Privacy Policy
Your privacy is important to us. This policy explains how we collect, use, and protect your information.
Effective Date: January 1, 2026
Last Updated: February 27, 2026
1. Introduction
Welcome to Scrubly, operated by Scrubly LLC ("we," "our," or "us"). We respect your privacy and are committed to protecting your personal data. This Privacy Policy explains how we collect, use, and safeguard your information when you visit our website and use our AI-driven interview simulation services.
By using our Service, you consent to the data practices described in this policy. If you do not agree with this policy, please do not use the Service.
This Privacy Policy applies to information we collect through the Service and in email, text, and other electronic communications. It does not apply to information collected offline or by third parties.
2. Information We Collect & Payment Security
We only collect the minimum amount of data necessary to provide and improve our services.
2.1 Account Registration
When you register, we collect your name and email address, securely managed via Google Firebase — a Google LLC cloud platform with industry-standard security infrastructure.
2.2 Payment Information
We do not store your credit card details on our servers. All payment processing is securely handled by Stripe, a certified PCI-DSS Level 1 compliant third-party payment processor. Stripe's privacy policy governs all payment data.
2.3 Automatically Collected Information
When you access the Service, we automatically collect standard usage data such as pages visited, features used, practice session metrics, IP address, browser type, operating system, and session cookies necessary for authentication and service delivery.
3. AI Processing & Audio Data (OpenAI API)
To provide real-time interview feedback and speech-to-text functionality, we process your typed text and spoken audio using the OpenAI API.
No AI Training
Data submitted through our service via the OpenAI API is NOT used by OpenAI to train their foundational models. We operate under OpenAI's API usage policies, which explicitly prohibit training on API user data by default.
Audio Privacy
When you use the microphone feature, your voice is sent to the OpenAI API solely for transcription purposes. We do not permanently store your voice recordings on our servers.
4. HIPAA Disclaimer & Protected Health Information (PHI) — CRITICAL NOTICE
Scrubly is an educational and interview preparation tool. It is NOT a HIPAA-compliant platform.
Users are strictly prohibited from entering, speaking, or submitting any real, identifiable patient information or Protected Health Information (PHI) of any kind through the Service — including in typed answers, voice recordings, or uploaded documents.
5. California Privacy Rights (CCPA/CPRA)
If you are a resident of California, you are granted specific rights regarding your personal information under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):
Right to Know & Access
You can request details about the personal data we have collected about you, including the categories of data, the purposes for which it is used, and the third parties with whom it is shared.
Right to Delete
You can request the deletion of your personal data and account at any time by contacting us at support@heyscrubly.com.
Do Not Sell My Personal Information
We strictly do NOT sell your personal data to any third parties. Scrubly is ad-free and we do not allow advertisers to target you based on your data.
Right to Correct
You can request correction of inaccurate personal information we hold about you by contacting us at support@heyscrubly.com.
6. How We Share Your Information
6.1 We Do NOT Share With:
- ❌ Healthcare employers or recruiting agencies
- ❌ Nursing schools or educational institutions
- ❌ Data brokers or advertisers
- ❌ Any third party for their own marketing purposes
6.2 Trusted Service Providers (Limited Sharing)
We share data only with the following trusted service providers, strictly for operating the Service:
- Google Firebase — Authentication and database (Firestore)
- Stripe — Payment processing (PCI-DSS Level 1 compliant)
- OpenAI — AI text generation, audio transcription, and text-to-speech
7. Data Security
We implement industry-standard security measures, including those provided by Google Firebase (encryption at rest and in transit) and Stripe (PCI-DSS Level 1 compliance), to protect your personal information.
However, no method of transmission over the internet or electronic storage is 100% secure, and we cannot guarantee absolute security. You use the Service at your own risk with respect to data security.
8. Children's Privacy
Our Service is intended for individuals who are at least 18 years of age. We do not knowingly collect personal information from anyone under 18. If we discover that we have collected information from a minor, we will delete it immediately.
9. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date at the top. For material changes, we will also notify you via email if you have an account with us.
Your continued use of the Service after changes are posted constitutes acceptance of the updated policy.
10. Contact Us About Privacy
If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data (including data deletion requests under CCPA or any other right listed above), please contact us at:
Scrubly LLC
All Inquiries (Privacy, Data Requests & General Support): support@heyscrubly.com
We will respond to all privacy inquiries within 30 days as required by law.