Privacy Policy

Last updated: June 30, 2026

TL;DR — We never read your page content, track your browsing history, or sell your data. We only know which domain you are on, whether you saw an ad for 2+ seconds, and whether you clicked it.

1. Who We Are

ScrollPay ("we", "us", or "our") operates the ScrollPay Chrome extension (Extension ID: fgdofdfagpjbbmkcgjmnfidokeopdcip) and the website at scrollpay.app. This Privacy Policy explains how we collect, use, store, share, and protect personal data when you use our extension or website.

For questions or requests related to this policy, contact us at privacy@scrollpay.app.

2. What Data We Collect and Why

The table below describes all personal and sensitive data we collect, the purpose for collecting it, and the legal basis where applicable.

Data Purpose Legal Basis
Domain name (e.g. "twitter.com") — not the full URL, not page content To display the ad widget on supported sites and attribute impressions correctly Legitimate interest / performance of contract
Ad impression signal — whether the widget was visible for 2+ seconds To award XP and report aggregated view counts to advertisers Performance of contract
Ad click signal — whether you clicked the call-to-action button To award click-bonus XP and bill advertisers accurately Performance of contract
Email address and account password — entered voluntarily in the extension popup's "Sign in" form to connect your scrollpay.app account To authenticate you to your ScrollPay account via Google Firebase Authentication. Your password is transmitted directly to Firebase Auth using the official Firebase SDK and is never received, stored, or logged by ScrollPay's own servers. Only a Firebase-issued authentication token (not your password) is used in subsequent API calls. Consent / performance of contract
Referral code (optional, provided by you) To credit the person who referred you Legitimate interest
User ID — a randomly generated identifier stored locally To associate XP and session data with your account without requiring a login Legitimate interest / performance of contract
XP balance and transaction history To display your earnings, process redemptions, and prevent abuse Performance of contract
Payout information (e.g. Bitcoin wallet address, provided by you at withdrawal) To process BTC payouts Performance of contract
IP address — your device's network IP, captured on each earn request To enforce per-IP rate limits (max 10 requests/minute), detect multi-account abuse (3+ accounts earning from the same IP in one day), and prevent fraud. IP addresses are stored transiently for fraud analysis and are not linked to browsing activity. Legitimate interest (fraud prevention and platform integrity)
Miner handle / nickname (optional, chosen by you) To display your identity on the public leaderboard and in the XP marketplace. Handles are publicly visible — do not use your real name unless you intend for it to be public. Consent
Referral code and referral relationships To attribute recruits to referrers, calculate override XP bonuses, and detect referral fraud rings Legitimate interest / performance of contract

3. Data We Do Not Collect

We are designed to collect the minimum data necessary. We do not collect:

The extension's content script runs on all URLs (<all_urls> permission) solely to inject the ad widget overlay. It does not read, transmit, or store any page content.

4. IP Address Collection and Use

Each time the extension submits an earn request to our servers, your device's IP address is transmitted as part of the standard HTTP request. We use IP addresses solely for the following purposes:

IP addresses are stored in Google Firebase Firestore. Rate-limit records expire after 5 minutes. IP-to-account mapping records are retained for 8 days and then automatically overwritten. We do not use IP addresses for geolocation targeting, advertising, or any purpose other than those described above.

We do not sell, rent, or share IP addresses with third parties except as required by law.

5. Passwords and Account Credentials — Full Disclosure

The extension popup contains a "Sign in & Connect" form where you may optionally enter your scrollpay.app email address and password to link your website account to the extension. Here is exactly how those credentials are handled:

The content script (which runs on all websites) never touches passwords. Although the content script is granted the <all_urls> permission to inject the ad widget overlay, it:

In summary: the only password ScrollPay ever receives is your own ScrollPay account password, entered voluntarily in the extension popup's sign-in form, and it is processed exclusively by Firebase Auth — not by ScrollPay. No third-party passwords, session cookies, or credentials are ever accessed. If you have any concerns, you may inspect the extension's source code by navigating to chrome://extensions, enabling Developer Mode, and clicking "Inspect views".

6. How We Handle and Use Your Data

7. Data Storage

8. Data Sharing and Disclosure

We do not sell, rent, or trade your personal data. We share data only in the following limited circumstances:

9. Data Retention

We retain your account data for as long as your account is active. If you request account deletion, we will remove your personal data within 30 days, except where retention is required by law (e.g. financial transaction records, which may be retained for up to 7 years). Aggregated, anonymized analytics data may be retained indefinitely as it cannot identify you.

10. Data Security

We implement industry-standard security measures to protect your data, including:

No method of electronic storage or transmission is 100% secure. If you believe your account has been compromised, contact us immediately at privacy@scrollpay.app.

11. Third-Party Services

The extension integrates with the following third-party services. Each has its own privacy policy:

We do not embed third-party analytics SDKs (e.g. Google Analytics, Mixpanel) in the extension.

12. International Data Transfers

Your data is stored and processed primarily in the United States via Google Firebase. If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, your data may be transferred to and processed in a country with different data protection laws. Such transfers rely on Google's Standard Contractual Clauses or other appropriate safeguards.

13. Your Rights

Depending on your location, you may have the following rights regarding your personal data:

To exercise any of these rights, email privacy@scrollpay.app. We will respond within 30 days. We may verify your identity before fulfilling a request.

You may also uninstall the extension at any time to immediately stop all data collection by the extension.

14. Children's Privacy

ScrollPay is not directed at children under the age of 13 (or 16 in the EEA). We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, please contact us at privacy@scrollpay.app and we will delete it promptly.

15. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date at the top of this page and, where feasible, provide in-extension notice. Your continued use of ScrollPay after changes are posted constitutes acceptance of the updated policy. We encourage you to review this page periodically.

16. Contact

For privacy-related questions, requests, or complaints, contact us at:

ScrollPay
Email: privacy@scrollpay.app

If you are in the EEA and believe we have not handled your data in compliance with applicable law, you have the right to lodge a complaint with your local data protection authority.