// legal · privacy

Privacy Policy.
Plain language, no dark patterns.

This is the full legal version. The plain-language summary below covers what 95% of people want to know in 30 seconds.

GDPR + CCPA compliant Last updated · 7 July 2026
// 30-SECOND SUMMARY

What you actually want to know.

  • We collect what we need to run your account + the daily brief. Nothing for resale.
  • Your drafts, briefs, and content never train shared AI models. Ever.
  • You own every piece of content ScoutRival generates for you. Export it any time as Markdown.
  • We use Appwrite (accounts + data), Stripe (billing), Resend (email), and vetted AI providers. That's it.
  • EU and UK customers: full GDPR. California: full CCPA. Data deletion on request, no questions.
  • One email gets you everything you need: [email protected]

01What we collect

We collect three categories of information — only what's needed to deliver the product, only when you give it to us.

Account data

When you sign up: name, work email, password (managed by Appwrite), authentication provider tokens if you use Google or LinkedIn SSO. If you upgrade to a paid plan: company name and billing address (handled by Stripe — we never see your card number).

Product data

To deliver the daily brief, we process: your business URL, voice samples you paste during onboarding, the competitor list you build, any briefs we generate for you, and any content you approve or edit. This is the substance of the service.

Usage data

Standard product telemetry — which features you use, error logs, performance metrics, anonymous page-view counts. We use this to keep ScoutRival fast and to know which features matter. We do not sell, share, or rent any usage data.

// WE DO NOT COLLECT

Browsing history outside ScoutRival. Location data beyond country (from IP). Camera, microphone, or contact list. Anything we don't actively need to run your account.

02How we use it

Each piece of data serves a specific purpose. Here's the full list — there is no "other":

We do not use your data to train shared AI models. Your content does not improve other customers' results.

03Third-party services

We use a small, deliberate set of sub-processors. Each one has a specific job:

// APPWRITE
Authentication, database, and file storage, running on our own managed infrastructure. Holds your account credentials and product data.
// STRIPE
Billing, subscription management, payment processing. PCI-DSS Level 1. We never see your card number. stripe.com/privacy
// GOOGLE APIs
Search Console (Search Analytics) and the Chrome UX Report — accessed only when you connect them, to power your SEO & AI-Visibility reports. See section 10 for the full disclosure. policies.google.com/privacy
// AI PROVIDERS
OpenRouter, Anthropic, OpenAI, and Google (Gemini) for text; fal.ai for images. Used to generate your content — via no-training / zero-retention modes where available. On paid plans you can bring your own API keys.
// DATA COLLECTION
Apify and our own crawling service, plus a self-hosted SearXNG search instance. Used to collect publicly-accessible competitor and market signals from the sources you choose. Your personal data does not pass through them.
// RESEND
Transactional email delivery (sign-up verification, billing receipts, daily brief notifications). resend.com/privacy
// HOSTING
Our application and databases run on our own managed cloud infrastructure. Standard server logs (IP, user-agent, timestamp) are processed to operate and secure the service.
// PLAUSIBLE
Privacy-respecting, cookieless website analytics. No personal identifiers, no cross-site tracking. plausible.io/privacy

04Cookies & tracking

We use the fewest cookies we can get away with. Specifically:

We do not use third-party advertising cookies, retargeting pixels, or cross-site trackers. There is no cookie banner because there is nothing to consent to beyond what's strictly necessary.

05Data retention

We hold data only as long as it's useful. Specifically:

  1. Active account data — kept for as long as your account is active
  2. After cancellation — your data is retained for 30 days so you can change your mind, then deleted
  3. Briefs + content you've shipped — kept for 90 days after cancellation in case you need to re-export, then deleted
  4. Billing records — retained for 7 years per tax/accounting requirements (kept by Stripe)
  5. Usage logs — anonymized after 90 days, fully deleted after 13 months

You can request immediate deletion at any point — see Your Rights below.

06Your rights · GDPR + CCPA

If you're in the EU, UK, Switzerland (GDPR), or California (CCPA), you have these rights — and they apply to everyone equally because the easier path is to honor them globally:

To exercise any of these: email [email protected]. We respond within 30 days, usually within 24 hours. No paperwork, no friction.

// CALIFORNIA · CCPA

You also have the right to know what categories of personal information we collect, opt-out of "sale" (we don't sell), and not be discriminated against for exercising your rights. We honor all of these.

07Children's privacy

ScoutRival is a B2B product for businesses. We do not knowingly collect data from anyone under 16. If you believe a minor has provided us data, email [email protected] and we'll delete it immediately.

08How we keep data safe

09Updates to this policy

We update this policy when something changes — a new sub-processor, a new feature that processes data differently, a legal requirement. When we do:

10Google user data · Search Console

ScoutRival's SEO & AI-Visibility feature lets you connect your own Google Search Console account so we can display your organic search performance inside your dashboard. This section explains exactly what we access and how we use it, in line with the Google API Services User Data Policy.

What we access

How we use it

Disconnecting & revoking access

You can disconnect Google Search Console at any time inside ScoutRival, which revokes our access and deletes the stored token. You may also revoke access directly at myaccount.google.com/permissions.

// LIMITED USE

ScoutRival's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not transfer or use Google user data to serve advertising or to train AI models, and only allow humans to read it with your explicit permission (for example, to provide support you request), for security purposes, or where required by law.

11Contact

Anything privacy-related — questions, requests, complaints — goes to one inbox:

// PRIVACY OFFICE
[email protected]
// MAILING ADDRESS
ScoutRival · Dhaka, Bangladesh · (full registered address available on request)
// DATA PROTECTION OFFICER
[email protected]
// EU SUPERVISORY AUTHORITY
You also have the right to lodge a complaint with your local supervisory authority — for example the Irish DPC, German BfDI, or French CNIL.
// QUESTIONS ABOUT THIS POLICY?

We read every email.

Privacy questions, data requests, GDPR audits, or "I just want to make sure I understand this" — all welcome.