ScopeDocs Inc. (“ScopeDocs,” “we,” “us,” or “our”) describes how we collect, use, store, and share personal information when you use our websites and products, including scopedocs.ai, app.scopedocs.ai, and related services (collectively, the “Services”).
ScopeDocs is an AI-native knowledge platform that helps engineering teams connect code hosts, work trackers, chat tools, databases, and documents into source-linked documentation, search, and in-product chat. We do not use your connected workspace content to train third-party foundation models for general model training — AI features run through subprocessors under our instructions, as described below.
Questions? Contact us at hello@scopedocs.ai or ScopeDocs Inc., 7 Sanderling Ct, Alameda, CA 94501, United States.
Summary of key points
- What we collect depends on how you use the Services, which integrations you connect, and the privacy choices you make in the product. See What information do we collect?
- Sensitive personal information: we do not knowingly process sensitive personal information as defined by applicable U.S. state privacy laws.
- Integrations: we process metadata and content from systems you connect (for example GitHub, Slack, or Linear) to provide the features you request. You control which integrations are enabled in your workspace.
- Product analytics & improvement (opt-in): when you enable this in cookie preferences or Settings, we may use product analytics and diagnostic tools (including providers such as PostHog) to understand usage and reliability, and may store chat questions and helpfulness feedback to improve the assistant. Session replay and similar debugging features are part of that optional stack when enabled.
- Your rights depend on where you live. See Your privacy rights and contact us to exercise them.
1. What information do we collect?
Personal information you provide
In short: we collect information you give us when you create an account, use the Services, or contact us.
- Account and profile data: name, email address, authentication identifiers, workspace and organization membership, and preferences you set in the product.
- Communications: information you send in support requests, feedback, or sales conversations.
- Privacy choices: your saved cookie preferences and opt-in status for optional product analytics & improvement.
We use email magic-link sign-in through our authentication provider. We do not require social-media login today.
Integrations and workspace content you connect
In short: when you connect third-party tools, we process the data needed to sync, index, search, generate documentation, and power chat — as authorized by you.
Depending on which integrations you enable, this may include:
- Code and engineering artifacts — repository names, file paths, pull requests, commits, changelists, and related metadata from providers such as GitHub or Perforce.
- Work tracking — issues, projects, and comments from tools such as Linear.
- Messaging — channel metadata and message content from Slack (scoped to what your workspace authorizes).
- Documentation sources — pages, databases, and blocks from Notion, Confluence, or similar connectors.
- Files — PDFs or documents you upload or sync (for example via Google Drive), including extracted text and structured summaries we generate to make them searchable.
- External databases — schema and query results from PostgreSQL or other databases you connect for read-only context, subject to your configuration.
You control which integrations are connected and can disconnect them in the product. Integration access generally uses OAuth or credentials you supply; we store tokens encrypted at rest.
Information collected automatically
In short: we automatically collect technical and usage information to operate, secure, and — where permitted — improve the Services.
This may include:
- Log and usage data — IP address, browser and device type, operating system, language, referring URLs, timestamps, feature interactions, error reports, and performance diagnostics.
- Product analytics & improvement (opt-in) — when you enable this in cookie preferences, we and our analytics providers (such as PostHog) may collect event data about how you navigate and use the app, and — if enabled in our project configuration — session replay data to debug UX issues. We may also store chat questions and helpfulness feedback on our systems to improve retrieval and answer quality. We configure replay and masking to reduce collection of sensitive fields where feasible.
- Essential cookies and local storage — session authentication, security, and strictly necessary operation of the Services (always on).
- Display preferences — we save theme and similar UI choices on your device by default so the app remembers how you like to view it.
Like many online services, we use cookies, pixels, local storage, and similar technologies. See Cookies and similar technologies.
We infer approximate location from IP address for security and localization. We do not require precise GPS location for the core product.
2. How do we process your information?
In short: we use information to provide the Services, keep them secure, support you, and — with appropriate legal bases — improve the product.
We process personal information to:
- Create and manage accounts and authenticate users.
- Provide features you request — documentation generation, wiki, chat, knowledge graph, PR explainers, PDF understanding, search, and integrations.
- Sync and index content from connected systems so your workspace can search and cite it.
- Operate AI features — retrieve context, generate responses, and maintain citations using third-party model providers under our instructions.
- Secure the Services — fraud prevention, abuse detection, audit logging, and incident response.
- Communicate with you — service announcements, security notices, and support.
- Improve the product — aggregated usage trends, reliability monitoring, and (when you opt in) product analytics, session diagnostics, and optional chat feedback via tools such as PostHog.
- Comply with law and enforce our terms.
Product analytics & improvement (opt-in): if you enable this in Settings or cookie preferences, we may collect usage analytics and store events such as chat question text, session identifiers, and thumbs-up/down feedback on our systems to improve ScopeDocs and the assistant. You may withdraw consent at any time; new collection stops prospectively. If you do not opt in, we do not run this optional program for your account.
3. What legal bases do we rely on?
In short: we process information only when we have a valid reason under applicable law.
If you are in the EEA, UK, or Switzerland, we may rely on:
- Contract — processing needed to provide the Services you signed up for.
- Legitimate interests — securing and operating the Services, preventing abuse, and understanding aggregated usage, balanced against your rights.
- Consent — optional product analytics & improvement. You may withdraw consent at any time via in-app controls or by contacting us.
- Legal obligation — when required by law or valid legal process.
If you are in Canada, we may rely on express or implied consent where permitted, or other lawful bases described above. You may withdraw consent subject to legal and contractual restrictions.
4. Cookies and similar technologies
In short: we use essential technologies to run the app; optional cookies require your choice in the product.
| Category | Purpose | Default |
|---|---|---|
| Necessary | Sign-in, security, core app operation | Always on |
| Product analytics & improvement | Usage analytics and debugging (e.g. PostHog events; session replay when enabled) and optional chat questions and feedback to improve the assistant | Off until you opt in |
| Display preferences | Theme and similar UI choices on this device | On by default |
How to control cookies
- Signed-in users: open Settings → Manage cookie preferences (or the cookie modal when prompted) on app.scopedocs.ai.
- Marketing site: where we offer a cookie notice on scopedocs.ai, you may set preferences before signing up.
- Browser controls: you can block or delete cookies in your browser; essential features may not work if you block necessary cookies.
By creating an account and using the Services, you acknowledge our Terms of Service and this Privacy Policy. Optional analytics and improvement features still require the in-app choices described above unless we notify you otherwise after a future policy update reviewed with counsel.
5. When and with whom do we share personal information?
In short: we share information with service providers, at your direction, or when required by law.
We may share personal information in these situations:
- Service providers and subprocessors that process data on our behalf under contract, including:
- Hosting and database (e.g. Supabase / PostgreSQL infrastructure)
- Authentication (e.g. Supabase Auth)
- AI inference providers (e.g. OpenAI, Anthropic, Together AI, Google GenAI) — prompts and outputs for features you use
- Product analytics (e.g. PostHog) — when you opt in to product analytics & improvement
- Email and operational tooling — as needed to run the Services
- Integrations you connect — when you export to Notion or otherwise direct data flow to a third party.
- Business transfers — merger, acquisition, financing, or sale of assets, with notice where required.
- Legal and safety — to comply with law, respond to lawful requests, or protect rights, safety, and security.
We do not sell personal information for money. We do not buy marketing lists from data brokers.
A current list of subprocessors may be published on our website or provided on request at hello@scopedocs.ai.
6. AI-based features
We offer AI-assisted documentation, chat, and analysis using third-party models and our orchestration layer. Inputs you submit (including retrieved workspace context) may be transmitted to AI providers to generate outputs for you. Providers process data under their terms and our agreements; we configure services for inference, not for using your workspace content to train public foundation models.
You must not use AI features in violation of applicable provider terms or law.
7. Connected integrations (supplement)
This section supplements the rest of this notice for data obtained through integrations you enable.
- Your authorization: each integration is enabled by a workspace admin or authorized user through OAuth or credentials you supply. Scopes are shown on the provider’s consent screen.
- Minimum access: we request read-oriented or write-back scopes needed for the feature (for example read repos for indexing, or write-back to Notion only when you use export).
- Workspace isolation: integration data is scoped to the workspace that connected it.
- Disconnect: you may disconnect integrations in Settings; we stop new syncs and can delete stored copies per your request and our retention practices.
- No training on your content: we do not use your connected Slack messages, repo content, or issue text to train third-party foundation models for general model development.
Provider-specific terms also apply (for example GitHub, Slack, or Linear terms).
8. How long do we keep your information?
We retain personal information for as long as your account is active and as needed to provide the Services, comply with law, resolve disputes, and enforce agreements. Retention for connected workspace content generally follows your account lifecycle and workspace deletion requests.
When we no longer need information, we delete or anonymize it where feasible. Backup copies may persist for a limited period before automatic purge.
9. How do we keep your information safe?
We implement technical and organizational measures designed to protect personal information, including encryption of integration tokens, access controls, and monitoring. No method of transmission or storage is 100% secure; use the Services in a secure environment and protect your account credentials.
10. Do we collect information from minors?
The Services are not directed to children under 16 (or 13 where applicable law sets a lower age with parental consent). We do not knowingly collect personal information from children. Contact us if you believe we have collected a child’s information.
11. Your privacy rights
Depending on your location, you may have rights to:
- Access and obtain a copy of your personal information
- Correct inaccurate information
- Delete personal information
- Restrict or object to certain processing
- Portability — receive data in a portable format where applicable
- Withdraw consent for processing based on consent (without affecting prior lawful processing)
- Opt out of certain analytics, marketing, or — where applicable — targeted advertising or “sale/share” as defined by U.S. state law
How to exercise rights: email hello@scopedocs.ai. We may verify your request. Authorized agents may submit requests where permitted by law with proof of authority.
EEA/UK: you may lodge a complaint with your local supervisory authority.
Opt-out shortcuts
- Product analytics & improvement: Settings → Manage cookie preferences → turn off Product analytics & improvement
- Marketing email: use unsubscribe links in emails we send
12. United States residents
California (CCPA/CPRA summary)
In the preceding 12 months we may have collected identifiers (name, email, IP), customer records (account info), internet activity (usage and — if you opted in — analytics events), and approximate geolocation derived from IP.
We use this information for the business purposes described in this notice. We do not sell personal information. We may share information with service providers under contract. California residents may request access, deletion, and correction, and may opt out of sale/share where applicable. Contact hello@scopedocs.ai.
Other U.S. states
Residents of Colorado, Virginia, Connecticut, and other states with comprehensive privacy laws may have similar rights. Contact us to exercise them. We honor Global Privacy Control (GPC) signals where required by applicable state law.
13. International transfers
We are based in the United States. If you access the Services from outside the U.S., your information may be processed in the U.S. and other countries where our providers operate. We use appropriate safeguards (such as standard contractual clauses) where required for cross-border transfers.
14. Do-Not-Track
Some browsers offer “Do Not Track” (DNT). There is no uniform standard for DNT. We do not respond to all DNT signals today. See United States residents for GPC where applicable.
15. Changes to this notice
We may update this Privacy Policy from time to time. The “Last updated” date at the top of the published page will change when we do. Material changes may be communicated by in-app notice, email, or prominent website notice where required. Continued use after the effective date constitutes acceptance of the updated notice, subject to your rights to withdraw consent for optional processing.
If we change optional analytics or improvement practices in a material way, we may ask you to review cookie preferences again.
16. Contact us
ScopeDocs Inc.
7 Sanderling Ct, Alameda, CA 94501, United States
hello@scopedocs.ai
For privacy requests — access, correction, deletion, or questions about subprocessors — email hello@scopedocs.ai with the subject line “Privacy request” and the email address associated with your account.