Privacy Policy

Last updated: July 24, 2026

1. Who we are

ScopeGuard ("we", "our", "us") provides a signal inbox that summarizes and prioritizes customer-facing emails from mailboxes you explicitly connect. This policy explains what we collect, how we use it, and the choices you have.

2. Data we collect

  • Account data: email address and hashed password (managed by our authentication provider).
  • Connected mailbox metadata: the email address, provider (Gmail/Outlook), and connection identifiers of inboxes you link through Unipile.
  • Email content processed for triage: subject, sender, snippet, thread ID, timestamp, and body of messages within your scan window. We do not fetch attachments.
  • AI classification output: the summary, category, urgency, confidence, and reasoning generated for each item.
  • Product telemetry: usage counts, error logs, and cost tracking necessary to operate the service.

3. How we use your data

  • To scan connected mailboxes and classify messages into your dashboard.
  • To draft replies you explicitly request.
  • To send replies from your connected mailbox at your direction.
  • To improve reliability, cost, and accuracy of the service (aggregate metrics only — never model training on your content).

We do not sell your data, share it with advertisers, or use your email content to train third-party AI models.

4. Subprocessors

We use the following processors under contractual data protection terms:

  • Supabase — authentication and encrypted database storage.
  • Cloudflare Workers — application hosting.
  • Unipile — mailbox connectivity (Gmail, Outlook).
  • Google Gemini via Lovable AI Gateway — AI classification and reply drafting. Requests are not retained for model training.

5. Retention & deletion

Classified items and connected-account metadata persist until you disconnect the mailbox or delete your account. Disconnecting a mailbox removes the connection at Unipile and deletes associated items from ScopeGuard. Account deletion is available on request at the contact address below and completes within 30 days.

6. Security

All data is transmitted over TLS. Mailbox connection tokens are held by Unipile — we store only opaque account identifiers. Database access is protected by row-level security so each user can read only their own rows. Passwords are checked against known-breached lists at signup.

7. Your rights (GDPR / CCPA)

You may request access, correction, export, or deletion of your personal data, and you may object to or restrict processing. To exercise any right, contact us at the address below. You also have the right to lodge a complaint with your local supervisory authority.

8. International transfers

Our infrastructure and subprocessors may process data in the United States and the European Union. We rely on Standard Contractual Clauses where required.

9. Changes to this policy

We will notify you by email of material changes at least 14 days before they take effect.

10. Contact

Data protection questions: privacy@scopeguard.app.