This Privacy Policy describes how SignalScout (“we”, “us”) processes personal data when you use https://scout.nuits.net and related services (the “Service”).
1. Who we are
SignalScout is operated as a software product at scout.nuits.net. For privacy requests, emailsupport@scout.nuits.net. This section must be updated with the registered legal entity name and postal address before enterprise sales.
Payments for credit packs are processed by Polar as Merchant of Record. Polar handles tax collection and customer receipts for the sale. Polar's privacy terms also apply to checkout data they process as Merchant of Record.
2. Data we collect
- Account: email address, user ID, credit balance, and account creation time.
- Authentication: single-use magic-link tokens lasting 15 minutes, plus a signed HttpOnly session cookie lasting 30 days.
- Usage: run history, research type, units charged, status, timestamps, and credit ledger entries including refunds.
- Inputs you provide: lead lists, product and value proposition text, competitor domains, and free-sample form fields. Treat personal data in those inputs as customer-controlled content.
- Monitoring: the accounts on your watchlist, the check log for each one, and the signals we found. See section 4.
- Delivery settings: the destinations you connect, which may include an email address, a Slack workspace and channel, a webhook URL, or a CRM account, plus a per-destination log of what we sent and whether it arrived.
- Integration credentials: access tokens for services you connect. These are encrypted at rest and are never included in a data export.
- Free-tool abuse control: IP address and calendar-day counters.
- Technical logs: request path, status, and latency in Cloudflare Workers logs. Optional error monitoring is used through Sentry when configured.
- Payments: Polar handles email, payment method, and tax location. We store purchase metadata needed to grant credits, including order ID and credit amount.
3. Why we process data
- Provide the Service: account access, authentication, research runs, and credits, based on contract or legitimate interests.
- Security and abuse prevention: Turnstile, IP free limits, and rate limits, based on legitimate interests.
- Billing and accounting: legal obligation or contract, through Polar and our ledger.
- Support and product improvement: legitimate interests.
We do not sell personal data. We do not scrape or resell contact databases. You bring your own lists.
Research we do for you is stored against your account only. We do not build a shared company database from customer watchlists, and one customer's research is never used to answer another customer's check.
SignalScout never contacts the people we research. We deliver research to you: in the app, by email digest to your own address, to a Slack workspace you connect, to a webhook you own, or as a note on a record in a CRM you connect. Every one of those destinations belongs to you. Where you enable a destination, prospect information you asked us to research leaves our systems for that destination, which you chose and operate.
Two consequences worth stating plainly. The email digest contains research about the companies and people on your watchlist, so enabling it sends that content to whoever provides your inbox. The same applies to a Slack workspace, a webhook endpoint, or a CRM: each is a system you control, and once we deliver there, that system's own terms govern the copy. Digest email carries no open or click tracking.
4. Continuous monitoring
If you put an account on your watchlist, we check it once a week and keep a record of what we found: a short summary, the source URL, the publication date, and the copy we drafted for you. That record may name individuals, because a leadership change names a person. It is held against your account and nobody else's.
You choose how long the wording is kept, from 30 to 400 days, with a default of 180. We keep a content-free fingerprint of each signal for the life of the watch so that a future check knows the event was already reported to you and does not report it twice. The fingerprint records that we saw a page, never what it said.
5. Subprocessors
We use the following processors to operate the Service:
- Cloudflare: hosting, D1, Durable Objects, Queues, DNS, Turnstile, and TLS.
- Polar: checkout, tax, and receipts as Merchant of Record.
- Resend: transactional magic-link email and, if you enable it, the signal digest.
- OpenRouter: model API routing for research agents, including underlying model providers.
- Exa and Firecrawl: public-web research tools used by agents.
- Slack: only if you connect a workspace, to deliver signals to a channel you choose.
- HubSpot: only if you connect an account, to attach a note to a record you own.
- Sentry: optional error monitoring when configured.
A webhook endpoint you configure is not a subprocessor of ours. It is a destination you choose and operate, and data reaching it is an onward transfer at your instruction.
6. International transfers
Infrastructure and AI providers may process data in the United States and other countries. Where required, we rely on appropriate transfer mechanisms offered by those providers, including contractual data protection terms.
7. Retention
- Magic-link tokens: 15 minutes and single-use.
- Session cookie: 30 days, or until logout or account deletion.
- Free-usage IP counters: 30 days.
- Account, runs, and ledger: until you delete your account or we close the Service.
- Watchlist: until you remove the account or delete your account.
- Signal wording and the check log: your setting, from 30 to 400 days, default 180.
- Signal fingerprints: the life of the watch. These are content-free.
- Agent check transcripts: 35 days.
- Delivery queue and attempt logs: 30 days.
- Connected-integration tokens: until you disconnect, or account deletion.
- Polar retains payment and tax records under its own policies as Merchant of Record.
8. Your rights
Depending on your location, you may have rights to access, correct, export, delete, object to, or restrict processing. In the product you can:
- Export your account, runs, ledger, watchlist, signals, check log, delivery destinations, and delivery history as JSON. The export never includes an access token or a webhook signing secret, even encrypted.
- Delete your account. This erases the user, token, run, ledger, watchlist, signal, check, delivery, and integration rows we hold, and the stored transcripts of the research agents that produced them. Where we hold a token for a service you connected, we attempt to revoke it at that service first.
- Disconnect any delivery destination on its own, without deleting the account.
- Unsubscribe from the digest with one click in any digest email.
- Log out, which clears the session cookie.
Email support@scout.nuits.net for other requests. We aim to respond within 30 days, or sooner where law requires.
9. Cookies and analytics
We use one essential session cookie, ss_session, after sign-in. Cloudflare may set security cookies related to Turnstile. We do not use third-party advertising cookies by default. Optional product analytics (Cloudflare Web Analytics or Plausible) is cookie-free when enabled and does not require a consent banner for essential operation. If we add advertising or non-essential tracking cookies for EU users, we will add consent controls.
10. Business customers (DPA)
B2B customers that process personal data through lead inputs may rely on ourData Processing Addendum in addition to this Privacy Policy.
11. Children
The Service is for business users aged 18 and over. We do not knowingly collect data from children.
12. Changes
We may update this policy. Material changes will be reflected by the “Last updated” date and, where appropriate, a notice in the product.
13. Contact
support@scout.nuits.net. We expect to reply to support email within two business days.