Privacy Policy
Effective date: August 2026 · Last updated: August 2026
This Privacy Policy explains how SCRIBA (“SCRIBA”, “we”, “us”, or “our”) collects, uses, shares, and protects information in connection with the SCRIBA content automation service and application. SCRIBA is operated by Ran Hodos, a licensed sole proprietor (“עוסק מורשה”) in Israel, under the trade name SCRIBA. This is our own privacy policy for the SCRIBA application and service.
1. Who this policy is for
SCRIBA is a business-to-business service. Our customers are professionals and business owners (“Clients”) who authorize SCRIBA to create and publish content on their behalf to their own social media accounts and websites. This policy describes the information we handle for those Clients and for the connected accounts they authorize.
2. What information we collect
We collect the following categories of information:
- Information you provide to us. When a Client onboards, we collect details such as name, business or brand name, email address, website, professional field, target audience, content preferences, brand colors, and example stories or materials provided for content creation.
- Information obtained through Meta permissions. When a Client authorizes SCRIBA to manage their content through Meta’s APIs, we access and store the identifiers and credentials required to publish on their behalf. This includes the Facebook Page ID, the Instagram Business Account ID, and the access token issued by Meta for that authorization. We also read the limited Page and account data required to publish content and to confirm that content was published (for example, published post identifiers and basic engagement metadata).
- Content. The text, articles, and images that SCRIBA generates for the Client, and the posts published to the Client’s connected accounts.
- Information collected automatically. When our application is used, we and our service providers may automatically collect technical and usage information such as IP address, browser and device information, log data, timestamps, and error diagnostics.
3. How we use information and why
We process information for the following purposes:
- To provide the core service: generating content and publishing it on the Client’s behalf to their authorized Facebook Page, Instagram Business account, LinkedIn profile, and blog or website.
- To send the Client approval emails containing content previews, and to act on the Client’s approvals.
- To confirm successful publication and to record the resulting post identifiers.
- To operate, maintain, secure, troubleshoot, and improve the service.
- To communicate with the Client about their account and service.
We process this information to perform our service for the Client and based on the authorization the Client grants (including the authorization granted through Meta’s permission flow). We do not sell personal information, and we do not use it for advertising to third parties.
4. How information is shared
We share information only as needed to operate the service, with the following categories of service providers (“sub-processors”), each of which processes data on our behalf:
- Meta Platforms, Inc. — to publish content to, and confirm publication on, the Client’s connected Facebook Page and Instagram Business account, through the Meta APIs.
- Anthropic — to generate content text using the Claude API.
- Supabase — for database and file storage of content, images, and configuration.
- Render — for application hosting.
- Microsoft 365 — for sending and managing service email.
We may also disclose information if required by law, to comply with legal process, or to protect the rights, property, or safety of SCRIBA, our Clients, or others.
5. Data retention
We retain information for as long as it is needed to provide the service to the Client, and as required to comply with our legal obligations, resolve disputes, and enforce our agreements. When information is no longer needed, we delete it or take steps to render it no longer identifiable. A Client may end the service and request deletion at any time (see “How to request deletion” below).
6. Security
We take reasonable technical and organizational measures to protect the information we handle, including the access tokens used for publishing. Access tokens are stored in restricted server environments and are not exposed publicly. No method of transmission or storage is completely secure, but we work to protect information against unauthorized access, alteration, and disclosure.
7. How to request deletion of your data
You may request access to, correction of, or deletion of your data at any time. To make a request, contact us at the email address below and describe your request. We will respond and act on valid deletion requests within a reasonable time. A Client may also revoke SCRIBA’s access to their connected accounts at any time through their Meta account settings, which stops any further access or publishing.
Data deletion and privacy requests:
Email: office@scriba.biz
8. Children
SCRIBA is a business service intended for use by adults. It is not directed to individuals under the age of 18, and we do not knowingly collect personal information from children.
9. International users
SCRIBA is operated from Israel, and information may be processed and stored by us and our service providers in Israel and in other countries where those providers operate. By using the service, you understand that information may be transferred to and processed in these locations.
10. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date at the top of this page. Material changes will be communicated to Clients where appropriate.
11. Contact us
If you have any questions about this Privacy Policy or our handling of information, contact us:
SCRIBA (operated by Ran Hodos, עוסק מורשה)
Email: office@scriba.biz
Website: https://www.scriba.biz/
This page is the official privacy policy of the SCRIBA application and service.