ScopePaid
Privacy Policy
This Privacy Policy explains how ScopePaid processes personal and project information when you use the service. It is product documentation for transparency — not a substitute for legal advice.
- Last updated:
- 14 August 2026
- Effective:
- 26 July 2026
1. Introduction
ScopePaid helps freelancers and small agencies document approved project scope, analyse change requests, prepare client options and record decisions. This policy describes what we collect today, why we collect it, and the choices available to you.
2. Who operates ScopePaid
ScopePaid is operated by SHAIK MAHAMMED JILANI from India. For privacy questions and data-rights requests, use privacy@scopepaid.com or the Contact page. Support is available at support@scopepaid.com.
3. Who this policy covers
- Account holders who create and manage a ScopePaid workspace
- People who open a public approval link and optionally provide a name, email or comment when responding
- People who submit the public contact form
Workspace team roles beyond the account owner are not generally available in the current product. Studio team features remain planned.
4. Information account holders provide
- Account name and email (via our managed authentication provider)
- Workspace name and related onboarding details you enter
- Client names and client email addresses you choose to store on projects
- Support messages you send through the contact form
5. Information clients / approval participants provide
- Selected decision option on a published approval page
- Optional participant name and email
- Optional comment or clarification message
- Timestamps associated with views and decisions
Participants do not need a ScopePaid account. They interact through a secure no-login link provided by the project owner.
6. Project and scope information
- Project names, platforms, values, deadlines and related metadata
- Scope baselines and scope items
- Client-request text and owner notes
- Classifications, price and time estimates
- Public approval page content prepared by the owner
- Activity events, notification records and email-delivery records
ScopePaid does not currently provide uploaded-document storage. Do not rely on this product as a file archive.
7. AI Scope Assistant data
When an authorized workspace owner explicitly runs an AI-assisted analysis, ScopePaid may process the minimum content needed for that analysis:
- Relevant locked-scope items and exclusions from the active project baseline
- The current client request (title and description) and optional request source label
- Relevant freelancer / owner notes already attached to that request
- Necessary pricing context (currency and optional hourly-rate hint)
- Structured suggestion outputs (classification, effort ranges, draft client-facing copy and related fields)
- Limited operational metadata (analysis status, model, token or estimated-cost figures where recorded, and a one-way input fingerprint for idempotency)
ScopePaid does not send unrelated projects, private approval tokens, notification history, billing information, authentication secrets or unnecessary personal profile data to the AI provider. Complete provider prompts are not retained as duplicate customer documents in ScopePaid; we store structured results and operational metadata instead of full prompt archives.
AI is optional. Manual classification and drafting remain available. AI does not publish approval pages, email clients, set final prices or change request lifecycle status on its own.
8. Technical, usage and security information
- IP address and user agent where needed for security, rate limiting or email delivery
- Rate-limit and abuse-prevention metadata
- Authentication and session data managed by our authentication provider
- Application preference storage in your browser (see the Cookie Policy)
ScopePaid does not currently load third-party product analytics scripts. In-product “analytics” views show scope-change summaries derived from your workspace records, not an external tracking suite.
9. Contact and support information
Contact form submissions (name, email, optional business name, topic and message) are stored so we can respond. When email delivery is configured, a copy may be sent to the support inbox.
10. Payment information
Lemon Squeezy acts as Merchant of Record for paid ScopePaid subscriptions. ScopePaid does not store full payment-card details. When you complete an enabled paid purchase, Lemon Squeezy processes payment and billing information under its own terms and privacy practices. ScopePaid does not process customers’ project or client invoices.
11. How information is used
- Provide authentication, workspaces, projects, baselines and change-request workflows
- Publish and record client approval decisions at the owner’s direction
- Send owner notifications and optional owner-triggered client emails
- Provide optional AI suggestions when explicitly requested
- Enforce plan limits and prevent abuse
- Respond to support and privacy requests
- Maintain security, integrity and service reliability
12. Legal bases — where applicable
Where data-protection laws such as the GDPR apply, we rely on appropriate bases such as contract performance, legitimate interests (for example securing the service and preventing abuse), consent where required, and legal obligation. The specific basis depends on your location and the processing activity.
13. How AI processing works
- AI runs only when an authorized owner explicitly requests analysis
- Purpose: generate editable suggestions that help the owner compare a client request with the locked scope baseline (classification, hidden requirements, effort/timeline/price guidance and draft client-facing wording)
- Categories transmitted to the third-party AI service provider when enabled: relevant locked-scope items and exclusions, the current client request, relevant freelancer notes on that request, and necessary pricing context for the active project only
- ScopePaid does not transmit unrelated project records, approval-access tokens, notification history, billing records or unnecessary personal data for this purpose
- Outputs are suggestions and may be inaccurate or incomplete
- Owners must review and explicitly apply any classification, estimate or copy
- AI does not make final project decisions and does not automatically contact clients
- Generated results are stored in the workspace as structured AI-analysis records for owner review, history and plan metering. Full prompt transcripts are not kept as a separate document archive
- ScopePaid does not claim that prompts or outputs have zero provider retention. Retention at the provider follows the operator’s AI provider account settings and applicable provider policies. ScopePaid’s own retention is described in the Retention section
14. Service providers and subprocessors
ScopePaid uses third-party service providers for authentication, cloud hosting and data storage, transactional email delivery, optional AI-assisted processing, and subscription billing. These providers process information only as necessary to provide their respective services.
Lemon Squeezy acts as Merchant of Record for paid ScopePaid subscriptions. ScopePaid does not store full payment-card details.
A category-level summary is also available on the Subprocessors page.
15. International processing and transfers
Your information may be processed in the regions where our service providers operate, including the United States and other locations. Where required, appropriate transfer safeguards will be applied under applicable law.
16. Retention
- Active account data — retained while the workspace/account remains active so you can use the product
- Approval and decision history — retained as part of the project record; decided snapshots are designed to remain immutable for audit integrity
- AI analyses — structured results and operational metadata are retained with the related request and workspace while the project remains active, so owners can review history and so monthly plan limits can be enforced. ScopePaid does not retain complete provider prompt transcripts as duplicated customer documents. When a project or workspace is permanently deleted under the account-deletion process, associated AI-analysis records are deleted with that deletion (or removed by the operator purge path). Limited anonymized operational aggregates may remain only where needed for security, abuse prevention or legal obligations
- Notifications and email delivery records — retained to show delivery status and support troubleshooting
- Contact submissions — retained as needed to handle your enquiry and for reasonable follow-up
- Security logs and rate-limit metadata — retained for a limited period for security and abuse prevention
- Subscription billing records — retained as required by the Merchant of Record (Lemon Squeezy) and applicable law
We do not promise instantaneous deletion from all backups. Some information may be retained where necessary for security, fraud prevention, disputes, legal claims or legal obligations.
17. Security
We use technical and organisational measures appropriate to the service, including authenticated access, server-side authorization, workspace isolation controls, hashed approval tokens and encryption in transit. No method of transmission or storage is completely secure. See the Security page for a high-level summary.
18. User choices and privacy rights
Depending on where you live, you may have rights to request access, correction, deletion, restriction, portability or objection, and to withdraw consent where processing is consent-based. Rights are not absolute and may be limited by law or competing obligations (for example preserving security or dispute records).
To submit a request, use the Contact form with topic “Privacy/data request” or email the privacy contact below. We may need to verify your identity before acting. You may also have the right to complain to a supervisory authority where applicable.
19. Client participant requests
If you interacted only through an approval link, contact the project owner first for corrections to the commercial discussion. You may also contact ScopePaid using the privacy channel. We may need information that helps us locate the relevant workspace record and will not disclose another customer’s confidential project data inappropriately.
20. Account and workspace deletion
Self-serve account export and deletion are not currently available in the product. You can request assistance through the Contact form. Downgrading a plan does not delete existing projects, requests, approvals or audit history; new creation may be limited while over plan capacity.
When a project or workspace is permanently deleted through the operator-assisted deletion process, associated AI-analysis records for that project or workspace are deleted as part of the same lifecycle (database foreign keys cascade, and operator purge helpers exist for controlled clean-up). Archiving a project without permanent deletion keeps AI history with the archived project until permanent deletion occurs.
22. Children
ScopePaid is intended for business use by adults. It is not directed to children, and we do not knowingly collect personal information from children.
23. Automated decision-making
ScopePaid does not make solely automated decisions that produce legal or similarly significant effects about individuals. AI suggestions require owner review before any client-facing publication or commercial decision is confirmed in the product.
24. Policy changes
We may update this policy as the product changes. Material changes will be communicated to account holders by reasonable means (for example email or in-product notice) before they take effect where required.
25. Contact information
Privacy contact: privacy@scopepaid.com
Support contact: support@scopepaid.com