Privacy Policy
Version 2026-08-26, in effect from 2026-08-26. This is not the current version.
Who is responsible
Spritz Solutions, LLC, an Alabama limited liability company, of Mountain Brook, Alabama, is responsible for the information Scriptorium holds about you. Contact: support@spritzsolutions.com.
We process this information in order to provide Scriptorium to you. That is the basis for it.
What we collect, and why
When you sign up: your name, your email address, and — if you choose to give them — your school and expected graduation year.
The name is so your shared comments can carry a first name and initial rather than nothing. The email address is how you sign in. School and graduation year are optional: they tell us which seminaries are actually using Scriptorium, and the graduation year is how we know when to remind you to add a second sign-in address before your school one stops working. Neither is checked against anything, and neither is ever shown to other users.
What you put in: your books, notes, research, writing, and Scripture connections. This is the archive. We store it so you can use it, and for nothing else.
When you sign in: the date you last used each of your sign-in addresses, so you can see which of them still works.
Server logs. Our hosting provider keeps standard server logs for a short period, including the address of each page requested and the IP address it came from. We do not use these for anything except diagnosing faults.
We do not collect analytics. There are no trackers, no advertising, no third-party scripts watching what you read. The only cookie Scriptorium sets is the one that keeps you signed in.
Where it lives
Your archive is stored in a PostgreSQL database hosted by Supabase in the
ca-central-1 region, in Canada. The application runs on Vercel. Sign-in emails
are sent through Supabase.
Those two companies process data on our behalf, under their own agreements. Nobody else has access.
Who can see it
Only you, except for the shared book comments you individually choose to share — see the Terms of Service for exactly what those show.
One person, John Burruss, administers Scriptorium and can see shared comments in order to moderate them. No administrator can read your private comments through Scriptorium — the database itself refuses it, rather than a policy someone could decide to ignore.
Two people, John Burruss and Allen Jones, hold maintenance credentials to the database itself. That access exists so the service can be kept running, and it is not used to read anyone's archive.
How long we keep it
Until you ask us to delete it.
That is deliberate. An archive of thirty years of reading is worth keeping, and someone who leaves and returns should find their books. Dormant accounts are kept indefinitely rather than cleaned up.
If you ask for deletion, it happens for real, and we will tell you what was deleted.
Your rights
You can ask us to send you a copy of everything Scriptorium holds about you, correct anything wrong, or delete it. Write to support@spritzsolutions.com and a person will answer — expect a reply within a few days rather than a few weeks.
If you are in the UK or the European Union, you also have the right to object to processing, to restrict it, and to complain to your data protection authority.
Security
Sign-in is by emailed link, so there is no password of yours to lose. The connection is encrypted. Each person's archive is kept separate from every other person's.
No system is perfect. If something goes wrong that affects your data, you will be told what happened, what it affected, and what was done about it — promptly, and in plain words.
If this changes
If this policy changes, you will be told and asked to accept the new version. Old versions are kept so you can see what you agreed to and when.