Privacy & Cookies
How browser text, API requests, persistent agent-infrastructure state, billing data, infrastructure metadata, cookies, and advertising are handled.
ScrubMyText browser tools
Text entered into the ScrubMyText browser tools is designed to be processed locally in your browser. The browser-tool logic does not intentionally submit pasted text to the ScrubMyText API for cleaning, inspection, scanning, redaction, comparison, secret detection, JSON validation, context sanitization, or agent preparation.
Document Safety Scanner
Files selected in the Document Safety Scanner are designed to be parsed and analyzed locally in your browser and are not intentionally submitted to the ScrubMyText REST API or MCP endpoint. The current PDF scanner loads open-source PDF.js parser code from a content-delivery network; the scanner does not intentionally transmit the contents of your selected document to that provider. DOCX parsing uses a locally hosted open-source ZIP parser. As with other website visits, infrastructure providers can receive ordinary request metadata.
The scanner can display extracted document text and findings in the browser. Refreshing or closing the page clears the current in-memory scan.
ScrubMyText REST API and MCP text requests
Text submitted directly to the REST API or MCP endpoint must be transmitted to the service for processing. The application is designed not to persist ordinary ScrubMyText text-tool inputs or outputs in its billing and usage database.
Persistent data used by agent infrastructure
LockMyAction processes structured action arguments transiently when deriving an action fingerprint and is designed not to store or echo those arguments. A deterministic fingerprint is a stable identifier, not anonymization, so action arguments should not contain passwords, API keys, or secret tokens. When a lock is created, the service stores the API-key hash that owns the record, the customer-supplied or derived action key, lock identifiers, status, and timestamps needed to prevent duplicate actions for the configured retention period.
CatchMySignal stores inbox metadata and the event bodies delivered to a temporary inbox until the inbox expires or is deleted. Event payloads are currently limited to 64 KB and stored as UTF-8 text. The random webhook token is stored as a hash in the application database; the webhook URL itself necessarily travels through hosting/network infrastructure and should be treated as a secret.
ApproveMyAction stores the approval title, optional description, status, timestamps, optional reviewer note, owner API-key hash, and a hash of the approval token. The approval page keeps the token in the URL fragment so it is not sent to the website server during the initial page request; the page then sends it to the API in the body of the approval-status/decision request.
Production control products store the minimum state needed to enforce their documented operation: API-key ownership hashes; generated record identifiers; status and timestamps; counters and limits; hashes of caller-supplied resource, subject, reservation, and nonce keys; action, incident, outcome, evidence, task, terms, context, and parent digests; hashes of bearer tokens; quorum member-slot decisions; deadline and escalation timestamps; and review-capacity pool and reservation counters. TraceMyContext stores digest lineage and a short caller-supplied processing-stage label. Reconciliation records can store the most recent evidence digest. These tools are designed not to store raw messages, shared HMAC secrets, task or incident descriptions, action payloads, context content, outcome payloads, reviewer contact information, payment credentials, or external evidence.
Terms, policy, compensation, context-rights, and disclosure controls keep bounded metadata rather than the underlying content. PinMyTerms stores a terms digest, version label, optional price/currency, status, and expiry—not the terms body. MatchMyPolicy compares caller-supplied policy tokens in memory and does not persist them. CompensateMyAction stores action and compensation digests plus lifecycle state. RevokeMyContext and LicenseMyContext store context, policy, and successor digests plus status or rights metadata—not context content. MeterMyDisclosure stores owner-scoped recipient and category digests, retry-key hashes, configured limits, and cumulative unit counters; it is not intended to store disclosed content or recipient identities.
TrustMyChoice stores the exact target type, provider domain, canonical HTTPS endpoint, version, optional interface digest, task category, optional region and decision thresholds, hashed contributor/subscriber and retry-key identifiers, structured outcome/reliability/latency/price metrics, an optional ReceiptMyAction record identifier, timestamps, and digest-only correction or appeal requests and status. Free contributor enrollment stores a one-way hash derived from the Cloudflare Access issuer and subject plus a one-way hash of the current key; it does not store the contributor email. TrustMyChoice does not accept or intentionally store prompts, responses, credentials, raw IP addresses, raw user agents, contact details, or free-form reviews. Public cards expose only aggregate evidence after at least three distinct verified contributor identities have contributed; before that, dimensions remain marked insufficient evidence. Identity verification limits duplicate sources but does not verify the submitted outcome or provider ownership. Receipt linkage means the caller owns a matching ScrubMyText receipt record, not that ScrubMyText verified the external service outcome or provider identity.
Bearer capability, lease, handoff, and task-acceptance tokens are returned to callers and stored only as hashes. They should be treated as secrets. VerifyMySignal processes the supplied message and shared secret in memory to verify the signature; only a nonce-derived hash and expiry are stored after a successful fresh verification.
Expired records become eligible for deletion and are removed during application cleanup or related access. Cleanup is not guaranteed to occur at the exact second a retention period ends.
Usage and billing data
To enforce monthly limits, the service stores usage counters associated with hashed identifiers such as an API-key hash or public-IP hash. Paid account records can include Stripe customer and subscription identifiers, plan information, and API-key hashes. Payment-card details are handled by Stripe rather than stored by ScrubMyText.
Infrastructure and first-party analytics
Hosting, security, analytics, and related infrastructure providers can process ordinary request metadata such as IP addresses, browser or device information, requested URLs, timing, and HTTP headers. Secret-bearing URLs such as CatchMySignal webhook URLs should be treated accordingly. The browser text-tool logic is designed so pasted text is not intentionally included in analytics events.
ScrubMyText keeps first-party aggregate usage counters for items such as page path, external referrer hostname, API transport, tool name, authentication category, request outcome, aggregate x402 revenue, developer-call-to-action category, Checkout stage, and coarse client class such as browser, API client, known crawler, known monitor, synthetic test, or unknown. Client classification happens in memory; raw user agents are not stored in these counters. Checkout analytics record only bounded stages and plan names, not Checkout session IDs or customer details.
These counters are designed not to store pasted text, raw IP addresses, raw user agents, API keys, email addresses, wallet addresses, Checkout session IDs, transaction hashes, or other individual user identifiers.
Optional Google Analytics
Google Analytics 4 loads only after a visitor chooses Allow analytics. It is not loaded on the API-account, approval, document-scanner, or browser-tool workspace routes. ScrubMyText sends page locations without query strings or URL fragments, keeps Google advertising storage and signals disabled, disables automatic form-interaction, site-search, and outbound-link events, and does not send pasted text or custom events containing tool input or output.
Your choice is stored in your browser's local storage. If your browser sends a Global Privacy Control signal, optional analytics remains disabled. Disabling analytics updates Google's consent state and attempts to remove Google Analytics cookies for this site.
Optional Google Analytics is currently disabled.
Google describes how it processes Analytics data in How Google uses information from sites or apps that use its services.
Google AdSense, cookies, and advertising
If Google AdSense advertising is enabled on eligible content pages, third-party vendors including Google may use cookies or other identifiers for ad serving and measurement. Visitors can manage personalized Google advertising through Google Ads Settings and review Google's partner-sites information at Google's privacy information.
ScrubMyText does not intend to send text pasted into its local browser tools to Google AdSense as ad-targeting content.
Security-tool limitations
Secret detection, redaction, untrusted-text scanning, context sanitization, duplicate-action protection, webhook capture, human approval, budget counters, receipts, signed-signal verification, leases, capability tokens, stop state, handoffs, reconciliation, provenance anchors, and task commitments are narrow technical safeguards with documented limits. They should not be treated as substitutes for your own application security, identity, authorization, accounting, legal review, logging, monitoring, or backup controls.
Questions
Privacy questions can be sent to scrubmytext@gmail.com.
ReworkMyText
The ReworkMyText browser tool processes pasted and extracted document text in the browser. The paid API/MCP tool transmits supplied text to the API Worker for deterministic processing and is designed not to persist ordinary text-tool inputs or outputs in the billing/usage database.
