ScopePaid
Privacy Policy
This Privacy Policy explains how ScopePaid processes personal and project information when you use the service. It is product documentation for transparency — not a substitute for legal advice.
- Last updated:
- 25 July 2026
1. Introduction
ScopePaid helps freelancers and small agencies document approved project scope, analyse change requests, prepare client options and record decisions. This policy describes what we collect today, why we collect it, and the choices available to you.
2. Who operates ScopePaid
ScopePaid is operated by the business entity that will be identified in the operator information section once production legal fields are configured. Until then, contact us through the Contact page or the privacy email listed at the end of this policy.
3. Who this policy covers
- Account holders who create and manage a ScopePaid workspace
- People who open a public approval link and optionally provide a name, email or comment when responding
- People who submit the public contact form
Workspace team roles beyond the account owner are not generally available in the current product. Studio team features remain planned.
4. Information account holders provide
- Account name and email (via our authentication provider, Clerk)
- Workspace name and related onboarding details you enter
- Client names and client email addresses you choose to store on projects
- Support messages you send through the contact form
5. Information clients / approval participants provide
- Selected decision option on a published approval page
- Optional participant name and email
- Optional comment or clarification message
- Timestamps associated with views and decisions
Participants do not need a ScopePaid account. They interact through a secure no-login link provided by the project owner.
6. Project and scope information
- Project names, platforms, values, deadlines and related metadata
- Scope baselines and scope items
- Client-request text and owner notes
- Classifications, price and time estimates
- Public approval page content prepared by the owner
- Activity events, notification records and email-delivery records
ScopePaid does not currently provide uploaded-document storage. Do not rely on this product as a file archive.
7. AI Scope Assistant data
When an authorized workspace owner explicitly runs an AI-assisted analysis, ScopePaid may process:
- Relevant request text and related project or baseline excerpts
- Structured suggestion outputs (for example classification, effort ranges, draft copy)
- Limited usage metadata such as analysis counts and, where recorded, token or cost estimates
AI is optional. Manual classification and drafting remain available. AI does not publish approval pages, email clients, set final prices or change request lifecycle status on its own.
8. Technical, usage and security information
- IP address and user agent where needed for security, rate limiting or email delivery
- Rate-limit and abuse-prevention metadata
- Authentication and session data managed by Clerk
- Application preference storage in your browser (see the Cookie Policy)
ScopePaid does not currently load third-party product analytics scripts. In-product “analytics” views show scope-change summaries derived from your workspace records, not an external tracking suite.
9. Contact and support information
Contact form submissions (name, email, optional business name, topic and message) are stored so we can respond. When email delivery is configured, a copy may be sent to the support inbox.
10. Payment information — future only
Paid ScopePaid checkout is not active. We do not currently collect payment card details for ScopePaid subscriptions. When billing launches, payment details will be handled by the designated merchant of record; ScopePaid still will not process your clients’ project invoices.
11. How information is used
- Provide authentication, workspaces, projects, baselines and change-request workflows
- Publish and record client approval decisions at the owner’s direction
- Send owner notifications and optional owner-triggered client emails
- Provide optional AI suggestions when explicitly requested
- Enforce plan limits and prevent abuse
- Respond to support and privacy requests
- Maintain security, integrity and service reliability
12. Legal bases — where applicable
Where data-protection laws such as the GDPR apply, we rely on appropriate bases such as contract performance, legitimate interests (for example securing the service and preventing abuse), consent where required, and legal obligation. The specific basis depends on your location and the processing activity.
13. How AI processing works
- AI runs only when an authorized owner explicitly requests analysis
- Relevant request, project and baseline text may be sent to the configured AI provider (currently OpenAI when enabled)
- Outputs are suggestions and may be inaccurate or incomplete
- Owners must review and explicitly apply any classification, estimate or copy
- AI does not make final project decisions and does not automatically contact clients
- ScopePaid does not claim that prompts or outputs have zero provider retention. Retention follows the operator’s AI provider account settings and applicable provider policies
14. Service providers and subprocessors
Current and planned processors used to operate ScopePaid:
| Provider | Purpose | Status |
|---|---|---|
| Clerk (opens in new tab) | Authentication, session management and account identity | active |
| Supabase (opens in new tab) | Application database, storage of workspace and project records | active |
| Resend (opens in new tab) | Transactional email delivery for owners and optional owner-triggered client emails | conditional |
| OpenAI (opens in new tab) | AI Scope Assistant — optional analysis when an owner explicitly requests it | conditional |
| Cloudflare (opens in new tab) | Application hosting and edge delivery (deployment target) | active |
| Lemon Squeezy | Future Merchant of Record / subscription billing for ScopePaid plans | planned |
Lemon Squeezy is listed as planned only. It is not an active merchant of record for ScopePaid while checkout is inactive.
A structured list is also available on the Subprocessors page.
15. International processing and transfers
Your information may be processed in the regions where our subprocessors operate, including the United States and other locations. Where required, appropriate transfer safeguards will be applied under applicable law.
16. Retention
- Active account data — retained while the workspace/account remains active so you can use the product
- Approval and decision history — retained as part of the project record; decided snapshots are designed to remain immutable for audit integrity
- AI analyses — retained with the related request/workspace while needed for history, limits and owner review
- Notifications and email delivery records — retained to show delivery status and support troubleshooting
- Contact submissions — retained as needed to handle your enquiry and for reasonable follow-up
- Security logs and rate-limit metadata — retained for a limited period for security and abuse prevention
- Future payment records — when billing launches, billing records will be retained as required by the merchant of record and applicable law
We do not promise instantaneous deletion from all backups. Some information may be retained where necessary for security, fraud prevention, disputes, legal claims or legal obligations.
17. Security
We use technical and organisational measures appropriate to the service, including authenticated access, server-side authorization, workspace isolation controls, hashed approval tokens and encryption in transit. No method of transmission or storage is completely secure. See the Security page for a high-level summary.
18. User choices and privacy rights
Depending on where you live, you may have rights to request access, correction, deletion, restriction, portability or objection, and to withdraw consent where processing is consent-based. Rights are not absolute and may be limited by law or competing obligations (for example preserving security or dispute records).
To submit a request, use the Contact form with topic “Privacy/data request” or email the privacy contact below. We may need to verify your identity before acting. You may also have the right to complain to a supervisory authority where applicable.
19. Client participant requests
If you interacted only through an approval link, contact the project owner first for corrections to the commercial discussion. You may also contact ScopePaid using the privacy channel. We may need information that helps us locate the relevant workspace record and will not disclose another customer’s confidential project data inappropriately.
20. Account and workspace deletion
Self-serve account export and deletion are not currently available in the product. You can request assistance through the Contact form. Downgrading a plan does not delete existing projects, requests, approvals or audit history; new creation may be limited while over plan capacity.
22. Children
ScopePaid is intended for business use by adults. It is not directed to children, and we do not knowingly collect personal information from children.
23. Automated decision-making
ScopePaid does not make solely automated decisions that produce legal or similarly significant effects about individuals. AI suggestions require owner review before any client-facing publication or commercial decision is confirmed in the product.
24. Policy changes
We may update this policy as the product changes. Material changes will be communicated to account holders by reasonable means (for example email or in-product notice) before they take effect where required.
25. Contact information
Privacy contact: privacy@scopepaid.com
Support contact: support@scopepaid.com