Alchemy Lab SCP Researcher · Privacy
Privacy policy

What SCP Researcher does with your information

Effective 21 September 2026

SCP Researcher is a reader app for the SCP Wiki, made by Alchemy Lab. The short version: your data stays on your device, and the app has no ads, analytics, or trackers.


What the app stores, and where

Everything SCP Researcher keeps about you — which articles you've read, your reading queue, notes, saved offline copies, and settings — is stored on your device only, in the app's private storage. Alchemy Lab does not receive it and cannot see it.

Uninstalling the app deletes all of it.

Network requests the app makes

To show you articles, the app requests pages and metadata from two services run by others:

  • scp-wiki.wikidot.com — the article pages you open. Requests carry only the address of the page you asked for.
  • api.crom.avn.sh (the Crom API) — article titles, ratings, authors, and tags, used to build lists and credit authors.

These are ordinary web requests, like a browser would make. Those services can see your IP address and which pages you request, and handle that under their own policies. SCP Researcher sends them nothing else — no identifiers, no reading history, no account information.

Optional: Library Sync

This section applies only if you choose to sign in to Library Sync. Without signing in, nothing in it happens.

If you sign in to Library Sync, your reading progress is synchronized between your devices through Alchemy Lab's server. This is designed so that we cannot read your data:

  • Your reading data is encrypted on your device with a key derived from your password before it is sent. The server stores only ciphertext and cannot decrypt it. If you lose your password and recovery phrase, neither can we.
  • The server holds your email address (to identify your account) and the encrypted data. That is all.
  • If you sign in with Google: Google confirms who you are, and the key that unlocks your library is kept in your Google Drive, in a hidden folder that only this app can see (Google calls it the app-data folder). The server still stores only ciphertext and cannot read your data; Google holds the key file but never the encrypted data. Neither alone can read your library. We receive your Google account's email address and a stable account identifier from Google, nothing else, and we never see your Google password. You can remove the app's access at any time in your Google account's third-party access settings; your recovery phrase then remains the way back in.
  • All traffic is encrypted in transit.

You can sign out at any time in Settings, which removes the session from that device.

To delete your account and everything stored for it — every synced item, your keys, and the sessions on all your devices — use Settings → Library Sync → Delete account in the app (you confirm by typing your email), use the deletion page at alcove.alchemylab.sh/account/delete (sign in once there to prove the account is yours), or write to the address below and we will do it for you within 30 days. Our nightly database backups can hold a copy of deleted data for up to eight weeks. Your reading history on the device itself is yours and stays until you clear it in Settings.

What the app does not do

  • No advertising, and no advertising identifiers.
  • No analytics, crash reporting, or usage tracking of any kind.
  • No third-party SDKs that collect data.
  • No selling or sharing of personal information — there is none to sell.

Children

SCP Researcher is not directed at children under 13, and the articles it displays are rated for older audiences. We do not knowingly collect information from children; the app does not collect information from anyone unless they sign in to sync.

Changes

If this policy changes, the new version will be posted at this address with an updated effective date.

Contact

[email protected]

The terms for using the app and Library Sync are at alchemylab.sh/scp-researcher/terms.