Draft
Privacy Policy
This Privacy Policy explains how Scorefold ("we", "us") collects, uses, stores, and shares personal data when you use our website and application. We operate from Israel and serve users worldwide. This policy should be read together with our Terms of Service and Cookie Policy.
1. Who we are
Scorefold is operated from Israel. For privacy-related requests, contact [email protected]. We act as the data controller for personal data described in this policy.
2. Data we collect
Account data: email address, authentication identifiers (e.g. from Google or GitHub OAuth, or magic-link tokens), and account settings. Usage data: search queries you submit, timestamps, feature usage, subscription tier, fresh-check consumption, and cached-result access. Technical data: IP address, browser type, device information, referral URLs, and server logs needed for security and operations. Payment data: subscription status, plan, billing period, and transaction identifiers. Full payment card numbers are processed by our payment processor when payments go live; we do not store them. Communications: messages you send to support and our replies.
3. How we use data
We use personal data to: provide and operate the Service (run checks, display results, manage your personal cache); authenticate users and prevent abuse; process subscriptions and renewals via our payment processor (when payments go live); send transactional emails (login links, billing notices); improve reliability and product quality; comply with legal obligations; and enforce our Terms and Acceptable Use Policy. We do not sell your personal data.
4. AI and third-party processing
To generate summaries and run the aggregation pipeline, we send query-related data to subprocessors including cloud hosting (Cloudflare), search APIs (e.g. Serper), and AI providers (e.g. Workers AI or OpenAI). These providers process data on our instructions to deliver the Service. Snippets shown to you are short excerpts from public sources; summaries are separate AI-generated syntheses.
5. Legal bases (EU/UK users)
Where GDPR or UK GDPR applies, we rely on: contract performance (providing the Service you subscribed to); legitimate interests (security, fraud prevention, product improvement — balanced against your rights); legal obligation; and consent where required (e.g. non-essential cookies or marketing, if offered).
6. Retention
Account data is retained while your account is active and for a limited period after deletion to resolve disputes, enforce Terms, and meet legal requirements. Cached check results are stored per your plan (e.g. personal cache with a defined TTL). Server logs are retained for a limited operational period. Payment records follow our payment processor retention and applicable tax law.
7. Sharing
We share data with: payment processor (when payments go live); infrastructure and AI subprocessors listed above; professional advisers where required; and authorities when legally compelled. We require subprocessors to protect data under appropriate agreements.
8. International transfers
Data may be processed in Israel, the United States, the European Union, and other countries where our providers operate. We use appropriate safeguards for cross-border transfers where required (e.g. Standard Contractual Clauses).
9. Your rights
Depending on your location, you may have rights to access, correct, delete, restrict, or object to processing of your personal data, and to data portability. EU/UK users may lodge a complaint with a supervisory authority. California residents may have rights under CCPA/CPRA, including knowing what we collect and requesting deletion, subject to exceptions. To exercise rights, email ${siteConfig.contact.privacy}. We may verify your identity before responding.
10. Security
We implement technical and organizational measures appropriate to the risk, including encryption in transit, access controls, and monitoring. No method of transmission or storage is 100% secure.
11. Children
The Service is not directed at children under 18. We do not knowingly collect data from children. Contact us if you believe a child has provided personal data.
12. Changes
We may update this Privacy Policy. Material changes will be communicated as required by law. The current version is always available at https://scorefold.app/privacy/.