The short version
- scrimpl runs on your Mac. Your screenshots, versions, brand kit and fonts stay in folders on your Mac, not on our servers.
- Your scrimpl account is online, so you can sign in on any Mac: your email, your plan and your credits. Nothing from your library.
- To simplify or edit a screenshot, the image and its text go through our API to Claude, made by Anthropic, for that one job. We don't store them, and nobody trains AI models on them.
- Paddle sells our paid plans and top-ups as merchant of record. It takes the payment, sends the invoice, handles tax and refunds. We never see your card.
- No selling of data, no ads, no trackers. You can download your data in the app, and have your account deleted anytime.
- Questions or requests: hello@scrimpl.com.
Who we are
scrimpl is made and sold by Milos Zdrale ("scrimpl", "we", "us"), Sime Milutinovića Sarajlije 1, 71123 Istočno Sarajevo, Bosnia and Herzegovina. We decide how and why the personal data in this policy is used (we are its "controller"), except where we process it for a business customer (see Using scrimpl for a business). For anything about your data, write to hello@scrimpl.com.
This policy covers the scrimpl app (the Mac app, or the same app opened in your browser on your Mac), the scrimpl Chrome extension, the scrimpl connector for AI agents (MCP), the scrimpl API and account service, and this website, scrimpl.com.
How scrimpl works
scrimpl is a local app. When you open it, a small scrimpl server starts on your Mac, and the editor talks to that server at localhost. Your library is a folder on your Mac. Two parts are online:
- Your scrimpl account: signing in, your plan and your credits. It is what lets the same account work on any Mac.
- The scrimpl API: when you ask for AI work, it checks your credits, passes that one request to Claude and sends the result back to your Mac. It does not save the screenshot, its text or the result.
Nobody at scrimpl can see your library: it never leaves your Mac except for the parts you send for AI work.
What stays on your Mac
Everything in this table is stored on your own Mac. We cannot see it, and you can open, copy or delete it at any time.
| What | Where on your Mac | Why |
|---|---|---|
| Screenshots you import and what you make from themVersions, simplified screens, previews, notes, tags, the activity log | Your library folder, in your Documents folder (the app shows where) | To run the editor and keep every version |
| Settings, brand kit and fontsPreferences, logo, colours, style references and fonts you upload | The app's storage on your Mac, and your library folder | To remember how you work and use your brand |
| Profiles on this MacIf several people share a Mac: name, email, a password kept only as a scrypt hash, sign-in sessions, the Terms version accepted | ~/Documents/scrimpl/accounts | To keep each person's library and settings apart on one Mac |
| Your sign-in on this MacThe sign-in tokens for your scrimpl account, encrypted; in the Mac app the key is kept in your Mac's Keychain | scrimpl's data folder | So you stay signed in |
| Usage logTime, feature, model, token counts, cost and duration of each AI request, short error messages. No screenshot content | scrimpl's data folder (in the Mac app: ~/Library/Application Support/scrimpl) | To show what used credits and fix slow or failing requests |
| Text read from screenshotsMade by Apple's on-device text recognition; this step never leaves your Mac | scrimpl's data folder (a cache) | So Simplify keeps the exact words |
| Brand kits and logos read from websites | scrimpl's data folder (a cache) | So a brand or logo is instant next time |
| Mac app capture logFile names and timings of screenshots it noticed, errors | ~/Library/Logs/scrimpl/capture.log | To fix "the pop-up didn't appear" |
What our cloud keeps
Your scrimpl account lives in a database run for us by Supabase; the scrimpl API and this website run on Vercel. This is all they keep about you:
| What | Details | Why |
|---|---|---|
| Account | Email address, sign-in sessions, when the account was made, the Terms version you accepted and when. You sign in with a password, with a 6-digit code we email you, or with Google; a password is kept only as a hash by Supabase's sign-in service, and with Google we receive only what confirms your email address | To sign you in on any Mac |
| Plan and credits | Plan, whether it is billed monthly or yearly, its status and renewal dates, credit balances (the plan's and bought top-ups), and a history of credits used and added (time, feature, amount) | To give you the plan you have and count credits |
| AI request records | For each request: time, feature, model, credits, token counts, cost, duration, whether it worked, a short error message. No screenshot, no text from it, no instruction, no result | To charge credits fairly, refund failed requests and keep costs in check |
| Billing link | Paddle's ids for you, your subscription and each top-up you bought, your plan, its status and billing dates, and a record of each notice from Paddle we applied (its id, type and time) | To switch your plan on, renew it and end it |
| Service logs | IP address, time, the address requested, status, browser or app version. No screenshot content | Security, preventing abuse and fixing errors |
What leaves your Mac
To Claude, through the scrimpl API, when you ask for AI work
These features need Claude: Simplify (and Re-simplify and style variations), chat edits, translating, rewriting or making up texts, finding personal information to blur, reading a brand from a screenshot, planning a set, and writing a video storyboard or video screens. For each request, scrimpl sends what that job needs: the screenshot or the part you picked, the text read from it (or captured by the Chrome extension), your instruction, and settings such as the style, your brand colours and any reference images you added.
The request goes over an encrypted connection (HTTPS) from your Mac to the scrimpl API, which checks your account and credits and passes it to Anthropic's Claude API. The answer comes back the same way. The API holds the request in memory only while it runs and does not save the screenshot, the text, your instruction or the result.
Anthropic processes the request for us as a subprocessor (see Subprocessors). As stated in Anthropic's commercial terms, Anthropic may not train models on data sent through its API. Anthropic keeps API data for a limited time, for example to detect misuse, as described in its privacy policy and privacy center.
To websites, for brands and logos
When you ask scrimpl to use a website's brand, or when it recognises which product a screenshot shows and fetches that product's logo, scrimpl opens that public website from your Mac, like a visitor would, to read its colours, fonts and logo. The website sees an ordinary visit from your Mac. Nothing from your screenshot is sent to it.
Voice input
"Hold the mic and say it" uses your browser's built-in speech recognition. In Chrome, Google's speech service turns your voice into text; in Safari, Apple's does, under their own privacy policies. scrimpl receives only the text.
AI agents you connect
If you connect an AI agent to scrimpl through its connector (for example Claude Code, Claude Desktop, Codex or Cursor), the agent can ask scrimpl to import, simplify, edit and export, and it receives what it asks for, such as an exported image or the texts on a screen. What the agent does with that is between you and the agent's provider, under your agreement with them.
Updates
The Mac app checks scrimpl.com for a new version when it starts and every few hours, and downloads updates from there. That request carries your IP address and the app's version, nothing else.
Nothing else
scrimpl has no analytics, crash reporting, advertising or tracking code, in the app or on this website.
Payments, through Paddle
Our paid plans and top-ups are sold by Paddle (Paddle.com Market Limited; Paddle.com Inc. for buyers in the United States, Paddle.com (Canada) Ltd for buyers in Canada), our reseller and merchant of record. Paddle runs the checkout, takes the payment, sends receipts and invoices, charges VAT or sales tax and handles refunds. For that, Paddle collects your payment details, name, email and billing address, and uses them as a controller under its own privacy policy.
To link a purchase to your account, we give Paddle your account email and your account's id. Paddle tells us what we need to give you your plan and credits: Paddle's ids for you, your subscription and each purchase, the plan and whether it is billed monthly or yearly, its status and its billing dates, and the top-ups you bought. We never receive your card details.
We send email only about your account and service: your sign-in codes, notices about your plan or credits, and important changes to scrimpl or these policies. We send it through Resend. Paddle sends its own receipts and payment emails. We don't send marketing email unless you ask for it; any email that is not essential will have an unsubscribe link.
AI-assisted output marking
Images you export from scrimpl as PNG or SVG carry a small, invisible label in the file's metadata saying that they are AI-assisted and made with scrimpl. It uses standard fields that other apps can read: PNG text fields ("Software: scrimpl") and an XMP block with the IPTC "digital source type" for media made with AI, or an SVG <metadata> block. It does not change how the picture looks, and it contains no personal data: no name, account, date or anything about the content.
We add it because the EU AI Act asks providers of AI tools to mark AI-generated and AI-edited images in a machine-readable way, so people can tell how an image was made. Copying to the clipboard and many apps and websites remove metadata, so the label does not always survive.
What we never do
- We don't sell or rent personal data, and we don't share it for advertising.
- We don't use trackers, analytics or ad pixels in the app or on this website. See the Cookie notice.
- We don't train AI models on your screenshots, texts or results, and we don't let anyone else do so through scrimpl. Anthropic's commercial terms do not allow it to train on API data.
- We don't store your screenshots on our servers, and we don't look at your library. It is on your Mac.
Why we may use your data (legal bases)
- To provide scrimpl (contract, GDPR Article 6(1)(b)): your account, your plan and credits, and sending a screenshot to Claude when you ask for AI work.
- To keep it safe and working (legitimate interests, Article 6(1)(f)): security, preventing abuse of credits, fixing errors and keeping costs in check, with as little data as possible (request records and logs have no screenshot content).
- To meet legal duties (legal obligation, Article 6(1)(c)): accounting records and answering lawful requests from authorities.
- When you choose to (consent, Article 6(1)(a)): only for something optional, such as a newsletter if we ever offer one. You can withdraw consent at any time.
Using scrimpl for a business
Screenshots often show other people's data: customer names, emails, messages, order numbers. You decide what you import and what you send to Claude, and scrimpl can blur that information or swap it for made-up names before you share. When you use scrimpl for your business, your business is the controller of the data in your screenshots, and scrimpl acts as its processor when it passes a request to Claude. The Data Processing Addendum sets out how.
How long data is kept
- On your Mac: until you delete it. A deleted screenshot goes to the library's trash, where you can restore it, until you empty the trash.
- Screenshots and texts sent for AI work: not kept by us. Anthropic keeps API data only for a limited time, as described in its policies.
- Your account, plan, credits and request records: while your account exists. When you delete your account in the app, they are deleted at once; the record of Paddle's notices we keep (their ids and statuses) no longer points to you. We keep only what the law requires.
- Service logs at Vercel and Supabase: a short time set by those providers, at most 90 days.
- Billing: Paddle keeps purchase records as the seller, under its own policy. We keep the payout reports Paddle sends us for as long as accounting law requires.
- Emails you send us: as long as we need to help you, then up to 2 years.
Your rights
Under the GDPR, the UK GDPR, the Law on Personal Data Protection of Bosnia and Herzegovina and similar laws, you can ask to access your data, correct it, delete it, restrict or object to how it is used, and receive it in a portable format. You can withdraw consent you gave. You can also complain to a data protection authority: in Bosnia and Herzegovina, the Personal Data Protection Agency; in the EU or the EEA, the authority where you live or work; in the UK, the ICO.
Much of this you can do yourself:
- Download my data (in the app, click the credits pill in the top bar) gives you a zip of your library, settings and scrimpl account details.
- Delete account (in the same place) deletes your scrimpl account from our cloud: your profile, credit history, usage records and top-ups. A paid plan that still renews is cancelled at once. You type your email to confirm, and it cannot be undone. Your library stays on your Mac. Paddle, as the merchant of record, keeps its own invoices and customer record under its own policy.
- Your library is an ordinary folder you can open, back up or delete.
For anything else, write to hello@scrimpl.com. We answer within one month.
Security
- Your library stays on your Mac. Turn on FileVault and keep a backup: it is as safe as your Mac.
- Signing in to your scrimpl account (a password, a 6-digit code sent to your email, or Google) runs through Supabase's sign-in service. Your password is kept only as a hash, never in plain text or in a log, and we never see it. Passwords of profiles on your Mac are kept only as scrypt hashes.
- The app, the API, Supabase, Anthropic and Paddle talk to each other only over HTTPS.
- Our keys for Claude and the other services are kept on the server, never in the app.
- Your account data is protected so that each account can read only its own rows; only our server can change a plan or a balance.
- The scrimpl server on your Mac only answers your own Mac and refuses requests from other websites.
International transfers
We are based in Bosnia and Herzegovina, and the providers we use are in the United States (Anthropic, Vercel, Resend), Singapore and the United States (Supabase) and the United Kingdom (Paddle), with servers in several regions. When personal data from the EU, the EEA or the UK goes to a country without an adequacy decision, it is protected by the European Commission's Standard Contractual Clauses and the UK Addendum, which are part of each provider's data processing agreement. If you are in the EU, the EEA or the UK, the GDPR or the UK GDPR applies to how we handle your data, wherever we are.
Children
scrimpl is for people aged 16 and over, and you must be 18 to buy a paid plan. We don't knowingly collect data from children.
Changes to this policy
If we change this policy in a way that matters to you, we will tell you in the app or by email before the change applies. The version and date are at the top of this page.
Contact
Email hello@scrimpl.com, or write to us at Sime Milutinovića Sarajlije 1, 71123 Istočno Sarajevo, Bosnia and Herzegovina.