Privacy Policy
Version 1.0 · Last updated June 2026
Scriptvise (“we”, “our”, “us”) is an AI-assisted manuscript preparation platform for academic authors. This Privacy Policy explains what data we collect, how we use it, who we share it with, and what rights you have. By using Scriptvise you agree to this policy.
1. Data We Collect
| Category | What we collect |
|---|---|
| Account data | Email address, full name, avatar URL, authentication provider (email/password or Google OAuth), account creation date. |
| Manuscript content | The full text of your uploaded .docx manuscript, including title, abstract, sections, and references. Stored so we can run analyses and display your work. |
| Analysis results | Readiness scores, similarity risk flags, journal match scores, AI-generated suggestions and cover letters — all generated from your manuscript and stored against your account. |
| Usage data | Which features you use and how often (readiness analyses run, AI actions used, etc.) — used to enforce plan quotas and improve the platform. |
| Payment data | Subscription status and plan. We do not store card numbers; payment processing is handled by Razorpay or PayPal directly. |
| Consent record | The date and version number of the privacy consent you accepted before uploading manuscripts. |
| Log data | IP address, browser user-agent, and request timestamps — standard web server logs, retained for 30 days. |
2. Third-Party AI Model Providers
Scriptvise uses Google Gemini (via the Google AI / Generative AI API) to provide AI-powered features including:
- Title suggestions and abstract rewrites
- Academic tone improvement and grammar suggestions
- Reference checks and keyword optimisation
- Similarity risk explanations, safe rewrites, and paraphrase suggestions
- Journal match rationales, caution notes, and submission cover letters
When you trigger these features, the relevant manuscript sections (not the full document) are transmitted to Google’s API over an encrypted HTTPS connection. This processing is subject to the Google Gemini API Terms of Service and Google’s Privacy Policy.
Scriptvise does not use your manuscript content to train AI models. Deterministic analyses (readiness scoring, journal matching, similarity detection) run entirely on our servers and do not send your content to any third party.
3. How We Use Your Data
- ✓To provide the Scriptvise service — uploading, analysing, and displaying your manuscripts.
- ✓To enforce plan quotas and subscription entitlements.
- ✓To send transactional emails (account verification, password reset) via Resend.
- ✓To improve the platform — aggregated, anonymised usage statistics only.
- ✓To respond to your support requests.
- ✓To comply with legal obligations.
We do not sell your data, share it with advertisers, or use it for any purpose beyond providing and improving the Scriptvise service.
4. Encryption & Security
🔒 In transit
All data is transmitted over TLS 1.2+ (HTTPS). API calls to Google Gemini are also encrypted in transit.
🔒 At rest
Manuscript files and analysis data are stored in Supabase (PostgreSQL + S3-compatible storage) with AES-256 encryption at rest.
🔒 Passwords
Passwords are hashed with bcrypt before storage. We never store passwords in plaintext.
🔒 Access control
Row-Level Security (RLS) is enforced at the database level — your data is only accessible to your own account and platform administrators.
🔒 Authentication
Sessions use signed JWT tokens (NextAuth v5). Google OAuth users authenticate via Google’s secure OAuth 2.0 flow.
🔒 Incident response
In the event of a data breach we will notify affected users and relevant authorities within 72 hours as required by applicable law.
5. Data Retention
| Data type | Retention period |
|---|---|
| Manuscripts & analyses | Retained while your account is active. You can delete any manuscript at any time. |
| Account data | Retained while your account is active. Deleted within 30 days of account closure. |
| Generated reports | Stored in Supabase Storage for 90 days; re-generate at any time. |
| Payment records | Retained for 7 years for financial/legal compliance (Razorpay/PayPal records). |
| Server logs | Retained for 30 days, then automatically purged. |
| Consent records | Retained permanently as proof of your consent. |
6. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access:Request a copy of the personal data we hold about you.
- Correction:Update your name or email via Account → Profile.
- Deletion:Delete any manuscript from your dashboard. To delete your account and all associated data, contact us at support@scriptvise.com.
- Portability:Export your manuscript as .docx at any time using the Download button.
- Withdraw consent:You may withdraw consent to AI processing by deleting your manuscripts and closing your account. Note that withdrawal does not affect processing already performed.
- Objection:Object to processing for purposes other than service delivery.
7. Cookies
Scriptvise uses a single httpOnly session cookie (set by NextAuth) to keep you logged in. We do not use advertising cookies, third-party tracking pixels, or analytics cookies. No cookie banner is required beyond this notice.
8. Children’s Privacy
Scriptvise is intended for academic researchers and is not directed at children under 16. We do not knowingly collect data from anyone under 16. If you believe a child has created an account, contact us and we will delete it.
9. Changes to This Policy
We may update this policy from time to time. When we make material changes we will increment the version number and prompt you to re-consent before your next upload. The “Last updated” date at the top of this page reflects the most recent revision.
10. Contact Us
For privacy questions, data requests, or account deletion:
Email: support@scriptvise.com