Privacy Policy

Last updated 10 September 2026.

ScribeHold reads your iPhone’s message data on your own Windows PC and stores it in a local SQLite database. Message content, contact information, and attachments stay on your machine.

Who we are

ScribeHold is operated by Solimark, LLC ("we", "us"), which is the data controller for the personal data described in this policy. You can reach us at privacy@scribehold.com for any question about this policy or to exercise the rights described below.

What stays on your PC

The following never leaves your computer. We cannot read it, we do not receive copies of it, and we could not produce it if we were asked to.

  • Every message, attachment, and contact ScribeHold copies off the device
  • The working files the Windows service writes while it reads the phone
  • The SQLite search index used by the app

Because this data is stored only on your own device, it is under your control. Deleting the application's data directory removes it permanently.

What we collect, why, and on what legal basis

The table below is the complete list of personal data we process. Where we rely on legitimate interests, you have the right to object — see "Your rights" below.

Purchase and licensing data

  • What: your email address, the name you supply for licensing, and your subscription status and renewal dates.
  • Why: to sell you a licence, deliver it, validate it while you use the app, and provide support and refunds.
  • Legal basis: performance of a contract (UK/EU GDPR Article 6(1)(b)).
  • Note: card and payment details are handled by our payment processor and are never received or stored by us.

Licence validation requests

  • What: your licence identifier and your IP address, which is necessarily visible to our server when your app contacts it.
  • Why: to confirm an active subscription and to deliver renewed licences. No message data is transmitted in these requests.
  • Legal basis: performance of a contract (Article 6(1)(b)).

Update checks

  • What: every installation checks for a new version roughly every six hours, on both the direct download and the Microsoft Store build. That request carries the ScribeHold version you are running, your Windows version, which of the two builds you installed, a random eight-character install identifier, and your IP address, which is necessarily visible to our server. No message content, contacts, or attachments are transmitted.
  • About the install identifier: it is generated at random the first time ScribeHold runs and stored on your PC. It is not derived from your hardware, your Windows username, your machine name, or your licence. It is always sent: there is no setting that turns it off. The same identifier stays with the installation if you later buy a licence — it is not regenerated at that point, so update checks recorded while you were using the free version can afterwards be associated with your customer record.
  • What we store, and for how long: we keep one record per update check, indefinitely. Each record holds the ScribeHold version, which build you installed, the install identifier, the time of the check, and — if you hold a licence — your licence identifier. Nothing else: no message content, no contacts, no attachments, and no record of how you use the app. We keep these records rather than only a daily total so that a fault in how we read them can be corrected afterwards. The raw server logs the records are derived from are kept for up to 90 days and then deleted.
  • Whether this identifies you: for an installation with no licence, these records hold no information that identifies the person using it. For an installation with a licence, the licence identifier links them to your customer record, so we can tell that a particular customer is running a particular version.
  • Why: so we know which versions are actually in use, and can aim support and security fixes at the installations that are running them rather than guessing.
  • Legal basis: legitimate interests (Article 6(1)(f)) — keeping the installed base supported and secure. You can object to this processing at any time by emailing support@scribehold.com.
  • If you hold a licence: the update check also carries your licence identifier — an opaque billing reference, never your email address — so we can tell how many of the installations on a given version hold a licence, and prioritise accordingly. It is stored with the record of the check, which is what allows it to be connected to your customer record. Installations without a licence send no such identifier. Legal basis: performance of a contract (Article 6(1)(b)) — supporting the software you are licensed to use.

Website analytics

  • What: scribehold.com uses Google Analytics 4, which sets cookies and collects pages viewed, approximate location derived from IP address, device and browser type, and interactions such as clicking a download link.
  • Why: to understand which pages are useful and how people find the site.
  • A/B testing: some pages show one of several versions of an illustration, chosen at random on your first visit and remembered so you see the same one again. Which version you saw travels with the analytics events above, so we can tell which is more useful. It is stored in your browser, never sent to us on its own, and it holds no information about you.
  • Legal basis: consent, requested before these cookies are set.
  • Note: this applies to the website only. The ScribeHold application contains no analytics SDK and sets no analytics cookies; what it does send is the update check described above.

What we never collect

  • Message content of any kind
  • Contact names, phone numbers, or email addresses from your messages
  • Photos, videos, or any other attachments

Cookies

The site sets no cookies of its own. Your theme preference, your answer to the analytics question above, and which version of an illustration you were shown are kept in your browser's local storage, on your own device, and are never sent to us. These are strictly necessary to remember what you chose, so they do not require consent.

Analytics cookies, described above, are set only if you consent. You can change or withdraw your choice at any time, and refusing them does not restrict any part of the site or the product.

Who we share data with

We do not sell personal data and we do not share it for advertising. We use a small number of processors that handle data on our instructions:

  • Our payment processor, for taking payment and managing subscriptions
  • Our cloud hosting and email delivery providers, for running the licensing service and sending licence emails
  • Google Analytics, for website analytics, where you have consented

These providers may process data in the United States. Where personal data is transferred outside the UK or EEA, the transfer is covered by the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, together with supplementary safeguards where required. You can request a copy of the relevant safeguards by emailing us.

We may also disclose data where we are legally required to do so. Because message content never reaches us, it cannot be disclosed by us under any circumstances.

How long we keep data

  • Purchase and licensing records: for the life of your subscription and then for seven years, to meet tax and accounting obligations.
  • Update check logs: the raw server logs are kept for up to 90 days, after which they are deleted automatically. The records we derive from them — version, build, install identifier, licence identifier where there is one, and the time of the check — are kept indefinitely.
  • Website analytics: up to 14 months.
  • Support correspondence: up to 24 months after the conversation ends.

Your rights

If you are in the UK or the EEA, you have the right to access a copy of your personal data, to correct it, to have it erased, to restrict or object to how we use it, to receive it in a portable format, and to withdraw consent at any time where we rely on consent. Withdrawing consent does not affect processing that has already taken place.

To exercise any of these rights, email privacy@scribehold.com. We will respond within one month. We do not charge a fee, and we will not ask you for more information than we need to identify your records.

Please note that most of what ScribeHold handles — your messages, contacts, and attachments — is stored only on your own PC. We cannot access, export, or delete it on your behalf, because we never receive it. You can remove it yourself at any time by deleting the application's data.

We do not use your data for automated decision-making or profiling that produces legal or similarly significant effects.

Complaints

If you are unhappy with how we have handled your personal data, please contact us first so we can put it right. You also have the right to complain to a supervisory authority. In the UK this is the Information Commissioner's Office (ico.org.uk). In the EEA it is the data protection authority in the country where you live or work.

Children

ScribeHold is not directed at children and we do not knowingly collect personal data from anyone under 16.

Changes to this policy

If we change this policy we will update the date at the top of the page. Where a change materially affects how we use your personal data, we will tell you directly before it takes effect.

The app sends no message content. To object to the update check described above, email support@scribehold.com. Questions: privacy@scribehold.com.