SCOPRIX
← SCOPRIX

Privacy Policy

Last updated 2026-07-09.

Scoprix Labs LLC ("Scoprix", "we", "us") takes the data you trust us with seriously. This policy describes what we collect and how we use it. 1. What we collect. - Account info: email, password (hashed by our authentication provider, Supabase), company name, role (GC vs vendor). - Profile info you choose to share: trades, service area, license numbers, COI expiration, public contact info. - Project data you create or upload: project records, plan sets, quotes, estimates, takeoffs and takeoff reviews, schedule events, labor/cost reports, activity, action items. - Forwarded email: messages you (or your team) send to your organization's Scoprix inbox address are parsed and stored inside your organization, including attachments. - Billing: subscriptions and payments are processed by Stripe. We store your plan, seat count, and subscription status — we never see or store full card numbers. - Activity logs: who accessed what within your organization, used for security auditing. - Standard server logs and error reports: IP, user agent, request paths; application errors are captured by our monitoring provider with request metadata. 2. What we don't collect. - We do not run third-party advertising trackers or cross-site tracking cookies. We use privacy-friendly, cookieless web analytics (Vercel) that measures aggregate page views and coarse geography (country/region) without profiling you across other sites; sign-in cookies are limited to what authentication requires. - We do not sell or rent your contact info to data brokers. - We do not share project-level data with anyone outside your organization without an explicit grant (an accepted invitation, or an approved vendor claim). 3. How aggregation works. - Line-item pricing extracted from quotes feeds an anonymized aggregate dataset that powers market-rate features. Accepted prices also feed internal accuracy measurement, which calibrates our estimate models over time under the same safeguards. - Aggregates are exposed only when at least 5 records from at least 3 distinct vendors are present (minimum bucket size). - Aggregates are time-lagged by at least 30 days. We do not surface "what is vendor X bidding right now." - Individual vendor identities are never surfaced through the aggregate API. - You can opt out of contributing to aggregates by emailing admin@scoprix.ai. 4. Cross-organization sharing. - When you (a GC) upload a quote attributed to a vendor, that quote becomes visible to the vendor IF they later sign up and have their claim approved by you. - When you (a GC) invite a vendor org to bid on a project, the invited org sees only the project context you scoped them to — not other vendors' bids on the same project, and not your internal markup or notes. - Activity ledger entries are tagged with a visibility level (internal / all_invited / field_only) and the platform enforces who can read which. 5. Email. - We send transactional email (claim approvals, invitations, bid receipts, digests you can turn off in Settings) via Resend, on the send.scoprix.ai subdomain. Replies reach admin@scoprix.ai. - Marketing email, if we ever send it, will carry a one-click unsubscribe. 6. Data retention and backups. - Account data: kept for as long as your account is active. - Encrypted database backups are stored off-site (Cloudflare R2) for disaster recovery and cycle out on a rolling schedule. - On account deletion: account-identifying data is removed within 30 days (backup copies cycle out on the backup schedule). Aggregated, anonymized derivatives may persist if they can no longer be tied back to you. - Audit logs: retained for 12 months after last activity. 7. Your rights. - Export: email admin@scoprix.ai for a zip of your data. - Deletion: same email, with subject "Delete account". - Correction: edit your profile in-app, or email us. - We respond to verifiable rights requests within the timeframes the applicable law requires (45 days under the CCPA/CPRA, extendable once as permitted). - California residents (CCPA/CPRA). You have the right to know the categories and specific pieces of personal information we collect (see section 1), the purposes we use it for (operating and improving the service), and the categories of subprocessors we share it with (section 8); to delete it; to correct it; and to opt out of "sale" or "sharing." We do NOT sell your personal information and we do not "share" it for cross-context behavioral advertising. To the extent any information you provide is "sensitive personal information," we use it only to provide the service and do not use it for inferring characteristics. We will not discriminate against you for exercising these rights. Exercise any right by emailing admin@scoprix.ai. - EU/UK residents: you have the analogous rights under the GDPR/UK GDPR (access, rectification, erasure, restriction, portability, objection). 8. Subprocessors. - Supabase (authentication + database + file storage) - Vercel (web hosting + privacy-friendly, cookieless web analytics) - Vultr (document-processing API compute) - Stripe (payments) - Resend (transactional email) - Anthropic (Claude API for document parsing + AI features) - Sentry (error monitoring) - Cloudflare (encrypted off-site backups) Documents sent to our AI provider are used to perform the task you requested and are not used to train third-party models. 9. Security. We protect your data with encryption in transit (TLS) and at rest, row-level access controls that scope data to your organization, hashed credentials, per-request audit logging, and least-privilege access to production systems. No system is perfectly secure, but we design for defense in depth. 10. Data location and transfers. Scoprix operates in the United States and our subprocessors process data in the United States. If we expand to serve users in other regions, we will put appropriate transfer safeguards (such as Standard Contractual Clauses) in place. 11. Children. Scoprix is not directed at children under 13 and does not knowingly collect data from them. 12. Changes. We will email you and post in-app when we make a material change, and update the "last updated" date above. Continued use after the change constitutes acceptance. Questions or requests: admin@scoprix.ai.