Legal
Privacy Policy
Effective 29 September 2026 · Version 2026-09-29
This policy explains what personal information Avouro LLC ("Avouro", "we") collects through Scopebond: the websites, the hosted workspace (Scopebond Cloud), the sample workspace and the live demo. It also explains how we use that information and the choices you have. For your organization's workspace content, we act on your organization's behalf and follow its instructions. For account, billing and website data, we decide how the data is used.
What we collect
- Account information. Your name, email address and profile picture, and an identifier from the sign-in provider you choose: Google, Microsoft, GitHub or your company's single sign-on. We never receive your password for those services.
- Workspace information. Workspace names, members and their roles, invitations, rules, settings, and the audit log of changes.
- Activity records. What an AI tool attempted and what was decided: the type of action, the decision, the rule that applied, the time, and identifiers and cryptographic fingerprints. Records are designed not to contain prompts, file contents or secrets; secrets are removed before a record is signed.
- Connected computers. The name a computer reports when it connects, the AI tool it runs, and the public-key identifiers used to verify its records.
- Billing information. Payments are handled by Stripe. We never see or store your full card number. We keep your plan, subscription status, and the billing name, email, address and tax details that Stripe gives us.
- Messages. What you send when you contact us or ask to be told when a feature ships.
- Technical and usage information. IP address, browser and device information, and sign-in times, for security and to keep sessions working. We also record which pages and steps are used through PostHog, with automatic capture turned off, so no keystrokes, form contents or session recordings are collected.
Cookies and similar technology
We use one essential cookie to keep you signed in. PostHog stores a random identifier in your browser, and Cloudflare Turnstile may check that a sign-in comes from a person. We use no advertising cookies or cross-site trackers.
How we use information
We use it:
- to provide the Service: showing activity, sending alerts, invitations and the monthly report, and running billing;
- to keep the Service and our customers secure and to prevent abuse;
- to support you and to tell you about important changes to the Service or these policies;
- to understand, in aggregate, how the Service is used so we can improve it;
- to meet legal and tax obligations.
Where the GDPR or UK GDPR applies, we rely on one of these legal bases: performing our contract with you or your organization, our legitimate interests in running a secure and useful service, your consent where the law requires it, or a legal obligation.
We do not sell personal information. We do not share it for cross-context behavioural advertising. We do not use your data to train AI models.
Who we share it with
We share information only with service providers that process it for us under contract, and only as needed:
- Cloudflare: hosting, storage, backups and security.
- Stripe: payments and invoices.
- Resend: email delivery.
- PostHog: product analytics.
- Sentry: error monitoring.
- The sign-in provider you choose, to sign you in.
We may also disclose information when the law requires it, to protect rights and safety, or as part of a merger or sale of our business, in which case this policy continues to apply.
How long we keep it
- Account and workspace information: for as long as the account or workspace exists.
- Activity records: for your plan's retention period (30 days on Free, 90 days on Team, one year on Business, or as agreed for Enterprise), then removed.
- Deleted workspaces: purged after a 7-day undo period.
- Encrypted backups: roll off within 30 days.
- Billing and tax records: for as long as the law requires.
Your choices and rights
- You can download the personal data we hold about you at any time: Settings → Your data in the workspace.
- Workspace owners and admins can export records and the audit log, remove members, and delete the workspace.
- Depending on where you live, you may have the right to access, correct, delete or port your personal information, or to object to or restrict its use. Email support@scopebond.com and we will respond within 30 days. For data in an organization's workspace, we may refer you to that organization.
- California residents have the rights described above. We will not treat you differently for using them.
- If you are in the EU or UK, you may also complain to your data protection authority.
Security
Data is encrypted in transit, and our providers encrypt it at rest. Sign-in tokens are stored encrypted, and backups are encrypted. Access is limited to the people who need it. The Trust page describes our controls in more detail.
International transfers
We are based in the United States, and your information is processed there and wherever our providers operate. Where the law requires it, we rely on appropriate safeguards such as standard contractual clauses. A data processing agreement is available on request from sales@scopebond.com.
Children
Scopebond is a business service and is not directed to children. We do not knowingly collect personal information from anyone under 16.
Changes to this policy
If we make a material change, we will tell you by email or in the product before it takes effect. The version and effective date are shown at the top of this page.
Contact
Avouro LLC, Michigan, USA. Privacy questions and requests: support@scopebond.com. Security reports: security@scopebond.com.