Privacy Policy

Last updated: February 24, 2026

This Privacy Policy describes how Scavio ("we", "us", or "our") collects, uses, and protects information when you use the Scavio API and related services ("Service"). By using the Service, you agree to the practices described here.

1. Information We Collect

1.1 Account Information

When you create an account, we collect:

  • Email address
  • Name (if provided)
  • Payment information (processed by our third-party payment provider; we do not store full card numbers)

1.2 API Usage Data

When you use the API, we automatically collect:

  • API request metadata (timestamps, endpoints called, HTTP status codes)
  • Search queries and parameters you submit
  • Credit consumption and rate limit usage
  • IP address and API Key used for each request

1.3 Website Data

When you visit our website, we may collect:

  • Browser type and version
  • Pages visited and referral source
  • Device and operating system information

2. How We Use Your Information

We use collected information to:

  • Provide, maintain, and improve the Service.
  • Process billing and manage your subscription.
  • Monitor and enforce rate limits and acceptable use policies.
  • Detect, prevent, and respond to fraud, abuse, and security incidents.
  • Send transactional emails (account confirmations, billing receipts, service alerts).
  • Respond to support requests.
  • Generate aggregated, anonymized usage analytics.

3. Data Retention

  • Account data is retained for the duration of your account and up to 30 days after deletion.
  • API request logs (including search queries) are retained for up to 90 days, then automatically purged.
  • Billing records are retained as required by applicable tax and accounting laws.

4. Data Sharing

We do not sell your personal information. We may share data with:

  • Payment processors (e.g., Stripe) to handle billing.
  • Infrastructure providers that host and deliver the Service, bound by data processing agreements.
  • Law enforcement when required by valid legal process.

5. Data Security

We implement industry-standard security measures to protect your data, including:

  • TLS encryption for all API traffic and website connections.
  • Hashed and salted storage of authentication credentials.
  • Access controls limiting employee access to production data.
  • Regular security reviews of our infrastructure.

No method of transmission or storage is 100% secure. If you discover a security vulnerability, please report it to support@scavio.dev.

6. Cookies

Our website uses essential cookies for authentication and session management. We do not use third-party tracking cookies. If we add analytics in the future, we will update this policy and provide opt-out options.

7. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access the personal data we hold about you.
  • Request correction of inaccurate data.
  • Request deletion of your data.
  • Export your data in a portable format.
  • Object to or restrict certain processing.

To exercise any of these rights, contact us at support@scavio.dev. We will respond within 30 days.

8. International Data Transfers

The Service is operated from the United States. If you use the Service from outside the US, your data may be transferred to and processed in the United States. By using the Service, you consent to this transfer.

9. Children

The Service is not directed to individuals under the age of 16. We do not knowingly collect personal information from children. If we learn that we have collected data from a child, we will delete it promptly.

10. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email or a notice on the Service at least 30 days before they take effect. The "Last updated" date at the top reflects the most recent revision.

11. Contact

Questions or concerns about this Privacy Policy? Contact us at support@scavio.dev.