Effective 4 September 2026

Privacy

What ScoopData stores so a ranking can still point at a quote, who else can see that data, and how to ask for an export or a deletion review.

This is a product description of current behaviour, not a certification. We do not claim a particular data-residency region or that a deletion request has already been fulfilled.

Who this covers

This policy describes the ScoopData service at this site. It applies to people who create an account, join an organization, or visit the public pages.

ScoopData is a research console. It stores the evidence you collect and the reviews you make so a conclusion can be traced back to a quote. It is not a consumer social network and it is not directed at children.

What we store

Account and organization: name, email, password hash, organization name, membership role, sessions, and invitations. We do not store the password itself.

Research data you create: projects, source configuration, collected public records and their raw payloads, normalization and duplicate decisions, extracted signal candidates with exact source spans, reviews, clusters, scores, report snapshots, and research-run ledgers.

Operational records: billing subscription state from Stripe when Checkout is configured, email delivery status when Resend is configured, rate-limit rows, and append-only privacy requests.

Exports omit password hashes, session tokens, provider secrets, and other members' private fields. Card numbers never enter ScoopData; Stripe keeps them.

Where the evidence comes from

Live collection only uses approved public APIs you select for a project: Hacker News and Stack Exchange. Adapters keep canonical discussion links, timestamps, and the raw payload. Upstream HTML is never rendered.

Demonstration sources are labelled “Demonstration data” and never make network requests. They are not genuine evidence.

Public discussion you collect remains public at its source. ScoopData keeps a copy so your reviews stay attached to the exact wording.

How we use it

To run the workspace you asked for: sign you in, enforce the plan limits, collect and review evidence, send the notifications you configured, and produce reports.

Optional AI extraction, when a workspace enables it, sends bounded record text through Vercel AI Gateway. The model only proposes candidates. A person must accept or reject each quote before it can cluster.

We do not sell personal data. We do not use collected discussion to advertise to the people who wrote it.

Who else can see it

Application data is stored in a private database scoped to your organization.

Better Auth verifies credentials, sessions, organizations, and invitations.

Stripe handles Checkout, the customer portal, and subscription webhooks when billing is configured. ScoopData stores the resulting plan and status, not card data.

Resend sends verification, invitation, password-reset, report, and research-notification email when a sender is configured.

Inngest runs durable research and scheduled delivery in the background.

Sentry receives application error reports when an error-reporting destination is configured. Reports omit request bodies, cookies, and headers so a research quote is not the payload.

An AI provider is used only when a workspace turns on AI-assisted extraction.

Hacker News and Stack Exchange receive the collection requests you start. They already publish the records you collect.

Retention and deletion

The request is recorded for review. Immutable source evidence, report snapshots, security records, and billing history may be retained where integrity or legal obligations require it.

Source records are append-only. A revision is stored as a new row that names the record it supersedes. A deletion request does not silently cascade through that history.

Signed-in people can download an organization inventory and record an account deletion request under Workspace settings → Privacy. Organization deletion is owner-only. Requests stay visible with their status so you can see they were received.

Sessions and cookies

Sign-in sets a session cookie so the server can derive the active organization on each request. The client cannot choose an organization or role.

Public pages do not require a session. We do not run a marketing pixel on these pages.

Children

ScoopData is for people doing product research in a workspace. It is not offered to children under 16.

Changes

If this policy changes, the date at the top of the page will change. Material changes that affect how we handle account or evidence data will also be noted in the product when you next sign in.

How to reach us

Personal-data requests go through the signed-in privacy desk so we can see which organization they belong to. Open Workspace settings → Privacy to export an inventory or record a deletion request. Plan limits are listed on the pricing page.