ScouTrail← Home

Privacy Policy

Last updated: August 17, 2026

Pilot-stage legal draft, pending professional review.

This document accurately describes how ScouTrail works today, based on the actual product and its codebase. Operator, contact, and governing-law details have been confirmed, but the document as a whole has not yet been reviewed by a lawyer. Don't rely on it as a finished legal document until it has.

Who we are

ScouTrail ("we," "us") is the product available at scoutrail.app, operated by Rotem Sade.

Information we collect

  • Account information: the email address and password you sign up with, handled by our authentication provider (Supabase Auth).
  • Workspace information you provide: your company name, website domain, target market/location/language, and competitor names.
  • Website-derived facts: when you add your website, we run an automated, safety-restricted fetch of a small fixed set of your own pages (home, pricing, about, product) to suggest "Brand Truth" facts. Nothing from this becomes part of your profile until you explicitly approve it.
  • Buyer questions: the questions you approve for scanning.
  • Scan results: the answer text, citations, and mention data returned by third-party AI APIs when we send them your approved buyer questions.
  • Billing and subscription data: if you subscribe, Lemon Squeezy (our payment processor) collects your payment details directly. We never see or store your card number. We store only what's needed to manage your subscription: your Lemon Squeezy customer and subscription IDs, plan, status, and billing period dates.
  • Quick Check: when you run a free Quick Check at /quick-check without an account, we store the website address or topic you entered, the AI-generated findings (a short diagnosis of your website's content, not a claim about how you appear in any AI or search results), and a hashed (not raw) copy of your IP address for abuse and cost-limit protection. For a website check, we briefly read your homepage to generate that diagnosis, but we don't store the homepage text itself, only the findings derived from it. This is kept for up to 30 days, tied to a random browser cookie rather than your identity, and is only ever linked to your account if you sign up and we import it into your new workspace, after which the standalone anonymous copy is deleted. We don't require a separate consent step to run a Quick Check; this notice is that disclosure.
  • Post-scan feedback: after your workspace's first real scan completes, we may ask a short set of feedback questions from your dashboard. Answering is optional and scoped to your workspace.

How we use it

To run your scans, generate your Visibility Snapshot and Opportunity Cards, and operate your account. We do not sell your data, and we do not use your data to train AI models.

Third parties we share data with

Running ScouTrail requires sending some data to service providers. We don't use any advertising trackers, ad pixels, or cross-site tracking.

Active on every account

  • Supabase: database, authentication, and hosting infrastructure for all product data.
  • Vercel: hosts the application itself, and provides Vercel Web Analytics, a cookieless analytics tool that collects anonymized, aggregated page-view data (which pages are visited, approximate location, device/browser type) so we can understand traffic. It doesn't use cookies and doesn't track you across other sites.
  • Inngest: orchestrates the background jobs that run your scans.
  • Perplexity (Sonar API): receives the text of your approved buyer questions in order to generate an answer we can record and show you.
  • Lemon Squeezy: our payment processor and Merchant of Record for the paid subscription. They handle your checkout, collect and store your payment details (we never see your card number), calculate and remit sales tax/VAT, and provide the billing portal where you manage or cancel your subscription. Only active if you subscribe.

Optional, used only when configured on our side

  • OpenAI (web-search tool): an additional answer engine we support in the product; receives buyer-question text only on the accounts where it's enabled.

Cookies

We use two kinds of cookies, both required for the product to function. No third-party advertising or analytics cookies:

  • Authentication session cookies, set by Supabase Auth, to keep you signed in.
  • An active_workspace_id cookie (httpOnly) that remembers which of your workspaces you're currently viewing.

Data retention & deletion

Account and workspace data is retained while your account exists. Verified deletion requests are handled within 30 days. Limited backups and security logs may remain for a period afterward, according to our infrastructure providers' own retention schedules.

There's no self-serve deletion tool yet. Email hello@scoutrail.app to request deletion and we'll handle it manually within that window.

Anonymous Quick Check data (see above) is kept for up to 30 days, enforced by a daily automated job that deletes anything past that window, or the day after it's imported into a workspace you create, whichever happens first. Post-scan feedback (see above) is kept for as long as your account is active. Historical data from the earlier interactive preview that used to run at /pilot (now retired) is kept for 12 months from its original submission and then automatically deleted, independent of how long your account stays active. This only affects visitors who used that earlier preview. You can request earlier deletion of any of the above at the same address at any time.

Security

Your workspace's data is isolated from every other workspace using database-level Row-Level Security (RLS) policies, enforced by Postgres itself, not only by application code. The elevated service-role credential that can bypass RLS is never sent to your browser and is only used in server-side code.

Children's privacy

ScouTrail is a B2B product intended for business use and is not directed at children under 16. We don't knowingly collect information from them.

Compliance frameworks

We do not currently claim compliance with GDPR, CCPA, or any other specific privacy framework. If your organization has specific compliance requirements, email hello@scoutrail.app before using ScouTrail with real customer or business data.

Changes to this policy

We may update this page as the product changes. Material changes will be reflected here with an updated "Last updated" date.

Contact

hello@scoutrail.app