# Privacy Policy — DRAFT, NOT LEGAL ADVICE Same caveat as the Terms of Service: this is a real, structurally complete starting point, not a finished legal document. Have it reviewed before launch, particularly the sections on subprocessors and data retention — those need to match what you're actually doing, not a generic template. --- ## 1. What we collect **Account data:** your name, email, company name, and password (stored as a one-way hash, never in plain text). **Business data you enter:** job records, client names and contact information, cost estimates, payment records, change orders, and subcontractor contact information. This is your data and your clients'/subs' data, entered by you. **AI drafting inputs:** when you use a drafting feature (client updates, sub scope summaries, walkthrough summarization), the relevant job details are sent to Anthropic's API to generate a draft. See Section 4. **Billing data:** payment card details are handled entirely by Stripe — we never see or store your card number. We retain your Stripe customer ID and subscription status. **Usage data:** basic logs (timestamps, IP address, browser type) for security and debugging. ## 2. What we don't do We do not sell your data. We do not use your business data or your clients' data to train AI models. We do not share your data with third parties except the service providers listed in Section 4, who process it solely to help operate the Service. ## 3. How we use it To operate the Service, respond to support requests, send billing and account-related emails, and improve the product. We do not send marketing email without a clear opt-in. ## 4. Subprocessors (third parties who process data on our behalf) - **Anthropic** (api.anthropic.com) — processes the text you submit to AI drafting features, solely to generate the requested draft. Anthropic retains API inputs and outputs for 7 days by default, after which they are automatically and permanently deleted. Under standard commercial API terms, this data is never used to train Anthropic's models. - **Supabase** — stores all account and business data. - **Vercel** — runs the application. - **Stripe** — processes payments and stores payment methods. ## 5. Data retention and deletion Business data is retained for as long as your account is active. If you cancel, we retain your data for 30 days to allow export or reactivation, after which it is permanently deleted. You can request deletion at any time by contacting support@scopeflow.pro. ## 6. Security We use industry-standard practices — encrypted connections (HTTPS), hashed passwords, and tenant-isolated data access — but no system is perfectly secure, and we can't guarantee absolute security of information you transmit to us. ## 7. Your rights Depending on your location, you may have rights to access, correct, or delete your personal data, or to receive a copy of it. Contact support@scopeflow.pro to exercise these rights. [IF YOU EXPECT CALIFORNIA, EU, OR OTHER REGULATED CUSTOMERS, THIS SECTION NEEDS SPECIFIC CCPA/GDPR LANGUAGE — DO NOT SHIP WITHOUT A LAWYER'S INPUT IF SO.] ## 8. Children's privacy The Service is intended for business use by adults and is not directed at children. We do not knowingly collect data from anyone under 18. ## 9. Changes to this policy We'll notify you by email or in-app notice of material changes before they take effect. ## 10. Contact support@scopeflow.pro --- *Last updated: September 13, 2026. Replace every bracketed placeholder and have this reviewed by a lawyer, particularly Sections 4, 5, and 7, before accepting paying customers — especially any outside the U.S.*