Scripio — Privacy Policy

Last Revised: October 8, 2026

This Privacy Policy specifically governs Scripio, an automated personal finance tracking assistant on Telegram and web dashboard published by rafylabs.

Scripio is designed around a strict Zero-Storage Architecture for financial records: your sensitive transaction numbers, merchant details, and expense items are stored directly in your own private Google Spreadsheet, NEVER on developer application databases.

1. Google Sheets API Data Access & Limited Use

Requested Scopes: Scripio requests access to the Google Sheets API (https://www.googleapis.com/auth/spreadsheets) solely to read spreadsheet headers/sheet names and append confirmed expense/income transactions to your designated Google Sheet.

OAuth Authentication: When you connect your Google account via OAuth, the authentication token is encrypted at rest and in transit. Scripio only accesses the specific spreadsheet you designate.

Limited Use Compliance: Scripio's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Google API Limited Use Disclosure

Scripio's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

2. Zero-Storage Architecture for Financial Contents

No Permanent Financial Storage: The Scripio database (hosted on Cloudflare D1) stores only technical user metadata: Telegram User ID, linked Google Sheet identifier, user state, and optional notification preferences.

We DO NOT store or aggregate your financial balances, merchant names, expenditure categories, or receipts in our permanent database. Once you confirm a transaction, it is written directly to your Google Sheet.

Staged Transactions: Unconfirmed pending transactions staged while you verify details are stored temporarily and can be cancelled or cleared at any time.

3. Temporary Receipt Processing & No AI Training

Volatile In-Memory OCR: Receipt images, voice notes, and PDF statements uploaded via Telegram are processed in volatile memory by OCR and Vision AI models solely to parse transaction fields.

Instant Purge: Raw receipt image files are discarded immediately after extraction and are NEVER permanently archived on developer servers.

No AI Training: Your uploaded receipts, transaction text, and personal Google data are NEVER used to train, retrain, or improve machine learning or AI models.

4. Data Security, Retention, and Deletion

Security: All network exchanges use TLS 1.3 encryption. Webhooks are validated using cryptographic secret tokens.

Revoking Access: You can revoke Scripio's Google access at any time at https://myaccount.google.com/permissions.

Account Deletion: Typing /disconnect in the bot immediately clears your active Sheet connection. For complete technical record deletion, email mraflym46@gmail.com.

5. Contact Information

For inquiries or privacy concerns regarding Scripio:

Developer: Muhammad Rafly Mubarak (rafylabs)

Email: mraflym46@gmail.com

Website: https://rafylabs.com/privacy/scripio