Privacy Policy
Last updated: August 3, 2026
This Privacy Policy explains how Scout Prompt Score, Inc., doing business as "Scout" ("Scout," "we," "us," or "our"), collects, uses, shares, and protects personal information when you use the Scout website and services (the "Service"). It applies to our customers, prospective customers, and visitors — and to people whose information we process because a customer tracks their business in the Service (for example, a competitor a customer compares itself against). If you are in that last group, Section 7 explains the rights you have and how to exercise them; you don't need a Scout account to do so.
By using the Service, you agree to this Policy. If you don't agree, please don't use the Service.
1. Who we are and how to contact us
Scout is operated by Scout Prompt Score, Inc.. For any privacy question or request, contact us at support@scoutpromptscore.com or 605 W 9th Street, Unit #1007, Austin, TX 78701.
Which role we play, in each framework's own words:
- Under U.S. state privacy laws (including California's CCPA/CPRA and Texas's TDPSA), we are the "business" (California) / "controller" (Texas and most other states) for the personal information described in this Policy: we decide what is collected and why. The vendors listed in Section 5 that handle personal information on our instructions are our "service providers" (California) / "processors" (Texas and most other states).
- Under the EU/UK GDPR, where it applies, we are the controller of that same information, and those vendors are our processors or sub-processors.
There is one place this gets more specific. The business information you enter about the business(es) you track — and the AI answers we collect about them — is information you supply and control, and you can access, correct, export, or delete it in the Service at any time. We still handle it as a controller/business under this Policy, because we decide the purposes it is used for (running measurements, generating your reports, and producing the de-identified benchmarks described in Section 4). We are not acting as your processor or service provider for it, and this Policy — not a customer data processing agreement — governs it unless you and we sign one (see Section 5).
2. Information we collect
a. Information you provide:
- Account information — your name, email address, password (stored in hashed form), and profile details. If you sign in with Google, we receive basic profile information (such as name and email) from Google per your Google settings.
- Business information — details you enter about the business(es) you track, such as business name, address, website, and category/specialties, and related inputs the Service uses. Business information can itself be personal information. If you are a sole proprietor or an individual practitioner — a solo dentist, a one-van plumber, a single-attorney firm — your business name, address, phone number, or website may identify you personally. Where that is the case, we treat it as personal information and it gets every protection this Policy describes: the same access, correction, deletion, and export rights in Section 7, the same retention limits in Section 9, and the same "we do not sell or share it" commitment in Section 5. We do not maintain a separate, lesser standard for "business" data.
- Billing information — your plan and billing details. Payment card details are collected and processed directly by our payment processor, Stripe; we do not store your full card number. We receive limited information such as the card brand, last four digits, expiration, and transaction status.
- Communications — information you provide when you contact us (such as support emails) or respond to surveys.
- Free visibility checker — if you use our free public AI-visibility checker, we collect the business name and location you enter (to run the check) plus limited technical metadata (such as IP address and submission timing) used solely to prevent abuse and control cost. Providing an email afterward is optional; if you do, we send you your report and one short follow-up about Scout (about a week later), and then nothing more unless you subscribe. You can unsubscribe at any time via the link in those emails.
b. Information collected automatically:
- Usage data — how you interact with the Service (pages/features used, actions taken, timestamps).
- Device and log data — IP address, browser type, device and operating system information, and similar technical data.
- Cookies and similar technologies — see Section 6.
c. Information from third parties:
- Google (if you use Google sign-in), as described above.
- Stripe (payment and transaction status).
- Data the Service retrieves from AI Engines and public sources in the course of measuring visibility — this is generally about businesses and public AI outputs, not about you personally, but is described here for transparency.
d. Sensitive personal information. We do not intentionally collect sensitive personal information (such as government IDs, precise geolocation, health information, biometric or genetic data, racial or ethnic origin, religious beliefs, union membership, sexual orientation, or financial account numbers beyond what Stripe handles), and we ask that you not submit it. Scout works with business and marketing information only — we do not process patient, client, or customer records of yours. Because we do not collect it, we also do not use or disclose sensitive personal information for any purpose that would give you a right to limit that use under the CPRA. There is nothing for you to limit, and no "Limit the Use of My Sensitive Personal Information" mechanism is needed. If that ever changes, we will update this Policy and provide the mechanism before we start.
e. Notice at Collection — what we collect, why, and for how long. This table restates the sections above using the statutory categories California uses, so you can check our practices against the law directly. "Sold" and "shared" are used with their CCPA/CPRA meanings; as Section 5 explains, we do neither.
| Category (CCPA/CPRA) | What we collect | Why we collect it | How long we keep it |
|---|---|---|---|
| Identifiers | Name, email address, account ID, IP address, and (if you use Google sign-in) your Google account identifier | Create and secure your account, authenticate you, send reports and alerts, respond to you, prevent abuse | Life of your account; deleted when you delete your account (Section 9) |
| Customer records (Cal. Civ. Code §1798.80(e)) | Billing name, billing address, and the limited card metadata Stripe returns to us (brand, last four digits, expiration, transaction status) | Process payments, manage your subscription, meet tax and accounting obligations | Transaction records up to 7 years for tax and accounting; Stripe retains payment records under its own policy |
| Commercial information | Your plan and subscription history, the business(es) you track, and the reports and action plans generated for you | Provide and operate the Service, produce your monthly reports and recommendations, manage billing | Life of your account (Section 9) |
| Internet or network activity | Pages and features used, actions taken, timestamps, browser and device type, referring page | Operate, secure, troubleshoot, and improve the Service | Analytics is cookieless and aggregate (Section 6); server and application logs are kept only as long as needed for security and troubleshooting |
| Approximate location | The business address you enter, and coarse location inferred from IP address | Run location-specific visibility measurements; rate-limit and prevent abuse of the free checker | With the associated record (Section 9). We do not collect precise geolocation |
| Professional or business information | Business category, specialties, services, and credentials you enter about the business you track | Build the query set used to measure your AI visibility and to draft your action plans | Life of your account (Section 9) |
| Inferences | Your Prompt Score, score history, engine-level metrics, competitor findings, and recommendations | Deliver the core product — telling you how AI engines describe your business and what to fix | Life of your account. Raw AI query runs 90 days; stored AI answer text about 12 months (Section 9) |
| Sensitive personal information | None. We do not intentionally collect it — see Section 2(d) | Not applicable | Not applicable |
| Protected classifications, biometric data, audio/visual data, education records | None. We do not collect these | Not applicable | Not applicable |
We do not use any category above for a purpose materially different from the one stated, and we do not sell or share any of them (Section 5).
3. How we use information
We use personal information to:
- Provide, operate, maintain, and secure the Service, including creating your account and running visibility measurements.
- Process payments, manage subscriptions, and send billing-related messages (via Stripe and our email provider).
- Send you the Service's communications — including your monthly reports and event alerts — and respond to your requests.
- Send product updates and, where permitted, marketing emails (you can opt out — see Section 7).
- Run the free public visibility checker and, if you opt in, send your report and a single short follow-up about Scout — both with a one-click unsubscribe (see Section 7).
- Monitor, analyze, and improve the Service, develop new features, and troubleshoot.
- Detect, prevent, and address fraud, abuse, security issues, and violations of our Terms.
- Comply with legal obligations and enforce our agreements.
Legal bases (for international users where required): we process personal information as needed to perform our contract with you, for our legitimate interests in operating and improving the Service, with your consent (where required, e.g., certain cookies/marketing), and to comply with law.
4. Aggregated and de-identified data
We create and use aggregated or de-identified data derived from use of the Service — for example, cross-business benchmarks and visibility trends across AI Engines — to operate, analyze, improve, and develop the Service. This data does not identify you or any individual, and we maintain it in non-identifiable form.
5. How we share information
We do not sell your personal information for money, and we do not sell it for anything else of value. We also do not share your personal information for cross-context behavioral advertising — the separate concept California calls "sharing." We do not build advertising profiles, we do not run ad-tech or advertising cookies, we do not operate advertising pixels, and we do not disclose your information to advertising networks, data brokers, or anyone who would use it to target ads to you elsewhere. Our analytics is cookieless and does not track you across other sites (Section 6). In the twelve months before the date at the top of this Policy, we have not sold or shared personal information, and we have no plans to. Because there is no sale or sharing, there is no "Do Not Sell or Share My Personal Information" link to click — but see Section 6 for how we treat opt-out preference signals anyway.
We share personal information only as follows:
- Service providers / processors who help us run the Service, under contracts that limit their use of the information to providing services to us. These currently include:
- Stripe — payment processing.
- Vercel — application hosting, and privacy-friendly, cookieless website analytics (see Section 6).
- Resend — sending reports, alerts, and other emails.
- Neon — managed PostgreSQL database (where your account and business data is stored).
- Inngest — background-job orchestration (running scheduled measurements, reports, and alerts); it handles job and event metadata such as organization and business identifiers, and on some events a customer email address.
- AI Engine and measurement providers — currently OpenAI, Anthropic, Google, Perplexity, and SerpApi — to the extent queries are run through their services in operating the Service. See the subsection below and our Subprocessors page for the current list and the data each handles.
- Legal and safety — when we believe disclosure is required by law, legal process, or to protect the rights, property, or safety of Scout, our users, or others.
- Business transfers — in connection with a merger, acquisition, financing, reorganization, or sale of assets (including a change of corporate form or state of incorporation), your information may be transferred as part of that transaction, subject to this Policy.
- With your direction or consent — when you ask us to share information or otherwise consent.
Not every company we work with is our processor. Stripe (payments), Vercel (for its own cookieless analytics product), and Google (sign-in and business-listing lookups) act as independent controllers for their own operational data, under their own terms rather than ours. Their handling of that data is governed by their privacy policies, which are linked from our Subprocessors page.
AI Engines and model training — what happens to what we send them. Running a visibility check means sending a query to an AI engine. Those queries are about the business being measured (its name, location, and category) rather than about your account, but the question of what those providers may do with what we send is important enough to answer directly:
- We use these providers on commercial API terms with model training off. Under those terms, OpenAI, Anthropic, Google, and Perplexity do not use the content we submit through their APIs to train or improve their models. This is a deliberate configuration choice, not a default we assume — it is the difference between a commercial API account and a consumer ChatGPT or Claude.ai account, which do train on what you type into them.
- They may retain what we send briefly for their own abuse monitoring, as their terms permit, before deleting it. That is a security control on their side, not a training use.
- The no-training commitment covers the AI measurement providers named above. It does not extend to companies that act as independent controllers for their own data — most notably Stripe, which may use data it holds in that capacity for its own model development under its own privacy policy. We name that here rather than let a blanket claim quietly cover it.
- If a provider's terms change, or we add a provider whose terms differ, we will update this Policy and the Subprocessors page before that provider starts handling your data.
Changes to our subprocessors. We keep the current list on our Subprocessors page and update it before a new subprocessor begins processing customer data, so the page is the place to check. We do not currently operate a subscription list that emails customers in advance of each change. If your own compliance obligations require advance notice of new subprocessors, a right to object to them, or a signed data processing agreement with standard contractual clauses, contact us at support@scoutpromptscore.com and we will put an agreement in place with you — this is common for agencies whose own clients impose those obligations, and most self-serve customers will never need one.
6. Cookies and tracking
We use cookies and similar technologies to keep you signed in, remember preferences, secure the Service, and understand usage.
- Essential cookies — needed for the Service to function (e.g., authentication).
- Analytics — we use Vercel Analytics, a privacy-friendly analytics tool that does not set cookies and does not collect personal information, build advertising profiles, or track you across other sites. We load it only if you accept analytics in our cookie banner; if you decline (the default) or your browser sends a "Do Not Track" or Global Privacy Control signal, no analytics is loaded.
Your choices: you can control cookies through your browser settings, and through our cookie consent banner.
Opt-out preference signals (Global Privacy Control). We currently do respond to browser "Do Not Track" and Global Privacy Control (GPC) signals. We treat GPC in both of the ways it can matter:
- As a cookie preference — a GPC signal means no analytics is loaded, the same as declining in our banner.
- As a valid opt-out of sale and sharing — California's regulations require businesses to honor GPC as a legally binding request to opt out of the sale or sharing of personal information, not merely as a cookie setting. We treat it that way. As Section 5 explains, we do not sell or share personal information about anyone, so a GPC signal does not change what we do with your information — but we want the answer on the record rather than left to inference. The same applies to the opt-out preference signals recognized under Texas's TDPSA and comparable state laws.
Sending a GPC signal does not require an account, and we do not ask you to verify your identity to honor it.
7. Your choices and rights
Everyone:
- Access/update much of your account and business information directly in the Service.
- Export your data — request a full export of what Scout holds about your business from Account → Data & privacy in your dashboard.
- Marketing opt-out — unsubscribe via the link in marketing emails or in your notification settings. (We may still send essential transactional messages, such as receipts, reports tied to your subscription, and security notices.)
- Delete your account — you can delete your account in the Service; see Section 9 for retention.
U.S. state privacy rights (including California's CCPA/CPRA and Texas's TDPSA): Depending on your state, you may have the right to:
- Know/access the personal information we hold about you and how we use and share it, and to obtain a portable copy.
- Request correction of inaccurate personal information.
- Request deletion of your personal information.
- Opt out of the "sale" or "sharing" of personal information, of targeted advertising, and of profiling in furtherance of decisions that produce legal or similarly significant effects.
- Limit the use of sensitive personal information (see Section 2(d) — we do not collect it, so there is nothing to limit).
- Not be discriminated against for exercising your rights.
- Appeal a decision we make on your request, where your state provides that right (Texas and several other states do). If we decline a request, we will tell you why and how to appeal.
On targeted advertising and profiling, specifically. Texas's TDPSA and similar laws single these out, so we answer them directly rather than folding them into the list above: Scout does not engage in targeted advertising. Scout does not sell personal data. Scout does not perform profiling in furtherance of decisions that produce legal or similarly significant effects concerning you — no credit, lending, housing, insurance, employment, education, or healthcare decisions are made or informed by anything we do. Scout scores how AI engines describe a business; it does not score, rank, or make decisions about people. There is accordingly nothing to opt out of on these three grounds, and we will update this Policy before that changes.
How to make a request. You can reach us any of these ways — pick whichever suits you:
- In the Service — for access, export, and deletion, the fastest route is Account → Data & privacy in your dashboard, which handles the request directly.
- Our web form — scoutpromptscore.com/contact.
- Email — support@scoutpromptscore.com.
We will verify your request and respond within the timeframe required by law. If you have an account, we verify by confirming you control the account email. If you don't have an account — for example, because we hold information about your business only as a result of someone else tracking it — we will ask for enough information to match your request to the records we hold, and no more; we will not create an account or ask you to sign up in order to exercise a right. You may use an authorized agent where permitted.
International users (EU/UK and others): see Section 11.
8. Data security
We use reasonable administrative, technical, and organizational measures designed to protect personal information (such as encryption in transit, hashed passwords, and access controls). However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your login credentials confidential. A plain-English description of the specific controls we run — and of what we honestly don't have yet — is published at scoutpromptscore.com/security.
If there is a breach. If personal information we hold is subject to a breach of security that is likely to affect you, we will notify you and the appropriate regulators as required by applicable law, without undue delay once we have confirmed the breach and identified who is affected. Notice to you will go to the email address on your account, and will describe — as far as we know it at the time — what happened, what information was involved, what we are doing about it, and what you can do. Where the law sets a specific deadline (for example, 72 hours to notify a supervisory authority under the GDPR), we will meet it. We will not delay telling you in order to complete an investigation first; we would rather tell you what we know and follow up.
9. Data retention
We keep personal information only as long as it serves the purpose it was collected for, plus any period the law requires. We apply these periods:
| What | How long we keep it | Why |
|---|---|---|
| Account information (name, email, hashed password, settings) | For the life of your account. Deleted when you delete your account — immediately and permanently, with no grace period | It is what makes your account work |
| Business profiles, scores, reports, and action plans | For the life of your account; deleted with the account | Your score history is the product; you can also delete individual businesses at any time |
| Raw AI query runs (the verbatim calls we make to AI engines) | 90 days, then automatically deleted | Data minimization — the extracted signals we keep are enough; the raw calls are not |
| Stored AI answer text (the answers engines gave, which can name people and competitors) | About 12 months, then automatically deleted | The same reason, on a longer window because reports and trends draw on it |
| Free visibility checker submissions, including the anti-abuse metadata in Section 2(a) (IP address, user agent, submission timing) | 90 days, then automatically deleted | Long enough to catch abuse patterns and to send the one follow-up email about a week out; no reason to keep it after that |
| Unsubscribe / do-not-contact records | Indefinitely | This one is deliberate. It is a short list of email addresses that asked us never to write again. Deleting it is how companies accidentally re-email people who opted out |
| Billing and transaction records | As long as tax, accounting, and audit law require — generally up to 7 years | Legal obligation. Stripe separately retains payment records under its own policy |
| Aggregated / de-identified benchmark data (Section 4) | Indefinitely, in non-identifiable form | It no longer identifies anyone, and it is what makes cross-business benchmarks possible |
| Server and application logs | Only as long as needed for security, troubleshooting, and abuse investigation | Operating a service safely |
When you delete your account, we delete or de-identify your personal information promptly, except where retention is required (for example, transaction records for tax and accounting, or as Stripe retains payment records under its own policies). Aggregated and de-identified data (Section 4) may be retained. Where an exact period is not stated above, we determine how long to keep information by asking how long it is needed for the purpose it was collected for, how long the law requires us to keep it, and whether it is needed to resolve a dispute or enforce our agreements.
10. Children's privacy
The Service is a business tool intended for adults (18+) and not directed to children. We do not knowingly collect personal information from anyone under 18 (or under the minimum age in their jurisdiction). If you believe a child has provided us personal information, contact us and we will delete it.
11. International users and data transfers
The Service is operated from and hosted in the United States and is intended primarily for U.S. users. We do not market the Service in the EU, the UK, or the EEA, and we do not monitor the behavior of people there. If you access the Service from outside the U.S., your information will be transferred to, stored, and processed in the United States, where privacy laws may differ from those in your country.
If and to the extent the EU/UK GDPR applies to you, you may have rights to access, correct, delete, restrict, or object to processing of your personal information, to data portability, and to lodge a complaint with your local supervisory authority; and we rely on the legal bases described in Section 3. To exercise these rights, contact support@scoutpromptscore.com.
How a transfer to the U.S. is lawful. We would rather be specific than vague about this, because "your data goes to the U.S." is a disclosure, not a safeguard:
- Today, we do not have Standard Contractual Clauses in place as a standing transfer mechanism for self-serve signups. Where a person in the EU or UK chooses to sign up, the transfer of their information to the U.S. is necessary to perform the contract they are entering into with us and is made at their own request — the derogation in Article 49(1)(b) of the GDPR (and its UK equivalent).
- If you need Standard Contractual Clauses, we will sign them. Email support@scoutpromptscore.com and we will put a data processing agreement incorporating the current EU SCCs and the UK International Data Transfer Addendum in place with you, together with the transfer risk assessment they require. We would rather do that before you sign up than argue about it afterward.
- Our own infrastructure providers (Vercel, Neon, Resend, Stripe, and the AI Engine providers in Section 5) transfer data under the SCCs incorporated in their own data processing agreements.
EU/UK representative and Data Protection Officer. Because we do not target or monitor people in the EU, the EEA, or the UK, we have not designated a representative under Article 27 of the GDPR, and we have not appointed a Data Protection Officer — our processing does not involve large-scale systematic monitoring or large-scale special-category data, which are the conditions that would require one under Article 37. If EU/UK use of the Service becomes more than incidental, we will appoint a representative and name them here before continuing to offer the Service there. Until then, EU and UK users should contact us directly at support@scoutpromptscore.com, and we will handle the request as if a representative had received it.
12. Third-party links and services
The Service may link to or interoperate with third-party websites and services (including AI Engines, Google, and Stripe). We are not responsible for their privacy practices; their handling of your information is governed by their own policies.
13. Changes to this Policy
We may update this Policy. If we make material changes, we'll provide reasonable notice (for example, by email or in-app) and update the "Last updated" date. Your continued use of the Service after changes take effect means you accept the updated Policy.
14. Contact us
Scout Prompt Score, Inc. Privacy: support@scoutpromptscore.com Mail: 605 W 9th Street, Unit #1007, Austin, TX 78701
