Privacy Policy

Last updated: 5 October 2026

This policy is written in English. Translations are offered for convenience; where they differ, the English version is the one that applies.


ScormCraft turns documents into SCORM packages, offers tools that build and inspect SCORM packages in your browser, and makes the SCORM Debugger extension. This page describes what each of them stores, what leaves your machine, and who else sees it.

1. Accounts

If you create an account we store your email address, the name you give us, and an encrypted form of your password. If you sign in with Google, GitHub or another sign-in service offered on the login page, we receive your email address and name from that service, and keep the identifier and access token it gives us so that you can sign in with it again.

Anything else you add to your profile - a picture, your company, job title, phone number, address or social profile links - is stored only because you entered it, and you can change or remove it in your profile.

To protect accounts we record when you signed in, how many times, and the IP address of your current and previous sign-in. If you arrived through a link with campaign parameters, the first-touch details described under Cookies are copied onto your account when you register.

2. Documents you convert, and the packages we generate

When you upload a document to the SCORM converter, we read it once to extract its text. The uploaded file itself is not kept after the request.

To write the course, the first 4,000 characters of that text are sent to OpenAI's API (model gpt-4o-mini), which returns the course outline, module text and quiz questions. Do not upload documents containing information you are not allowed to share with a service provider.

The generated SCORM package and its preview are stored on our server so that you can preview and download them. They are not shared with anyone, and we delete them on request: ask through the contact form.

3. Tools that run in your browser

The SCORM Tester, MP4 to SCORM, HTML to SCORM and SCORM Extractor tools work entirely in your browser. The files you open in them are read and packaged on your own device and are never uploaded to us. Your browser only downloads the scripts, styles and fonts the tools need from this website.

4. The SCORM Debugger extension

The extension counts how its own panel is used, so that we can see which parts of it help and which get in the way. It records these events, and nothing else:

  • The debugger attached to a SCORM session
  • The panel showed a SCORM API error - that one was shown, not what it said.
  • A report was downloaded, or shared
  • Help was opened
  • A suggested fix was clicked
  • Events were dropped - if the extension could not send its events for a while, a count of how many it discarded.

Each record holds the name of the event, a random identifier for one session with the panel, the extension version and two timestamps. It contains no page content, no page address, no course data and nothing you typed, and it is not linked to an account.

These records are stored on our own servers and are deleted 90 days after they arrive.

When the extension is installed it tells this website once, so that we can count installs. That is stored as an install event together with the first-touch details described under Cookies, if your browser has them.

If you rate the extension from its panel, we store the score, any comment you add, a random installation identifier, and your account if you are signed in.

5. Messages you send us

The contact form sends your name, email address, subject and message to us by email so that we can reply. It is not stored in a database.

When the extension is removed, Chrome opens a page on this site that offers a box to say what went wrong. If you write something and send it, we store what you wrote, the extension version, the language of the page and the name of your browser and operating system, worked out from your request. We do not ask for your name or email.

If you leave your email address to hear from us, we store it with the name, company and answer you gave and the first-touch details described under Cookies. The email confirming it carries an unsubscribe link, and using it stops further emails.

6. API tokens

If you create an API token, or authorise an application to act for you, we store the token's name, its scopes, when it was created and last used, and when it expires. The token itself is stored only as a hash. You can see and revoke your tokens in your profile.

7. Where your data is stored, and who else sees it

Accounts, generated packages and the records above are stored on servers we run. We do not sell or rent personal information, and we do not share it for advertising.

We use a small number of services that necessarily see some data in order to work:

  • Stripe - payment details, if and when you subscribe to a paid plan. Payment happens on Stripe's own page; we never see or store your card number.
  • Mailgun - delivers the email we send you. Mailgun tells us whether each message was delivered, failed, was marked as spam or was unsubscribed from, and we keep that record with the recipient's address.
  • Cloudflare Turnstile - checks that the person submitting the registration, contact, uninstall and converter forms is not a bot. Cloudflare sees your browser's request to its check.
  • OpenAI - writes the course from the text of a document you convert, as described in section 2.
  • Session Replay - the "Report a bug" button at the foot of each page. Your browser loads its script and stylesheet from Session Replay's server, and the script itself sends nothing. Pressing the button opens the Session Replay browser extension, or a note on where to get it. Nothing is uploaded until you choose to send a report. A report carries a screenshot or recording of the page, its address and title, your browser details, the page's console messages, and any comment or drawing you add to it. A recording also carries the network requests the page made while recording (address, method, status, headers, timing and size, with passwords, cookies and authorization headers removed) and what you did on the page: what you clicked, which form fields you changed and the values you entered in them, forms you submitted and pages you moved between. Password, card number and one-time-code fields are left out. The page's API response bodies are included only if you switch that on for a recording. The full list is in Session Replay's privacy policy.

We also disclose information if the law requires it, or to protect the rights and safety of our users.

8. Cookies

This website sets these cookies itself:

  • Session - keeps you signed in and carries the converter's result between pages.
  • Language and consent - remember the language you chose and your answer to the cookie banner, for one year.
  • Visitor identifier - a random value kept for 90 days, so that visits from the same browser can be counted once. We store only a one-way hash of it.
  • First touch - for 90 days, how you first arrived: the campaign parameters in the link, the site that referred you and the first page you opened.
  • Converter and extension markers - remember that this browser has used its free conversion, and that an extension install has already been counted.

Google Analytics, Yandex Metrika and the Facebook Pixel load only after you accept cookies in the banner. If you decline, or do not answer, they are not loaded at all.

Ahrefs Web Analytics counts visits to this website's pages. It is loaded on every page and does not wait for your answer to the banner.

9. Error and performance monitoring

Our server records how it handles each request - the address requested, how long it took, and any error - so that we can find and fix faults. These records go to monitoring infrastructure we run ourselves, not to a third party.

If you accept cookies, a share of page loads also reports how long the page took to load and any script errors to the same monitoring server.

10. Your rights

You can ask us to show you the personal data we hold about you, correct it, delete it, or send you a copy. You can delete your account yourself in your account settings, or write to us and we will do it. If you are in the EU or UK you also have the right to complain to your data protection authority.

11. Children

ScormCraft is not intended for children under 16 and we do not knowingly collect their personal data.

12. Changes to this policy

If we change what ScormCraft collects, this page changes with it, and the date at the top changes. Material changes will be announced to registered users by email.

13. Who we are, and how to reach us

The data controller for this service is the operator of scormcraft.com.