Skip to content

Privacy Policy

Effective date: September 1, 2026 Last updated: September 1, 2026

  1. Who We Are and What This Covers

This Privacy Policy describes how Scylla Technologies (“we,” “us,” or “our”) collects, uses, discloses, and protects information in connection with BarCheck, a product of Scylla Technologies, including barcheck.ai, app.barcheck.ai, the BarCheck web application, the free BarScan tool, the BarCheck WordPress plugin, any BarCheck browser extension, and related services (collectively, the “Service”).

This policy governs data handling only. Disclaimers about the nature of the Service — including that Scylla Technologies is not a law firm, that the Service does not provide legal advice, and that no attorney-client relationship or privilege is created — are set out in our Terms of Service and Legal Disclaimer.

The Service is a business tool for law firms, marketing agencies, and similar organizations. It is operated from the United States and is offered solely to users located in the United States. It is not offered or directed to individuals or organizations outside the United States.

  1. Our Role: Controller and Service Provider

For account, billing, support, and usage information, Scylla Technologies acts as the controller (or “business”) and this policy describes our own practices.

For Customer Content — the URLs, pages, articles, ads, and other materials you submit or designate for scanning — Scylla Technologies acts as a processor and “service provider” on your behalf. We process that content under your instructions to deliver the Service, and we do not sell it, share it for cross-context behavioral advertising, or use it for any purpose outside the direct business relationship, except as permitted by law and described here. If Customer Content contains personal information about other people, you are the controller of that information and are responsible for having a lawful basis and any required notices or consents.

  1. Information We Collect

Account information. Name, email address, firm or agency name, role, password credentials, and account settings.

Billing information. Plan, subscription status, billing history, transaction records, and partial payment-card details. Full payment card numbers are collected and processed directly by our third-party payment processor; we do not store them.

Customer Content. URLs, web pages, advertisements, articles, marketing copy, scripts, and other materials you submit or designate for scanning, together with the scan results, findings, coverage labels, reports, and Accuracy Review observations the Service generates from them, and the scan history associated with your account.

Usage and technical data. Log data, IP address, approximate location derived from IP, browser and device type, operating system, referring pages, pages viewed, timestamps, scan counts and durations, features used, quota consumption, and error and diagnostic data.

Plugin and extension data. Where you install the WordPress plugin or a browser extension, the content of the pages you choose to scan or designate for monitoring, the site URL and related page metadata, plugin configuration and license status, and version/update-check requests.

Communications. Emails, support tickets, demo and contact-form submissions, and the contents of your messages to us.

Marketing and cookie data. Information described in Section 8.

We do not intentionally collect sensitive personal information, and you should not submit it. See Section 6.

  1. Sources of Information

We collect information (a) directly from you, (b) automatically as you use the Service, (c) from the websites and URLs you submit or designate for scanning, (d) from publicly available sources consulted during Accuracy Reviews, and (e) from our service providers, such as our payment processor and email delivery provider.

  1. How We Use Information

We use information to:

  • Provide the Service: run Compliance Scans and Accuracy Reviews, generate findings and reports, monitor designated sites, and deliver results to you;
  • Create, authenticate, and administer accounts, seats, and organizations;
  • Process payments, manage subscriptions, quotas, metered usage, and renewals;
  • Provide support and respond to your requests;
  • Secure the Service, authenticate users, detect and prevent fraud and abuse, enforce our Terms, and debug and troubleshoot;
  • Send transactional communications such as reports, scan alerts, receipts, and account and policy notices;
  • Send product updates and marketing communications, from which you may opt out at any time;
  • Maintain, improve, test, and develop the Service and the Reference Library, including by reviewing errors and misclassifications and by using de-identified or aggregated data;
  • Comply with legal obligations and establish, exercise, or defend legal claims.
  1. Sensitive and Third-Party Information — Your Responsibility

The Service is designed for content that is published or intended for publication. You must not submit privileged communications, client confidences, protected health information, financial account or payment card numbers, government identification numbers, biometric data, or other sensitive personal information. Content submitted to the Service is not privileged or confidential by reason of its submission. If you submit information about other people, you represent that you have the rights and authority to do so.

  1. Artificial-Intelligence Processing

Parts of the Service are performed using one or more third-party artificial-intelligence model providers. When you run a scan or review, the content you submit and relevant reference material are transmitted to a model provider for processing so that findings can be generated. That processing is governed by commercial agreements that restrict the provider’s use of the transmitted data to providing the service to us.

We do not use identifiable Customer Content to train third-party foundation models, and our agreements with model providers do not permit them to use Customer Content submitted through the Service to train their general-purpose models.

We may use Customer Content, Output, and usage data internally — including in de-identified or aggregated form — to evaluate quality, correct errors, and improve the Service and the Reference Library. We may change model providers, methods, and infrastructure at any time, provided that comparable contractual protections apply.

Automated systems can produce inaccurate or incomplete results. We do not use the Service to make decisions that produce legal or similarly significant effects about individuals.

  1. Cookies, Analytics, and Tracking Signals

We use cookies and similar technologies for authentication, session management, security, load balancing, remembering preferences, and basic analytics about how the Service is used. You can control cookies through your browser settings; disabling essential cookies may prevent the Service from functioning.

We do not use third-party advertising cookies to serve targeted advertising, and we do not sell personal information or share it for cross-context behavioral advertising. Because we do not engage in that activity, browser “Do Not Track” and Global Privacy Control signals do not change our practices; where required, we honor recognized opt-out preference signals.

  1. WordPress Plugin and Browser Extension Disclosures

The BarCheck WordPress plugin and any BarCheck browser extension communicate with Scylla Technologies’ servers to authenticate your license, transmit the content of pages you choose to scan or monitor, return results, and check for updates. They collect and transmit only what is needed for those functions.

Information obtained through the plugin or extension is used solely to provide and improve the user-facing features of BarCheck. It is not sold, is not transferred to third parties except to the service providers described in Section 10 (and as required by law or in connection with a business transfer), is not used or transferred for advertising or creditworthiness purposes, and is not used to determine anything about individuals. We do not use it for any purpose unrelated to providing the Service.

  1. How We Share Information

We do not sell personal information and do not share it for cross-context behavioral advertising. We disclose information only as follows:

Service providers. Vendors that process information on our behalf, limited to these categories: cloud infrastructure and hosting; artificial-intelligence model providers; payment processing; email delivery; customer support tooling; error monitoring and analytics; and security services. Each is bound by contract to use the information only to provide services to us.

Your organization. If your account belongs to a firm or agency plan, the account administrator and authorized users can access scans, reports, settings, and usage under that account.

Legal and safety. When we believe disclosure is required by law, regulation, subpoena, court order, or other legal process, or is reasonably necessary to enforce our Terms, investigate suspected fraud or abuse, or protect the rights, property, or safety of Scylla Technologies, our users, or the public. Where legally permitted, we will make reasonable efforts to notify the affected customer.

Professional advisors. Our attorneys, accountants, auditors, and insurers, under duties of confidentiality.

Business transfers. In connection with a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or part of our business, subject to this policy’s protections for the transferred information.

With your direction or consent. When you ask us to share information, including through an integration you enable.

De-identified and aggregated data. We may create and disclose de-identified or aggregated information — such as statistics about scan volumes, finding types, and error rates — that does not identify you, your clients, or any individual. We maintain such data in de-identified form and will not attempt to re-identify it.

  1. Data Retention

We retain information for as long as needed for the purposes described in this policy:

  • Account and billing records: for the life of the account and afterward as required for tax, accounting, audit, and legal purposes (generally up to seven years).
  • Customer Content, scan results, and reports: for the life of the account so you can access scan history, unless you delete them sooner or request deletion. After account closure, they are deleted or de-identified within ninety (90) days, except where retention is required by law or reasonably necessary to resolve a dispute or enforce our agreements.
  • Logs and technical data: typically up to twenty-four (24) months, and longer where needed for security investigations.
  • Support communications: up to three (3) years after the last interaction.
  • De-identified and aggregated data:

Backups are purged on our routine backup cycle after the corresponding records are deleted.

  1. Security

We use commercially reasonable technical and organizational measures designed to protect information, including encryption in transit, access controls and least-privilege permissions, authentication requirements, logging, and hosting on infrastructure with industry-standard protections. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for safeguarding your credentials and for controlling who has access to your account.

  1. Your Privacy Rights and Choices

Everyone. You may access and update account information in your account settings, delete scans and reports, opt out of marketing email using the unsubscribe link or by emailing [email protected] (you cannot opt out of transactional messages), and request deletion of your account.

U.S. state privacy rights. Depending on your state of residence, you may have the right to: confirm whether we process your personal information and access it; obtain a portable copy; correct inaccuracies; delete it; obtain information about categories of personal information collected, sources, purposes, and categories of recipients; opt out of sale, sharing for targeted advertising, and profiling with legal or similarly significant effects (we do not engage in these activities); and limit use of sensitive personal information (we do not collect it for such uses). You will not be discriminated or retaliated against for exercising these rights.

How to exercise rights. Email [email protected]. We will verify your request using information associated with your account and will respond within the time required by applicable law (generally 45 days, extendable where permitted). You may use an authorized agent with written permission and verification.

Appeals. If we decline your request, you may appeal by replying to our response or emailing [email protected] with the subject line “Privacy Appeal.” We will respond within the time required by applicable law and will tell you how to contact your state attorney general if you disagree with the outcome.

Requests about Customer Content. If your personal information appears in content submitted by one of our customers, we act as a service provider. Please direct your request to that customer; we will assist them as required by law.

California. In the preceding twelve months we have collected the following categories of personal information under the CCPA/CPRA: identifiers; commercial information; internet or other electronic network activity information; geolocation data (approximate, derived from IP); professional or employment-related information; and, to the extent contained in content you submit, other information described in Cal. Civ. Code § 1798.80. We collect these for the business purposes described in Section 5, retain them as described in Section 11, and disclose them for business purposes to the categories of recipients described in Section 10. We have not sold personal information or shared it for cross-context behavioral advertising in the preceding twelve months, and we do not knowingly do so for anyone, including minors under 16. We do not use or disclose sensitive personal information for purposes requiring a “Limit the Use” option.

  1. United States Only

The Service is intended for use in the United States only. Information we collect is stored and processed in the United States and, in limited cases, in other countries where our service providers operate. We do not offer or direct the Service to individuals or organizations located outside the United States, and we do not intentionally collect personal information from them. If you are located outside the United States, please do not use the Service or submit information to us. If you believe we hold information about you and you are located outside the United States, contact [email protected] and we will address the request as required by applicable law.

  1. Children

The Service is a business tool intended for adults. We do not knowingly collect personal information from children under 16. If you believe a child has provided us information, contact [email protected] and we will delete it.

  1. Third-Party Sites and Sources

The Service accesses and processes third-party websites, pages, and sources at your direction. Those properties are governed by their own privacy policies, and we are not responsible for their practices. Links in the Service or in Output to third-party materials are provided for convenience and do not constitute endorsement.

  1. Changes to This Policy

We may update this policy. Material changes will be announced by email or in-app notice and the “Last updated” date will change. Changes take effect on the stated effective date, and continued use after that date constitutes acceptance.

  1. Contact Us

Scylla Technologies — BarCheck
Privacy: [email protected]
Legal: [email protected]
Support: [email protected]