This Privacy Policy explains what personal data Scout IP collects, why, how we protect it, and what rights you have. We are committed to being transparent and straightforward - this document describes what actually happens on the platform, not generic boilerplate. We are bound by the EU General Data Protection Regulation (GDPR) and applicable Italian data protection law (D.Lgs. 196/2003 as amended).
The data controller responsible for your personal data is:
Scout IP S.r.l.
Via Sile n. 41, 31056 Roncade (TV), Italy
Email: scoutip.info@gmail.com
Website: scoutip.it
Scout IP S.r.l. is registered as an Innovative Start-up (Startup Innovativa) under Italian law (D.L. 179/2012). For any privacy-related matters, please contact us at scoutip.info@gmail.com. Based on the nature and scale of our processing activities, we are not legally required to appoint a formal Data Protection Officer (DPO). All privacy inquiries are managed directly by our privacy team.
When you register, we collect:
Providing your email, password, and role is a mandatory contractual requirement to create an account and use the platform. Without this data, we cannot provide our services to you. All other fields are optional.
The most sensitive data you provide is your idea text: the description of the technology or invention you want to analyse. We treat this with particular care.
You have a choice about how this is handled:
You can change your privacy mode at any time in your account settings.
When you run a patent search, we store:
Added 3 September 2026. The list above previously stopped at "search job metadata", which described these as operational records. They are more than that: read together, the features and the search sentence describe your invention. Stating that they exist matters more than the words we would have used to soften it.
For security, fraud prevention, and service operation, we automatically collect:
On our public pages - the landing page, before you have an account - we count how the site is used, so we know which parts people read and where they lose interest. This section exists because the policy previously did not describe it.
What is recorded: that a page was viewed, how far down it was scrolled (25/50/75/100%), which of the audience tabs were opened, which call-to-action buttons were clicked, interactions with the guessing game, how long the page was open, and where the visit came from (the referring site or campaign tag in the link).
What is not recorded, and cannot be:your IP address is not stored with these events - the table that holds them has no column for it. It is used for about two minutes, and only to count requests so the endpoint cannot be flooded, then it expires on its own; that is the whole of it. (Corrected 21 August 2026: the previous wording said only that the IP is not stored, which was true of the events table and left this out.) Neither is any name, email, or account. The events of one visit are grouped under a random identifier that exists only in the browser tab's memory for the length of that visit: nothing is written to your device, and two visits by the same person cannot be connected. This is why the measurement needs no consent banner - there is no storage on your equipment to consent to.
Legal basis: our legitimate interest in understanding whether our own website communicates what it should (Art. 6(1)(f) GDPR). Because the data cannot be traced to you, it cannot be used to make any decision about you.
Retention: these events are deleted automatically after 90 days. Until 20 August 2026 they had no expiry, which was an oversight rather than a decision; the deletion now runs hourly.
We record when two of the emails we send you are opened, and if you click a link in them. They are:
Why. For the first, so we know whether to follow up or leave you alone - a question we would otherwise answer by writing to you again. For the second, because it is the only way to tell whether that invitation works at all.
What we do not do. We do not record the opening of any other email we send you. In particular we do not record it for password resets or for messages about your account access: whether you opened a message about your own credentials, and at what time, is not something we need to know. We do not record it for booking confirmations either.
How it works, and who does it. The measurement is made by Resend, the provider that already sends all our email and is listed in section 4 - not by a separate analytics company. It works by including a small image and, for links, by routing the click through the provider. We store the time of the first open, how many times it was opened, and the time of the first click.
How to refuse. Every one of these emails carries an unsubscribe link. Using it stops the email and the measurement: we treat it as a refusal of both. You can also ask us at any time using the contact details in section 9, and you can ask for what we have recorded to be deleted.
The processors above are the ones the platform itself uses. Two more can involve your personal data outside it, and they were not previously named:
Two things about what happens next, because they go further than "we keep notes" and you should not have to guess them. The transcript is kept indefinitely - we do not delete it on a timer - as our record of what was discussed and agreed. And it is searchable by our team through the internal assistant described below, rather than filed away unread.
You can ask us for a recording and its transcript, and you can ask us to delete them. Deletion is permanent and it is recorded: once a call is deleted it cannot be brought back, not even by the tool that supplied it.
While you are setting up a search, we record which of the five setup steps you are on and when you move between them: the description, the core features, the keywords, the classification areas, and the final review. Moving backwards is recorded the same way as moving forwards.
Why. So we can see where the setup is hard. Before this we could only tell which step a draft had reached by looking at which data it contained, which cannot see a step you opened, read and left - and that is exactly the step worth fixing. Today 23 of every 58 people who reach the classification step never reach the review step, and we do not know why.
What is recorded: your account, the draft you are working on, the step you entered, the step you came from, and the time. Nothing you typed is in these records - not your description, not your features, not your classification codes. Those are covered by sections 2.2 and 2.3 and are unaffected by this.
This is not the website measurement in section 2.6. That one cannot be connected to you at all, by design. This one is connected to your account, because a funnel that cannot follow one person through five steps measures nothing. It is kept in a separate place for that reason, so the anonymous measurement stays anonymous.
Legal basis: our legitimate interest in knowing whether our own product is usable (Art. 6(1)(f) GDPR). You can object under Art. 21 by writing to us, and we will stop recording it for your account.
Retention: these records are deleted automatically after 90 days.
Under GDPR, we must have a legal basis for each type of processing. Here is a plain-language breakdown:
Because our platform is AI-driven, we want to be absolutely clear: we do not use your personal data for automated decision-making or profiling that produces legal or similarly significant effects concerning you (as defined in Art. 22 GDPR). Our AI operates purely as an analytical tool to evaluate the idea texts you submit and assist you in your research, not to make judgments about you as an individual.
We use the following third-party services to operate Scout IP. All are engaged under appropriate data processing agreements.
| Third Party | Purpose | Data Shared | Location |
|---|---|---|---|
| Google LLC (Cloud Vertex AI) | AI processing of idea text to generate reports | Your idea text | EU (europe-west4); US provider, EU SCCs apply |
| Voyage AI | Turning your idea text and patent text into the numeric "meaning fingerprints" the search compares | Your idea text, and the search terms derived from it | USA |
| Resend | Sending service emails (sign-in links, notifications) | Your email address and the content of that email | USA |
| Qdrant (self-hosted) | The search index of patent fingerprints | Patent data (public) and the fingerprint of your query while the search runs | EU |
| Google LLC (BigQuery) | Reading the public patent dataset that fills our index | Patent identifiers and classification codes. No personal data. | EU |
| EPO (European Patent Office) | Patent database search | Search queries (CPC codes). No personal data. | EU |
| Railway (railway.app) | Cloud infrastructure and application hosting | All application data as processed on server | EU (Amsterdam, NL) |
| PostgreSQL database | Persistent storage of account data, jobs, reports | All structured data described in Section 2 | EU (Amsterdam, NL) |
| Redis | Temporary in-memory storage for Local Mode | Idea text (Local Mode, TTL 2h); job metadata | EU (Amsterdam, NL) |
Regarding Google Cloud Vertex AI: your idea text is sent to Google's enterprise API to generate your analysis, and that processing runs in Google's European region (europe-west4). Google does not use it to train or fine-tune any model. By default Google may retain prompts for up to 30 days for the sole purpose of monitoring for abuse of its usage policies; we have applied for the documented exemption that removes this retention, and we are completing a Google Cloud Data Processing Addendum with a Zero Data Retention agreement. Until both are in place we describe the position as it is rather than as we intend it. Google LLC remains a US-established provider, so EU Standard Contractual Clauses apply to the engagement.
All of our own infrastructure - servers, database, and search index - runs within the European Union. Personal data leaves the EU in two cases, each of them a row in the table above: your idea text and the search terms derived from it go to Voyage AI to be turned into the numeric fingerprints the search compares; and your email address, together with the content of that email, goes to Resend when we send you a service message. The analysis itself no longer belongs on that list: since 08/09/2026 it runs in Google's European region, though Google LLC remains a US-established provider and the Standard Contractual Clauses stay in place for that reason. Nothing else leaves. We do not sell your data to any third party, ever.
Business Transfers:
If Scout IP S.r.l. is involved in a merger, acquisition, restructuring, or sale of all or a portion of its assets, your personal data may be transferred to the acquiring entity. We will notify you via email and/or a prominent notice on our platform of any such change in ownership and outline your choices regarding your personal data.
Scout IP's own infrastructure is hosted entirely within the European Union (Railway, Amsterdam, Netherlands). Three providers established in the United States process personal data for us. Google LLC(Cloud Vertex AI) receives your idea text to produce the analysis, and since 8 September 2026 it processes it in Google's European region - so the processing does not leave the EU, while the provider remains US-established. Voyage AI receives your idea text and the search terms derived from it, and processes them in the United States. Resend receives your email address and the content of the service emails we send you, in the United States. Corrected 3 September 2026: this section previously described the transfer to Google as the only one, while the table in section 4 above already listed the other two. Corrected again 8 September 2026: it described all three as transfers outside the EU, which stopped being true for Google when the processing region moved.
For the engagement with Google we rely on: (a) EU Standard Contractual Clauses (SCCs) approved by the European Commission; (b) processing in Google's European region, so the processing itself does not leave the EU; and (c) Google's contractual undertaking not to use the text to train or fine-tune any model. Google may by default retain prompts for up to 30 days solely to monitor for abuse of its usage policies, and we have applied for the documented exemption that removes this. If you would like more information about the safeguards in place for any of these transfers, please contact us at scoutip.info@gmail.com.
Corrected 7 September 2026. Two of the periods below were stated here and applied by nothing: the twelve months for security and authentication logs, and the twenty-four months for searches on a dormant account. There was no task and no expiry, so those rows were kept indefinitely while this page named a period. Both now have a deletion that runs, and a check that reports when it stops running - because the first of these periods was already found unenforced once, on 20 August, for a different table.
We keep your data only as long as needed for the purpose it was collected, or as required by law.
When you request deletion of your account or data, we process the request within 30 days. Data is first flagged as deleted (making it inaccessible to you and to Scout IP), then permanently and irreversibly removed within that 30-day window.
What a deletion removes, and the one thing it does not. We stated the promise above before we stated its limit, and the limit belongs here rather than in a sentence you would have to infer. A deletion removes your email address and the credentials attached to it, every invention description you gave us - in your finished searches and in the drafts you never submitted - every draft in its entirety, and any internal note our team wrote about your searches.
What remains is the row that records that a search ran: when, how long it took, what it cost us and how the engine behaved. It no longer carries your description, your address, or anything that points back to you, and we keep it because our accounting and our own measurements of search quality are built on it. If you would rather those rows went too, write to us at the address in section 9 and we will remove them.
As a person whose data we process, you have the following rights:
Added 7 September 2026: access and portability now take one click. Two of the rights above no longer need an email. In Settings you can download everything we hold about your account as a JSON file (Art. 15 and 20). Until that date the copy had to be asked for and produced by hand, which is a right that exists on paper and within 30 days. Deleting your account (Art. 17) is still done by writing to the address below, and we do it waits on somebody.
One thing that file cannot contain: the descriptions you sealed with your own passphrase arrive still encrypted, because we do not have your passphrase. The file includes the encrypted text and the wrapped key, which is everything we hold - your own browser is what can open it. An export claiming to hand you that text in the clear would be proof that the encryption promise is not real.
To exercise any of these rights, contact us at scoutip.info@gmail.com. We will respond within 30 days. We will not charge you for legitimate requests. We may ask you to verify your identity before fulfilling a request.
You also have the right to lodge a complaint with the Italian data protection authority (Garante per la Protezione dei Dati Personali, www.garanteprivacy.it) or the supervisory authority in your EU country of residence.
Corrected 3 September 2026. This section previously said that "even a database breach does not expose your idea texts in readable form". That was true of the description field and not of the search, which stores what it derived from your description in readable form. The overstatement is corrected below rather than removed quietly, and the same sentence has been corrected in the product where it was shown while you chose your passphrase.
We take the security of your data seriously and have implemented technical measures proportionate to our current scale:
Data Breach Notification:
No security system is perfect. In the event of a personal data breach that poses a high risk to your rights and freedoms, we will notify you and the relevant supervisory authority without undue delay, in compliance with GDPR obligations. If you discover a security issue, please report it responsibly to scoutip.info@gmail.com.
Scout IP allows you to generate a shareable public link for any of your reports. If you activate this feature:
Public report links do not expose your account details, email address, or idea text - only the report content (patent analysis, threat level, prior art list).
Scout IP does not use tracking cookies or advertising cookies, and no third-party analytics tools. Corrected 20 August 2026: this section previously said your browser storage held only your sign-in token. It also held an identifier used to measure website usage, which should have been listed here and should not have been stored at all. That identifier is gone, and existing ones are erased from your browser the next time you open the site.
Corrected 7 September 2026:the list below used to have two entries and ended with the words "nothing else". There were fifteen, and the two it left out were the ones that matter most - the invention description in plain text when you choose to keep it on this device, and the key that opens your encrypted descriptions. Nothing new is being stored; what changes is that this page now says so. The list is generated from the same declaration the software writes from, so it cannot fall behind the product again.
The complete list of what Scout IP stores on your device:
token)scoutip_consent)scoutip_cookie_consent)scoutip.draft.local.…)scoutip_local_idea_…)scoutip_privacy_onboarded)scoutip_dismissed_drafts)scoutip_feedback_prompted_…)scoutip-vault)scoutip_wizard_note_…)scoutip_search_mode_…)scoutip_clone_…)scoutip_private_report_redirect)vault-change-rimandato)admin_view_as)Every one of them is needed for something you asked the software to do, which is why none of them waits for a consent: there is nothing optional in the list. Website-usage measurement (section 2.6) is not in it at all, because it keeps its identifier in the browser tab's memory and writes nothing.
We no longer write, and actively delete, the following:
scoutip_sid - A per-visitor identifier used to measure website usage until 20 August 2026. It should never have been stored; it is erased the next time you open the site.None of it is used for cross-site profiling, and none of it is shared with anyone.
Scout IP is not intended for use by persons under the age of 18. We do not knowingly collect personal data from minors. If you believe we have inadvertently collected data from a minor, please contact us and we will delete it promptly.
We may update this Privacy Policy as our platform evolves. When we make material changes, we will notify you by email or by a notice on the platform before the changes take effect. The date at the top of this document indicates when it was last updated.
For any privacy questions, data subject requests, or concerns:
Scout IP S.r.l.
Via Sile n. 41, 31056 Roncade (TV), Italy
Email: scoutip.info@gmail.com
Website: scoutip.it
We aim to respond to all privacy enquiries within 5 business days, and will always respond within 30 days as required by GDPR.