Privacy Policy
Last updated: 22 June 2026
This Privacy Policy explains how Scale Media AI("we", "us") processes personal data when you use Sales by ScaleMedia.ai(the "Service"). We act as the data controller. We are committed to the principles of the EU General Data Protection Regulation (GDPR/DSGVO) and applicable US privacy laws.
1. Data we process
- Account data: your email address, a securely hashed password, and (optionally) your name.
- Usage data: the website URLs you analyze, the generated reports, and token-usage totals.
- Technical data: a strictly-necessary session cookie for authentication. We do not use advertising or tracking cookies.
2. Purposes & legal bases (Art. 6 GDPR)
- Providing the Service and your account — performance of a contract (Art. 6(1)(b)).
- Securing the Service and preventing abuse — legitimate interests (Art. 6(1)(f)).
- Sending account emails (verification, password reset) — contract / legitimate interests.
3. Third-party processors & international transfers
When you run an analysis, the target URL and the public website content we fetch are sent to our AI gateway, OpenRouter, which routes the request to the underlying model (currently Google Gemini 3.1 Flash Lite), and are processed under those providers' terms and privacy policies. This may involve transfers outside the EU/EEA. We also use infrastructure and email providers acting as processors on our behalf. We rely on appropriate safeguards (e.g. Standard Contractual Clauses) where required.
4. Retention
We keep your account data and reports until you delete them or your account. You can delete individual reports at any time.
5. Your rights
Under the GDPR you have the rights of access, rectification, erasure, restriction, data portability, and objection. Residents of California and other US states may have rights to know, delete, and opt out of "sale/sharing" (we do not sell personal data). To exercise any right, contact us at info@scalemedia.ai. You may also lodge a complaint with a supervisory authority.
6. Security
Passwords are hashed (bcrypt), sessions use signed httpOnly cookies, and traffic is served over HTTPS. No method of transmission or storage is 100% secure, but we apply industry-standard measures.
7. Cookies
We use a single strictly-necessary cookie to keep you signed in. We do not use advertising or cross-site tracking cookies. Because only essential cookies are used, no consent is legally required, but you can review the details and manage your preferences in our Cookie Policyand via the "Cookie Settings" link in the footer.
8. Contact
Scale Media AI, Kurt-Schumacher-Str. 104, 82256 Fürstenfeldbruck, Germany. Email: info@scalemedia.ai. See also our Imprint.
This document is a template provided for convenience and is not legal advice. Please have it reviewed and adapted by a qualified lawyer before relying on it.
