Skip to content
SCRAPFALL

Legal

Privacy

Last updated 20 August 2026.

What we store

What we do not store

Card numbers never reach our servers: checkout is hosted by Stripe, which sends back an identifier and a result. We do not run advertising trackers, we do not sell anything to anyone, and no personal data appears in our logs.

Cookies

Two, both strictly necessary. One holds the rotating refresh token that keeps you signed in; it is HttpOnly, so no script can read it. The other holds a CSRF token, which is readable on purpose because the page has to echo it back in a header. There are no analytics cookies.

Erasure

Delete your account from the account page. It stops working immediately and every session ends. Thirty days later everything that identifies or describes you is permanently erased — your address, your profile, your stash, your sessions, your progress, your links to Google or Discord. The window exists so a deletion made in anger at two in the morning can still be undone. A nightly job does the erasing; nobody has to remember.

Financial records tied to a completed purchase are kept as long as tax law requires, which is the one exception — and they are kept pseudonymised. At erasure they are detached from you and stamped with a fresh random code that appears nowhere else and maps to nothing: an auditor can still see that a purchase happened, for how much, on what date, and which movements belonged together. They cannot see whose. Our copy of the payment processor’s own record of the checkout, which carries your address, is emptied at the same moment.

Contact

Access, correction and erasure requests go to contact.

Privacy · SCRAPFALL