Privacy Policy
Version date: 30 August 2026
1. Who we are
ScoutCo operates the platforms available at earshots.io, trackscout.io, mixscout.io, cutscout.io, filescout.io, scoutco.io and podlook.io (together, "the Service"). Each of these, including Podlook, is a product of ScoutCo. References to "ScoutCo", "we", "us", or "our" in this policy mean ScoutCo as the operator of the Service.
We operate cloud-based review and approval platforms designed for use by audio, video and podcast professionals — post-production teams, music supervisors, sound houses, podcast producers — and their clients. Data controller contact details are available on request.
If you have any questions about this policy or how we handle your data, contact us at: info@scoutco.io
2. Scope
This policy applies to all personal data processed through the Service, including data provided by organisations (B2B clients) and their end users (reviewers, composers, music supervisors, editors, podcast hosts and guests, and other collaborators).
We act as:
- Data Controller — in respect of account holders and billing contacts
- Data Processor — in respect of personal data uploaded or generated by our clients within projects (e.g. end-user email addresses, comments, transcripts, and audio/video content)
3. What data we collect
3.1 Account and identity data
- Name and email address
- Company name and role (optional but encouraged)
- Password (stored as a hashed value — never in plain text)
- Billing information (processed by our payment provider; we do not store card details)
3.2 Project and usage data
- Audio, video and podcast files uploaded to projects
- Transcripts, translations, AI-generated summaries and clip suggestions derived from uploaded content at your instruction
- Timestamped comments, playback annotations, and approval records
- Share link activity (access events, IP addresses, timestamps)
- Platform usage data (pages visited, features used, session duration)
3.3 Technical data
- IP address and approximate geolocation
- Browser type and version
- Device type and operating system
- Cookies and session tokens (see Section 9)
3.4 Communications
- Support requests and correspondence
- Survey responses or feedback you choose to submit
4. Legal basis for processing
We process personal data on the following legal bases under UK GDPR:
- Contract performance — to provide the Service to account holders
- Legitimate interests — for platform security, fraud prevention, and product improvement
- Legal obligation — to comply with applicable law (e.g. tax records, law enforcement requests)
- Consent — for non-essential cookies and marketing communications, where opt-in consent is obtained
5. How we use your data
- To create and manage your account
- To deliver the platform's core features (file storage, review, sharing, comments, approvals)
- To provide the content features you invoke — transcription, translation, AI summaries and clip suggestions
- To send transactional emails (account activation, password reset, share link notifications)
- To investigate and resolve support issues
- To monitor platform security and detect abuse
- To improve the product through aggregated, anonymised analytics
- To comply with our legal obligations
We do not use your data to train AI or machine learning models, and we do not sell your data to third parties. Where you invoke AI-assisted features, the relevant content is sent to the service providers listed in Section 8 solely to perform that operation and return the result; those providers are contractually restricted from using it to train their models. Voice dictation for comments is processed entirely in your browser — that audio never reaches our servers.
6. Storage and infrastructure
Files uploaded to the Service (audio, video, and project data) are stored using Amazon Web Services S3 object storage, with data held in AWS US-East regions and mirrored to Cloudflare R2 object storage for delivery. Database records (accounts, project metadata, comments, transcripts) are stored in Supabase, hosted on infrastructure within the European Economic Area. Each product line runs in its own isolated database — Podlook data is held separately from the other products' data.
We have selected these providers specifically for their data residency controls and security posture.
7. Access controls and internal data handling
Access to client project data is strictly limited. The following controls are in place:
- Founders and employees of ScoutCo do not have routine access to client project content
- Database-level access is restricted to the Chief Technology Officer for operational purposes only
- Access events at infrastructure level are logged and auditable
- No client project data is shared between competing client accounts
We take our position as a platform used by competing commercial entities seriously. Our access controls are designed to ensure that no commercially sensitive information — including client lists, project timings, or creative content — is accessible to platform operators in the ordinary course of business.
8. Data sharing
We share personal data only with:
- Infrastructure providers acting as processors on our behalf: Amazon Web Services (storage, media processing, transcription, translation), Cloudflare (hosting, delivery, email routing), Supabase (databases and authentication), Resend (transactional email), and Netlify (legacy hosting, being decommissioned)
- AI service providers acting on your instruction: Anthropic (summaries and clip suggestions) and AssemblyAI (transcription) — in each case solely to perform the requested operation, with no use of your content for model training
- Error-monitoring services (Sentry) — technical event data only, not project content
- Payment processors (e.g. Stripe) for billing purposes
- Professional advisors (legal, accountancy) bound by confidentiality obligations
- Law enforcement or regulatory bodies when required by law
We do not share client data with other clients, third-party advertisers, or data brokers.
9. Cookies
We use strictly necessary cookies to maintain your session and authenticate your account. We do not use third-party advertising cookies.
Analytics cookies (where used) are first-party and anonymised. You will be presented with a cookie preference banner on first visit and can update your preferences at any time via your account settings.
10. Data retention
- Active account data is retained for the duration of your subscription plus 12 months
- Deleted project files are removed within 30 days of deletion
- File Share links expire automatically (currently 8 days), after which their files are scheduled for removal
- Billing records are retained for 7 years as required by HMRC
- Support correspondence is retained for 3 years
- Server logs are retained for 90 days
11. Your rights
Under UK GDPR, you have the right to:
- Access — request a copy of the personal data we hold about you
- Rectification — correct inaccurate or incomplete data
- Erasure — request deletion of your data (subject to legal retention obligations)
- Restriction — ask us to pause processing in certain circumstances
- Portability — receive your data in a machine-readable format
- Object — to processing based on legitimate interests
- Withdraw consent — where processing is consent-based
To exercise any of these rights, email info@scoutco.io. We will respond within one calendar month. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
12. International transfers
Where data is transferred outside the UK or EEA (including file storage and certain processing in the United States), we ensure appropriate safeguards are in place, including Standard Contractual Clauses or reliance on adequacy decisions where applicable.
13. Changes to this policy
We may update this policy from time to time. Material changes will be notified by email to account holders at least 14 days before they take effect. Continued use of the platform following notification constitutes acceptance.
14. Contact
ScoutCo
Email: info@scoutco.io
Website: earshots.io