Last updated: June 30, 2026
TL;DR — We never read your page content, track your browsing history, or sell your data. We only know which domain you are on, whether you saw an ad for 2+ seconds, and whether you clicked it.
ScrollPay ("we", "us", or "our") operates the ScrollPay Chrome extension (Extension ID: fgdofdfagpjbbmkcgjmnfidokeopdcip) and the website at scrollpay.app. This Privacy Policy explains how we collect, use, store, share, and protect personal data when you use our extension or website.
For questions or requests related to this policy, contact us at privacy@scrollpay.app.
The table below describes all personal and sensitive data we collect, the purpose for collecting it, and the legal basis where applicable.
| Data | Purpose | Legal Basis |
|---|---|---|
| Domain name (e.g. "twitter.com") — not the full URL, not page content | To display the ad widget on supported sites and attribute impressions correctly | Legitimate interest / performance of contract |
| Ad impression signal — whether the widget was visible for 2+ seconds | To award XP and report aggregated view counts to advertisers | Performance of contract |
| Ad click signal — whether you clicked the call-to-action button | To award click-bonus XP and bill advertisers accurately | Performance of contract |
| Email address and account password — entered voluntarily in the extension popup's "Sign in" form to connect your scrollpay.app account | To authenticate you to your ScrollPay account via Google Firebase Authentication. Your password is transmitted directly to Firebase Auth using the official Firebase SDK and is never received, stored, or logged by ScrollPay's own servers. Only a Firebase-issued authentication token (not your password) is used in subsequent API calls. | Consent / performance of contract |
| Referral code (optional, provided by you) | To credit the person who referred you | Legitimate interest |
| User ID — a randomly generated identifier stored locally | To associate XP and session data with your account without requiring a login | Legitimate interest / performance of contract |
| XP balance and transaction history | To display your earnings, process redemptions, and prevent abuse | Performance of contract |
| Payout information (e.g. Bitcoin wallet address, provided by you at withdrawal) | To process BTC payouts | Performance of contract |
| IP address — your device's network IP, captured on each earn request | To enforce per-IP rate limits (max 10 requests/minute), detect multi-account abuse (3+ accounts earning from the same IP in one day), and prevent fraud. IP addresses are stored transiently for fraud analysis and are not linked to browsing activity. | Legitimate interest (fraud prevention and platform integrity) |
| Miner handle / nickname (optional, chosen by you) | To display your identity on the public leaderboard and in the XP marketplace. Handles are publicly visible — do not use your real name unless you intend for it to be public. | Consent |
| Referral code and referral relationships | To attribute recruits to referrers, calculate override XP bonuses, and detect referral fraud rings | Legitimate interest / performance of contract |
We are designed to collect the minimum data necessary. We do not collect:
The extension's content script runs on all URLs (<all_urls> permission) solely to inject the ad widget overlay. It does not read, transmit, or store any page content.
Each time the extension submits an earn request to our servers, your device's IP address is transmitted as part of the standard HTTP request. We use IP addresses solely for the following purposes:
IP addresses are stored in Google Firebase Firestore. Rate-limit records expire after 5 minutes. IP-to-account mapping records are retained for 8 days and then automatically overwritten. We do not use IP addresses for geolocation targeting, advertising, or any purpose other than those described above.
We do not sell, rent, or share IP addresses with third parties except as required by law.
The extension popup contains a "Sign in & Connect" form where you may optionally enter your scrollpay.app email address and password to link your website account to the extension. Here is exactly how those credentials are handled:
chrome.storage, not in Firestore, and not in any log. Only the Firebase-issued token is stored locally and used for authenticated API calls.The content script (which runs on all websites) never touches passwords. Although the content script is granted the <all_urls> permission to inject the ad widget overlay, it:
In summary: the only password ScrollPay ever receives is your own ScrollPay account password, entered voluntarily in the extension popup's sign-in form, and it is processed exclusively by Firebase Auth — not by ScrollPay. No third-party passwords, session cookies, or credentials are ever accessed. If you have any concerns, you may inspect the extension's source code by navigating to chrome://extensions, enabling Developer Mode, and clicking "Inspect views".
chrome.storage.local on your device. This data never leaves your device except as part of authenticated API requests to our servers.localStorage.We do not sell, rent, or trade your personal data. We share data only in the following limited circumstances:
We retain your account data for as long as your account is active. If you request account deletion, we will remove your personal data within 30 days, except where retention is required by law (e.g. financial transaction records, which may be retained for up to 7 years). Aggregated, anonymized analytics data may be retained indefinitely as it cannot identify you.
We implement industry-standard security measures to protect your data, including:
No method of electronic storage or transmission is 100% secure. If you believe your account has been compromised, contact us immediately at privacy@scrollpay.app.
The extension integrates with the following third-party services. Each has its own privacy policy:
We do not embed third-party analytics SDKs (e.g. Google Analytics, Mixpanel) in the extension.
Your data is stored and processed primarily in the United States via Google Firebase. If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, your data may be transferred to and processed in a country with different data protection laws. Such transfers rely on Google's Standard Contractual Clauses or other appropriate safeguards.
Depending on your location, you may have the following rights regarding your personal data:
To exercise any of these rights, email privacy@scrollpay.app. We will respond within 30 days. We may verify your identity before fulfilling a request.
You may also uninstall the extension at any time to immediately stop all data collection by the extension.
ScrollPay is not directed at children under the age of 13 (or 16 in the EEA). We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, please contact us at privacy@scrollpay.app and we will delete it promptly.
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date at the top of this page and, where feasible, provide in-extension notice. Your continued use of ScrollPay after changes are posted constitutes acceptance of the updated policy. We encourage you to review this page periodically.
For privacy-related questions, requests, or complaints, contact us at:
ScrollPay
Email: privacy@scrollpay.app
If you are in the EEA and believe we have not handled your data in compliance with applicable law, you have the right to lodge a complaint with your local data protection authority.