SoftScrolls
Menu

Privacy Policy

Last updated: September 21, 2026

SoftScrolls is run by one person - Jebin J S, an independent developer based in India. There is no company behind this, no marketing department, and no customer database. That shapes everything below: most of this policy is about what Google's advertising and analytics products do on a site that carries them, because that is genuinely the largest thing happening to your data here.

We do not sell your personal data, and we have never been paid for anyone's email address.

The short version

  • There are no accounts on this site, so there is nothing for you to log into and nothing for us to lose.
  • We use Google Analytics to see which pages get read, and Google AdSense to pay for the hosting. Both set cookies and both send data to Google.
  • The contact form sends us your name, your email address and your message. It goes to an inbox. That is the whole system.
  • The mockup and screenshot tools run entirely in your browser. The images you load into them never reach our server, because there is no code in the app that could send them.
  • Our Android apps store their data on your device. Two of them show ads, which means Google's ad SDK sees an advertising ID.
  • You can turn off the ad personalisation and the analytics, and the links to do it are further down rather than buried.

Who we are, and how to reach us

SoftScrolls is the trading name used by Jebin J S, an individual publisher and Android developer in India. Under India's Digital Personal Data Protection Act we are the data fiduciary for the data described here; under the GDPR and the UK GDPR we are the controller; under California law we are the business.

Write to contact.jebinjs@gmail.com for anything in this policy, including a request to see, correct or delete what we hold. The same address handles grievances, so there is no separate escalation route to find - it reaches the person who can actually do something. We aim to answer within seven days and to finish the job within thirty.

What this policy covers

This website, the calculators and tools on it, the contact form, and the Android apps we publish on Google Play: Money Manager, Block Puzzle Gems and Party Flashlight.

It does not cover Google Play itself, or any site we link to. When you follow a link out of here you are on someone else's property under someone else's policy, and we have no visibility into what they do.

What we collect on this website

Things you choose to send us

The contact form asks for four things, and refuses to submit without them: your name, your email address, what the message is about, and the message itself. All four are put in an email and sent to our inbox by Resend, which is the service that does the actual delivering. We reply from that inbox.

Two details worth stating plainly, because they are the kind of thing a policy usually skips:

Your IP address is read when you submit the form, and it is used to count how many messages have come from your connection in the last ten minutes. It is held in the server's memory for that window, it is never written to a database, and it is never put in the email. It exists to stop a script emptying our sending quota, and it disappears when the window closes or the server restarts.

The form also contains a hidden field that you will never see and never fill in. Automated submissions fill it in. When that happens the message is discarded and nothing is sent. It is a spam trap, not a tracker, and it reads nothing about you.

Why we are allowed to do this: you asked us a question and we are answering it. Under the GDPR that is our legitimate interest in running a contactable publication; under the DPDP Act it is the purpose you gave the data for.

How long we keep it: the message stays in the inbox while the conversation is useful and we clear correspondence older than twenty-four months. Ask us to delete a thread sooner and we will.

Things collected automatically when a page loads

Server logs. The site is served by our hosting provider, which records the usual things a web server records: the page requested, the time, the IP address the request came from, the browser's user agent string, and the referring page. These are operational records - they are how a broken page or an attack gets found - and they age out of the platform's retention automatically. We do not build profiles from them and we do not connect them to anything else.

Google Analytics 4. This tells us which articles people read, how they arrived, roughly where in the world they are, and whether a calculator got used. It works by setting cookies in your browser that hold a randomly generated identifier - a number that distinguishes one browser from another without knowing whose browser it is. Google receives your IP address as part of the request. For visitors in the EU, the UK and Switzerland, Google discards the IP before it is logged; the location we see is a coarse estimate derived from it, not an address.

We look at this in aggregate. There is no report in our account that shows an individual person's path through the site, and we have never tried to build one.

Google AdSense. The ads on this site are Google's, and they pay for the hosting, the domain and the time spent writing. When an ad loads, Google and its ad technology partners may set cookies or read ones already set, and may use them to choose which ad to show you, to cap how often you see the same one, to count clicks, and to detect fraud. Where personalised advertising is switched on for you, that selection draws on activity across other sites that use Google's advertising products, not just this one.

Google explains what it does with this data in How Google uses information from sites or apps that use our services, and the full picture is in the Google Privacy Policy. We are a publisher in that arrangement, not a party with access to the profile.

Fonts. The typefaces are downloaded to our server when the site is built and served from our own domain. Your browser never contacts Google's font servers, so loading a page here does not tell Google anything by itself.

Things that never leave your browser

The mockup studio, the screenshot generators and the device frame tools are unusual, and the difference is worth spelling out: they run as code in your browser, not as a service on our server.

Images you drop into them are held in your browser's own storage - IndexedDB for the artwork and the saved projects, localStorage for the small index that lets the project list appear instantly. Nothing is uploaded, because the application contains no upload. There is no account, no sync, and no copy of your work anywhere but your own machine. If you clear your browser's site data, your projects are gone and we cannot restore them, which is the honest cost of the tool working this way. Export a project to keep it.

This was a deliberate decision rather than a missing feature. People put unreleased product screenshots through these tools, and a tool that is structurally incapable of uploading them is worth more than one that promises not to.

The calculators work the same way. The numbers you type are used to produce the result in front of you and are not transmitted anywhere.

Typing in the search box sends your query to our own server, which ranks it against a prebuilt index and sends back the matching pages. We do not store search queries and we do not attach them to a visitor.

Cookies and similar technologies

A cookie is a small file a site asks your browser to keep. Here is what gets set and by whom.

Set byExamplesWhat it doesExpires
Google Analytics_ga, _ga_*Tells one browser apart from another so page views can be counted as sessionsUp to 2 years
Google AdSense and its partners__gads, __gpi, IDE, NID, test_cookieChooses and measures ads, limits repeats, detects click fraudSession to 2 years, depending on the cookie

The site itself sets no cookies of its own. It has no login, no cart, no preferences to remember on a server, and nothing that needs one.

Turning them off. Every browser can block or delete cookies, and blocking third-party cookies stops most of the above without affecting how the site reads. Google also publishes tools that work regardless of browser settings:

Consent. In the EEA, the UK and a growing number of other places, analytics and advertising cookies may only be set once you have agreed to them. We are rolling out a consent notice that asks before those scripts load. Until it is live on every page, the opt-out tools above are the immediate and reliable way to stop this, and they take effect straight away.

Our Android apps

Each app has a Data safety section on its Google Play listing, filled in by us and displayed by Google. That listing is authoritative for the version you installed. What follows is the plain-English summary.

Money Manager. Your financial records - transactions, accounts, budgets, loans, savings goals, investments - are written to a database on your phone and stay there. They are not uploaded, not backed up to us, and not visible to anyone but you. We have no server holding anyone's finances, which also means we cannot recover your data if you lose your device or uninstall the app without exporting first. Use the export feature.

Block Puzzle Gems and Party Flashlight. Both are free and supported by ads, with optional in-app purchases. Two consequences:

Ads are served by Google AdMob. The SDK receives your device's advertising ID - a resettable identifier Android provides for exactly this purpose - along with coarse device and app information, and uses it to select and measure ads. What Google does with it afterwards is covered by the same partner sites and apps policy linked further up this page.

You can reset that ID or delete it outright from Settings > Privacy > Ads on your device. Deleting it stops personalised advertising in every app on the phone, not only ours.

Purchases go through Google Play Billing. Google takes the payment and tells us that an entitlement was granted. We never see your card details, your billing address, or your name - the transaction is between you and Google.

Party Flashlight and the microphone. The Live Flash mode asks for microphone access so it can read how loud the room is and fire the flash in time. It measures a level. No audio is recorded, stored, or transmitted, and if you never open Live Flash the permission is never requested.

The game content in our apps is not directed at children, and we do not knowingly collect data from anyone we know to be under 13 - or under the higher age that applies where you live, which is 16 in parts of the EEA and 18 in India.

Who your data is shared with

Not sold, not traded, not rented. Shared with these, because each one performs a function we cannot perform ourselves:

WhoWhat they getWhat for
Google (Analytics, AdSense, AdMob, Play)Page views, cookie and advertising identifiers, IP address, device and app informationAudience measurement, serving and measuring ads, distributing and billing for apps
ResendThe contents of a contact form submissionDelivering the message to our inbox
Our hosting providerRequest logs, including IP addressServing the site and keeping it up

We will also disclose data where a law or a valid legal order requires it. If SoftScrolls is ever sold or transferred, this data would move with it, and this page would say so before it happened.

Where your data goes

We are in India. Google, Resend and our hosting provider all run infrastructure in the United States and elsewhere, so data described here is processed outside India, outside the EEA and outside the UK.

For transfers out of the EEA and the UK, those providers rely on the European Commission's Standard Contractual Clauses and the UK Addendum, and publish their terms. We have no separate mechanism of our own to offer, because we are not the party moving the data across borders - they are.

How long things are kept

WhatHow long
Contact form messagesUp to 24 months in the inbox, or until you ask us to delete the thread
Rate-limiting record of your IPTen minutes, in memory only
Google Analytics event dataPer the retention window set on the property, capped at 14 months. Aggregate reports outlive it
Advertising cookiesPer the expiry in the cookie table above, or until you clear them
Server logsPer the hosting platform's own retention, typically weeks rather than months
Anything in the browser toolsUntil you delete it. We never had a copy

Your rights

These belong to you wherever you are, and we will act on a request whether or not the law in your country compels us to. One email to the address at the top of this page starts any of them.

  • Know what we hold. Given the list above, the honest answer for most readers is "an analytics record that is not identifiable as you, and nothing else". If you have written to us, we hold that thread.
  • Get a copy, in a form you can take elsewhere.
  • Correct anything wrong.
  • Delete it.
  • Object to what we are doing with it, or ask us to restrict it.
  • Withdraw consent you gave, without that being harder than giving it was.

We may ask you to confirm who you are before acting, because handing someone else's messages to whoever asks would be the worse failure. We will not charge you, and we will not treat you differently for asking.

If you are in India. The Digital Personal Data Protection Act gives you access, correction, erasure and grievance redressal, and the right to nominate someone to exercise those rights if you cannot. Our grievance contact is the email address above. If we do not resolve your complaint, you can escalate it to the Data Protection Board of India.

If you are in the EEA or the UK. Our legal bases are: consent for analytics and advertising cookies; legitimate interests for keeping the site secure, answering your mail, and understanding in aggregate what gets read; and legal obligation where one applies. You have the rights listed above plus the right to complain to your national data protection authority, which in the UK is the ICO. You do not have to come to us first, though we would rather you did.

If you are in California. In the last twelve months we have collected identifiers (including IP address and cookie identifiers), internet activity information, coarse location inferred from IP, and - if you wrote to us - your name, email address and whatever you told us. Sources, purposes and recipients are all set out above. We do not sell personal information for money. Using advertising cookies is treated as "sharing" for cross-context behavioural advertising under the CPRA, and My Ad Center plus blocking third-party cookies is how you stop it today. We do not use sensitive personal information to infer characteristics, and we have never knowingly sold or shared the data of anyone under 16. You have the right to know, delete, correct, opt out and not be discriminated against for using any of them.

For completeness: SoftScrolls does not meet the revenue or volume thresholds that make the CCPA apply to a business. We are telling you this rather than implying an obligation we do not have - and we will still honour these requests.

Security

The site is served over HTTPS and pinned to it by HSTS, so a browser that has been here once will not fall back to plain HTTP. The pages also send headers that stop them being framed inside another site, hold back the full address of the page you came from when you follow a link out, and switch off the camera, microphone and location APIs entirely - this site has no use for any of the three. The contact endpoint validates everything it receives and rate-limits submissions, and mail leaves over an authenticated, encrypted connection.

The best security property here is structural rather than technical: we hold almost nothing. There is no user database to breach, no stored passwords, no payment details, and no copy of anything you made in the browser tools.

We are not going to tell you your data is perfectly safe. No one can say that honestly about anything connected to the internet. What we can say is that the amount of your data sitting on our side of the wire is close to zero, and that if we ever become aware of a breach affecting personal data we hold, we will tell the people affected without delay and report it to the relevant regulator inside the 72 hours that both the GDPR and India's DPDP Rules allow.

Children

This site and these apps are general-audience products, not directed at children. We do not knowingly collect personal data from a child, and we do not build profiles of anyone we have reason to believe is one. If you are a parent or guardian and believe your child has sent us something, email the address above and we will delete it.

Changes to this policy

When what we do changes, this page changes, and the date at the top records it. If a change is significant - a new category of data, a new recipient, a new purpose - we will say so on the page rather than quietly revising a sentence. If a change needs your consent, we will ask for it before it takes effect.

Contact

Questions, requests and complaints all go to contact.jebinjs@gmail.com, or through the contact page if you would rather use a form. See also our terms of service.