SignalScoutHome

Privacy Policy

Last updated: 2026-05-04

What we collect

  • From you (the customer): email, password (bcrypt-hashed — we never see plaintext), billing details (handled by Stripe — we only see the subscription status, never card numbers).
  • From Reddit (publicly available): Reddit usernames and the bodies of public posts + comments that match our buyer-intent filters. We do NOT collect private messages or non-public content.
  • Derived from AI processing: intent scores, clustered signals, lead enrichment attributes (industry, role, tech sophistication, ICP fit) computed from public Reddit activity.

Why we collect it

  • To match you (the customer) with relevant Reddit users who have expressed paying intent.
  • To enable you to do outreach (Pro tier — DM template generation).
  • To audit our compliance with right-to-be-forgotten requests.
  • To bill your subscription via Stripe.

Retention

  • Customer accounts: retained until you delete your account.
  • Evidence rows + signal_lead joins: retained 90 days after last activity, then pruned automatically.
  • Lead profiles (Reddit usernames + enrichment): retained until a right-to-be-forgotten request is filed, at which point the lead row is deleted and an audit log entry is recorded.
  • RTBF audit log: retained indefinitely for compliance proof (no PII beyond the redacted username and requestor email).

Your rights (GDPR / CCPA)

You have the right to:
  • Access: email [email protected] for a copy of all data we hold about you.
  • Correct: same address — we'll update inaccurate data within 30 days.
  • Delete (right to be forgotten): use the RTBF form — works for anonymous Reddit users without an account here.
  • Portability: we can export your account + saved-signal data as JSON on request.
  • Opt out (CCPA): we do not sell personal data. CCPA opt-out is automatic.

Third parties we use

  • Stripe — processes payments. We never store full card numbers.
  • Anthropic (Claude) — processes Reddit post bodies for intent classification + lead enrichment. Data is not used to train Anthropic models per their commercial terms.
  • OpenAI — generates text embeddings used for clustering. Data is not used to train OpenAI models per their API terms.
  • Reddit — source of public post and comment data. We use the public JSON endpoints (no OAuth, no actions on your behalf).
  • Hetzner Online GmbH — hosts the SignalScout application + Postgres database.

Contact

Privacy questions? Email [email protected]. For deletion requests, the RTBF form is the fastest path.