Overview & Scope
Application and binding scope of this privacy policy
Skribbix operates a real-time collaborative visual whiteboard application located at scribbix.com. We recognize that visual diagrams, wireframes, and team brainstorming sessions contain critical information belonging to individual creators and organizations.
This Privacy Policy details our practices for acquiring, storing, transmitting, and safeguarding information gathered across our web application, WebSocket sync servers, and user authentication systems.
Information We Collect
Categories of data processed during workspace usage
We gather minimal data strictly necessary to deliver high-performance visual whiteboard collaboration:
Account & Identity Credentials
When signing up via email or Google OAuth, we record your name, email address, profile photo URL, and secure authentication tokens.
Canvas Elements & Workspace Data
Vector shapes, pencil strokes, text nodes, sticky note text, uploaded graphics, and spatial coordinates created inside whiteboards.
Technical & Connection Telemetry
IP address, browser type, device information, and active WebSocket connection metadata required to render real-time participant cursors.
How We Use Your Data
Purpose and necessity of processing
Real-Time Synchronization
Broadcasting drawing updates, line moves, and cursor interactions instantly across connected participants in a whiteboard room.
Account & Room Security
Verifying workspace ownership, enforcing access permissions, and guarding against unauthorized access to private rooms.
Google OAuth & Verification Compliance
Adherence to Google API Services User Data Policy
Google Domain Verification & Scope Transparency
Skribbix integrates Google Sign-In for seamless user verification. We request only standard open identity scopes:
Our use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including Limited Use requirements.
Security & Transport Encryption
Protecting data in motion and at rest
We enforce technical and organizational measures to safeguard client data:
- •SSL/TLS 1.3 Encryption: All WebSocket data streams and HTTP API payloads are encrypted end-to-end.
- •Token Authorization: Access keys and session tokens validate identity on every WebSocket event.
Your Data Rights & Retention
Access, export, and complete deletion
Contact & Inquiries
Direct privacy communications
For privacy questions, data requests, or compliance feedback, contact our privacy team:







