Skip to content

Legal · Privacy

What we hold, why we hold it, and how to make us stop.

NicheScout reads publicly-posted reviews, forum threads and job postings on your instruction and turns them into scored signals. That means we store text other people wrote. This page explains exactly what that means, for you and for them.

Effective
Sep 1, 2026
Last updated
Sep 1, 2026
Status
Unreviewed draft

01Clause

Who this covers

This policy covers the NicheScout web application and marketing site. It describes two different relationships, and they are governed by different rules:

  • Customers — people who create an account, run trackers and pay us. We are the controller of your account and workspace data.
  • Authors of the content we retrieve — people who posted a review, comment or job listing on a public platform that one of our customers chose to track. We are also a controller of that text, because we decide the purpose (signal analysis) and the means. See clause 3.

“NicheScout”, “we” and “us” refer to the operator of NicheScout. Reach us at privacy@nichescout.app.

Not yet appointed

This draft does not name a legal entity, a registered address, an EU or UK representative under Article 27, or a data protection officer. Those must be filled in before launch, and the answer to whether an Article 27 representative is required depends on where the operating entity is established.

02Clause

What we collect

Account data

Your email address, and — if you sign in with Google — the display name and avatar URL Google returns. Passwords are handled by Supabase Auth and stored as salted hashes; we never see or store the plaintext. We record when you signed up and when you were last active.

Workspace content you create

Workspace names and niche descriptions, tracker configuration (which app, subreddit, category or search query you point at), notes you write, and the ideas and competitor entries generated from your signals.

Retrieved source content

For every tracker you arm, we store the items it returns. For each item that is: the title and body text, the author’s public display name or handle as published, a star rating where one exists, the post timestamp, the URL of the original, a detected language, the source platform, and the raw API or search response we received. We do not attempt to resolve a display name to a real identity, an email address, or a profile on another platform.

Billing data

Stripe processes payments. We store your Stripe customer id, subscription status, plan tier and billing period — never a card number, CVC or bank detail. Those never touch our servers; the card is entered on Stripe’s own checkout page.

Technical and usage data

Server logs (IP address, user agent, request path, timestamp, response status) generated by our hosting provider, and metered usage counters — how many trackers are active and how many AI analysis runs you have consumed this billing period — which we need to enforce plan limits. Product analytics are optional and off unless configured; see clause 12.

03Clause

Third-party review and forum text

This is the part of NicheScout that needs the most careful explanation, so we are stating it plainly rather than burying it.

When a customer arms a tracker, we retrieve items from public sources — App Store and Play Store reviews, Reddit threads, G2 and Capterra reviews, Product Hunt listings and comments, Upwork job postings — and store them so they can be clustered into signals and cited as evidence. Those items routinely include the author’s public display name or handle. That makes them personal data under the GDPR and UK GDPR, even though they were posted publicly.

Our legal basis

We rely on legitimate interests — Article 6(1)(f). The interest is our customers’ and our own interest in understanding what users of a product category are actually saying, in order to build and improve software. Our balancing assessment, in short:

  • The content was deliberately published to a public audience by its author, on a platform whose terms contemplate public reading and quotation.
  • We store the minimum that makes a signal verifiable: the text, the handle as published, the rating, the date and a link back. We do not enrich, de-anonymise, or link an author across platforms.
  • We do not build profiles of individuals and we do not target individuals. Analysis is aggregate: a signal is a cluster of many posts, and the individual is never the unit of interest.
  • Retrieved content is visible only inside the workspace that configured the tracker. It is not public, not indexed, not sold, and not shared between customers.
  • We honour objection and erasure requests from authors without requiring them to justify the request. See clause 10.

Why we do not notify each author

Article 14(5)(b) relieves a controller of the duty to notify data subjects where doing so would involve disproportionate effort. Items arrive at volume, most carry no contact address, and messaging every reviewer would be both impracticable and more intrusive than the processing itself. This public page, together with the removal route in clause 10, is the safeguard we offer in place of individual notice.

Special categories

We do not knowingly process special-category data (Article 9) and do not target sources likely to contain it. Reviews occasionally disclose health or belief information incidentally. If you find such content in NicheScout, tell us at privacy@nichescout.app and we will remove it. A qualified lawyer should review whether the current source mix requires a formal Data Protection Impact Assessment; our own view is that it likely does.

04Clause

Legal bases

Account, workspaces, trackers
Performance of a contract (Art. 6(1)(b)) — we cannot provide the product without them.
Payments and invoices
Contract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c)) for tax and accounting records.
Retrieved review and forum text
Legitimate interests (Art. 6(1)(f)) — assessed in clause 3.
Security logs and abuse prevention
Legitimate interests (Art. 6(1)(f)) — keeping the service available and unabused.
Transactional email
Contract (Art. 6(1)(b)) — password resets, receipts, digests you enabled.
Product analytics and marketing email
Consent (Art. 6(1)(a)) where required, withdrawable at any time.

05Clause

How we use it

  • Running the product: polling your trackers, storing what they return, clustering items into signals, generating ideas and competitor entries.
  • Enforcing plan limits: counting active trackers and analysis runs against your tier.
  • Billing: creating and reconciling Stripe subscriptions.
  • Transactional email: sign-in links, password resets, receipts, and the digests you turn on.
  • Keeping the service up and honest: error diagnosis, abuse detection, capacity planning.

We do not sell personal data. We do not share it with advertisers. We do not use your workspace content, or the source content in it, to build features for other customers.

06Clause

AI processing

Signal extraction and idea generation are performed by Anthropic’s Claude models. Retrieved item text — including the author display name where it appears inside the excerpt — is sent to Anthropic’s API for that analysis, along with your workspace’s niche description.

  • Anthropic acts as our processor under a data processing agreement, and under its commercial terms does not use API inputs or outputs to train its models.
  • Model output is stored as signals and ideas in your workspace.
  • No automated decision with a legal or similarly significant effect on an individual is made. Signals score topics, not people.

AI output is probabilistic. Clustering can mis-group an item and a summary can be wrong. Every signal links to the underlying excerpts so you can check it, and you should.

07Clause

Subprocessors

These are the third parties that process data on our behalf. We will post material changes to this list here before they take effect.

NicheScout subprocessors
SubprocessorPurposeData it seesWhere
SupabaseDatabase, authentication, storageAll account and workspace data, including retrieved source contentUnited States
VercelApplication hosting and edge networkRequest metadata, server logs, IP addressesUnited States / global edge
StripePayments and subscription billingEmail, billing address, card data (entered directly with Stripe)United States
AnthropicAI signal extraction and idea generationRetrieved item text and niche descriptionsUnited States
SerpAPIRetrieval of App Store, Play Store, G2 and Capterra resultsSearch queries derived from your tracker configurationUnited States
ResendTransactional email deliveryEmail address, message contentUnited States / EU
Google AnalyticsProduct analytics — only if the deployment sets a measurement idPseudonymous usage events, truncated IPUnited States
Google (Sign-In)Optional OAuth sign-inEmail, name, avatar URL, only if you choose GoogleUnited States
Product HuntRetrieval of Product Hunt listings and commentsAPI queries derived from your tracker configurationUnited States

Reddit, the App Store, Google Play, G2, Capterra and Upwork are sources, not subprocessors: we read from them, we do not send them your data beyond the query needed to retrieve results.

08Clause

Retention

We keep things for as long as they are useful for the purpose we collected them for, and no longer. Concretely:

Retrieved source items
For as long as the tracker that collected them exists. Deleting a tracker deletes its items immediately and irreversibly; deleting a workspace deletes everything in it. We additionally purge items older than 24 months, since a signal built on three-year-old reviews is not evidence of anything current.
Signals, ideas and notes
For the life of the workspace. Deleted with it. Free-plan signal history is limited to 30 days as a product limit, not a retention promise.
Account and profile
Until you delete your account, then removed from live systems within 30 days and from encrypted backups within a further 35 days.
Billing records
Invoices and payment records retained for 7 years to meet tax and accounting obligations, even after account deletion. This is a legal obligation and survives an erasure request.
Usage counters
24 months, so that disputes about metered limits can be resolved.
Server and application logs
30 days, then rotated out.
Support correspondence
24 months from the last message in the thread.

09Clause

Your rights

If the GDPR or UK GDPR applies to you, you have the right to access, rectify, erase, restrict processing of, and port your personal data, and to object to processing based on legitimate interests. You may withdraw consent at any time where we rely on it, and you may complain to your supervisory authority.

If you are a California resident, you have the right to know, delete and correct, and to opt out of sale or sharing. We do not sell or share personal information as those terms are defined in the CCPA/CPRA and we do not use it for cross-context behavioural advertising.

Email privacy@nichescout.app to exercise any of these. We respond within 30 days. We will ask you to verify control of the account email; we will not ask for a copy of your ID.

10Clause

If your post appears here

You did not sign up for NicheScout and you are entitled to have your content removed from it. You do not need to give a reason and you do not need a lawyer.

Email privacy@nichescout.app with the URL of the original post, or the platform and display name you posted under. We will:

  • Acknowledge within 5 business days.
  • Locate and delete every stored copy of the item, across every customer workspace that retrieved it, within 30 days.
  • Add a suppression record keyed to the source URL so re-polling cannot re-ingest it.
  • Remove the excerpt from any signal that cited it, and re-score that signal without it.
  • Confirm to you in writing when it is done.

11Clause

International transfers

Our infrastructure and every subprocessor listed in clause 7 operate in or route through the United States. Where personal data of people in the EEA or UK is transferred there, we rely on the European Commission’s Standard Contractual Clauses, the UK Addendum, and where applicable the subprocessor’s certification under the EU-US Data Privacy Framework. Copies of the relevant terms are available on request.

12Clause

Cookies and analytics

NicheScout sets a small number of cookies. The only ones that are always present are the Supabase authentication cookies, without which you cannot stay signed in. Analytics are loaded only if the deployment is configured with a Google Analytics measurement id, and the loader honours your browser’s Do Not Track setting.

The full inventory — names, purposes and lifetimes — is on the cookies page.

13Clause

Security

Row-level security in Postgres scopes every read to the workspaces you belong to; the service-role key never reaches a browser; traffic is TLS-only. The full description, including what we have not done yet, is on the security page.

If we suffer a breach affecting your personal data, we will notify the relevant supervisory authority within 72 hours of becoming aware, and notify you without undue delay where the risk to you is high.

14Clause

Children

NicheScout is a business tool and is not directed at children. You must be at least 16 to create an account. We do not knowingly collect data from children; if you believe a child has an account, tell us and we will delete it.

15Clause

Changes and contact

We will post any change here and update the “last updated” date above. Material changes — a new purpose, a new subprocessor category — will be emailed to account holders at least 14 days before they take effect.

Privacy questions and requests: privacy@nichescout.app. Everything else: hello@nichescout.app.