Privacy Policy
This Privacy Policy describes how The Founders Ltd ("we", "us", or "our") collects, uses, processes, and discloses your personal information when you use the Scrolls mobile application (the "Service").
Last updated: 13 August 2026
1. Introduction
The Founders Ltd is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application, Scrolls ("the App"), which is available on iOS and Android platforms.
Please read this Privacy Policy carefully. By accessing or using the App, you agree to the collection and use of information in accordance with this policy. If you do not agree with the terms of this Privacy Policy, please do not access the App.
We may update this Privacy Policy from time to time to reflect changes to our practices or for other operational, legal, or regulatory reasons. We encourage you to periodically review this page for the latest information on our privacy practices.
2. Information We Collect
We collect information to provide features of the App and to operate our services. The information we collect falls into the following categories:
2.1 Information You Provide to Us
Account Registration Information. When you create an account, we collect:
- Email address. Required for account creation and authentication via a one-time passcode (OTP) sent by email.
- Google account information. If you choose to sign in using Google OAuth, we receive your name, email address, and profile picture from Google in accordance with Google's OAuth scope. Your interaction with Google is governed by Google's privacy policy.
- Username. You select a username during the onboarding process. This username is visible to other users of the App in social features, including friend lists, book clubs, and discussion posts.
- Avatar. An optional profile image. If you sign in via Google, your Google profile picture may be imported. You may change or remove your avatar at any time.
- Display name. An optional field that may be shown to other users in social features.
Content You Create. When you use social features, we collect and store:
- Messages and posts you publish in book club discussions
- Bookmarks you create, including any optional labels
- Reports you submit regarding other users, including the reported user's identifier, the reason for the report, and contextual information
Communications. If you contact us via email or any other channel, we retain a record of your communication in order to process your enquiry.
2.2 Information Collected Automatically
Reading Activity Data. The App collects data about your reading activity in order to deliver core functionality:
- Reading progress. Your current position within each book, measured by chunk index and total chunk count.
- Reading statistics. Experience points (XP) earned, total chunks read, number of books finished, current streak count, longest streak, and the date of your last reading session.
- Library data. Which books you have added to your personal library and the dates they were added.
- Bookmarks. The position within a book at which you placed a bookmark and any associated label.
- Daily activity. The number of scrolls performed per day and the dates on which achievements were unlocked.
- Session history. Records of scrolls and time spent reading per book, used to power reading statistics and gamification features.
- Completed books. A list of books you have finished, along with the date of completion and the last-opened timestamp for each book.
This data is stored locally on your device. When you are signed in to an account, it is additionally synced to our cloud infrastructure so that your progress is available across multiple devices.
Social Activity Data. When you use social features, we store:
- Friend relationships (mutual connections) and pending friend requests
- Your list of blocked users
- Book club memberships, including your role within each club (owner or member)
2.3 Device and Application Data
Local Preferences. Certain settings are stored exclusively on your device and are never transmitted to our servers:
- Dark mode / light mode preference
- Reader font size selection
- Dictionary lookup toggle state
- Context preview toggle state
Cached Content. The App caches the following data locally to support offline reading:
- Book content (text chunks for books you have opened or added to your library)
- The weekly poem, cached for the current week
- Dictionary lookup results, stored in an in-memory cache capped at 500 entries
Cached book content is deleted when you remove a book from your library or when you sign out of your account.
2.4 Anonymous Analytics Data
Separately from the account and reading activity data described above, we collect a small set of anonymous, aggregate usage events: app opens, reading session length, and which features you use (such as Read Aloud, book clubs, or friends). See Section 9 for the full description of how this is kept anonymous. This data is never linked to the account data described in Sections 2.1 and 2.2.
3. How We Use Your Information
We use the information we collect to provide, maintain, and improve the App, and to operate our services. Specifically, we use your information for the following purposes:
- Account management. To create and manage your account, authenticate you when you sign in, and maintain your profile settings.
- Service delivery. To provide core reading functionality, including delivering book content, tracking your reading progress, and enabling bookmarks.
- Cross-device sync. To synchronise your reading progress, library, bookmarks, and preferences across your devices when you are signed in.
- Social features. To enable friend connections, book club creation and membership, discussion posts, and the display of other members' reading progress within clubs.
- Gamification. To calculate and display experience points, streaks, achievements, and reading statistics.
- Content delivery. To fetch book content from our content providers, retrieve dictionary definitions, and serve weekly poems.
- Moderation and safety. To process user reports, enforce community guidelines, and maintain a safe environment for all users.
- Technical operations. To ensure the App functions correctly, diagnose technical issues, and maintain the security of our infrastructure.
We do not use your personal information for behavioural advertising, targeted advertising, or any form of profiling for marketing purposes.
4. Legal Basis for Processing (EEA/UK Users)
If you are located in the European Economic Area or the United Kingdom, we process your personal data on the following legal bases under the GDPR and UK GDPR:
- Contractual necessity. Processing is necessary for the performance of our agreement with you to provide the App's services (e.g., storing your reading progress, managing your account, delivering content).
- Consent. Where you have given explicit consent (e.g., signing in via Google OAuth, which requires your authorisation with Google).
- Legitimate interests. Processing is necessary for our legitimate interests, including maintaining the security and integrity of our services, moderating user content, and improving the App, provided these interests are not overridden by your data protection rights.
- Legal obligation. Processing is necessary to comply with applicable legal obligations.
5. Sharing and Disclosure of Your Information
We do not sell, rent, or trade your personal information. We share your information only in the circumstances described below:
5.1 Service Providers
We engage third-party service providers to perform functions on our behalf. These providers have access to your personal information only to the extent necessary to perform these functions and are obligated not to disclose or use it for any other purpose. Our service providers include:
| Provider | Category | Data Accessed | Jurisdiction |
|---|---|---|---|
| Supabase | Backend infrastructure (authentication, database, file storage) | Authentication credentials, user account data, reading activity data, social data | United States |
| Google (Google Sign-In) | Authentication provider | Email address, name, profile picture (via standard OAuth scope) | United States |
| Dictionary API (dictionaryapi.dev) | Content provider | Search query (the word being looked up) | United States |
| Poetry DB (poetrydb.org) | Content provider | None — requests a random poem | United States |
| Project Gutenberg | Content provider | Book identifier requested | United States / Germany |
| Hugging Face | Machine learning model hosting | None — downloads a model file | France / United States |
| PostHog | Anonymous product analytics | Anonymous usage events (app opens, reading session length, feature usage) tied to a random device identifier only — no account identifiers | European Union |
5.2 Other Users
When you use social features, certain information about you is visible to other users of the App:
- Your username and avatar are visible to users with whom you are connected as friends and to members of book clubs you join.
- Your display name (if set) is visible in the same contexts.
- Your reading progress within a book club is visible to other members of that club.
- Messages and posts you publish in book club discussions are visible to other members of that club.
5.3 Legal Requirements
We may disclose your personal information if required to do so by law or in response to valid requests by public authorities (e.g., a court order or government regulation). We may also disclose information when we believe in good faith that disclosure is necessary to protect our rights, enforce our terms of service, protect the safety of users, or investigate fraud.
5.4 Business Transfers
In the event of a merger, acquisition, reorganisation, or sale of assets, your personal information may be transferred as part of that transaction. We will notify you via email and/or a prominent notice on the App of any such change in ownership or control.
6. Data Storage, Security, and Retention
6.1 Security Measures
We implement industry-standard technical and organisational measures to protect your personal information:
- Encryption in transit. All data transmitted between the App and our servers is encrypted using HTTPS (TLS 1.2 or higher).
- Encryption at rest. Data stored in our database is encrypted at rest through Supabase's infrastructure.
- Secure authentication. We use the PKCE (Proof Key for Code Exchange) flow for OAuth authentication. No passwords are stored directly by Scrolls — authentication is handled via a one-time passcode sent by email or Google OAuth.
- Local storage. Data stored on your device uses platform-native storage mechanisms (SharedPreferences on Android, UserDefaults on iOS).
- Access controls. Database access is governed by Row Level Security (RLS) policies that ensure users can only access their own data and data explicitly shared with them (e.g., club members accessing club content).
No method of electronic storage or internet transmission is absolutely secure. While we strive to protect your personal information, we cannot guarantee its absolute security. In the event of a data breach likely to result in a risk to your rights and freedoms, we will notify you and the relevant supervisory authority in accordance with applicable law.
6.2 Data Retention
We retain your personal information for as long as your account is active or as needed to provide the App's services. Specifically:
- Active accounts. Account data and reading activity data are retained for the duration of your account.
- Account deletion. When you delete your account, social data (friendships, club memberships, discussion posts) is removed immediately. Reading data and purchase history are retained for a period of 12 months in a soft-deleted state to allow for account recovery. After 12 months, all data is purged from our servers.
- Recovery window. If you sign back in within 12 months of deleting your account, your account and all associated data can be restored.
- Local data. Data stored locally on your device is retained until you clear the App's data, uninstall the App, or sign out.
7. Your Rights and Choices
Depending on your jurisdiction, you may have certain rights regarding your personal information. This section summarises those rights. Where your rights arise from specific legislation, we note the relevant law.
7.1 General Rights
- Account settings. You may update your username, display name, and avatar at any time from within the App's profile settings.
- Account deletion. You may delete your account at any time. This action removes your social data immediately and places your reading data in a 12-month recovery window before permanent deletion.
- Guest mode. You may use the App without creating an account. In guest mode, all data remains stored locally on your device and is not synced to our servers.
7.2 Rights for EEA and UK Users (GDPR / UK GDPR)
If you are located in the European Economic Area or the United Kingdom, you have the following rights:
- Right of access (Article 15 GDPR). You may request a description of the personal data we process about you and a copy of that data.
- Right to rectification (Article 16 GDPR). You may request that we correct inaccurate or incomplete personal data.
- Right to erasure (Article 17 GDPR). You may request the deletion of your personal data ("right to be forgotten") where there is no compelling lawful ground for continued processing.
- Right to restrict processing (Article 18 GDPR). You may request that we suspend the processing of your personal data in certain circumstances.
- Right to data portability (Article 20 GDPR). You may request a copy of your personal data in a structured, commonly used, machine-readable format.
- Right to object (Article 21 GDPR). You may object to the processing of your personal data where we rely on legitimate interests.
- Right to withdraw consent (Article 7(3) GDPR). Where processing is based on consent, you may withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
- Right to lodge a complaint. You have the right to lodge a complaint with a supervisory authority. If you are in the UK, you may complain to the Information Commissioner's Office (ico.org.uk).
7.3 Rights for California Users (CCPA / CPRA)
If you are a resident of California, you have additional rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act:
- Right to know. You may request information about the categories and specific pieces of personal information we have collected, the categories of sources, the business purposes for collection, and the categories of third parties with whom we share your information.
- Right to delete. You may request deletion of personal information we collected from you, subject to certain exceptions.
- Right to opt out of sale or share. We do not sell or share your personal information. This right does not apply.
- Right to limit use of sensitive personal information. We do not use sensitive personal information beyond what is necessary to provide the App's services.
- Right to non-discrimination. We will not discriminate against you for exercising your CCPA/CPRA rights.
7.4 How to Exercise Your Rights
To exercise any of the rights described above, or to ask questions about how we process your data, please contact us at [email protected]. We will respond to verified requests within the timeframes required by applicable law.
8. On-Device Artificial Intelligence
The App includes a "Story so far" feature that generates summaries of the content you have read. This feature uses a language model (Qwen3-0.6B) that runs entirely on your device:
- The model is downloaded once from Hugging Face at the time of first use and stored locally on your device.
- All inference (the process of generating a summary) occurs on your device. Your reading content is not transmitted to any external server for AI processing.
- After the initial model download, the summarisation feature does not require an internet connection.
- We do not collect, store, or analyse the prompts or outputs generated by the on-device model.
9. Analytics and Tracking
The App uses PostHog to collect anonymous, aggregate product analytics — for example, how often people open the App, how long reading sessions last, and which features (such as Read Aloud, book clubs, or friends) are used. This is configured to be genuinely anonymous, not merely "aggregated":
- Each event is tied only to a random identifier generated on your device. It is never linked to your account, email address, username, or any other information that identifies you.
- We do not create a "person" profile for you in PostHog — the setting that would let events be linked together into an identifiable profile is switched off entirely.
- Your IP address is discarded before it is stored, so it is never used to infer your location.
- We do not record your screen or session activity. The App displays copyrighted book text, and we have specifically disabled this feature to make sure that text is never captured.
- If you reinstall the App or clear its data, the random identifier resets — there is no way to link your activity across that reset.
We do not use this data for behavioural advertising, targeted advertising, or profiling, and it is never combined with your account data described in Section 2.1/2.2.
The App does not respond to the HTTP Do Not Track (DNT) header because we do not track users across third-party websites or services, and do not use device identifiers for advertising purposes.
The marketing website (this site) does not set third-party tracking cookies. Essential functionality cookies may be used where necessary for the site to operate correctly.
10. Device Permissions
The App requests the following permissions on your device:
- Internet access (Android:
android.permission.INTERNET). Required for authenticating your account, synchronising reading progress, fetching book content, retrieving dictionary definitions, and delivering weekly poems.
The App does not request access to your camera, microphone, location, contacts, phone state, SMS, file system, calendar, or any other sensitive permission.
11. Children's Privacy
The App is not directed to children under the age of 13 (or the applicable age of consent in your jurisdiction). We do not knowingly collect, maintain, or use personal information from children under 13, and no part of the App is designed to solicit personally identifiable information from children under 13.
Parental consent is required before we collect, use, or disclose a child's personally identifiable information. If we learn that we have collected personal information from a child under 13 without verifying parental consent, we will take steps to delete that information promptly.
If you believe that a child under 13 has provided us with personal information, please contact us at [email protected].
12. International Data Transfers
Your personal information may be processed in countries other than the country in which you reside. The countries where our service providers operate (including the United States) may not have data protection laws equivalent to those in your jurisdiction.
Where we transfer personal data outside the European Economic Area, we ensure an adequate level of protection by relying on appropriate safeguards, including but not limited to Standard Contractual Clauses (SCCs) approved by the European Commission, or other legally recognised transfer mechanisms.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal developments, or other factors. When we make material changes, we will notify you through the App (e.g., via an in-app notice) or by email before the changes take effect.
We indicate the date this Privacy Policy was last updated at the top of this page. We encourage you to review this policy periodically. Your continued use of the App following the posting of changes to this policy constitutes your acceptance of those changes.
14. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
The Founders Ltd
Email: [email protected]
We aim to respond to all enquiries within three business days.