Privacy policy
Last updated 30 August 2026
Scrolly is a mobile app where a small, invite-only group of friends share scrollies: usually a link to a video somewhere else, sometimes a video filmed on a phone. It is published and operated by 312.dev LLC, and the servers behind it are ours. Nothing about this app is a data business.
This policy says what we store, where it lives, how long it stays, and what you can ask us to do with it. If something here is unclear, ask: scrolly@312.dev.
The short version
- We store your account, the things you post, and what you have watched.
- We do not store the videos you link to from TikTok, Instagram, YouTube or anywhere else. We store the link. Your phone fetches the video.
- There is no analytics, no crash reporting, no advertising and no tracking of any kind in the app.
- We have never sold or shared anyone's information, and we are not going to.
- Delete your account from inside the app, and everything above goes with it.
What we store
| What | Where it comes from | Why we have it |
|---|---|---|
| Your email address, and if you signed in with Apple or Google, their account identifier for you. A Google sign-in also leaves us the tokens Google issues with it, which are what would let us ask Google again who you are | You, or Apple, or Google | Signing you in, and reaching you if we need to |
| Your username and profile picture | You | So other people in your group know who posted what |
| The links you post: the address, the title you give it, and the platform we read off the address. Scrollies carried over from the old Scrolly server also carry the original creator's name and a thumbnail address, which that server collected before this one existed | You. Nothing here fetches the page you linked to | Building the feed |
| Video files you upload from your camera or photo library, and the thumbnail your phone makes from each one | You, and your phone | Playing them back for your group |
| Comments, replies, hearts, emoji reactions, favourites, and any GIF you pick | You | They are the app |
| Which scrollies you have watched and how far through each one you got | Your app | Scrolly gives you posting credit for watching, so this is what that rule runs on |
| Your notification settings, and a push token for each device you enabled notifications on | You, and Apple or Google | Delivering notifications you asked for |
| Your sign-in sessions, each recorded with the IP address and the app or browser identification it was created from | Your device, automatically | Keeping you signed in. Deleting your account ends every one of them at once, which is the only way to end one you did not start on the device you are holding |
| Reports you file and members you block | You | Moderation. A report is visible to your group's host; a block is not visible to anyone but you |
| Your group's name, invite code, settings and time zone | Whoever set the group up | Running the group. The time zone is how the daily reminder knows it is morning where you are |
| Your phone number, only if you joined Scrolly back when signing in meant a text message | You, at the time. Nothing collects one now | Nothing. It is left over, and it is still on the record we hold for you. See below |
About that last row. Scrolly used to sign people in with a text message. It does not any more: sign-in is Apple, Google or an emailed code, nothing sends a text message, and nothing asks anybody for a number. A host adding somebody to a group used to be asked for theirs and is not any more; a member added now gets a placeholder in that field, derived from their own account, that never was a phone number.
What we have not done is delete the numbers we already hold. The column they sit in cannot be left empty and cannot be removed without rebuilding the table, and that rebuild is waiting on something else. So if you joined during the text-message era, your number is still on your record, nothing reads it, and it goes when your membership does. We would rather say that than call it gone.
What we do not store
- Third-party video and audio. When someone posts a TikTok, a Reddit clip, an Instagram reel or a YouTube video, the server keeps a link and the social details around it. Your phone goes and gets the media from the platform it lives on, at the moment you play it. There is no copy on any server of ours. The other half of that is worth saying: because your phone asks the platform for the video directly, that platform sees the request, the same way it would if you had opened the link in a browser. Avoiding it would mean keeping a copy on our server, which is the thing we are not doing.
- Anything about how you use the app, beyond what is listed above. There is no analytics package, no crash reporter, no session recorder, no advertising SDK, and no marketing pixel anywhere in Scrolly. We do not read your advertising identifier. We do not build a profile of you.
- Your location. The app never asks for it. The closest thing we hold is your group's time zone, which someone typed in once.
- Payment information. Scrolly does not charge for anything.
- Passwords. There are none. Sign-in is Apple, Google, or a six-digit code emailed to you, and the code is stored encrypted and expires in ten minutes.
- Private messages. Scrolly has no direct messaging. Every comment is visible to your group.
Who else touches it
These are the companies we use to run Scrolly. Each one gets only what it needs to do its job, and none of them is allowed to use it for anything else.
| Company | What reaches them |
|---|---|
| Cloudflare | Every request to Scrolly passes through their network, so they see your IP address. They also store the files you upload. |
| Turso | The database, hosted in Ohio. Everything in the table above except uploaded files. |
| Expo | Notifications are handed to Expo to deliver, so they see your push token and the notification text, which can include a username and the first part of a comment. Expo also serves app updates, which tells them your app version and platform. |
| Apple and Google | Their push services deliver the notification to your device. If you sign in with Apple or Google, they also confirm your identity to us. Apple's Hide My Email works: we get the relay address and never see your real one. |
| Resend | Your email address and the six-digit sign-in code, when you sign in that way. |
| Giphy | What you type into the GIF search box, which our server asks them for on your behalf. The picture itself is a different matter: your phone fetches every GIF straight from Giphy, so they see your IP address, including for a GIF somebody else posted in a thread you are only reading. |
| The App Store and Google Play | They collect their own install and crash data under their own policies. We cannot switch that off and we do not see anything from it that identifies you. |
How long we keep it
Nothing is deleted on a schedule. Assume that what is in your group stays in your group until somebody removes it, and that removing it is something a person does.
- A scrollie deleted from the group is really gone: the row, every file we stored for it, and the comments, reactions and watch records attached to it. Your group's host can delete any scrollie in the group. For your own, email us and we will take it down.
- A deleted comment is gone, along with any replies to it.
- Sign-in sessions expire ninety days after their last use.
- A push token whose device Apple or Google tells us is gone is deleted, along with the delivery records for it, within about fifteen minutes of them saying so.
- Sign-in codes expire in ten minutes.
- When a host removes someone from a group, that person's username and phone number are overwritten and their notification settings and push tokens are deleted. What they posted stays where it is, because deleting it would take other people's comments and reactions with it. Deleting all of it is what deleting your account is for, and that asks which you want before it does anything.
- Our database provider keeps rolling snapshots so we can recover from a failure, so deleted rows can survive in one until it rolls off. We never open a snapshot to bring back something somebody asked us to delete, and re-applying a deletion is part of any restore.
What is on your phone
Your sign-in token lives in the operating system's secure storage, the Keychain on iOS and encrypted preferences whose key is held in the Android Keystore on Android. Your preferences and a cache of scrollies you have already watched live in ordinary app storage. Deleting the app removes all of it, and removes nothing from the server.
Your choices
- Turn notifications off in Settings and the push token for that device is deleted.
- Change your username, and add or remove your profile picture, whenever you like.
- Ask us to take down any scrollie or comment you posted, without closing your account.
- Block anyone in your group.
- Ask us for a copy of everything we hold about you.
- Ask us to correct something that is wrong.
- Delete your account and everything attached to it, from Settings in the app or by asking us.
Deleting your account is a button: Settings, then Delete account. It asks what to do with your scrollies and comments, and then does it, with nobody in the middle. Everything else on that list is one email to scrolly@312.dev, and so is deleting your account if you cannot get into the app. We will confirm we got it within ten business days and finish within forty-five days, which is the deadline California sets and the one we apply to everybody. If we cannot do something you asked for, we will say why rather than going quiet. You will never be treated differently for asking, and there is nothing to treat you differently with: the app has no paid tier.
You can have someone else make a request for you. We will ask you to confirm it is genuinely on your behalf before we act on it.
US state privacy laws
California's Consumer Privacy Act, and the comparable laws in Virginia, Colorado, Connecticut, Utah, Indiana, Kentucky and Rhode Island, each apply to businesses above a size threshold. The lowest of those thresholds is thirty-five thousand residents of one state; the California revenue threshold is over twenty-six million dollars a year. Scrolly has a few dozen users in total and earns nothing. None of these laws applies to it, and we would rather say that plainly than pretend to a compliance programme we do not have.
The rights those laws grant are cheap to honour at this size, so we honour them anyway. That is the list in the previous section: know, access, correct, delete, take a copy with you, and not be penalised for asking.
Three things those laws ask about by name:
- Sale or sharing. We have never sold personal information and we have never shared it for cross-context behavioural advertising, which is the other thing California means by that word. There is no advertising in Scrolly at all. So there is no Do Not Sell or Share My Personal Information link on this site, because there is nothing behind it. If your browser sends a Global Privacy Control signal, it is already satisfied. The same is true of the older Do Not Track header some browsers still send: nothing here tracks you across other sites over time, so a Do Not Track signal has nothing to turn off.
- Sensitive personal information. We do not collect any of it. No government identifiers, no financial account details, no precise location, no race, religion or union membership, no genetic, neural or biometric data, no health information, and nothing about anyone's sex life or sexual orientation. There is therefore no Limit the Use of My Sensitive Personal Information link either.
- Automated decisions. Nothing decides anything about you: no access, no eligibility, no price, no profile. The feed does sort itself, and you pick how. Oldest first is time. Round robin takes turns between whoever posted. Best puts the scrollies with the most watches, reactions and comments at the top and then takes turns as well, so one person does not fill the screen. Those counts are the group's, not yours, and the only part of the feed that depends on you is which scrollies you have already watched.
Children
Scrolly is not for children under 13 and we do not knowingly hold anything from one. Groups are invite-only, so who is in a group is decided by the person who runs it. If you believe a child under 13 has an account, email us and we will delete it.
Security
Everything travels over HTTPS. Uploaded files are in a private bucket that no public URL reaches; every read goes through a check that you are in the group the file belongs to. Sign-in codes are stored encrypted rather than in the clear: the database alone cannot read one back, and the one thing that can is server-side, with no web route in front of it. Nobody outside 312.dev LLC has access to the database.
We are a very small operation and we will not pretend otherwise. If you find a security problem, email scrolly@312.dev and we will take it seriously.
Changes
If this policy changes, the date at the top changes with it and the current version is always at scrolly.312.dev/privacy. If a change actually affects what happens to your data, we will tell you in the app rather than quietly editing this page.
Contact
312.dev LLC, publisher and operator of Scrolly.