ScopeGov← Back to home
Legal · Privacy

Privacy Policy

Last updated: [DATE OF PUBLICATION] · Effective on publication

Draft for internal review. This is a first pass, written to match how ScopeGov’s codebase actually handles data (see subprocessors below) — it is not legal advice and hasn’t been reviewed by counsel. Fields in amber need real values before this goes live, and the retention, jurisdiction, and cookie sections in particular should get a lawyer’s eyes given you’re handling client contract and payment data across borders.
On this page
  • 1. Who we are
  • 2. What we collect
  • 3. How we use it
  • 4. AI processing
  • 5. Subprocessors
  • 6. Legal basis
  • 7. Retention & deletion
  • 8. Your rights
  • 9. Security
  • 10. International transfers
  • 11. Children
  • 12. Changes to this policy
  • 13. Contact

1. Who we are

ScopeGov (“ScopeGov,” “we,” “us”) is a scope-governance platform for agencies: it drafts Statements of Work, monitors client communication against them, and manages the change orders and invoicing that follow. This policy explains what we collect through scopegov.app and sign.scopegov.app (our client-signing portal), and what we do with it.

ScopeGov is operated by Saltern Studio Ltd., a company registered in [Kenya / registration number], with a registered address at [registered address]. See our Terms of Service for the full contracting relationship.

2. What we collect

We collect different data depending on who you are to us:

  • Agency accounts. Name, work email, password (hashed via Supabase Auth), workspace and role, and optionally a TOTP factor if you enable two-factor authentication.
  • Content you create. Statements of Work, change orders, invoices, client and project records, and any briefs, drafts, or comments you enter into the product.
  • Client & signer data. Names, emails, and signatures of the people your agency invites to review or sign a document through the portal — provided by you, not collected directly from them beyond what’s needed to complete a signature.
  • Forwarded correspondence. If you forward client emails to a project’s Guardian inbox (via Postmark), we process the message content to check it against that project’s signed scope.
  • Billing data. Handled by Paystack; we store the resulting subscription status and plan tier, not full card numbers.
  • Usage & device data. IP address, browser/device information, and in-app activity, used for security (e.g. session integrity, audit logging) rather than marketing analytics.

3. How we use it

  • To provide the product — generating SOWs, running Guardian checks, routing approvals, rendering invoices and PDFs.
  • To secure accounts — session management, MFA enforcement on governance-level permissions, and the audit trail of who did what.
  • To operate the business — billing, customer support, and service emails (trial reminders, overdue-payment notices, invite and approval notifications).
  • To maintain the service — error monitoring, background jobs (e.g. nightly reconciliation and portfolio rollups), and abuse prevention.

We do not sell personal data, and we do not use your workspace’s content to train models for other customers.

4. AI processing

Two parts of ScopeGov send data to third-party AI providers to function:

  • SOW drafting and Guardian classification send the relevant brief, SOW text, or forwarded message content to Anthropic’s Claude API to generate a draft or a scope-match verdict.
  • Semantic search over your SOW history uses OpenAI’s embeddings API to convert document text into vector representations stored in our own database.

Both are processed under those providers’ standard API terms, which — as of this policy’s drafting — do not use API-submitted content to train their models. We send only what’s needed for the specific request (e.g. one project’s SOW and the message being checked), not your full workspace, and results are scoped back to the workspace that generated them.

5. Subprocessors

We use the following subprocessors to run ScopeGov. We’ll update this table when that list changes.

ProviderPurposeData involved
SupabaseDatabase, authentication, file storageAll workspace data; account credentials
VercelApplication hosting & background jobsRequest/session data in transit
AnthropicSOW drafting, Guardian classificationSOW text, forwarded message content
OpenAIDocument embeddings for searchSOW and document text
ResendTransactional email deliveryRecipient email, notification content
PostmarkInbound email parsing (Guardian)Forwarded message content and headers
PaystackSubscription billingBilling contact details; payment handled by Paystack directly

6. Legal basis

Where GDPR or a similar framework applies, we process agency account and content data under contract (to provide the service you signed up for) and client/signer data under legitimate interest — completing the specific document your agency sent them — or, where required, consent collected at the point of signing. We process billing data under legal obligation (tax and accounting records).

7. Retention & deletion

We keep workspace content for as long as your account is active, plus a limited grace period after cancellation so you can export or reactivate. As implemented today: cancelled-workspace data is purged on a scheduled basis, and completed projects are retained for a period before automatic purge unless your plan’s document-history settings say otherwise. If you’d like an exact number of days for each of these, add it here: [retention periods]. You can request earlier deletion at any time — see Contact.

8. Your rights

Depending on where you’re located, you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. To exercise any of these, email privacy@scopegov.app. If you’re a client or signer whose data was submitted by an agency using ScopeGov, we’ll generally direct your request to that agency first, since they control the underlying relationship — but reach out and we’ll help route it.

9. Security

Data is stored in Postgres with row-level security enforced per workspace, so one agency’s data is never queryable by another’s session. Sensitive workspace secrets are isolated in a separate, deny-all table reachable only by trusted server processes. We support and, for governance-level permissions, enforce two-factor authentication. No system is perfectly secure — see our Security page for more detail and how to report a concern.

10. International transfers

ScopeGov and its subprocessors operate infrastructure in multiple regions. Where personal data moves across borders — for example to a subprocessor headquartered outside your country — we rely on that provider’s standard contractual clauses or equivalent safeguards. Specifics: [hosting region(s), SCC details].

11. Children

ScopeGov is a business tool. It isn’t directed at, and we don’t knowingly collect data from, anyone under 18.

12. Changes to this policy

We’ll post material changes here with an updated date, and where required, notify workspace owners directly.

13. Contact

Questions about this policy or your data: privacy@scopegov.app.

ScopeGov is operated by Saltern Studio Ltd., Nairobi, Kenya.
PrivacyTermsDPASecurityCookies