Scout legal

Privacy Policy

Last updated: July 14, 2026

This policy explains what personal data Scout collects, why we collect it, who processes it on our behalf, and the rights you have over it.

1. Who is responsible

The data controller for Scout is [OPERATOR LEGAL NAME AND ADDRESS]. For any privacy question or request, contact [support email].

2. Data we collect

  • Account data. Your email address and authentication details, handled through our infrastructure provider Supabase.
  • Payment data. Payments are processed by Stripe. Stripe handles your card details; Scout never stores them. We keep only non-sensitive billing records such as what you bought and when.
  • Usage analytics. Events about how you use the product (pages viewed, features used), collected via PostHog and Vercel Analytics.
  • Error data. Technical diagnostics when something breaks (error messages, device and browser information), collected via Sentry.
  • Forecast history. The forecasts you generate and their graded results, stored so we can show your history and our public track record.
  • Support correspondence. Messages you send us and our replies.

We do not collect special categories of personal data and we do not sell personal data.

3. Why we use it

  • to provide the service: authentication, generating and storing forecasts, showing your history and allowances
  • to process payments and manage subscriptions and packs
  • to understand product usage and improve the service
  • to detect, diagnose, and fix errors and abuse
  • to communicate with you about your account, billing, and material changes
  • to send marketing communications, only if you have opted in

4. Legal bases (GDPR)

Where the GDPR applies, we rely on:

  • Contract (art. 6(1)(b)): account management, forecast generation, billing, support.
  • Legitimate interest (art. 6(1)(f)): product analytics, error monitoring, abuse prevention, securing the service. You can object at any time.
  • Consent (art. 6(1)(a)): marketing emails and non-essential cookies. You can withdraw consent at any time without affecting the service.
  • Legal obligation (art. 6(1)(c)): retaining billing records for accounting and tax law.

5. Processors we use

We share personal data only with service providers that process it on our behalf under data processing agreements:

  • Supabase: authentication, account management, and application data (EU-hosted)
  • Stripe: payment processing (card details, billing history)
  • Vercel: web hosting and Vercel Analytics (aggregate usage metrics)
  • PostHog: product analytics (feature usage events)
  • Sentry: error monitoring (crash reports, technical diagnostics)
  • Anthropic: AI model inference used to produce forecast text from match data

We may also disclose data where the law requires it, or in connection with a sale or restructuring of the business, in which case this policy continues to apply.

6. How long we keep it

  • Account data and forecast history: for as long as your account exists, then deleted or anonymized within 90 days of account deletion.
  • Billing records: as long as accounting and tax law requires (typically 5 years).
  • Analytics and error data: up to 24 months, then deleted or aggregated.
  • Support correspondence: up to 24 months after the matter is closed.

Forecasts that appear in our public track record may be retained in anonymized form, disconnected from your account, to preserve the integrity of the published record.

7. Your rights

If you are in the EU/EEA (and in many other places), you have the right to:

  • access the personal data we hold about you
  • have inaccurate data rectified
  • have your data erased (the right to be forgotten)
  • receive your data in a portable, machine-readable format
  • restrict or object to certain processing, including any based on legitimate interest
  • withdraw consent at any time, where processing is based on consent
  • lodge a complaint with your supervisory authority (in Denmark, Datatilsynet; elsewhere, your local data protection authority)

To exercise any of these rights, email [support email]. We respond within one month as the GDPR requires.

8. Cookies

Scout uses two kinds of cookies and similar technologies:

  • Essential. Required for sign-in, security, and billing sessions (set by Scout, Supabase, and Stripe). These cannot be switched off.
  • Analytics. Used by PostHog and Vercel Analytics to understand product usage. Where consent is required, these run only after you accept them, and you can change your choice at any time.

9. International transfers

Some of our processors are located outside the EU/EEA, including in the United States. Where personal data leaves the EU/EEA, we rely on the European Commission's Standard Contractual Clauses (SCCs) or an adequacy decision, together with additional safeguards where appropriate. Our Supabase database can be hosted in the EU.

10. Security

We protect personal data with encryption in transit, access controls, and reputable infrastructure providers. No system is perfectly secure; if a breach affects your data in a way that creates a high risk to you, we will notify you and the supervisory authority as the law requires.

11. Children

Scout is not for anyone under 18, and we do not knowingly collect data from minors. If you believe a minor has created an account, contact [support email] and we will delete it.

12. Changes to this policy

We may update this policy from time to time. For material changes we will notify you by email or in-app notice before they take effect. The date at the top shows the latest revision.

13. Contact

Privacy questions and requests: [support email]. Controller: [OPERATOR LEGAL NAME AND ADDRESS].