Who this covers
This policy describes how Quintessence Group, Inc. (“Scoped”, “we”, or “us”) handles personal information through scoped.ai, Scoped Cloud at app.scoped.ai, the Scoped desktop and mobile apps, and support. The terms of service cover use of the product. Charter and Aether, our other products, have their own privacy notices.
We decide how account, billing, security, website, and support information is used. When your employer or another organization provides your workspace, it decides what work is stored and who can access it, and Scoped processes that workspace information to provide the service. That organization may have its own privacy notices and obligations. Ask its workspace administrator about requests involving shared work.
Information we collect
Information comes from you, from people who invite you or contribute to your workspace, from imports and clients you authorize, and from your use of the service.
- Account and profile
- Name, email address, job title, username, and preferences such as notification settings and timezone. Also email-verification status, workspace memberships, roles, and invitations. If you use a password, we store only a hash of it.
- Sign-in with Google, Microsoft, or Slack
- Where offered, and only if you choose it, we receive your name, email address, and account identifier from that provider. For Google, we also receive your profile photo address. We request only basic identity and keep none of the sign-in tokens the provider issues. We do not request access to your email, calendar, files, contacts, or Slack messages.
- Account security
- Sessions, including the IP address, browser, and sign-in method. Two-factor authentication secrets and backup codes, which are stored encrypted. Passkey public keys and device details (private keys stay on your device). Short-lived verification codes, stored as hashes. API keys, stored as hashes, with the time each key was last used and a record of key changes.
- Your team’s work
- Issues, projects, initiatives, cycles, comments, labels, status updates, and activity recording who changed what. Attachments are a title and an external URL, never an uploaded copy of the linked file.
- Information about your clients and contacts
- Companies, contacts, deals, notes, follow-ups, and imported spreadsheets you or your teammates add. These can include other people’s names, email addresses, phone numbers, job titles, locations, social media profiles, and notes about your relationship with them. Scoped does not buy or enrich this information from other sources.
- Workspace setup
- Workspace name, industry, and primary use case.
- Billing
- Plan, trial and subscription status, and billing identifiers from Stripe. When an administrator starts a purchase, Stripe receives their email address and the workspace name. Stripe and Link, not Scoped, collect your payment details. Scoped shows your card type, last four digits, and invoices by reading them from Stripe when you open billing, and does not store full card numbers.
- Agent and integration access
- For agents and other clients you authorize: client details, permissions, workspace bindings, and token-related records. Changes a connected agent makes are recorded in workspace history with the tool it used.
- Email we send
- The account, billing, reminder, and activity messages we send, with their delivery status. If an address permanently bounces or reports a message as spam, we keep a hash of it so we stop sending there.
- Support requests
- Your reply address, the category, subject, and description you send, any steps to reproduce, and diagnostic details (platform, app version, error code, page) only if you choose to include them. The support form does not accept attachments.
- Technical and operational
- Request records with paths, status codes, timings, and account or workspace identifiers. Load-balancer logs, which include IP addresses, browser information, and full request URLs (for example, search terms). Counters that limit repeated requests from an IP address. Error details, which may contain contextual information. Database backups contain copies of the records they protect.
How we use it
- Provide your account and workspace, authenticate access, preserve project history, and carry out actions you or authorized members and clients request.
- Manage plans, trials, subscriptions, and billing.
- Send email verification, invitations, password recovery and security codes, billing notices, reminders, and the activity notifications you turn on, and respond to support requests.
- Suggest help articles that fit your workspace’s primary use case.
- Detect abuse, enforce permissions, investigate errors, maintain reliability, and recover from incidents.
- Meet applicable legal obligations, resolve disputes, and protect the rights and safety of users and the service.
We do not sell personal information or share it for targeted advertising, and we do not use your workspace content to train machine-learning models.
Where data-protection law requires a legal basis, we rely on: performing our agreement with you, for account, service, and billing delivery; legitimate interests in secure operation, support, and preventing misuse, balanced against your rights; compliance with legal obligations; and consent where required. For workspace content handled on an organization’s instructions, that organization is responsible for its legal basis. Accepting our terms is not consent to every use of personal information.
Account and authentication details are needed to provide Cloud access. Other content is your choice, although omitting it may limit the features you can use.
Cookies, storage and icons
Scoped Cloud uses cookies that keep you signed in and protect sign-in and support forms. These cookies are necessary for the service to work. Browser storage remembers preferences such as your selected workspace, table layouts, and collapsed groups. Clearing cookies signs you out, and clearing browser storage resets those preferences.
The website and apps contain no advertising trackers, session replay, or product-analytics scripts. Hosting and download providers still process request information to deliver and protect their services. The download page detects your operating system in your browser to recommend a desktop option. It does not require an account.
On scoped.ai, a host-only cookie can remember your website cookie preferences for 180 days. Optional analytics and advertising remain off on this website regardless of the preference you save today. We will ask again before enabling either purpose. Dismissing the notice hides it only for the current tab session and saves no preference. You can reopen cookie settings at any time. Scoped Cloud at app.scoped.ai handles its own cookies separately.
To show company icons, the web and mobile apps load each company’s small website icon directly from that company’s domain. The icons on the connected-agents page load from the providers’ own sites. As with any web request, those sites receive your IP address and browser information. The desktop app does not make these requests.
Who receives information
Your workspace. Information you add is available to people with the relevant workspace access. Members can see other members’ names, email addresses, and authorship information. Owners and administrators manage membership and permissions, and can export workspace records, including personal information within them.
Service providers. We use Amazon Web Services for Cloud hosting, databases, backups, logs, and desktop downloads. Vercel hosts this website and our domain records. Resend delivers our email, including recipient details, message content, and any links in the message. Our mailbox providers receive the email you send us. Stripe and its merchant-of-record service, Link, process payments and taxes under their own privacy terms. If you sign in with Google, Microsoft, or Slack, that provider takes part in the sign-in. Providers act on our instructions or under their own terms where they have a direct relationship with you, such as Link for your purchase.
Support and operations. A support request becomes an item in Scoped’s internal support workspace, where the people handling support can see it. Personnel handling support, maintenance, or security may need to access information relevant to that work.
Legal and business circumstances. Information may be disclosed where required by law, to address fraud or security threats, or to establish or defend legal claims. If Scoped is involved in a merger, acquisition, or transfer of its business, information may be transferred subject to applicable privacy obligations and required notices.
Connected agents and integrations
You can authorize external AI agents and other clients through the Model Context Protocol (MCP) or an API key. Consent identifies a workspace and the permissions requested. A connected client can read information or take actions within the access you grant and your own permissions. Its actions become part of workspace history. Charter, another Quintessence Group product, connects the same way when a workspace authorizes it. It can then read and update the records its permissions cover, including clients and deals.
Data returned to a connected client leaves Scoped. That provider’s privacy terms, retention, model-training settings, and other policies govern its copy. Review those terms before connecting. Revoking a connection stops future access through that grant. It does not recall information already received or undo completed changes.
Desktop and mobile apps
Desktop. Desktop workspace records stay on your computer or in an external database you choose. They are not automatically copied into Scoped Cloud, and the desktop app does not require a Scoped account. An optional local password is stored only as a hash. The app stores database connection credentials in the operating system’s credential store. It includes no automatic telemetry, analytics, or crash-report uploads. It writes local runtime files and saves the workspace exports and diagnostic bundles you request. Diagnostics redaction is best effort, so review a bundle before sharing it.
Downloading the app creates requests to the download host, and an update check you start contacts the download service. Connections to a database or an agent you choose are separate from telemetry. Removing the app does not by itself erase your database, credential store entries, exports, or backups. See the desktop recovery guide for recovery and removal guidance.
Mobile. The mobile app signs in to Scoped Cloud and keeps its session in the device’s secure storage. Voice commands and the chat assistant run entirely on your device, using speech-recognition and language models built into the app and the operating system. Audio is never recorded to storage or sent to Scoped or any other service. Transcripts stay in the app’s memory until you save them as work, and chat history is cleared when the app restarts. Actions and searches the assistant runs on your behalf go to Scoped Cloud like any other request.
Location and security
Scoped Cloud is hosted by Amazon Web Services in the United States (Northern Virginia). Our providers and support operations may process information in other locations. Using the service from another country therefore involves transferring your information to the United States, whose data-protection laws may differ from those where you live. Contact us for information about how a transfer that concerns you is handled.
Our safeguards include access controls, hashed passwords, encrypted two-factor secrets, session revocation, HTTPS, and encrypted database storage. These are safeguards, not a promise of perfect security or end-to-end encryption. You also help protect your information by securing your accounts, reviewing membership, and choosing agent permissions carefully.
How long information stays
Workspace records remain while the workspace exists unless they are deleted through an available deletion process. Archiving is not deletion: archived work stays in the workspace. Session and token expiration ends access but does not necessarily erase every associated record at that moment.
- Support requests: the message, reply address, and diagnostics are erased after 90 days. The internal support item created from a request is kept as a support record.
- Logs: application and load-balancer logs are kept for up to 90 days, and network logs for 30 days.
- Security records: counters that limit repeated sign-in, verification, and email attempts are keyed by IP address, or by a keyed hash of an IP address, email address, or account, and are deleted within hours.
- Billing and email records: subscription records stay with the workspace. Payment event records, trial eligibility, and email delivery and suppression records are kept to operate billing and email, meet legal obligations, and resolve disputes. Stripe and Link keep their own records under their own terms.
- Everything else: account, support, and security information is kept for as long as needed for the purposes above, including resolving requests, investigating misuse, and meeting legal obligations.
Deletion from the active database does not immediately remove backup copies. Automated database backups are kept for 14 days. A database snapshot taken before each release is also kept until newer releases replace it, which can be longer. Deleted information can therefore remain in backups for a period after deletion.
Export and deletion
- Export work. Workspace owners and administrators can export supported workspace records as JSON. Exports include attachment titles and URLs, not the linked files. They exclude authentication secrets and sessions, agent grants and tokens, pending invitations, and password-reset records. Each export describes its omissions.
- Manage access. Cloud account controls let you review and revoke sessions, connected agents, and API keys. Workspace administrators manage membership. Revocation does not delete copies already exported or shared.
- Delete a Cloud workspace. The workspace’s sole owner confirms the workspace name and their password. Any paid subscription must have ended first. The workspace and its workspace-owned records are then removed from the active database. Export first if you need to keep a copy.
- Delete a Cloud account. Transfer or resolve sole ownership of your workspaces first. Account deletion removes your sign-in account, sessions, security settings, and memberships, and revokes associated access. It does not delete shared work you authored. A historical profile with your name, email address, job title, username, preferences, and timestamps remains for attribution, even after sign-in access is removed.
Account and workspace deletion therefore do not erase every personal record. Billing records held by Stripe and Link, payment event and trial records, email delivery records, and backups are handled as described above. Contact us to request further removal or anonymization. We will assess what applicable law requires and explain any limits. The Cloud controls above do not delete data in a database you operate, on another person’s device, or in independent copies held by an agent provider or the host of a linked attachment.
Your privacy rights
Depending on your location and which laws apply, you may have rights to access, correct, delete, or receive a portable copy of personal information; object to or restrict certain processing; withdraw consent where processing is based on consent; or complain to a data-protection authority. Withdrawal does not affect earlier lawful processing. Some US state laws also provide rights relating to sale, targeted-advertising sharing, or sensitive information, and a right to appeal a denied request. We do not sell personal information or share it for targeted advertising.
Send a request to support@scoped.ai. We may need to verify your identity and, where relevant, an authorized representative’s authority. We will respond under the rules and timeframes that apply to the request and will not discriminate against you for exercising your rights. These rights have exceptions, and we will explain a refusal where required.
If an organization controls the workspace information in your request, contact its administrator as well. We may need to direct the request to that organization or help it respond.
Children
Scoped is a business tool for people 18 and older, as the terms of service require. It is not directed to children, and we do not knowingly collect personal information from them. If you believe a child has provided personal information, contact us so we can investigate and delete it where appropriate.
Changes to this policy
The effective date at the top of this page identifies the current version. When we make material changes, we will explain them and give notice before they take effect where reasonably practicable, and we will obtain consent where the law requires it. A revised policy does not by itself authorize uses that require your consent.
Contact
Privacy questions or requests: support@scoped.ai.
Quintessence Group, Inc.
PO Box 5047, Breckenridge, CO 80424, United States