Privacy Policy

Last updated: April 1, 2026

ScalitOS SRL ("we", "us", "our") operates the ScalitOS platform. This Privacy Policy explains how we collect, use, store, and protect your personal data when you use our service. We are committed to protecting your privacy and complying with the General Data Protection Regulation (GDPR) and applicable EU data protection laws.

1. Data We Collect

We collect the following categories of personal data:

Account Data

When you create an account, we collect your name, email address, and an encrypted version of your password. If you subscribe to a paid plan, we process billing information through our payment processor (Stripe) — we never store your full card details on our servers.

Usage Data

We automatically collect data about how you interact with ScalitOS, including pages visited, features used, content generated, timestamps of activity, and device/browser information. This helps us improve the platform and provide you with relevant analytics.

Content Inputs

When you use our features, we process the text, prompts, brand information, images, and other content you provide as input. This data is used exclusively to generate your requested outputs and improve your personalized experience within the platform.

Uploaded Files

If you upload images, videos, or documents as reference material for ad creation or content generation, these files are stored securely on our servers and may be analyzed by our AI systems to deliver accurate results. You retain full ownership of your uploaded content.

2. How We Use Your Data

  • Service delivery — to create your account, authenticate your sessions, process your content generation requests, and deliver the core ScalitOS experience.
  • Personalization — to tailor written for you outputs to your brand profile, voice DNA, and content preferences.
  • Analytics and improvement — to understand platform usage patterns and improve our features, performance, and user experience.
  • Billing — to process payments, manage subscriptions, and send transaction-related communications.
  • Communication — to send you service updates, security alerts, and (with your consent) product announcements. You can opt out of marketing communications at any time.
  • Legal compliance — to meet our legal obligations, respond to lawful requests, and protect our rights.

3. AI Processing and Third-Party Providers

ScalitOS uses third-party AI services, including OpenAI's language models (GPT-5.2), image generation (GPT Image 1), video generation (Sora 2), and text-to-speech services to power its features. When you use features:

  • Your input prompts and content are sent to these providers for processing.
  • These providers process data in accordance with their own privacy policies and data processing agreements we hold with them.
  • We do not use your content to train AI models. Your inputs are processed transiently to generate outputs and are not retained by third-party providers beyond what is necessary for content delivery.
  • written for you outputs are stored in your account for your access and are not shared with other users.

4. Data Sharing

We do not sell, rent, or trade your personal data to any third party. We share data only with:

  • Infrastructure providers — cloud hosting and database services that store your data securely under strict data processing agreements.
  • Payment processor — Stripe processes payment transactions on our behalf under PCI-DSS compliance.
  • AI service providers — OpenAI processes your content inputs for generation purposes only, as described above.
  • Legal requirements — we may disclose data if required by law, court order, or to protect the safety and rights of our users or the public.

5. Data Security

We implement robust technical and organizational measures to protect your data:

  • All data in transit is encrypted using TLS 1.2+ (HTTPS).
  • Passwords are hashed using bcrypt with unique salts — we never store plain-text passwords.
  • Authentication uses time-limited JWT tokens with secure session management.
  • Access to production systems is restricted to authorized personnel only.
  • We conduct regular security reviews and follow industry best practices.
  • Login attempt rate limiting and brute-force protection are active on all accounts.

6. Your Rights Under GDPR

As a data subject in the EU, you have the following rights:

  • Right of access — you can request a copy of the personal data we hold about you.
  • Right to rectification — you can update or correct inaccurate data directly in your account settings or by contacting us.
  • Right to erasure — you can request deletion of your account and all associated data. We will process this within 30 days.
  • Right to data portability — you can request your data in a structured, machine-readable format.
  • Right to restrict processing — you can request that we limit how we process your data in certain circumstances.
  • Right to object — you can object to data processing based on our legitimate interests.
  • Right to withdraw consent — where processing is based on consent, you can withdraw it at any time.

To exercise any of these rights, contact us at legal@scalitos.com. We will respond within 30 days. You also have the right to lodge a complaint with your local data protection authority.

7. Data Retention

We retain your personal data for as long as your account is active or as needed to provide our services. Specifically:

  • Account data — retained until you delete your account.
  • Generated content — retained in your account until you delete it or close your account.
  • Usage analytics — aggregated and anonymized data may be retained indefinitely for service improvement.
  • Billing records — retained for 7 years as required by Romanian tax and accounting regulations.
  • Login and security logs — retained for 90 days for security and fraud prevention.

After account deletion, we will remove your personal data within 30 days, except where retention is required by law.

8. International Data Transfers

Your data may be processed outside the European Economic Area (EEA) by our AI service providers. In such cases, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission, to protect your data to the same standard required within the EEA.

9. Contact

For privacy-related inquiries, data requests, or complaints:

ScalitOS SRL

Romania, EU

Email: legal@scalitos.com

If you have any questions about these policies or your rights, please contact us at legal@scalitos.com. We are committed to transparency and will respond to all inquiries within 30 days.

ScalitOS SRL · Romania, EU · All rights reserved © 2026