Grow Your Scope

Privacy Policy — Scope (Grow Your Scope™)

Diyako Tech Innovations Pvt. Ltd.

Effective date: 29 August 2026 · Last updated: 29 August 2026


1. Who we are and what this policy covers

This Privacy Policy explains how Diyako Tech Innovations Pvt. Ltd. ("Diyako", "we", "us", "our") — the company behind Grow Your Scope™ and its products Scope (for individuals) and Scope for Teams (for organisations) — collects, uses, shares, and protects personal information.

Our two different roles — please read this first, it matters:

Data-protection law treats us differently depending on how you use Scope:

  • When you use Scope as an individual (you signed up for yourself), we are the Data Controller (called "Data Fiduciary" under India's DPDP Act). We decide why and how your personal data is processed, and this entire policy governs that relationship.

  • When your employer or organisation provides Scope to you (through Scope for Teams), your employer is the Data Controller/Fiduciary, and we act as their Data Processor. We process your data on your employer's documented instructions, under a Data Processing Agreement with them. For that data, your employer's privacy policy also applies, and certain requests (like deletion) may need to go through your employer. Section 9 explains exactly what this means for you, including the strong privacy protections we build in regardless.

This policy applies to our websites (growyourscope.com and related domains), the Scope application, and related services (together, the "Services"). The Services are intended only for individuals aged 18 or older (see Section 12).


2. The information we collect

Information you provide:

  • Account data: name, email address, password (stored hashed, never in plain text), and profile details you choose to add.
  • Practice content: your reps, reflections, journal notes, situation descriptions, emotion/mood selections, and your conversations with Diya (our AI coach). This is your private practice content — see Section 6 and Section 9 for how strictly we protect it.
  • Verification content: the responses you submit for skill verification, which produce your Verified Skills and Evidence Pack.
  • Payment data: processed by our payment provider (Razorpay). We do not store your full card details; we receive limited transaction confirmation data.
  • Communications: messages you send us (e.g. support requests to support@growyourscope.com).

Information collected automatically:

  • Usage and device data: app interactions, feature usage, streaks/activity, device and browser type, IP address, approximate location (derived from IP), and similar technical data, collected via our own systems and analytics/error-monitoring tools (see Section 8).
  • Cookies and similar technologies: see our Cookie Policy and Section 11.

Information from your organisation (Scope for Teams only):

  • When your employer enrols you, we receive your work email, name, team/department assignment, and role (employee/manager/HR/owner) from your organisation.

Some features let you record your mood or emotional state as part of practice. Where such data may be considered sensitive under applicable law, we process it solely to provide the Services to you, on the basis of your consent and/or the performance of our contract with you. This data is treated as private practice content (see Section 6) and is never disclosed to your employer.


3. How we use your information (and our legal basis)

PurposeLegal basis (GDPR) / DPDP ground
Provide and operate the Services (your account, reps, verification, Evidence Pack)Performance of contract
Power Diya, the AI coach, to respond to your practicePerformance of contract
Compute your progress, Verified Skills, and Culture FingerprintPerformance of contract
Keep the Services secure, prevent fraud/abuse, maintain reliabilityLegitimate interests
Send transactional and (with consent where required) lifecycle emailConsent / legitimate interests
Comply with legal obligations (tax, accounting, legal requests)Legal obligation
Improve the ServicesLegitimate interests / consent

4. Diya, our AI coach — how AI is used

Diya is an AI-powered coach built on large language model technology (provided via our AI sub-processor). When you interact with Diya:

  • Your messages are processed to generate Diya's responses.
  • Diya is a supportive coaching tool. Diya is not a medical, psychological, legal, or financial professional, and does not provide professional advice or make decisions about you. See our Diya AI Disclaimer for full details.
  • Diya includes wellbeing safeguards: if you express serious distress, Diya responds with care and may surface crisis-support resources.

For Scope for Teams users: your Diya conversations are private and are never shared with your employer — see Section 9.


5. How we share information

We do not sell your personal information. We do not share it for cross-context behavioural advertising. We disclose personal data only:

  • To sub-processors / service providers who help us operate the Services, under contract and only as needed (see Section 8).
  • To your organisation (Scope for Teams only): strictly limited to the aggregate and outcome data described in Section 9 — never your private practice content.
  • For legal reasons: to comply with law, respond to lawful requests, enforce our terms, or protect rights, safety, and security.
  • In a business transfer: if we are involved in a merger, acquisition, or asset sale, subject to this policy.
  • With your consent: for any other disclosure.

6. Your private practice content — our core commitment

This is central to what Scope is. Your reps, reflections, journal notes, emotion selections, and Diya conversations are your private practice content. We treat this content with heightened protection:

  • It is not visible to your employer (Scope for Teams) — this is enforced in our system architecture, not merely promised as policy.
  • It is used to operate the Services for you (compute progress, power Diya, produce your own private insights) and is not disclosed except as strictly necessary to provide the Services or as required by law.

7. International data transfers

We are based in India, and our Services and data are hosted on cloud infrastructure located in the United States (Google Cloud / Firebase). If you access Scope from India, the EU/UK, or elsewhere, your personal data will be transferred to and processed in the United States and potentially other countries where our sub-processors operate.

  • For EU/UK users (GDPR): these transfers are made under appropriate safeguards, including Standard Contractual Clauses (SCCs).
  • For India users (DPDP): cross-border transfer is permitted subject to the DPDP Act and any government-notified restrictions.
  • By using the Services, you understand your data will be processed in these locations. Where consent is the basis, we obtain it as required.

8. Sub-processors and service providers

We use trusted third parties to operate the Services. Each processes data only as needed and under contract. Our current sub-processors include:

Sub-processorPurposeLocation
Google LLC (Firebase / Google Cloud)Hosting, database, authentication, cloud functionsUnited States
Anthropic, PBCAI (Diya coach)United States
Brevo (Sendinblue SAS)Transactional & lifecycle emailEU
Razorpay Software Pvt. Ltd.Payment processingIndia
Upstash, Inc.Rate limiting / cachingUnited States
Functional Software, Inc. (Sentry)Error monitoringUnited States
Vercel Inc.Web hosting / deliveryUnited States

We update this list as our sub-processors change and, for B2B customers, provide notice per the Data Processing Agreement.


9. Scope for Teams — the employer/employee relationship

When your organisation provides Scope to you, we act as a Data Processor on your employer's behalf. This section explains what your employer can and cannot see, and your protections.

What your employer CAN see:

  • Aggregate, team-level data: the team's Culture Fingerprint, aggregate progress (the "Climb Line" — headcounts, never individual names or pace), and aggregate insights.
  • Your verified outcomes: the Verified Skills you earn and their confidence level (not the underlying reflections) — because a verified credential is, by design, shareable proof.
  • Your participation status: that you are enrolled and engaging, at an aggregate level.

What your employer CAN NEVER see (enforced by our architecture):

  • Your individual reps, reflections, journal notes, and emotion/mood entries.
  • Your conversations with Diya.
  • Any wellbeing or distress signals.
  • Your individual daily activity or pace compared to teammates.

This boundary is not a setting that can be toggled — it is built into how the system stores and serves data. Scope is not a surveillance, performance-management, or automated-employment-decision tool.

Your rights in the B2B context: because your employer is the Controller, some requests (e.g. correction or deletion of employer-directed data) may be directed to or coordinated with your employer. However, your private practice content and your personal Evidence Pack remain protected as described, and you retain rights over your personal account and portable credentials (see Section 10 and our Data Ownership & Portability Terms).


10. Data ownership and portability — your Evidence Pack is yours

Scope is built so that the verified credentials you earn belong to you, not to any employer. Your Evidence Pack — your Culture Fingerprint and Verified Skills — is a personal, portable record.

  • If you leave an organisation that provided Scope, your employer loses access to your data, but you retain your personal account and Evidence Pack, which continues as your personal credential.
  • You control what you share from your Evidence Pack and with whom.
  • Full details are in our Data Ownership & Portability Terms.

11. Cookies and tracking

We use cookies and similar technologies for essential functionality, security, and analytics. You can control non-essential cookies as described in our Cookie Policy and via your browser settings.


12. Age of users

The Services are intended only for individuals aged 18 and older. We do not knowingly collect personal data from anyone under 18. If we learn we have collected data from a person under 18, we will delete it.


13. Data retention

We retain personal data for as long as your account is active and as needed to provide the Services, then for the period required to comply with legal, tax, and accounting obligations, resolve disputes, and enforce agreements.

  • Account and practice data (reps, reflections, journal notes, Diya conversations, verification data): retained while your account is active and for 12 months after account deletion or inactivity, except where a longer period is required by law.
  • Financial and transaction records: retained for approximately 8 years in accordance with Indian tax and company-law requirements (including the Income Tax Act and Companies Act). This longer period reflects mandatory statutory retention obligations, not a general data-retention preference.
  • Support communications: retained for 24 months.

For B2B, retention, return, and deletion on contract termination are governed by the Data Processing Agreement.


14. Security

We implement technical and organisational measures to protect personal data, including encryption in transit and at rest, access controls, authentication, and the architectural privacy boundaries described above. No system is perfectly secure, but we work to protect your data and to notify you and relevant authorities of breaches as required by law (including DPDP breach-notification duties and, for EU users, GDPR's 72-hour notification requirement).


15. Your rights

Depending on where you live, you have rights over your personal data:

Under India's DPDP Act: access, correction, completion, updating, and erasure of your data; grievance redressal; nomination. Contact us at support@growyourscope.com.

Under GDPR (EU/UK): access, rectification, erasure, restriction, portability, objection, and rights regarding automated decision-making. You may withdraw consent at any time and lodge a complaint with your supervisory authority.

Under CCPA/CPRA (California): the right to know, delete, correct, and opt out of "sale"/"sharing" (we do not sell or share for cross-context advertising), and the right to non-discrimination for exercising your rights.

Grievance Officer / Data Protection Contact: In accordance with the DPDP Act, 2023, you may address data-protection grievances to Gaurav Sharma, Founder, Diyako Tech Innovations Pvt. Ltd., at support@growyourscope.com. We will acknowledge and respond within the period prescribed under applicable law.

To exercise any right, contact support@growyourscope.com or use our Data Rights page. We will respond within the timeframes required by applicable law. For B2B users, see Section 9 regarding requests routed through your employer.


16. Changes to this policy

We may update this policy. We will post the updated version with a new "last updated" date and, for material changes, provide additional notice as required.


17. Contact us

Diyako Tech Innovations Pvt. Ltd. Email: support@growyourscope.com Governing law and jurisdiction: Rajasthan, India (for contractual matters — see applicable Terms).