Privacy Policy
What personal information Skryp collects, why, who receives it, how long we keep it, and your rights under the Protection of Personal Information Act (POPIA).
In force from 2 October 2026
Who we are
Skryp decides why and how your personal information is processed for your account (the “responsible party” in POPIA). Write to support@skryp.dev with any privacy question or request; our information officer reads that address.
What we collect and why
- Your account: your email address and password when you sign up, and your name and workspace name if you give them. We keep the password only as a salted scrypt hash. We use these to run your account and to send account and payment notices.
- Google or GitHub sign-in: if you sign in with Google or GitHub, that provider tells us your account ID there, your verified email address and your name. We use them only to sign you in and to set up your account. We never receive your Google or GitHub password, and we keep no access to your account there.
- The terms you accepted: which version and when, at sign-up and with each payment, as the record of our agreement.
- Payments: amounts, dates, references and what was bought. From Paystack we keep a customer code and, for plan renewals, a card authorisation code. You enter card details on Paystack’s page; we never see or store card numbers. We use this for billing, receipts, refunds and our accounting records.
- Your requests: for each request, the URL or search query, time, tool, credits, route and exit country (its receipt), and a copy of the result for 14 days so you can see it in the dashboard. We use this to charge you correctly, show you your history and answer support questions.
- What you create: API keys (stored only as hashes), datasets, monitors, workflows, recipes, files and saved logins. Saved logins are encrypted with AES-256-GCM and used only for your own requests.
- Messages: what you send us by email.
- Security: the IP address of sign-in, sign-up and password-reset attempts, held in memory for up to an hour to stop password guessing, and not stored.
Your email address and a password (or a Google or GitHub sign-in) are needed to open an account, and payment details (entered with Paystack) to buy a plan or credits. Without them we cannot give you an account or the paid features. Everything else is up to you.
Cookies and your browser
After you sign in we set one cookie, skryp_session, which keeps you signed in for up to 30 days. It cannot be read by scripts on the page. Signing in with Google or GitHub also sets a cookie for up to 30 minutes that ties the sign-in to your browser. We use no analytics, advertising or tracking cookies, and load no third-party tracking scripts. Your browser keeps your playground drafts, and briefly the reference of a payment in progress, in its own storage; neither is sent to anyone else.
Personal information in pages you collect
Pages you ask Skryp to fetch can contain other people’s personal information. You decide what is collected and what it is used for, so for that information you are the responsible party and we process it only on your instructions, as your operator. Follow the law when you collect it; see the Acceptable Use Policy.
Who receives it
We share personal information only with the providers that do part of the work, each for its part: payments with Paystack, emails with our email provider, pages you request with our proxy, unblocking and extraction providers. They are listed, with what each receives, on the Subprocessors page. We do not sell personal information. We disclose it to others only when the law requires.
Transfers outside South Africa
Several of these providers process information outside South Africa, including in the United States. We send them only what they need to perform our agreement with you, which POPIA allows (section 72(1)(c)), and each processes it under its own terms and privacy commitments.
How long we keep it
- Account details: until you close your account.
- Copies of results: 14 days.
- Request history, keys, datasets, monitors, workflows, files and saved logins: until you delete them or close your account.
- Payment records: for as long as tax and accounting law requires, without your name or email once your account is closed.
- Backups: overwritten within 14 days, so deleted information leaves them within that time.
Your rights
- See and correct your details in Settings, or ask us for a copy of the personal information we hold about you.
- Delete it: close your account in Settings, which deletes your details and your workspace’s data at once (payment records stay, as above), or ask us to delete something specific.
- Object to how we process your information, or withdraw a consent you gave.
- Write to support@skryp.dev for any of these. We may ask you to confirm the request comes from your account’s email address.
You can also complain to the Information Regulator:
- Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg, 2191
- POPIAComplaints@inforegulator.org.za (complaints) · enquiries@inforegulator.org.za (enquiries)
- 010 023 5200 · toll-free 0800 017 160
Security
How we protect information is described on the Security page. If we learn of a breach that affects your personal information, we tell you and the Information Regulator as POPIA requires.
Children
Skryp is not for anyone under 18, and we do not knowingly collect children’s personal information.
Changes
We will update this policy when what we do changes, and email account holders about material changes before they apply.