Your data
Privacy Policy
Effective September 10, 2026
Scratch Copilot processes project code or costume data only when you request a related feature. It does not receive your Scratch password, sell personal data, or use personal data for advertising.
1. Who this service is for
Scratch Copilot is an independent browser extension for adults, parents, teachers, and invited testers using the official Scratch editor. It is not affiliated with the Scratch Foundation or MIT.
The current beta is not directed to children under 13 acting independently. A child under 13 should not sign in without authorization and supervision from a parent or school. If you believe a child provided data without appropriate authorization, contact us so we can delete it.
2. Data we process
- Account data: Google or Microsoft sign-in provides an email address, display information, and an account identifier through Supabase Authentication.
- Project context: when a message is sent, an AI comment is requested, teacher feedback is generated, or projects are compared, the open project's ID, title, editor language, code structure, sprite and stage names, variables, lists, and project comments may be processed. A comparison also processes the public Scratch project ID or URL you enter and that project's public code.
- AI content: messages and optional assignment requirements you send, and answers, comments, or teacher-feedback drafts generated by the AI service.
- Costume data: creating a costume processes your description. Editing a costume also processes an image of the selected costume and its SVG source when available.
- Usage data: model and provider, token counts, estimated cost, request status, and latency. We do not use this data to build an advertising profile.
- Operational logs: our web server may record your IP address, request time and path, and browser user agent for security, abuse prevention, and diagnosing failures.
Do not put private information into project names, comments, variables, lists, chat messages, or assignment requirements.
3. How we use data
We use this data only to authenticate users, compare projects, generate project-aware answers, comments, teacher-feedback drafts, and SVG costumes, preserve short-term chat history, enforce service limits, prevent abuse, diagnose failures, and operate the service. Project comparison is performed by our server using public data fetched from Scratch and does not use an AI model. We do not sell personal data or use it for targeted advertising.
4. Service providers
Supabase provides authentication and database storage. OpenRouter and the model provider selected for a request process the relevant request and project or costume data to generate an answer, comment, teacher-feedback draft, or SVG costume. Their infrastructure may process data in countries where they operate.
OpenRouter selects the model provider for each request under its routing rules. Depending on the selected provider, request data may be retained or used as described in that provider's data policy. Our use of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.
5. Storage and retention
- Project code, comparison inputs and results, assignment requirements, costume descriptions, and, when editing a costume, its image and SVG source are sent for the current request but are not stored in our database.
- Teacher-feedback drafts, including assignment requirements and a student display name entered by the teacher, are stored only in the current browser. The stage image and exported PNG are not sent to our server.
- The project ID, title, and chat messages are retained for up to 30 days.
- Non-content AI usage records are retained for up to 90 days.
- Operational logs are retained only as long as reasonably necessary for security and service operation.
- Your sign-in identity remains until you delete the account.
6. Your controls
The extension menu lets you clear the conversation for the current project or delete your account and its associated chat and usage data. Deleting the account does not delete the Google or Microsoft account or the Scratch project. Signing in again later creates a new service account; deleted history is not restored.
7. Security
We use HTTPS, access controls, and row-level database policies designed to protect stored data. No online service can guarantee absolute security.
8. Changes and contact
We may update this policy as the service changes. The effective date above will be revised when material changes are published. Questions, access requests, and deletion requests can be sent to support@scratchcopilot.org.