Privacy Policy

Your scope data is private until you say otherwise

What we collect, why we collect it, who else sees it, and how you switch any of it off. No dark patterns, no pre-ticked boxes.

Last updated · 2025-06-01Effective 2025-06-01Privacy requests: service@scopeguard.work

01What we collect

Four buckets, and one short list of things we deliberately never touch.

  • Account information. Email address, display name, a salted one-way hash of your password (never the password itself), and your interface preferences — language and theme.
  • Business data you enter. Project names, Scope Baselines, deliverable lists, revision rounds, your quote and hourly rate, every add-on entry with its hours and amount, and the add-on invoices you generate.
  • Usage data. Pages visited, features used, error logs, browser and device type, and an approximate region inferred from your IP address — country or city level, never a street.
  • Payment metadata from Creem. Subscription status, plan type, the date of the last payment and the last four digits of the card. Full card numbers and CVV never reach our servers.
  • What we do not collect: your contacts, your location trail, your clipboard, your client's identity documents, or any biometric data.

02How we use it

  • Running the product. Calculating creep against your baseline, generating add-on invoices, rendering the client read-only view.
  • Account and security. Verifying sign-in, flagging unusual access, preventing abuse of the free tier.
  • Improving the product. Aggregated, de-identified counts of which flows get used and which get abandoned. We look at the shape of the funnel, not at your projects.
  • Necessary notices. Receipts, renewal reminders, security alerts and material changes to the terms or this policy. These cannot be unsubscribed from, so we send them only when they matter.
  • Marketing. Off by default. If you opt in, every message carries a one-click unsubscribe link that works immediately.
  • What we never do: sell personal data, rent mailing lists, or feed your scope data into third-party model training.

04Third parties and the limits of sharing

Three processors, each with a narrow job and a hard boundary.

  • Creem — payments. Receives the email address and order details needed for checkout, and handles card data independently as merchant of record. Shared strictly to complete the transaction and issue the invoice.
  • Supabase — database and authentication hosting. Stores your account and business data as our processor, isolated by row-level access rules. It may not use your data for its own purposes.
  • Email delivery. Receives the recipient address and message body only — used for verification mails, receipts, and the add-on invoices you choose to send.
  • Client read-only view. Only after you generate a token link can the holder see that project's baseline and add-on entries. It never exposes your account, your other projects, or your contact details. Revoke it and the link dies on the spot.
  • Legal requests. We disclose only what a valid legal instrument actually requires, at the minimum scope, and we tell you first wherever the law allows.
  • Never: advertisers, data brokers, or anyone buying a list.

05Retention and deletion

Nothing is kept “just in case”. Every category has a clock on it.

DataRetention period
Account & business dataKept while the account is open; cleared from production within 30 days of deletion30d
Backup copiesRotated out of backup media within 90 days90d
Payment & invoicing recordsRetained as required by tax and accounting lawLegal
Error & access logsRolling window, then automatically purged90d
Revoked client-view tokensInvalid immediately; the record is removed within 30 daysInstant
Deleting your account is irreversible. Export your projects, entries and invoices first — the export button sits right above the delete button for exactly that reason.

06Your rights

All of these are free to exercise, and using them never degrades your service.

  • Access and copy. One click in settings exports every project, entry and invoice as CSV and PDF.
  • Correction. Account details and business data are editable in place. For anything you cannot reach yourself, write to us and we will fix it.
  • Deletion. Delete a single project or the whole account. Both are permanent.
  • Portability. Exports are plain CSV and PDF — they open in a spreadsheet or import into another tool without a conversion step.
  • Withdraw consent. Revoke a client-view link, unsubscribe from marketing, or turn off non-essential analytics at any time.
  • Object or restrict. Ask us to pause a specific kind of processing. We answer within 30 days, and we say yes or explain why not.
  • To exercise any of these, email service@scopeguard.work with Privacy in the subject line. We reply within five business days.

07Security

  • HTTPS end to end in transit; encryption at rest in the database; passwords stored as salted one-way hashes.
  • Row-level access. By default only the owning account can read its own rows — the isolation is enforced by the database, not by application code alone.
  • Least privilege. Team access to production data requires a request and leaves an audit trail.
  • Breach notice. If an incident is likely to affect your rights, we notify affected users within 72 hours of becoming aware, describe what happened, and state what we are doing about it.
  • No system is perfectly secure. Use a unique, strong password for your account, and turn on your email provider's two-factor authentication — your inbox is the recovery path.

08Contact and policy updates

  • Privacy questions and rights requests: service@scopeguard.work, subject line Privacy. Answered within five business days.
  • Policy updates are published on this page. Changes that affect your rights are emailed at least 30 days before they take effect.
  • ScopeGuard is not intended for people under 18. If we learn we have collected a minor's data, we delete it promptly.
Last updated 2025-06-01 · Effective 2025-06-01 · Prototype copy; have counsel review the final wording before launch.

Still holding a privacy question?

Write to us with Privacy in the subject line. A person reads it, and answers within five business days.