ScenarioDeck
ProductHow it worksAgentsPricingSecurityDocs
ProductHow it worksAgentsPricingSecurityDocs
Download

ScenarioDeck legal

Privacy Policy

Last updated 15 August 2026

This policy describes the current website data boundary and the limited commerce and licensing data ScenarioDeck will use when those services are enabled.

On this page

  1. Operator and contact
  2. Website and analytics
  3. Commerce and licensing
  4. Local State Cards
  5. Sharing and retention
  6. Security and your choices

Operator and contact

Roman Novikov PE (Tax Number 1020738), ofA13, The Grove, Cascavelle, Mauritius, operates ScenarioDeck. For privacy questions or requests, contact info@scendeck.com.

Website and analytics

Our website is hosted through Cloudflare. Normal delivery and security operations can process request data such as technical request information and security logs. We use Cloudflare Web Analytics for aggregate traffic, page-performance, and referral insights. The website does not use advertising pixels or a marketing account requirement.

The first-party funnel event layer is enabled. The website records a small allowlisted set of decision events — such as a pricing action, download-page platform availability, a checkout attempt, or a shared card landing — through its own endpoint. Each event carries only a bounded event name and coarse dimensions such as a page class or platform. It never includes email addresses, names, raw IP addresses, transaction identifiers, activation tokens, State Card contents, authentication material, share identifiers or keys, or full URLs and query strings. Shared-card landing pages never load third-party analytics scripts, and their events carry only a fixed page class.

See the published analytics boundarydocumentationfor the event vocabulary, retention, and access model. Analytics is never used as the source of truth for purchases, trials, entitlements, or product access.

Commerce and licensing

When Paddle checkout and ScenarioDeck entitlement services are enabled, Paddle processes payment, tax, fraud, billing, and buyer-support data as authorised reseller and Merchant of Record under itsPrivacy Notice. ScenarioDeck may receive and retain the limited Paddle-derived identifiers and status information needed to reconcile a transaction, issue or update a software entitlement, and provide activation support. ScenarioDeck does not receive or store raw payment-card details from Paddle checkout.

The entitlement design stores licence and transaction references, subscription status where relevant, activation timestamps, and hashed machine-slot identifiers. Support messages are processed when you choose to send them to us. We do not describe unimplemented commerce flows as active collection.

Local State Cards

State Cards and State Capsules are local product artifacts by default. ScenarioDeck does not automatically upload their contents to this website or to licensing services merely because you capture or open a State Card. Browser, API, and authentication-related state can be sensitive, so you remain responsible for review and redaction before sharing or export.

ScenarioDeck's dedicated sharing relay stores encrypted share ciphertext, not readable State Card contents. The decryption material stays in the share link fragment and is not sent to the website or relay in a query parameter. Ordinary shares do not include machine-local protected values, Development Profile or authentication state, credentials, passwords, cookies, or tokens.

Sharing and retention

We use Cloudflare to host and protect the website and Paddle for transactions when checkout is available. We share data with these providers only as needed for their respective services, legal obligations, security, or support. We do not sell personal data or use it for cross-site advertising.

We retain website, security, support, and commerce records only for as long as reasonably needed for the purpose described, to resolve disputes, or to meet legal obligations. Shared ciphertext expires or may be revoked and is deleted according to the sharing service cleanup policy. Local State Cards remain under your local storage control rather than a central ScenarioDeck retention schedule.

Security and your choices

We use HTTPS for website and service traffic, keep service secrets on the server side, and design entitlements to be signed. These measures reduce risk but do not guarantee absolute security. You may contact us to ask about access, correction, deletion, or another privacy concern where applicable. Transaction records held by Paddle may also require a request through Paddle buyer support.

© 2026 ScenarioDeck

SupportDocsBeta scopePrivacyTermsRefunds