Privacy
Last updated: 2026-08-20
Controller
Company: Davide Grasböck
Address: Hirschstettner Straße 63, 1220 Vienna, Austria
Email: support@scalebrowser.net
What the product itself does not send us
Scalebrowser runs on your own machine. Profiles, cookies, saved passwords, passkeys and the screenshots an agent takes are written to your disk and stay there. We operate no hosted execution, so none of that reaches us, and a breach on our side cannot expose a file that never left your machine.
Account and contract
To create and run an account we process your email address, a hash of your password, your sessions and, if you enable them, your second factor and passkeys. Legal basis: performance of a contract, Art. 6(1)(b) GDPR. The data is deleted when you delete your account, after the 30-day restore window has passed.
Where a new account came from
When you create an account, we store once, next to it, where the sign-up came from and what it was made with: a mark or campaign tags in the address of the sign-up page if there were any, the country, region and city your network address belongs to according to a free database, the name of your browser, your operating system, your device type and your preferred language. Your network address itself is not stored.
We also store the monthly value described under "How we count visits". Within the same month it lets us see which of our pages that browser opened before signing up, and which site the first of those visits came from.
We use this for one thing: to see which of our pages and which outside links bring customers. It is not stored on your device, no advertising network ever sees it, and it is deleted with your account. Legal basis: our legitimate interest in knowing which parts of our own site work, Art. 6(1)(f) GDPR. You can object at any time by writing to the address above.
Cookies on this website
This website sets two cookies, both of them necessary for it to work at all. One carries your login session, so that you stay signed in between pages. The other is set only when you confirm your identity for a sensitive action, such as changing your password or deleting your account, and it expires shortly afterwards.
A third cookie exists only if you ask for it. On the opt-out page you can tell us not to count this browser. That page sets a cookie named sb-count, which holds a fixed word, stays on this domain only and expires after one year.
We run no tracking pixels, no advertising network and no third-party scripts, which is why this site asks you for no cookie consent: the first two cookies are what the service needs to function, and the third one is your own request. Legal basis: performance of a contract, Art. 6(1)(b) GDPR, and for the third cookie carrying out your objection, Art. 21 GDPR.
How we count visits
We count how often our public pages and our documentation are opened, and we do it on our own server rather than with a script in your browser. Nothing is placed on your device for this, so there is nothing here you would have to agree to.
One line is written per page view. It holds the path you opened, the site that linked you here if there was one, campaign tags in the address, and a few details our server derives from the request: the country, region and city your network address belongs to according to the free DB-IP Lite database, whether that address is known to belong to a data centre, the Tor network or a VPN, the name of your browser, your operating system, your device type and your preferred language. Your network address itself is not stored.
To tell visitors apart, the line carries a value computed from your address, your browser identification and a secret that only our server knows. That value is one-way and changes every month, so the same visitor counts once per month and is a new one the month after. If you are signed in, the value is computed from your account instead, so you count once per month on every device you use. Programs that read our documentation in a machine format, such as llms.txt, are counted the same way as a separate kind of line. No advertising network ever sees any of it. Lines are deleted after 90 days.
We use it for one thing: to see whether the pages we publish bring anyone. Legal basis: our legitimate interest in knowing whether our own site works, Art. 6(1)(f) GDPR. You can object at any time under Art. 21 GDPR: open the opt-out page to stop counting this browser, or write to the address above.
Payment
Payments run through Stripe. We do not see or store card numbers; Stripe processes them as the payment provider and returns only what we need for billing and for the subscription state. Legal basis: performance of a contract, Art. 6(1)(b) GDPR, and our legal obligation to keep invoices, Art. 6(1)(c).
The free check
The check measures the browser you visit it with and shows you the result. Measuring starts when the page opens, because measuring is the service you came for. The values are sent to our server to be judged there and are not kept from that request. Legal basis for that step: Art. 6(1)(b) GDPR, performing what you asked for.
The measurement then joins a reference set, so that the rarity figures beside your result come from real traffic rather than from a cited study, and so that the tool can tell you when it recognises a device it has seen before. Every feature is stored as a keyed hash and never in the clear; separately, a plain counter records how often a value like a screen size occurs, which carries no route back to any measurement. No record holds an IP address, a cookie, an account or any identifier of you. Legal basis: our legitimate interest, Art. 6(1)(f) GDPR. Records expire after 90 days.
You can object at any time under Art. 21 GDPR by writing to the address above. A shared copy of a result is different: it holds the full reading in the clear, it only exists because you clicked to create it, and you can revoke it from its own page.
Error diagnostics
When something fails, the application reports the error to a collector we host ourselves. Those reports carry no identifier: no account id, no email, no IP address. Values that could identify a person are removed before sending, and again on arrival. Legal basis: our legitimate interest in a working service, Art. 6(1)(f) GDPR.
You can object to this at any time, and in the desktop app you do not even have to: crash reporting is off until you switch it on, under Settings, Error reports. Turning it back off takes effect immediately and costs you no functionality.
Profile sync
Your installation encrypts each profile on your own device and uploads only the result, so that it survives a lost machine and your other machines can fetch it. This runs from the moment you sign in: the key is created on your device, never reaches us, and we therefore store data we cannot read and cannot hand to anyone. Legal basis: performance of a contract, Art. 6(1)(b) GDPR.
You can switch it off, in the desktop client under Settings, and you can keep individual profiles out of it. What we hold then is nothing at all; what we hold while it runs is the encrypted block, its size, when it changed and an opaque identifier per profile.
For this one feature we act as your processor rather than as the controller. The terms of that are in our data processing agreement, which applies without you having to sign it.
Processors
We use the following processors, each under a data processing agreement:
- Contabo GmbH, Munich: the servers, the database and the error collector we run ourselves. Located in the EU.
- Cloudflare: DNS, TLS, inbound email, and the object storage holding the encrypted backups and the encrypted sync data
- Amazon Web Services: transactional email, sent from eu-central-1
- Stripe: payments and invoicing
Some of these are US companies. Where data reaches a third country, the transfer is covered by the EU standard contractual clauses.
Server logs
Our servers keep the usual access logs: the requested address, the time, the response code, the browser string and the IP address. We need them to run the service and to notice an attack, and we do not use them to build a profile of you. Legal basis: our legitimate interest in a working and secure service, Art. 6(1)(f) GDPR. They are deleted after seven days.
How long we keep things
Account and contract data: until you delete the account, plus the 30-day window in which it can still be restored. Invoices: seven years, because Austrian tax law requires it (§ 132 BAO). Measurements from the free check, and a report you chose to share: 90 days. Error reports: 90 days. Server logs: seven days. Encrypted backups: 35 days, so a copy can survive there for that long after deletion before the rotation passes over it.
Two things we are asked to state
Providing your email address is not required by law, but it is required by the contract: without it we cannot create an account, and without an account there is no subscription and no download. Everything else is optional and you can see which, because it is behind a switch.
We make no automated decisions about you in the sense of Art. 22 GDPR, and we do no profiling. Nothing here scores you, ranks you or decides anything about your contract by itself.
Changes to this notice
If what we process changes, this text changes with it, and the date at the top moves. If a change matters to you, for example a new processor or a new purpose, we tell you by email rather than leaving you to notice.
Your rights
You have the right to access, rectification, erasure, restriction of processing, data portability and to object to processing based on legitimate interest. Where we rely on your consent, you can withdraw it at any time with effect for the future, without that making the processing before it unlawful. Write to support@scalebrowser.net and we will answer within one month.
You also have the right to complain to a supervisory authority. In Austria that is the Datenschutzbehörde, Barichgasse 40-42, 1030 Vienna.