Legal · Privacy
What we hold, why we hold it, and how to make us stop.
NicheScout reads publicly-posted reviews, forum threads and job postings on your instruction and turns them into scored signals. That means we store text other people wrote. This page explains exactly what that means, for you and for them.
- Effective
- Sep 1, 2026
- Last updated
- Sep 1, 2026
- Status
- Unreviewed draft
01Clause
Who this covers
This policy covers the NicheScout web application and marketing site. It describes two different relationships, and they are governed by different rules:
- Customers — people who create an account, run trackers and pay us. We are the controller of your account and workspace data.
- Authors of the content we retrieve — people who posted a review, comment or job listing on a public platform that one of our customers chose to track. We are also a controller of that text, because we decide the purpose (signal analysis) and the means. See clause 3.
“NicheScout”, “we” and “us” refer to the operator of NicheScout. Reach us at privacy@nichescout.app.
Not yet appointed
02Clause
What we collect
Account data
Your email address, and — if you sign in with Google — the display name and avatar URL Google returns. Passwords are handled by Supabase Auth and stored as salted hashes; we never see or store the plaintext. We record when you signed up and when you were last active.
Workspace content you create
Workspace names and niche descriptions, tracker configuration (which app, subreddit, category or search query you point at), notes you write, and the ideas and competitor entries generated from your signals.
Retrieved source content
For every tracker you arm, we store the items it returns. For each item that is: the title and body text, the author’s public display name or handle as published, a star rating where one exists, the post timestamp, the URL of the original, a detected language, the source platform, and the raw API or search response we received. We do not attempt to resolve a display name to a real identity, an email address, or a profile on another platform.
Billing data
Stripe processes payments. We store your Stripe customer id, subscription status, plan tier and billing period — never a card number, CVC or bank detail. Those never touch our servers; the card is entered on Stripe’s own checkout page.
Technical and usage data
Server logs (IP address, user agent, request path, timestamp, response status) generated by our hosting provider, and metered usage counters — how many trackers are active and how many AI analysis runs you have consumed this billing period — which we need to enforce plan limits. Product analytics are optional and off unless configured; see clause 12.
03Clause
Third-party review and forum text
This is the part of NicheScout that needs the most careful explanation, so we are stating it plainly rather than burying it.
When a customer arms a tracker, we retrieve items from public sources — App Store and Play Store reviews, Reddit threads, G2 and Capterra reviews, Product Hunt listings and comments, Upwork job postings — and store them so they can be clustered into signals and cited as evidence. Those items routinely include the author’s public display name or handle. That makes them personal data under the GDPR and UK GDPR, even though they were posted publicly.
Our legal basis
We rely on legitimate interests — Article 6(1)(f). The interest is our customers’ and our own interest in understanding what users of a product category are actually saying, in order to build and improve software. Our balancing assessment, in short:
- The content was deliberately published to a public audience by its author, on a platform whose terms contemplate public reading and quotation.
- We store the minimum that makes a signal verifiable: the text, the handle as published, the rating, the date and a link back. We do not enrich, de-anonymise, or link an author across platforms.
- We do not build profiles of individuals and we do not target individuals. Analysis is aggregate: a signal is a cluster of many posts, and the individual is never the unit of interest.
- Retrieved content is visible only inside the workspace that configured the tracker. It is not public, not indexed, not sold, and not shared between customers.
- We honour objection and erasure requests from authors without requiring them to justify the request. See clause 10.
Why we do not notify each author
Article 14(5)(b) relieves a controller of the duty to notify data subjects where doing so would involve disproportionate effort. Items arrive at volume, most carry no contact address, and messaging every reviewer would be both impracticable and more intrusive than the processing itself. This public page, together with the removal route in clause 10, is the safeguard we offer in place of individual notice.
Special categories
04Clause
Legal bases
- Account, workspaces, trackers
- Performance of a contract (Art. 6(1)(b)) — we cannot provide the product without them.
- Payments and invoices
- Contract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c)) for tax and accounting records.
- Retrieved review and forum text
- Legitimate interests (Art. 6(1)(f)) — assessed in clause 3.
- Security logs and abuse prevention
- Legitimate interests (Art. 6(1)(f)) — keeping the service available and unabused.
- Transactional email
- Contract (Art. 6(1)(b)) — password resets, receipts, digests you enabled.
- Product analytics and marketing email
- Consent (Art. 6(1)(a)) where required, withdrawable at any time.
05Clause
How we use it
- Running the product: polling your trackers, storing what they return, clustering items into signals, generating ideas and competitor entries.
- Enforcing plan limits: counting active trackers and analysis runs against your tier.
- Billing: creating and reconciling Stripe subscriptions.
- Transactional email: sign-in links, password resets, receipts, and the digests you turn on.
- Keeping the service up and honest: error diagnosis, abuse detection, capacity planning.
We do not sell personal data. We do not share it with advertisers. We do not use your workspace content, or the source content in it, to build features for other customers.
06Clause
AI processing
Signal extraction and idea generation are performed by Anthropic’s Claude models. Retrieved item text — including the author display name where it appears inside the excerpt — is sent to Anthropic’s API for that analysis, along with your workspace’s niche description.
- Anthropic acts as our processor under a data processing agreement, and under its commercial terms does not use API inputs or outputs to train its models.
- Model output is stored as signals and ideas in your workspace.
- No automated decision with a legal or similarly significant effect on an individual is made. Signals score topics, not people.
AI output is probabilistic. Clustering can mis-group an item and a summary can be wrong. Every signal links to the underlying excerpts so you can check it, and you should.
07Clause
Subprocessors
These are the third parties that process data on our behalf. We will post material changes to this list here before they take effect.
| Subprocessor | Purpose | Data it sees | Where |
|---|---|---|---|
| Supabase | Database, authentication, storage | All account and workspace data, including retrieved source content | United States |
| Vercel | Application hosting and edge network | Request metadata, server logs, IP addresses | United States / global edge |
| Stripe | Payments and subscription billing | Email, billing address, card data (entered directly with Stripe) | United States |
| Anthropic | AI signal extraction and idea generation | Retrieved item text and niche descriptions | United States |
| SerpAPI | Retrieval of App Store, Play Store, G2 and Capterra results | Search queries derived from your tracker configuration | United States |
| Resend | Transactional email delivery | Email address, message content | United States / EU |
| Google Analytics | Product analytics — only if the deployment sets a measurement id | Pseudonymous usage events, truncated IP | United States |
| Google (Sign-In) | Optional OAuth sign-in | Email, name, avatar URL, only if you choose Google | United States |
| Product Hunt | Retrieval of Product Hunt listings and comments | API queries derived from your tracker configuration | United States |
Reddit, the App Store, Google Play, G2, Capterra and Upwork are sources, not subprocessors: we read from them, we do not send them your data beyond the query needed to retrieve results.
08Clause
Retention
We keep things for as long as they are useful for the purpose we collected them for, and no longer. Concretely:
- Retrieved source items
- For as long as the tracker that collected them exists. Deleting a tracker deletes its items immediately and irreversibly; deleting a workspace deletes everything in it. We additionally purge items older than 24 months, since a signal built on three-year-old reviews is not evidence of anything current.
- Signals, ideas and notes
- For the life of the workspace. Deleted with it. Free-plan signal history is limited to 30 days as a product limit, not a retention promise.
- Account and profile
- Until you delete your account, then removed from live systems within 30 days and from encrypted backups within a further 35 days.
- Billing records
- Invoices and payment records retained for 7 years to meet tax and accounting obligations, even after account deletion. This is a legal obligation and survives an erasure request.
- Usage counters
- 24 months, so that disputes about metered limits can be resolved.
- Server and application logs
- 30 days, then rotated out.
- Support correspondence
- 24 months from the last message in the thread.
09Clause
Your rights
If the GDPR or UK GDPR applies to you, you have the right to access, rectify, erase, restrict processing of, and port your personal data, and to object to processing based on legitimate interests. You may withdraw consent at any time where we rely on it, and you may complain to your supervisory authority.
If you are a California resident, you have the right to know, delete and correct, and to opt out of sale or sharing. We do not sell or share personal information as those terms are defined in the CCPA/CPRA and we do not use it for cross-context behavioural advertising.
Email privacy@nichescout.app to exercise any of these. We respond within 30 days. We will ask you to verify control of the account email; we will not ask for a copy of your ID.
10Clause
If your post appears here
You did not sign up for NicheScout and you are entitled to have your content removed from it. You do not need to give a reason and you do not need a lawyer.
Email privacy@nichescout.app with the URL of the original post, or the platform and display name you posted under. We will:
- Acknowledge within 5 business days.
- Locate and delete every stored copy of the item, across every customer workspace that retrieved it, within 30 days.
- Add a suppression record keyed to the source URL so re-polling cannot re-ingest it.
- Remove the excerpt from any signal that cited it, and re-score that signal without it.
- Confirm to you in writing when it is done.
11Clause
International transfers
Our infrastructure and every subprocessor listed in clause 7 operate in or route through the United States. Where personal data of people in the EEA or UK is transferred there, we rely on the European Commission’s Standard Contractual Clauses, the UK Addendum, and where applicable the subprocessor’s certification under the EU-US Data Privacy Framework. Copies of the relevant terms are available on request.
13Clause
Security
Row-level security in Postgres scopes every read to the workspaces you belong to; the service-role key never reaches a browser; traffic is TLS-only. The full description, including what we have not done yet, is on the security page.
If we suffer a breach affecting your personal data, we will notify the relevant supervisory authority within 72 hours of becoming aware, and notify you without undue delay where the risk to you is high.
14Clause
Children
NicheScout is a business tool and is not directed at children. You must be at least 16 to create an account. We do not knowingly collect data from children; if you believe a child has an account, tell us and we will delete it.
15Clause
Changes and contact
We will post any change here and update the “last updated” date above. Material changes — a new purpose, a new subprocessor category — will be emailed to account holders at least 14 days before they take effect.
Privacy questions and requests: privacy@nichescout.app. Everything else: hello@nichescout.app.