
Last updated: May 24, 2026
At VScout, your privacy is fundamental. This policy explains what data we collect, how we use it, who we share it with, and how you can exercise your rights.
This Privacy Policy ("Policy") applies to the VScout platform operated by VScout ("we," "us," or "our"). It covers all users of our website at vscout.co, our application, API, and any related services (collectively, the "Service"). By using VScout, you agree to the collection and use of information in accordance with this Policy.
When you create an account, we collect:
As a recruiting platform, VScout processes candidate data that you or your organization uploads. This may include:
Important: You are the data controller for candidate data you upload to VScout. We act as a data processor on your behalf. You are responsible for obtaining appropriate consent from candidates before uploading their data.
We automatically collect:
Subscription payments are processed by our payment provider, Polar. We do not store credit card numbers or full payment details on our servers. We receive a customer ID, subscription status, and billing plan information from Polar.
When you connect a Google account to VScout (Sign in with Google, Google Calendar, or Gmail), we receive and store the following:
sub claim)integrations table so VScout can act on your behalf for features you authorizedYou can disconnect any Google integration at any time from Settings → Integrations. Disconnecting revokes our tokens, after which we can no longer call Google APIs on your behalf. You can also revoke access directly from your Google Account permissions page.
We use collected information for the following purposes:
VScout uses artificial intelligence to enhance recruiting workflows. Transparency about our AI practices is important to us:
We do not sell your personal data. We share information only with the following categories of recipients:
| Provider | Purpose | Data Processed | Location |
|---|---|---|---|
| Supabase | Database & authentication | All platform data | US (AWS) |
| Anthropic | AI processing (Claude API) | Resumes, job descriptions, chat | US |
| Vercel | Frontend hosting & CDN | No sensitive data at edge | Global (US primary) |
| Resend | Transactional email | Email addresses, names | US |
| Polar | Payment processing | Billing information | US/EU |
| PostHog | Product analytics | Usage data, device info | US/EU |
| Google (Sign in with Google) | Account authentication via OAuth 2.0 | Email, name, profile picture, Google account ID | US |
| Google Calendar + Meet | Interview scheduling, Meet link generation, free/busy lookups | Calendar events, attendees, RSVPs, Meet links | US |
| Gmail (send-only) | Sending candidate outreach from the user's account | Outbound message recipients, subjects, body, thread IDs | US |
| Google Chat | Vesper interview-summary bot in user-invited spaces | Space ID, message content the user sends to the bot | US |
| Google Ads | Server-side conversion measurement (offline conversions) | Hashed click identifier (GCLID), conversion event name | US |
| Google Analytics 4 + Tag Manager | Site analytics and conversion attribution | Pseudonymous client ID, page views, device/IP (truncated) | US |
| Google Indexing API (optional) | Notifying Google Search when JobPosting URLs change | Public job-posting URLs only - no candidate data | US |
A current list of sub-processors is maintained at /security and updated when we add or change a vendor.
VScout's use and transfer of information received from Google APIs (including Sign in with Google, Google Calendar, Gmail, Google Meet, and Google Chat) to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
The use of raw or derived user data received from Google Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.
| OAuth scope | Why VScout needs it |
|---|---|
| openid, userinfo.email, userinfo.profile | Sign in with Google - identifies your account, populates your profile (name, email, picture) |
| https://www.googleapis.com/auth/calendar | Create and update interview events on your calendar, read free/busy windows for you and invited interviewers, and attach Google Meet conference links to events you create through VScout |
| https://www.googleapis.com/auth/gmail.send | Send candidate outreach and follow-up emails through your Gmail account so replies land in your inbox. This scope is send-only - it does not grant VScout permission to read, list, modify, or delete messages |
| chat.bot (service account) | Power the Vesper bot in Google Chat spaces you explicitly invite it to - post interview summaries and respond to messages addressed to the bot. The bot cannot read messages in spaces it is not a member of |
VScout's use of data obtained through the scopes above is restricted as follows:
VScout is based in the United States. If you access our Service from outside the US (including the European Economic Area, UK, or other regions with data protection laws), your information will be transferred to and processed in the US.
For transfers of personal data from the EEA/UK to the US, we rely on:
Enterprise customers may request EU data residency. Contact admin@vscout.co for details.
We retain data only as long as necessary for its purpose:
| Data Type | Retention Period |
|---|---|
| Account data | Active account + 30 days after deletion request |
| Candidate data | Per your organization's configured retention policy; auto-anonymized after expiry |
| AI action logs | 12 months from creation |
| Analytics data | 26 months (anonymized after) |
| Billing records | As required by law (typically 7 years for tax purposes) |
When candidate data reaches its retention limit, we automatically anonymize it: personal identifiers are replaced with placeholder values, and do_not_contact is set. Anonymized records are retained for aggregate reporting but can no longer be linked to individuals.
Depending on your location, you may have the following rights regarding your personal data:
How to exercise your rights: Logged-in users can export or delete their data from Settings → Privacy & Data. You can also email admin@vscout.co. We will respond within 30 days (or 72 hours for deletion requests under GDPR).
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):
Categories of personal information collected (per CCPA definitions): Identifiers, professional/employment information, internet activity, geolocation (approximate, from IP), and inferences drawn from the above.
To exercise your CCPA rights, email admin@vscout.co with the subject line "CCPA Request." We will verify your identity before processing.
If you are in the European Economic Area (EEA) or United Kingdom, the General Data Protection Regulation (GDPR) applies. Here is how we comply:
For GDPR-related inquiries, contact our Data Protection team at admin@vscout.co.
You have the right to lodge a complaint with your local data protection authority if you believe your data is being processed unlawfully.
For more details on your GDPR rights and how to exercise them, visit our GDPR Rights page.
VScout is not directed at individuals under the age of 16. We do not knowingly collect personal data from children. If we learn that we have collected data from a child under 16, we will delete it promptly. If you believe a child has provided us with personal data, please contact us at admin@vscout.co.
We implement comprehensive security measures to protect your data:
No system is 100% secure. While we take extensive precautions, we cannot guarantee absolute security. For details, see our Security page.
We may update this Privacy Policy from time to time. Material changes will be communicated by email to your registered address and/or by a prominent notice on the Service at least 30 days before taking effect. Your continued use of VScout after changes become effective constitutes acceptance.
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices: