Privacy Policy
Last updated: [DATE PENDING — to be set before launch] · Applies to growyourscope.com and the Scope app.
Grow Your Scope™ (“Scope”, “we”, “us”) is committed to protecting your personal data. This policy explains what we collect, why we collect it, how we use it, and your rights — including under India's Digital Personal Data Protection Act 2023 (DPDP) and the EU General Data Protection Regulation (GDPR).
1. Who we are
Scope is a product of Diyako Tech Innovations Pvt. Ltd., a company registered in Rajasthan, India. For inquiries about our company or our registered address, write to support@growyourscope.com.
2. What data we collect
We collect only what is needed to provide the service:
- Account data: name, email address, password (hashed by Firebase), sign-up date, consent timestamp.
- Training data: reps completed, skill levels, streaks, Scope Score, journal notes, mission progress, checkpoints, badges.
- Community data: pod membership, posts and replies you write.
- AI interaction data: messages you send to Diya (our AI coach). These are used to generate your response and are not used to train our models.
- Payment data: subscription plan and status. Payment card details are processed by Razorpay and never stored by us.
- Device / technical data: FCM push token (if you grant notification permission), browser type, country (from IP, not stored beyond the request).
- Analytics data: page views, feature usage via Google Analytics 4 and PostHog. IP addresses are anonymised.
3. Why we collect it (legal bases)
- Contract performance: to provide the training, coaching, and community features you signed up for.
- Consent: for marketing emails (you can withdraw at any time) and for Diya's AI coaching.
- Legitimate interests: fraud prevention, security, and improving the service — balanced against your rights.
- Legal obligation: retaining payment records as required by applicable tax law.
4. How we use your data
- Operate and personalise your training experience.
- Generate Diya's coaching responses (sent to Anthropic's Claude API; see Section 6).
- Send transactional emails (account confirmation, payment receipts, streak nudges) via Brevo.
- Send push notifications if you have granted permission.
- Detect and prevent abuse, spam, and crisis situations in community posts.
- Produce aggregated, anonymous product analytics.
5. Data retention
- Active accounts: data is retained for as long as your account exists.
- Deleted accounts: all personal data is deleted within 30 days of account deletion (see Section 8).
- Payment records: retained for 7 years as required by law.
- Anonymised analytics: may be retained indefinitely (no personal identifiers).
6. Third-party processors
- Google Firebase (Auth, Firestore, Cloud Functions, FCM) — infrastructure and data storage. Servers in the US/EU.
- Anthropic — Claude API powers Diya. Messages are sent to Anthropic for inference. Anthropic does not train on API data by default. See anthropic.com/privacy.
- Razorpay — payment processing (India). Subject to Razorpay's privacy policy.
- Brevo — transactional email.
- Google Analytics 4 / PostHog — analytics. IPs anonymised.
- Vercel — web hosting.
We do not sell your data to any third party.
7. International data transfers
Our infrastructure (Firebase, Vercel, Anthropic) is primarily based in the United States. If you are based in India or the EU, your data may be transferred internationally. We rely on [CONTENT PENDING — Standard Contractual Clauses / adequacy decisions / DPDP cross-border transfer compliance] for these transfers.
8. Your rights
Under DPDP (India) and GDPR (EU/UK), you have the right to:
- Access your data — use “Download my data” in Settings → Privacy & Data.
- Erasure — use “Delete my account” in Settings → Privacy & Data. All personal data is permanently deleted.
- Correction — update your name in Profile settings.
- Portability — your data export is in machine-readable JSON format.
- Withdraw consent — for marketing emails, use the unsubscribe link in any email.
- Object / restrict processing — contact us (see Section 10).
- Lodge a complaint — with your national data protection authority.
9. Children
Scope is not directed at children under 18. We do not knowingly collect data from minors. If you believe a minor has registered, please contact us and we will delete the account promptly.
10. Contact & data requests
[CONTENT PENDING — email address for data protection queries, e.g. privacy@growyourscope.com]
We aim to respond to all data requests within 30 days.
11. Changes to this policy
We will notify you of material changes via email or an in-app notice at least 7 days before they take effect. The “Last updated” date at the top of this page always reflects the most recent version.