Scriptus / Privacy
Privacy
What we collect, and how to ask us to stop
This page describes Scriptus’s practices on 4 September 2026. It is a factual description, not legal advice. Counsel should review it before you treat it as a customer contract.
Operator: Scriptus · Dallas, TX · hello@getscriptus.com · Last updated 4 September 2026
Three surfaces
Scriptus is not one website.
Marketing is this static site at getscriptus.com. It is HTML on Hostinger. It does not run the product.
The operator app is app.getscriptus.com. Tenant owners and staff sign in there to configure a workspace. Members of a tenant do not come to getscriptus.com to pay.
Reader chat lives on the operator’s own site through an embed. Readers talk to that operator’s bot. They are that operator’s users, not Scriptus marketing leads.
Marketing site (this host)
As of 4 September 2026, getscriptus.com does not load Google Analytics, ad pixels, or a tag manager. We do not set a marketing cookie. We do not show a cookie banner because there is nothing non-essential to consent to on this host.
Clicks on “Book a Demo” and slider changes on the ROI calculator can write a first-party event into the browser’s dataLayer. That record stays in the page until you leave. It is not forwarded to a third-party analytics vendor. If we later attach a tag manager, this page will say so and we will add a consent path before any non-essential cookie.
If you email hello@getscriptus.com, we receive whatever you put in the message. If you open Calendly, Calendly’s privacy policy applies to that booking. Scriptus does not see your card on either path: cards go to Stripe Checkout or stay with Calendly. They never post to a Scriptus form.
The calculator is a model. It does not ask for your name, email, or payment details.
Operator app
When you sign in at app.getscriptus.com we keep a session so the admin stays yours. The session uses an HttpOnly cookie named scriptus_session, bound to a server row, with a 24-hour absolute lifetime. Logout revokes it. We do not store operator passwords; sign-in is through our auth provider, then we issue that cookie.
Workspace records include the account you create (name, email, workspace slug), membership and role, knowledge you upload, prompts, branding, integration secrets you enter, and conversation logs for that workspace. Those records are scoped to that workspace. We do not use one tenant’s corpus to answer another tenant.
If public workspace signup is enabled, checkout for the Scriptus fee ($5,000 setup + $500/month) is Stripe Checkout. Scriptus stores the signup row and the provisioned workspace. Stripe stores the card. That flag is off until a signed webhook has been dogfooded; until then operators book on Calendly and do not pay on getscriptus.com.
Readers on an operator’s bot
A reader who chats on an operator’s site is using that operator’s product. Questions, trial state, and any subscriber grant live in that workspace. Reader checkout — if the operator turns it on — stays on the operator’s rail (Woo, Kajabi, Stripe, or Whop). Scriptus maps a product id to access. We do not take a cut of reader subscriptions.
If you are a reader and want a copy or a deletion of your chat, start with the operator whose site you used. You may also write hello@getscriptus.com and we will route the request to the workspace owner. We do not sell reader transcripts.
Processors we actually use
Hostinger serves this marketing site. Neon holds application data. Resend sends transactional email (magic links, workspace-ready). Stripe handles cards when someone pays Scriptus. Calendly handles demo booking. Voice, if an operator enables it, is synthesized on demand by the voice provider the workspace configured — Scriptus does not keep an audio cache. Generation models are called only for workspaces that have a model bound; we do not claim zero-retention or “no training” for every provider in writing yet. Ask hello@getscriptus.com for the current list for your workspace.
Access, correction, deletion
Email hello@getscriptus.com with “privacy request” in the subject. Say whether you want a copy, a correction, or a deletion, and which surface (marketing email, operator account, or a named reader on a named site).
Owner: the Scriptus operator inbox. Target: we start the work within 5 business days and aim to finish within 30 days. Operator account deletion removes the membership and, on written request from a tenant owner, the workspace data we hold for that tenant, subject to backups that rotate on a 35-day window and any legal hold. We keep a content-free deletion receipt. This is a manual process today — there is not a self-serve “delete my account” button on the marketing site.
Children
Scriptus is sold to operators with a body of published work. The marketing site and the operator app are not directed at children under 16. We do not knowingly collect their information here.
Changes
When the collection story changes — a pixel, a new processor, or a self-serve deletion path — we update this page and the date at the top. The terms cover the commercial engagement.