Privacy and data use

ScriptEngine Privacy Policy.

This policy explains how REFINO LIMITED processes personal data when you visit ScriptEngine, create an account, purchase credits, use the API, participate in referrals, or contact support.

  • Effective August 1, 2026
  • Last updated August 1, 2026
  • Version 2026-08-01-r1

1. Controller

Who we are.

ScriptEngine is operated by REFINO LIMITED, a private limited company registered in Cyprus under company number HE 375240.

34 Stratigou Timagia, Santa Maria Court, Floor 2, Office 201
3107 Limassol, Cyprus
support@scriptengine.org

REFINO LIMITED is generally the controller for the processing described here. Upstream API providers, payment services, and other recipients may act as processors, independent controllers, or in another role depending on the activity and applicable law.

2. Scope

When this policy applies.

This policy covers visits to scriptengine.org; account registration, sign-in, and password recovery; API keys and balances; orders and payments; API requests and usage records; referrals; support and privacy correspondence; and the online withdrawal process.

It does not replace a third party's own privacy notice where you interact directly with a payment page, wallet, blockchain, linked documentation, model provider, or other independent service.

3. Data categories

Personal data we process.

Account and authentication data

We process your email address, password hash, account identifiers, referral relationship, account timestamps, accepted policy versions, age-confirmation timestamp, and authentication records. Server-side session identifiers are stored in hashed form. Password-reset records include a hashed reset token, a hashed form of the requesting IP address, and relevant timestamps.

Session and cross-site request-forgery cookies can remain valid for up to 30 days unless cleared, invalidated, or replaced sooner. Password-reset links are valid for 60 minutes. Reset records are retained for security and rate-limiting needs and are periodically eligible for cleanup.

API keys and balances

We process API-key names, identifiers and masked prefixes; one-way key verifiers; encrypted upstream credentials; credit and quota values; delivery, rotation, status, top-up and balance-sync records; and related timestamps. A newly issued or rotated customer secret is intended to be displayed once.

Orders, payments, refunds, and withdrawals

We process package, amount, currency, credits, order status and timestamps; payment route; limited Stripe checkout and payment references; limited BTCPay invoice and store references; accepted policy versions and purchase confirmations; and refund, reversal, recovered-credit, debt, dispute, and withdrawal records.

Full card details are collected by Stripe rather than ScriptEngine. Cryptocurrency checkout uses BTCPay Server and the relevant public blockchain or payment network. ScriptEngine does not ask for or intend to store card security codes, wallet private keys, or seed phrases.

API usage and diagnostic data

Usage records may include the account and API-key identifiers; HTTP method and route; status; latency and time-to-first-token; requested, returned and upstream model identifiers; provider or route label; streaming status; response and upstream request identifiers; system fingerprint; input, output, cached, cache-creation, reasoning and total token counts; finish reason; limited error code, type and message; response content type and byte count; truncation or transport diagnostics; and timestamp.

Hosting, security, mail, and network systems may separately process IP address, user-agent, browser, device, request, delivery, and network information for operation and protection of the service.

Prompts, files, and outputs

ScriptEngine processes customer prompts, messages, files, images, tool inputs, and model outputs only as needed to route a request and return its response. ScriptEngine does not use customer API content to train AI models and does not intentionally persist complete request bodies or normal model outputs after request completion.

Returned data may be inspected transiently to extract usage and diagnostic fields. Limited provider error messages and response-derived diagnostic metadata can be recorded and may contain text returned by a provider. Do not place secrets or unnecessary sensitive information in API content or support material.

Upstream processing differs by route

API content is transmitted to third-party upstream providers. Depending on the provider, route, contract, and provider policy, a provider may retain, review, analyse, or use submitted content for safety, abuse prevention, service improvement, or model training. ScriptEngine does not guarantee zero retention or no training by every upstream provider.

Do not submit personal, confidential, regulated, payment, password, key, health, children's, or other sensitive data unless you have a lawful basis and have independently established that the relevant end-to-end processing is suitable.

Support, referrals, and correspondence

Support and privacy requests may contain your email, message, attachments, order or request identifiers, diagnostic details, and follow-up history. Referral records include referral codes and relationships, reward status, credit amounts, order associations, and timing. Referrer-facing views use masked buyer email addresses and do not expose buyer spend totals.

4. Browser storage and analytics

Necessary storage and optional GA4.

TechnologyPurposeTypical duration
se_sessionSecure signed-in sessionUp to 30 days
se_csrfProtect state-changing account requestsUp to 30 days
scriptengine-themeRemember the light or dark themeUntil changed or browser data is cleared
scriptengine-referral-codePreserve referral attribution after following a referral linkUntil account creation or browser data is cleared
scriptengine-analytics-consent-v1Remember accept or reject choiceUntil changed or browser data is cleared
_ga and related GA4 cookiesOptional Google Analytics identifiers after acceptanceTypically up to two years, subject to configuration and browser controls

Google Analytics 4 is optional. By default, analytics storage is denied and the Google tag is not loaded. If you select Accept analytics, ScriptEngine loads GA4 measurement ID G-EXCXCDJ412 on public pages only. Google may then receive a sanitised page location limited to the site origin and pathname, the page title, referrer, interaction data, browser and device information, and approximate location derived from network information. Query strings and URL fragments are excluded from the page location sent by ScriptEngine.

Advertising storage, advertising user data, advertising personalisation, and Google signals remain disabled by ScriptEngine's tag configuration. The authenticated workspace does not load the analytics script. We do not intentionally send account email, order identifiers, password-reset tokens, complete API keys, prompts, model outputs, or payment credentials to GA4.

Rejecting optional analytics does not prevent account, checkout, or API functionality. Use here or in the footer to change your choice. Withdrawal stops future optional collection on that browser after the page reloads, but does not automatically erase data already processed; use a privacy request for that.

5. Purposes and legal bases

Why we process personal data.

PurposeTypical legal basis
Create accounts, authenticate users, complete checkout, provision credits and keys, route API requests, account for usage, provide support, and process withdrawals.Performance of a contract or steps requested before a contract.
Secure the service, prevent fraud and abuse, troubleshoot failures, protect customers and systems, and establish or defend claims.Legitimate interests, balanced against individual rights; and legal obligations where applicable.
Maintain payment, accounting, tax, consumer, withdrawal, dispute, and legally required records; respond to lawful requests.Legal obligation and legitimate interests.
Run optional Google Analytics after a user chooses to accept it.Consent, which can be withdrawn through Cookie settings.

Where processing is necessary to enter or perform a contract, refusing necessary information can prevent account creation, payment, provisioning, API access, or support. Optional analytics is not required for the service.

6. Recipients

Who may receive personal data.

  • Upstream API and model providers, which receive API content and associated technical information to produce a response.
  • Stripe, where card or supported wallet checkout is enabled.
  • BTCPay infrastructure, wallets, and public blockchain or payment networks, where cryptocurrency checkout is enabled.
  • Google Analytics, only after analytics consent on the relevant browser.
  • Hosting, database, backup, DNS, network, security, email, and monitoring providers needed to operate and protect the service.
  • Professional advisers, courts, regulators, law-enforcement bodies, and authorities where disclosure is lawful and necessary.
  • Parties to a genuine financing, merger, acquisition, restructuring, or asset transaction, subject to appropriate safeguards.

We do not sell personal data. The identities of some technical or upstream providers may be commercially confidential, but recipient categories do not remove our obligation to use appropriate agreements and safeguards.

7. International processing

Transfers outside Cyprus or the EEA.

ScriptEngine is available internationally and relies on providers that may process data outside Cyprus or the European Economic Area. Where GDPR transfer restrictions apply, we rely on or require a legally recognised mechanism where necessary, such as an adequacy decision, Standard Contractual Clauses, or another lawful safeguard.

Email support@scriptengine.org to request available information about safeguards relevant to your data.

8. Retention

How long we keep information.

We use retention criteria because different records serve different operational and legal purposes:

  • Complete API request bodies and normal outputs: not intentionally retained by ScriptEngine after the request completes; upstream rules differ.
  • Sessions and reset records: retained for their functional lifetime and proportionate security, audit, and rate-limiting needs.
  • Account and key records: retained while the account is active and afterwards where needed for closure, fraud prevention, security, disputes, or legal obligations.
  • Orders, refunds, and withdrawals: retained for applicable accounting, tax, payment, consumer, anti-fraud, and legal-claims periods.
  • Usage and security logs: retained only as needed for billing, support, service security, abuse prevention, troubleshooting, and disputes.
  • Support correspondence: retained for the active case and proportionate follow-up, quality, dispute, security, and legal needs.
  • Referral records: retained while rewards are pending or usable and for accounting, fraud, reversal, and dispute needs.
  • GA4 data: subject to the configured GA4 retention and Google's system rules; consent withdrawal stops future optional collection on that browser.
  • Backups: overwritten or removed on normal cycles unless preservation is required for security, recovery, or law.

When data is no longer needed, we delete or anonymise it unless continued retention is required or permitted by law.

9. Data-protection rights

Your choices and rights.

Depending on the law and circumstances, you may have rights to access, correct, erase, restrict, or receive personal data; object to certain processing; withdraw consent; and complain to a supervisory authority. Rights may be subject to conditions, identity verification, exceptions, and lawful retention duties.

Email support@scriptengine.org with the subject Privacy Request. Identify the account and describe the request. Do not send a password, complete API key, card details, seed phrase, or private key. We will respond within the period required by applicable law.

You may also complain to the Office of the Commissioner for Personal Data Protection of Cyprus or another competent supervisory authority.

10. Security

Measures appropriate to the service and risk.

Measures used by ScriptEngine include password hashing, one-way storage of session and customer-key verifiers, encrypted storage of upstream credentials, secure session cookies, CSRF controls, TLS in transit, access restrictions, and operational logging. No internet service or transmission method is completely secure.

You are responsible for protecting your password and API keys. Rotate a key promptly if you believe it has been exposed, update connected clients, and report suspected compromise to support using only the masked key prefix.

11. Automated controls

Billing, security, and abuse checks.

Automated systems may deduct credits, enforce stock or rate constraints, authenticate requests, detect security or abuse conditions, and apply payment or referral reversals. ScriptEngine does not currently intend to make solely automated decisions that produce legal or similarly significant effects. Contact support if you believe an automated control was applied incorrectly.

12. Age requirement

ScriptEngine is for adults.

ScriptEngine is intended only for people aged 18 or older. We do not knowingly offer accounts to children. Contact support if you believe a person under 18 supplied personal data contrary to this rule.

13. Third parties, changes, and contact

Keeping this policy current.

Third-party sites, payment pages, wallets, model providers, and documentation use their own privacy notices. We may update this policy when the service, providers, law, or data practices change. The effective date and version will change when a revised policy is published. Prior material versions may be retained where needed to identify which information applied.

REFINO LIMITED
Company number HE 375240
34 Stratigou Timagia, Santa Maria Court, Floor 2, Office 201
3107 Limassol, Cyprus
support@scriptengine.org

Related policy

Read the Terms of Service

Review the contract rules for accounts, credits, payments, API content, model access, referrals, and service changes.

Read the Terms