Legal
Privacy policy
What personal data srvScripts collects, why, how long we keep it, who processes it for us, and the rights you have — written in plain language.
This policy explains how srvScripts (“we”, “us”) handles personal data when you visit srvscripts.com, use our tools, create an account, subscribe to the newsletter, buy srvScripts Pro or a fix, or contact us. We collect as little as we can, keep it only as long as we need it, and never sell it.
1. Who is responsible
srvScripts is the controller of the personal data described here. Our full legal name and postal address are shown on every invoice and receipt and are available on request. For anything about privacy, write to us through the contact page and put “Privacy” in the subject. We reply within one business day (Monday to Friday, 09:00–18:00 UTC) and answer requests within one month.
2. What we collect and why
| What | Examples | Why we use it | Legal basis (GDPR) |
|---|---|---|---|
| Technical data from your visit | IP address, browser and device type, pages requested, date and time, referring page | Deliver pages, keep the site secure, block abuse, fix errors | Legitimate interests (running a secure website) |
| Tool inputs and results | Domains, hostnames, IP addresses, email headers, configuration snippets you enter | Run the check you asked for, show the result, enforce fair-use limits | Performing the service you request; legitimate interests |
| Emails sent to our test addresses | The full message, including headers and sender address | Analyse deliverability and produce your report | Performing the service you request |
| Account data | Email address, sign-in times, plan, saved monitors and domains, a hashed copy of your Tools API key, daily usage counters (sign-in uses one-time email links, so no password is stored) | Provide your account, Pro features and alerts | Contract |
| Payment and order data | Order reference, package, amount, PayPal transaction ID, payer name and email from PayPal, what you asked us to fix | Take payment, deliver the service, keep accounting records, handle refunds | Contract; legal obligation (tax and accounting) |
| Messages, support tickets and community posts | Your name, email, message, files you attach, posts in the community area | Answer you, deliver support, keep a record of the conversation | Contract or legitimate interests |
| Comments | Name, email (never published), the comment, IP address for spam checks | Publish your comment and keep spam out | Legitimate interests |
| Newsletter | Email address, sign-up and confirmation date (double opt-in), opens and clicks | Send the newsletter you asked for; the list is kept in our own WordPress database (FluentCRM), not with an outside mailing service | Consent (you can withdraw at any time) |
| Analytics (only with consent) | Pseudonymous usage data from Google Analytics | Understand which pages and tools are useful | Consent |
| Advertising (only if we show ads, and only with consent for personalised ads) | Cookie identifiers and ad interactions processed by Google | Show ads that fund the free tools | Consent |
| Security and abuse data | Hashed IP addresses, request counts, firewall and login events, security reports from browsers | Rate limits, preventing spam and attacks | Legitimate interests |
We do not ask for and do not want special categories of data (for example health or religion). Please do not paste passwords, private keys or other people’s personal data into tools or messages.
3. How the free tools handle your data
- Inputs are used only to run the check. Results are cached for up to 5 minutes so repeated checks are fast, then discarded.
- Share links. If you create a share link, that result is stored for 30 days and can be seen by anyone with the link.
- Fair-use counters store a one-way hash of your IP address (or your account ID) with a count of recent uses, for up to 24 hours.
- What is my IP. To show the approximate location and time zone of your IP address, we look it up in a copy of the DB-IP Lite database stored on our own server. Your IP address is not sent to DB-IP or anyone else for this. The time zone your browser reports is used only to compare it with that location and is not stored. Like other results, the result is cached for up to 5 minutes.
- Email deliverability test. Messages sent to a test address are analysed automatically and deleted straight after the analysis. Messages that are never analysed are deleted automatically after 3 hours. The report, which includes the headers of your message, is kept for 30 days so you can come back to it or share it.
- AI tools. Our AI tools use several AI engines. Depending on the tool, availability and load, the text you submit is sent to one of them to generate the answer: Anthropic, OpenAI, Google (Gemini), Groq, Cerebras, OpenRouter or Mistral, each under its own API data terms. Some free AI tiers allow the provider to use submitted text to improve its models, so never paste passwords, keys or customer data. Before sending, we remove private keys, passwords, tokens and API keys we recognise and, if you leave the box ticked, replace public IP and email addresses with placeholders. We do not save your input as a record of its own; the masked input is sent to the AI provider to produce the answer, and the answer, which can quote parts of it, is cached for up to 24 hours. Masking is best effort, so remove confidential data before you paste. The answer, which can quote parts of it, is cached on our server for up to 24 hours so an identical request is not sent twice, and is then deleted automatically. Usage counters store only a one-way hash of your IP address or your account ID. To have a cached answer removed sooner, contact us.
- Monitors. If you set up uptime, SSL or blacklist monitoring, we store the address you monitor, your alert email and the latest results until you delete the monitor or your account. Every alert email has a link that stops the monitor and deletes its data. Pro members can add a Slack, Discord or other webhook URL; alerts are posted there only if you set one.
- Error reports. If you use “Report an issue” on a guide, script, tool or review, we store the page, what you wrote and, only if you give it, your email address, which we use to tell you when the page is fixed. Your IP address is not stored; a one-way hash of it is kept for an hour to limit spam. Reports are deleted 12 months after they are received.
- Call recording transcription. Recordings you upload to the transcription tool are sent over HTTPS to our own server (transcribe.srvscripts.com) and processed there; no third-party speech service sees them. The audio file is deleted as soon as it has been decoded, and the transcript is deleted 24 hours after it is ready. Only upload recordings you have the right to transcribe, and where the law requires it, make sure callers were told the call was recorded.
4. Who processes data for us
We use a small number of service providers. Each processes data only on our instructions and under a data processing agreement or equivalent terms.
| Provider | What they do | Where |
|---|---|---|
| Our hosting provider | Runs the server that hosts the site, databases and mail | Data centre used for srvscripts.com |
| Cloudflare | Authoritative DNS for our domains | Global |
| PayPal (or another payment provider named at checkout) | Payments for Pro, fixes and services; the payment provider is an independent controller for the payment itself. We receive your email, the plan or package and a payment reference, never card or bank details | EU and worldwide |
| Google (Analytics, Tag Manager, Site Kit; AdSense if ads are shown) | Statistics, and advertising if enabled — only after consent | EU, USA and worldwide |
| AI providers (Anthropic, OpenAI, Google, Groq, Cerebras, OpenRouter, Mistral) | AI tools (only the text you submit, after redaction) | USA and EU |
| Globalping and other public measurement networks | Ping and traceroute tests you run (only the target you enter) | Worldwide |
| Spam and blacklist services (for example Spamhaus, Spamcop, SURBL, URIBL) | We query them with the IP address or domain being tested | Worldwide |
We may also disclose data when the law requires it, to protect our rights or users’ safety, or to a buyer if the business is transferred (you would be told).
5. Affiliate links and advertising
- Some reviews link to vendors through affiliate links. Clicking one takes you to the vendor’s site, where the vendor may set its own cookies to attribute a purchase. We receive a commission report, not your personal details.
- If ads are shown, they are served by Google AdSense, which uses cookies to measure and personalise ads only when you allow it in the cookie banner. srvScripts Pro members see no ads.
6. International transfers
Some providers are outside your country, including in the United States. Where data leaves the EU, EEA, UK or Switzerland, we rely on an adequacy decision (such as the EU–US Data Privacy Framework, where the provider is certified) or on the European Commission’s Standard Contractual Clauses, together with additional safeguards where needed.
7. How long we keep data
| Data | How long |
|---|---|
| Tool results cache | Up to 5 minutes |
| Uploaded call recordings (transcription tool) | Deleted as soon as decoded (seconds to minutes) |
| Transcripts | 24 hours, then deleted automatically |
| Fair-use counters | Up to 24 hours |
| Emails to test addresses | Deleted after analysis, at the latest after 3 hours |
| Email test reports and share links | 30 days |
| Server logs | Rotated within 30 days, unless needed to investigate an incident |
| AI answer cache | Up to 24 hours |
| Contact enquiries and support tickets | Up to 2 years, or for the length of a service contract plus the period tax law requires |
| Comments | As long as the comment is published |
| Account data and monitors | Until you delete your account (you can do this yourself on the account page); inactive free accounts may be deleted after 24 months |
| Orders, invoices and payment records | As long as tax and accounting law requires (usually 6 to 10 years) |
| Newsletter data | Until you unsubscribe, then a minimal record that you opted out |
| Consent records for cookies | Up to 12 months |
8. Cookies and similar technologies
We use strictly necessary cookies and local storage to make the site work, and analytics or advertising cookies only with your consent. Details, including every Google service we use and how to change your choice, are in the cookie policy.
9. Your rights
Depending on where you live, you have the right to:
- access the personal data we hold about you and get a copy;
- correct data that is wrong or incomplete;
- delete your data (“right to be forgotten”), unless we must keep it, for example for tax law;
- restrict or object to processing based on legitimate interests, including profiling;
- withdraw consent at any time (for example for cookies or the newsletter), without affecting earlier processing;
- data portability — receive data you gave us in a common machine-readable format;
- complain to a data protection authority, in particular in the country where you live or work. We would appreciate the chance to fix the problem first.
To use any of these rights, contact us through the contact page. We may ask you to confirm your identity. We answer within one month (extendable by two months for complex requests, in which case we tell you why).
10. California and other US state privacy laws
- We do not sell personal information, and we do not use it for cross-context behavioural advertising unless you have accepted advertising cookies.
- You can opt out of any “sale” or “sharing” at any time through the Do Not Sell or Share My Personal Information link in the cookie banner or footer. If your browser sends a Global Privacy Control (GPC) signal, we treat it as an opt-out automatically.
- You have the right to know, delete and correct personal information, and we will not treat you differently for using these rights.
11. Security
We protect data with HTTPS everywhere, an up-to-date server with a web application firewall and malware scanning, limited administrator access, sign-in by one-time email links instead of stored passwords, and regular backups. Payment card data never reaches our servers. If a breach puts your rights at risk, we will tell you and the relevant authority as the law requires.
12. Children
The site is meant for IT professionals and is not directed at children under 16. We do not knowingly collect data from children. If you believe a child has given us personal data, contact us and we will delete it.
13. Automated decisions
We do not make decisions with legal or similarly significant effects about you based solely on automated processing. Tool scores (for example the email deliverability score) are technical assessments of a message or server, not of you.
14. Changes
We update this policy when our services or the law change. The date below shows the current version. If a change is significant, we will tell account holders by email.
Last updated: 2 October 2026.