Scoutly privacy notice
Last updated: 2026-07-13.
What we collect
- Account: username, email address, hashed password, email-verification status.
- Profile: year group, free-text interests, free-text location, report schedule.
- Derived: a boolean is_minor flag computed from year group (true for Y9–Y13, false for 18+).
- Billing: subscription status, Stripe customer and subscription identifiers, and invoice amounts/outcomes. For under-18 accounts, the paying parent/guardian's name and email address. Card details never touch Scoutly — they are entered on and held by Stripe.
- Activity: timestamps of signup, consent, login, logout, verification, billing events, data export, and account deletion (audit log).
- Report deliveries: when each weekly report email was sent and how many items it contained.
- Rate-limiting: short-lived records of request IP addresses for abuse protection, pruned after 24 hours.
- Session cookie: a signed cookie containing only an account id while you are logged in.
We do not ask for or store: date of birth, real name (except the paying parent/guardian's name), school name, card numbers, or any data we have not listed above.
What we do with it
- Generate web search queries tailored to your year group and interests.
- Run those queries against Tavily (search) and send the result snippets to Anthropic (Claude) for classification.
- Store qualifying UK work-experience opportunities in a shared pool, and link them to your account.
- Email you a personalised report on the schedule you choose (using Resend as the email provider).
Third parties
By using Scoutly you agree that the data needed to run a scan (year group, interests, location, plus the search-result snippets being classified) is transmitted to:
- Tavily — web search.
- Anthropic — Claude API for query generation and classification.
- Resend — email delivery for your reports.
- Stripe — subscription payments. Stripe receives the payer's email and name and holds the card details; Scoutly only stores Stripe's customer/subscription identifiers and invoice amounts/outcomes.
Your password is never shared with any third party; your email goes only to Resend (to deliver mail to you) and, for the payer, to Stripe.
Your rights
- Access: download everything we hold on you as JSON from the Account page (log in first).
- Erasure / withdrawing consent: delete your account from the Account page. This removes your user, profile, matched opportunities, billing account, and delivery history, cancels any active subscription, and deletes the customer record at Stripe. Audit-log rows (signup / consent / deletion timestamps, no profile data) are retained so we can prove the request happened, and payment records are kept as described under Retention.
- Rectification: update your profile at any time.
- Marketing: opt-in is off by default and toggleable on the Account page.
Retention
Profile, account, and portfolio data: kept until you delete your account.
Audit log: kept indefinitely, but contains no profile content — only the user id and action (e.g. "signup", "account_deleted") and a timestamp.
Payment records (invoice amounts, dates, and outcomes — no card data) are retained for approximately six years to meet UK tax and accounting requirements. On account deletion they are anonymised: the stored account id no longer corresponds to any user.
Contact
Questions or requests? Email shailenjpatel@gmail.com.
Scoutly is a personal project. This notice describes current behaviour and will be updated as the service evolves.