This Privacy Policy explains how Scoped (“we”, “us”, “our”) collects, uses, stores, and protects personal data when you use getscoped.app.
This policy is designed to comply with:
We are committed to transparency. If anything here is unclear, contact us at hello@getscoped.app.
Under the LGPD, we are the data controller for studio owner and team member data. For client intake data submitted through your studio's forms, you (the studio) are the data controller and Scoped acts as the data processor.
Collected when you sign up:
Collected when you subscribe to a paid plan:
Collected automatically:
Collected when your clients fill your forms:
Under the LGPD and GDPR, we are required to identify a legal basis for each type of data processing.
| Data Type | Legal Basis |
|---|---|
| Account and studio data | Performance of contract (your use of the Service) |
| Billing data | Performance of contract, legal obligation |
| Usage data | Legitimate interest (service improvement, security) |
| Client intake data | Performance of contract (processing on your behalf) |
| Communications data | Legitimate interest (support and communications) |
We do not process sensitive personal data as defined under the LGPD (Article 5, II) or GDPR (Article 9) unless explicitly required and consented to.
We use your data only for the following purposes:
We do not:
We share data only with the following third-party services, which are necessary to operate Scoped:
| Service | Purpose | Data Shared | Location |
|---|---|---|---|
| Supabase | Database, auth, file storage | All platform data | US (AWS us-east-1) |
| Stripe | Payment processing | Billing data | US |
| Anthropic | AI brief generation | Brief form data (to generate output) | US |
| Resend | Transactional email | Email addresses, brief metadata | US |
| Vercel | Hosting and delivery | Request logs, IP addresses | US/Global CDN |
All third-party processors are bound by data processing agreements and comply with GDPR, LGPD, and applicable US law.
For EU users: data transfers to the US are covered by Standard Contractual Clauses (SCCs) where required under GDPR Article 46.
| Data Type | Retention Period |
|---|---|
| Account and studio data | Retained while your account is active + 90 days after deletion |
| Brief data | Retained while your account is active + 90 days after deletion |
| Client intake data | Retained while your account is active + 90 days after deletion |
| Billing records | 5 years (legal and tax obligation) |
| Server logs | 30 days |
| Waitlist emails | Until you are onboarded or request deletion |
When you delete your studio from the Settings page, all associated data (briefs, client data, team members) is permanently deleted within 90 days. Billing records are retained as required by law.
Depending on your jurisdiction, you have the following rights regarding your personal data:
If you are a resident of a US state with applicable privacy laws (including California, Virginia, Colorado, and others), you have the right to access, correct, delete, and opt out of the sale of your personal data. Scoped does not sell personal data.
Email us at hello@getscoped.app with the subject line “Privacy Request.” We will respond within 15 business days. We may ask you to verify your identity before processing the request.
Scoped uses the following cookies:
| Cookie | Purpose | Duration |
|---|---|---|
| Supabase auth session | Keeps you logged in | Session / 1 week |
| CSRF token | Security protection | Session |
We do not use advertising cookies, tracking pixels, or third-party analytics cookies. We do not use Google Analytics or similar tools.
We implement the following measures to protect your data:
In the event of a data breach that affects your personal data, we will notify you within 72 hours as required under GDPR Article 33, and within the timeframe required by the LGPD and applicable US state laws.
Scoped is not directed at children under the age of 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us at hello@getscoped.app and we will delete it promptly.
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email at least 14 days before the changes take effect. The “Last updated” date at the top of this page reflects the most recent revision.
For any privacy-related questions, requests, or complaints:
For complaints that we have not resolved to your satisfaction: