation, and grammar checking for the free tools Not a third party. Listed anyway because text you paste into the grammar tool leaves the web server to reach it, and a privacy notice that only names outside companies would be quietly incomplete. Nothing is retained there. | Our own server |
| Squad | Card payment processing Receives your payment details directly. We never see full card numbers. | Nigeria |
We may disclose data where legally required. We will not otherwise share it.
6. International transfers
We are established in Nigeria, but most of our infrastructure is in the United States and our network provider operates globally. Your manuscript and personal data will therefore be transferred outside Nigeria, and outside your own country, as a normal part of delivering the service.
Where personal data is transferred across borders we rely on the safeguards permitted under the Nigeria Data Protection Act 2023, and — where the UK or EU GDPR applies — on standard contractual clauses with our providers.
To be completed: confirm that data processing agreements are in place with Spaceship, Google, Cloudflare, and Anthropic, and that each incorporates standard contractual clauses. Without them this section is aspirational rather than accurate.
7. How long we keep it
- Manuscripts — kept for your 7-day rescan window plus 90 days, so results stay available while you finish revising, then deleted. You may request earlier deletion at any time.
- Scan results — kept with the manuscript they relate to.
- Account records — kept while your account is open. Closing your account deletes your manuscripts, your scan history, and the documents we produced, and removes your name, email address, and institution from our records.
- Contact enquiries — 24 months.
- Financial records — as long as Nigerian tax law requires.
- Logs — per our providers' standard rotation.
8. Security
We use access controls, encrypted sessions, hashed passwords, and private storage outside any public web directory. Data is encrypted in transit. No system is perfectly secure and we cannot guarantee absolute security — but we will notify you and the Nigeria Data Protection Commission (NDPC) without undue delay if a breach affects your personal data or your manuscript.
9. Your rights
Under the Nigeria Data Protection Act 2023, and under GDPR where it applies, you may:
- access the personal data we hold about you;
- have inaccurate data corrected;
- have your data deleted;
- restrict or object to how we process it;
- receive your data in a portable format;
- withdraw consent where processing relies on it;
- complain to the Nigeria Data Protection Commission (NDPC), or to the supervisory authority in your own country.
Email support@scriptreaders.com. We respond within one month. We may verify your identity first, particularly for deletion requests, because manuscripts are confidential and we will not hand one to the wrong person.
10. Children
This service is for researchers and postgraduate authors. We do not knowingly collect data from children under 18. If you believe we have, contact us and we will delete it.
11. Changes
We will update this policy as our practices change and revise the date above. Any change to how manuscripts are processed, retained, or shared will be communicated to account holders directly, not merely posted here.