Back to Home

Privacy policy

Scout IP · Scout IP S.r.l.
Effective Date: May 2026
Platform: scoutip.it

This Privacy Policy explains what personal data Scout IP collects, why, how we protect it, and what rights you have. We are committed to being transparent and straightforward - this document describes what actually happens on the platform, not generic boilerplate. We are bound by the EU General Data Protection Regulation (GDPR) and applicable Italian data protection law (D.Lgs. 196/2003 as amended).

1. Data controller

The data controller responsible for your personal data is:

Scout IP S.r.l.
Via Sile n. 41, 31056 Roncade (TV), Italy
Email: scoutip.info@gmail.com
Website: scoutip.it

Scout IP S.r.l. is registered as an Innovative Start-up (Startup Innovativa) under Italian law (D.L. 179/2012). For any privacy-related matters, please contact us at scoutip.info@gmail.com. Based on the nature and scale of our processing activities, we are not legally required to appoint a formal Data Protection Officer (DPO). All privacy inquiries are managed directly by our privacy team.

2. What data we collect

2.1 Account data

When you register, we collect:

  • Email address - used as your login identifier and for service communications.
  • Password - stored as a one-way cryptographic hash (bcrypt). We never store or see your plaintext password.
  • Role - the professional role you select at registration (investor, researcher, or lawyer). This determines your access level within the platform.
  • Organisation ID - if you are part of a team or organisation account (optional).

Providing your email, password, and role is a mandatory contractual requirement to create an account and use the platform. Without this data, we cannot provide our services to you. All other fields are optional.

2.2 Idea text - your search input

The most sensitive data you provide is your idea text: the description of the technology or invention you want to analyse. We treat this with particular care.

You have a choice about how this is handled:

  • Cloud Mode (default), for descriptions written from 28 August 2026: your description is encrypted in your browser, with a key derived from a passphrase only you know. That passphrase never reaches our servers, so we cannot open these descriptions - and neither can anyone who obtains a copy of our database. If you lose both the passphrase and the recovery code we give you, you can set a new passphrase and carry on searching - the descriptions already saved stay unreadable, by us as well, and your reports are unaffected. Your description is still sent to Google Gemini (our AI provider) while the search runs, because the analysis is an AI reading it - see Section 4.
  • Cloud Mode, for descriptions written before that date: encrypted in our database with AES-256-GCM using a per-user key that is itself encrypted with a master key we hold. We can open these, and they are not changed retroactively by setting a passphrase. The same applies to accounts belonging to our own team, which are not asked for a passphrase.
  • Local Mode: Your idea text is never written to our database. It is held temporarily in an in-memory cache (Redis) with a maximum lifetime of 2 hours, used only to complete your analysis, and then discarded. In Local Mode, your idea text is still sent to Google Gemini for processing.

You can change your privacy mode at any time in your account settings.

2.3 Search and analysis data

When you run a patent search, we store:

  • The patent results returned by the EPO database (patent numbers, titles, assignees, publication dates, CPC codes, abstracts) - these are public data from EPO OPS.
  • The AI-generated report and threat level for your search - stored linked to your account.
  • Search job metadata: status, timestamps, processing steps, and performance metrics.
  • What your description produced, and this is stored in readable form: the technical features extracted from it, the alternative wordings generated for each one, the classification areas chosen, and the sentence we build from them and hand to the search engine. Your report is stored in readable form too. These are not covered by the browser encryption described in 2.2 - only the description itself is. We keep them because the search cannot rank results, and we cannot tell you why a search behaved as it did, without them.

Added 3 September 2026. The list above previously stopped at "search job metadata", which described these as operational records. They are more than that: read together, the features and the search sentence describe your invention. Stating that they exist matters more than the words we would have used to soften it.

2.4 Technical and security data

For security, fraud prevention, and service operation, we automatically collect:

  • IP address - recorded at login, registration, and failed login attempts.
  • User agent - your browser or client type, recorded at the same events.
  • Audit log entries - a record of actions taken on the platform (e.g. search initiated, job completed), linked to your account. We do not log the content of your searches in audit logs - only the action type.
  • Authentication events - every successful login, failed login, and registration is logged with timestamp, IP address, user agent, and, for failed logins, the reason (wrong password, user not found, inactive account).
  • Your email preferences - whether you have agreed to receive referral codes, the date you agreed, which of the four places you did it from (the sign-up form, your settings, a link in an email, or the offer beside your referral code on a report you rated), and the date you withdrew it if you have. We keep the date you withdrew as well as the date you agreed, because that is what lets us show your request was acted on rather than merely assert it.

2.5 Data we do not collect

  • We do not use tracking cookies, advertising cookies, or third-party analytics tools (e.g. Google Analytics). We do measure how our public website is used - see section 2.6, which describes it in full - and we record when two kinds of our email are opened, described in section 2.7. Corrected 20 August 2026: this list previously read as though we measured nothing at all.
  • We do not collect payment information. There is no payment system in the current pilot.
  • We do not collect any sensitive personal data (health data, financial data, national identity numbers, etc.).
  • We do not collect data from social media accounts or third-party login providers.

2.6 How we measure our public website (added 20 August 2026)

On our public pages - the landing page, before you have an account - we count how the site is used, so we know which parts people read and where they lose interest. This section exists because the policy previously did not describe it.

What is recorded: that a page was viewed, how far down it was scrolled (25/50/75/100%), which of the audience tabs were opened, which call-to-action buttons were clicked, interactions with the guessing game, how long the page was open, and where the visit came from (the referring site or campaign tag in the link).

What is not recorded, and cannot be:your IP address is not stored with these events - the table that holds them has no column for it. It is used for about two minutes, and only to count requests so the endpoint cannot be flooded, then it expires on its own; that is the whole of it. (Corrected 21 August 2026: the previous wording said only that the IP is not stored, which was true of the events table and left this out.) Neither is any name, email, or account. The events of one visit are grouped under a random identifier that exists only in the browser tab's memory for the length of that visit: nothing is written to your device, and two visits by the same person cannot be connected. This is why the measurement needs no consent banner - there is no storage on your equipment to consent to.

Legal basis: our legitimate interest in understanding whether our own website communicates what it should (Art. 6(1)(f) GDPR). Because the data cannot be traced to you, it cannot be used to make any decision about you.

Retention: these events are deleted automatically after 90 days. Until 20 August 2026 they had no expiry, which was an oversight rather than a decision; the deletion now runs hourly.

2.7 When we record that an email was opened (added 27 August 2026)

We record when two of the emails we send you are opened, and if you click a link in them. They are:

  • the message a day after a search asking how it went;
  • the invitation to share Scout IP with someone else.

Why. For the first, so we know whether to follow up or leave you alone - a question we would otherwise answer by writing to you again. For the second, because it is the only way to tell whether that invitation works at all.

What we do not do. We do not record the opening of any other email we send you. In particular we do not record it for password resets or for messages about your account access: whether you opened a message about your own credentials, and at what time, is not something we need to know. We do not record it for booking confirmations either.

How it works, and who does it. The measurement is made by Resend, the provider that already sends all our email and is listed in section 4 - not by a separate analytics company. It works by including a small image and, for links, by routing the click through the provider. We store the time of the first open, how many times it was opened, and the time of the first click.

How to refuse. Every one of these emails carries an unsubscribe link. Using it stops the email and the measurement: we treat it as a refusal of both. You can also ask us at any time using the contact details in section 9, and you can ask for what we have recorded to be deleted.

2.8 If you talk to us (added 20 August 2026)

The processors above are the ones the platform itself uses. Two more can involve your personal data outside it, and they were not previously named:

  • Recorded calls. Walkthroughs and support calls may be recorded and transcribed with Fathom (USA). You are told at the start of the call and can ask us not to record.

    Two things about what happens next, because they go further than "we keep notes" and you should not have to guess them. The transcript is kept indefinitely - we do not delete it on a timer - as our record of what was discussed and agreed. And it is searchable by our team through the internal assistant described below, rather than filed away unread.

    You can ask us for a recording and its transcript, and you can ask us to delete them. Deletion is permanent and it is recorded: once a call is deleted it cannot be brought back, not even by the tool that supplied it.

  • Our internal assistant. Our team uses an internal assistant (built on Anthropic, USA, and reachable through Telegram) to find things in our own material: our handbook, our team files, and the call transcripts described above. It is used by our staff, not by customers, and it does not receive your idea text or your account data. What our staff ask it, and what it answered, is logged - so if you want to know whether your call has been looked at, we can tell you.

2.9 Which step of a search you are on (added 28 August 2026)

While you are setting up a search, we record which of the five setup steps you are on and when you move between them: the description, the core features, the keywords, the classification areas, and the final review. Moving backwards is recorded the same way as moving forwards.

Why. So we can see where the setup is hard. Before this we could only tell which step a draft had reached by looking at which data it contained, which cannot see a step you opened, read and left - and that is exactly the step worth fixing. Today 23 of every 58 people who reach the classification step never reach the review step, and we do not know why.

What is recorded: your account, the draft you are working on, the step you entered, the step you came from, and the time. Nothing you typed is in these records - not your description, not your features, not your classification codes. Those are covered by sections 2.2 and 2.3 and are unaffected by this.

This is not the website measurement in section 2.6. That one cannot be connected to you at all, by design. This one is connected to your account, because a funnel that cannot follow one person through five steps measures nothing. It is kept in a separate place for that reason, so the anonymous measurement stays anonymous.

Legal basis: our legitimate interest in knowing whether our own product is usable (Art. 6(1)(f) GDPR). You can object under Art. 21 by writing to us, and we will stop recording it for your account.

Retention: these records are deleted automatically after 90 days.

3. Why we collect your data - legal bases

Under GDPR, we must have a legal basis for each type of processing. Here is a plain-language breakdown:

  • Account data (email, password, role): necessary to perform the contract with you - i.e. to provide you with access to the platform (Art. 6(1)(b) GDPR).
  • Idea text and analysis outputs: necessary to perform the contract - you submit idea text in order to receive the analysis service (Art. 6(1)(b) GDPR).
  • IP address, user agent, authentication events, and audit logs: our legitimate interest in maintaining security, preventing misuse and fraud, and debugging service issues (Art. 6(1)(f) GDPR). This interest does not override your rights - we do not use this data for profiling or marketing.
  • Service communications: necessary to perform the contract, or our legitimate interest in keeping you informed about material changes (Art. 6(1)(b) and 6(1)(f) GDPR). One of these is worth naming: the day after a search finishes, if you have not rated the report, we send a single message asking how it went. It concerns a search you ran yourself, we send it once and never again, and every one of them carries a link that stops them.
  • Marketing communications: we send these only if you have asked us to, on the basis of your consent (Art. 6(1)(a) GDPR). Today that means one thing: a referral code that lets three people join free. It reaches you in the message described above, or in a short email of its own after you rate a report highly. You can give that permission when you register, from Settings → Email preferences, by clicking the offer in one of our emails, or from the offer shown beside your referral code on a report you rated - and you can take it back from that same settings page, or from the link at the bottom of any email, at any time and without giving a reason. Withdrawing it does not stop the service message above; those are two separate switches on purpose. We record when you agreed and which of those four places you were in when you did, so that if you ever ask, we can tell you. We never sell or rent your address, and we do not send promotional email to anyone who has not ticked that box. (Updated 6 September 2026: the referral code also reaches promoters in a short email of its own, and until this date that one was sent without checking this permission and carried no way to stop it. Both are now true of it. The same date added a fourth place to give the permission, beside the code on a rated report, and removed the mention of an occasional note about ScoutIP because no such message has ever been sent.) (Updated 26 August 2026: until this date this section said we sent no promotional email at all, which was true then.)

3.1 No automated decision-making

Because our platform is AI-driven, we want to be absolutely clear: we do not use your personal data for automated decision-making or profiling that produces legal or similarly significant effects concerning you (as defined in Art. 22 GDPR). Our AI operates purely as an analytical tool to evaluate the idea texts you submit and assist you in your research, not to make judgments about you as an individual.

4. Third-party processors

We use the following third-party services to operate Scout IP. All are engaged under appropriate data processing agreements.

Third PartyPurposeData SharedLocation
Google LLC (Cloud Vertex AI)AI processing of idea text to generate reportsYour idea textEU (europe-west4); US provider, EU SCCs apply
Voyage AITurning your idea text and patent text into the numeric "meaning fingerprints" the search comparesYour idea text, and the search terms derived from itUSA
ResendSending service emails (sign-in links, notifications)Your email address and the content of that emailUSA
Qdrant (self-hosted)The search index of patent fingerprintsPatent data (public) and the fingerprint of your query while the search runsEU
Google LLC (BigQuery)Reading the public patent dataset that fills our indexPatent identifiers and classification codes. No personal data.EU
EPO (European Patent Office)Patent database searchSearch queries (CPC codes). No personal data.EU
Railway (railway.app)Cloud infrastructure and application hostingAll application data as processed on serverEU (Amsterdam, NL)
PostgreSQL databasePersistent storage of account data, jobs, reportsAll structured data described in Section 2EU (Amsterdam, NL)
RedisTemporary in-memory storage for Local ModeIdea text (Local Mode, TTL 2h); job metadataEU (Amsterdam, NL)

Regarding Google Cloud Vertex AI: your idea text is sent to Google's enterprise API to generate your analysis, and that processing runs in Google's European region (europe-west4). Google does not use it to train or fine-tune any model. By default Google may retain prompts for up to 30 days for the sole purpose of monitoring for abuse of its usage policies; we have applied for the documented exemption that removes this retention, and we are completing a Google Cloud Data Processing Addendum with a Zero Data Retention agreement. Until both are in place we describe the position as it is rather than as we intend it. Google LLC remains a US-established provider, so EU Standard Contractual Clauses apply to the engagement.

All of our own infrastructure - servers, database, and search index - runs within the European Union. Personal data leaves the EU in two cases, each of them a row in the table above: your idea text and the search terms derived from it go to Voyage AI to be turned into the numeric fingerprints the search compares; and your email address, together with the content of that email, goes to Resend when we send you a service message. The analysis itself no longer belongs on that list: since 08/09/2026 it runs in Google's European region, though Google LLC remains a US-established provider and the Standard Contractual Clauses stay in place for that reason. Nothing else leaves. We do not sell your data to any third party, ever.

Business Transfers:
If Scout IP S.r.l. is involved in a merger, acquisition, restructuring, or sale of all or a portion of its assets, your personal data may be transferred to the acquiring entity. We will notify you via email and/or a prominent notice on our platform of any such change in ownership and outline your choices regarding your personal data.

5. International data transfers

Scout IP's own infrastructure is hosted entirely within the European Union (Railway, Amsterdam, Netherlands). Three providers established in the United States process personal data for us. Google LLC(Cloud Vertex AI) receives your idea text to produce the analysis, and since 8 September 2026 it processes it in Google's European region - so the processing does not leave the EU, while the provider remains US-established. Voyage AI receives your idea text and the search terms derived from it, and processes them in the United States. Resend receives your email address and the content of the service emails we send you, in the United States. Corrected 3 September 2026: this section previously described the transfer to Google as the only one, while the table in section 4 above already listed the other two. Corrected again 8 September 2026: it described all three as transfers outside the EU, which stopped being true for Google when the processing region moved.

For the engagement with Google we rely on: (a) EU Standard Contractual Clauses (SCCs) approved by the European Commission; (b) processing in Google's European region, so the processing itself does not leave the EU; and (c) Google's contractual undertaking not to use the text to train or fine-tune any model. Google may by default retain prompts for up to 30 days solely to monitor for abuse of its usage policies, and we have applied for the documented exemption that removes this. If you would like more information about the safeguards in place for any of these transfers, please contact us at scoutip.info@gmail.com.

6. How long we keep your data

Corrected 7 September 2026. Two of the periods below were stated here and applied by nothing: the twelve months for security and authentication logs, and the twenty-four months for searches on a dormant account. There was no task and no expiry, so those rows were kept indefinitely while this page named a period. Both now have a deletion that runs, and a check that reports when it stops running - because the first of these periods was already found unenforced once, on 20 August, for a different table.

We keep your data only as long as needed for the purpose it was collected, or as required by law.

  • Account data: retained for the duration of your account. If you request deletion, we will permanently delete your account data within 30 days of receiving your request.
  • Search jobs and reports:retained until you delete them using the platform's history deletion feature, or for up to 24 months after your last active use of the platform, whichever comes first. You can soft-delete individual jobs or your entire history at any time from your dashboard; the data is then permanently removed within 30 days.
  • Security and authentication logs: retained for 12 months from the date of the event, then permanently deleted. This retention period is justified by our legitimate interest in security and fraud prevention.
  • Idea text in Local Mode: maximum 2 hours in Redis, then automatically discarded. Nothing is written to our database - not while you are still typing it either. Until 27 August 2026 an unsubmitted draft did keep a copy, which was a defect and not a decision; those copies have been removed.
  • Idea text in Cloud Mode (encrypted): retained with your job data, subject to the same retention period as search jobs above. Deleted upon your request or at retention expiry. The same encryption covers the description while it is still a draft, before you run anything with it.

When you request deletion of your account or data, we process the request within 30 days. Data is first flagged as deleted (making it inaccessible to you and to Scout IP), then permanently and irreversibly removed within that 30-day window.

What a deletion removes, and the one thing it does not. We stated the promise above before we stated its limit, and the limit belongs here rather than in a sentence you would have to infer. A deletion removes your email address and the credentials attached to it, every invention description you gave us - in your finished searches and in the drafts you never submitted - every draft in its entirety, and any internal note our team wrote about your searches.

What remains is the row that records that a search ran: when, how long it took, what it cost us and how the engine behaved. It no longer carries your description, your address, or anything that points back to you, and we keep it because our accounting and our own measurements of search quality are built on it. If you would rather those rows went too, write to us at the address in section 9 and we will remove them.

7. Your rights under GDPR

As a person whose data we process, you have the following rights:

  • Right of access (Art. 15): you can request a copy of the personal data we hold about you.
  • Right to rectification (Art. 16): you can ask us to correct inaccurate data.
  • Right to erasure (Art. 17): you can request deletion of your personal data where there is no overriding legitimate reason to retain it.
  • Right to restriction of processing (Art. 18): you can ask us to restrict processing in certain circumstances.
  • Right to data portability (Art. 20): you can request your data in a structured, machine-readable format.
  • Right to object (Art. 21): you can object to processing based on our legitimate interests.
  • Right to withdraw consent: where we rely on consent as a legal basis, you can withdraw it at any time without affecting prior processing.

Added 7 September 2026: access and portability now take one click. Two of the rights above no longer need an email. In Settings you can download everything we hold about your account as a JSON file (Art. 15 and 20). Until that date the copy had to be asked for and produced by hand, which is a right that exists on paper and within 30 days. Deleting your account (Art. 17) is still done by writing to the address below, and we do it waits on somebody.

One thing that file cannot contain: the descriptions you sealed with your own passphrase arrive still encrypted, because we do not have your passphrase. The file includes the encrypted text and the wrapped key, which is everything we hold - your own browser is what can open it. An export claiming to hand you that text in the clear would be proof that the encryption promise is not real.

To exercise any of these rights, contact us at scoutip.info@gmail.com. We will respond within 30 days. We will not charge you for legitimate requests. We may ask you to verify your identity before fulfilling a request.

You also have the right to lodge a complaint with the Italian data protection authority (Garante per la Protezione dei Dati Personali, www.garanteprivacy.it) or the supervisory authority in your EU country of residence.

8. How we protect your data

Corrected 3 September 2026. This section previously said that "even a database breach does not expose your idea texts in readable form". That was true of the description field and not of the search, which stores what it derived from your description in readable form. The overstatement is corrected below rather than removed quietly, and the same sentence has been corrected in the product where it was shown while you chose your passphrase.

We take the security of your data seriously and have implemented technical measures proportionate to our current scale:

  • Passwords are hashed using bcrypt - never stored in plaintext.
  • JWT tokens are used for session authentication with configurable expiry.
  • Descriptions written from 28 August 2026 are encrypted in your browser with a key we never receive, so a breach of our database does not expose them. Descriptions written before that date are encrypted with AES-256-GCM using per-user keys wrapped by a master key we hold.
  • What a breach would expose, stated plainly. Not your descriptions, if they were written after that date. It would expose what the search made from them: the technical features, their alternative wordings, the classification areas and the search sentence, together with your report - all of which we keep in readable form, as section 2.3 sets out. Read together those describe your invention. We would rather you knew the limit than trusted a sentence that was wider than the truth.
  • All connections to the platform use HTTPS/TLS encryption in transit.
  • Access to the platform is invite-code gated during the pilot phase.
  • All authentication events are logged for security monitoring.

Data Breach Notification:
No security system is perfect. In the event of a personal data breach that poses a high risk to your rights and freedoms, we will notify you and the relevant supervisory authority without undue delay, in compliance with GDPR obligations. If you discover a security issue, please report it responsibly to scoutip.info@gmail.com.

9. Public report sharing

Scout IP allows you to generate a shareable public link for any of your reports. If you activate this feature:

  • The report becomes accessible to anyone with the link, without requiring a login.
  • The link contains a unique, unguessable token. There is no central directory of shared reports.
  • You can revoke the public link at any time by disabling sharing for that report.

Public report links do not expose your account details, email address, or idea text - only the report content (patent analysis, threat level, prior art list).

10. Cookies and local storage

Scout IP does not use tracking cookies or advertising cookies, and no third-party analytics tools. Corrected 20 August 2026: this section previously said your browser storage held only your sign-in token. It also held an identifier used to measure website usage, which should have been listed here and should not have been stored at all. That identifier is gone, and existing ones are erased from your browser the next time you open the site.

Corrected 7 September 2026:the list below used to have two entries and ended with the words "nothing else". There were fifteen, and the two it left out were the ones that matter most - the invention description in plain text when you choose to keep it on this device, and the key that opens your encrypted descriptions. Nothing new is being stored; what changes is that this page now says so. The list is generated from the same declaration the software writes from, so it cannot fall behind the product again.

The complete list of what Scout IP stores on your device:

  • Your sign-in token. (localStorage: token)
    Without it every page reload would ask you to sign in again. Until you sign out, or you clear your browser storage.
  • That you have seen the storage notice. (cookie: scoutip_consent)
    So the notice is not shown again on every page. One year, or until you clear your cookies.
  • The same acknowledgement, kept twice. (localStorage: scoutip_cookie_consent)
    The cookie can be read by the server and the copy survives if cookies are restricted; either one alone would show the notice again to somebody who had already dismissed it. Until you clear your browser storage.
  • The invention description you are writing, in plain text, when you chose to keep it on this device only. (localStorage: scoutip.draft.local.)
    In local mode this is the ONLY copy that exists: we deliberately do not store it on our servers, so the draft would be lost on a reload if the browser did not hold it. Removed when you sign out, and when the draft is submitted or abandoned. Never sent to us.
  • The invention description of a search you already ran in local mode, in plain text. (localStorage: scoutip_local_idea_)
    The report page has to show you what was searched, and in local mode our servers kept nothing to show. Removed when you sign out.
  • That you have made the cloud-or-local choice. (localStorage: scoutip_privacy_onboarded)
    So the choice is asked once rather than before every search. Until you clear your browser storage.
  • Which unfinished searches you told us to stop offering to resume. (localStorage: scoutip_dismissed_drafts)
    So a draft you dismissed does not come back on the next visit. Until you clear your browser storage.
  • That you have already been asked for feedback on a given report. (localStorage: scoutip_feedback_prompted_)
    So the same report does not ask you twice. Until you clear your browser storage.
  • The key that opens your encrypted descriptions on this device, and the salt it was derived from. (indexedDB: scoutip-vault)
    Only when you asked us to remember this device, so you are not asked for your passphrase every time. The passphrase itself is never stored, here or anywhere, and this key never leaves the browser. Removed when you sign out, when you use 'forget this device', and whenever the passphrase it belongs to has been replaced.
  • A one-line note explaining why the search screen opened the way it did. (sessionStorage: scoutip_wizard_note_)
    It is handed from one screen to the next; without it the explanation arrives nowhere. When you close the tab.
  • Whether a search is being run automatically or with the review steps. (sessionStorage: scoutip_search_mode_)
    It is handed from the box where you start to the screens that follow; without it a search you asked to run automatically would stop and ask you to review it. When you close the tab.
  • The parameters of a finished report you chose to edit. (sessionStorage: scoutip_clone_)
    They are carried to the search screen so it opens on what you already had. Read once and removed immediately; otherwise when you close the tab.
  • That you arrived at a private report link while signed out. (sessionStorage: scoutip_private_report_redirect)
    So the sign-in page can explain that a shared report needs its public link, instead of showing an error that looks like a fault. Read once by the sign-in page and removed.
  • That you postponed setting a new passphrase. (sessionStorage: vault-change-rimandato)
    So the request is not repeated on every screen for the rest of the visit. When you close the tab.
  • Which account a Scout IP administrator is inspecting. (sessionStorage: admin_view_as)
    Only ever written on Scout IP's own staff accounts, inside the admin console. A customer's browser never holds it. When the administrator leaves that view, or closes the tab.

Every one of them is needed for something you asked the software to do, which is why none of them waits for a consent: there is nothing optional in the list. Website-usage measurement (section 2.6) is not in it at all, because it keeps its identifier in the browser tab's memory and writes nothing.

We no longer write, and actively delete, the following:

  • scoutip_sid - A per-visitor identifier used to measure website usage until 20 August 2026. It should never have been stored; it is erased the next time you open the site.

None of it is used for cross-site profiling, and none of it is shared with anyone.

11. Minimum age

Scout IP is not intended for use by persons under the age of 18. We do not knowingly collect personal data from minors. If you believe we have inadvertently collected data from a minor, please contact us and we will delete it promptly.

12. Changes to this privacy policy

We may update this Privacy Policy as our platform evolves. When we make material changes, we will notify you by email or by a notice on the platform before the changes take effect. The date at the top of this document indicates when it was last updated.

13. Contact

For any privacy questions, data subject requests, or concerns:

Scout IP S.r.l.
Via Sile n. 41, 31056 Roncade (TV), Italy
Email: scoutip.info@gmail.com
Website: scoutip.it

We aim to respond to all privacy enquiries within 5 business days, and will always respond within 30 days as required by GDPR.