Privacy Notice

Last updated: 2026-05-10

This Privacy Notice explains how TallNBurly ("we", "us") collects and uses your personal data when you use Scriptd Hearts (the "Service"). We act as the data controller for personal data we collect through the Service.

Personal data we collect

  • Account data: email address used to sign in.
  • Service content: messages you paste into the Decoder and the AI's analysis. Saved only if you click "Save to history".
  • Usage and device data: log data, IP address, browser type, referring URLs, used to operate and secure the Service.
  • Support communications: any messages you send us.

Why we use it

  • To create and operate your account and provide Pro features (contract performance);
  • To analyze the messages you submit and return AI results (contract performance);
  • To prevent fraud and abuse and secure the Service (legitimate interests);
  • To improve the Service (legitimate interests);
  • To respond to support requests (contract / legitimate interests);
  • To comply with legal obligations.

Who we share data with

  • Paddle.com — our Merchant of Record. Handles checkout, payments, subscription management, taxes, refunds, and invoicing. See Paddle's privacy notice.
  • Hosting and infrastructure providers — Lovable Cloud (database, authentication, file storage).
  • AI processing — Lovable AI Gateway routes Decoder prompts to large-language-model providers (e.g. Google, OpenAI). The prompt and message are sent to these providers solely to generate your result.
  • Professional advisers (legal, accounting) where required.
  • Authorities where required by law.

We do not sell your personal data.

International transfers

Our service providers may process data outside your country, including in the United States. Where applicable we rely on Standard Contractual Clauses or equivalent safeguards.

Data retention

We keep account data while your account is active. Saved Decoder history is kept until you delete it or close your account. Logs are retained for a reasonable period for security and operations. Payment records are retained by Paddle as required by law.

Your rights

Depending on your jurisdiction you may have rights to access, correct, delete, restrict, port, or object to processing of your personal data, and to withdraw consent. To exercise these rights, contact us via support. EU/UK users have the right to complain to a supervisory authority. We aim to respond within one month.

Security

We use appropriate technical and organisational measures including encryption in transit and access controls.

Cookies

We use cookies and similar storage strictly necessary to keep you signed in and to operate the Service. We do not use marketing or advertising cookies.

Contact

For privacy questions or to exercise your rights, contact us via the support channels listed on the site.