ScopeDiff

Privacy Policy

What we collect, what we deliberately don't, and how to get it deleted.

Last updated August 5, 2026

ScopeDiff is operated by Khiem Lu, a sole proprietor in California, doing business as ScopeDiff (“we”, “us”). This policy covers scopediff.com and the ScopeDiff application.

The short version.We never keep the agreement you upload — it is read once to build your scope record, then dropped. We run no analytics and set no tracking cookies. The only thing we hold about your client is a name they choose to type. We don’t sell or share personal information.

Three parties, because it matters here

Most privacy policies describe two parties. ScopeDiff has three, and the middle one is why this policy is shaped the way it is:

  • Us— ScopeDiff, the service.
  • You— the account holder. Typically a software or design studio doing fixed-bid client work.
  • Your client— the person you share a record with. They have no account and never sign up. When you put their name or their commercial terms into a record, you decide what goes in and you remain responsible for it. For that information we act on your instructions, not our own.

What we collect

Account information

  • Your email address, and your GitHub username if you sign in with GitHub. Authentication is handled by Supabase Auth.
  • Your plan, subscription status, and the identifiers Stripe uses for your customer and subscription records.
  • An agency logo and accent color, if you upload them.

Content you put into a scope record

  • Project and client names, descriptions, deliverables, phases, milestones, acceptance criteria, estimates, scope boundaries, and any contract or milestone amounts you enter.
  • The structured record produced when we parse an agreement you upload. The agreement itself is not kept — see below.

Information from your client

Exactly one thing: a name they type, if they choose to mark a version as reviewed. It is optional, and they can leave it blank. We do not log who opens a shared record, we do not record their IP address or browser, and we set no cookie on the shared view.

GitHub activity, if you connect a repository

When you connect a repository, we read only pull request titles and descriptions, commit subject lines, and the GitHub usernames attached to them, for the branch and time window of the scan.

We do not read your code. No file contents, no diffs, no patches, no issues, no private repository data beyond the metadata just listed.

One thing worth stating plainly, because you can check it and we would rather you heard it from us: the GitHub permission we request (“repo”) is broader than what we use. GitHub’s classic OAuth scopes have no read-only option for private repositories — the narrowest scope that lets us read a private repo’s commit list is the same one that would allow writes. We do not write. Moving to a GitHub App with fine-grained permissions is the proper fix and is on our list. You can revoke access at any time from your GitHub settings.

Technical information

Our hosting provider records standard server logs (request paths, status codes, timing, and IP addresses) for reliability and abuse prevention. We also record a row each time you run an AI parse or a weekly upkeep pass — who ran it, when, and which project — so we can enforce fair-use limits. Neither contains the content of your documents.

The agreement you upload is not stored

When you import a signed SOW, contract, or proposal, the file is read once in memory to extract your deliverables, then discarded. It is not written to our storage. Only the structured scope record it produces is saved to your account.

Being precise about the boundary, because a vaguer claim would be a worse one: to read the document at all, its text is transmitted to our server and to Anthropic’s API (see sub-processors below). Our application code deliberately avoids writing document text into error logs. What we mean by “not stored” is that no copy of your file is retained after the parse completes.

While an import is in progress, the extracted result is held against your draft so a refreshed browser tab doesn’t lose a parse that took minutes. It is cleared when you publish a version or dismiss the import notice. If you start an import and abandon it without doing either, that extracted result stays with your draft until you delete the project or ask us to remove it.

How we use AI

We use Anthropic’s Claude models, via Anthropic’s API, to read an uploaded agreement into a structured record and to turn your notes or repository activity into proposed status updates.

Anthropic does not train its models on data submitted through its API.That is Anthropic’s commitment, and we are passing it along rather than making it in our own voice. Anthropic may retain API inputs for a limited period for safety and abuse monitoring under its own terms.

AI output can be wrong. A parsed record may miss, misstate, or invent detail, and it is your job to review it before you publish it to a client. See the Terms for what that means contractually.

Shared records and links

Publishing a version makes it readable at a long, randomly generated URL. There is no password and no sign-in: anyone holding that link can read the published record. You choose who receives it.

We tell search engines not to index these pages and instruct browsers not to leak the link in referrer headers. Those measures stop a link being found by accident; they cannot un-share a link that has been forwarded.

Links cannot currently be revoked or expired.If a link has reached someone it shouldn’t have, the only remedy today is deleting the project, which permanently destroys the record and every published version of it. We say the same thing on our security page, and we are not going to pretend it is a smaller limitation than it is.

Drafts are never visible to anyone but you.

Cookies and tracking

We run no analytics.No Google Analytics, no advertising pixels, no session recording, no third-party scripts of any kind — on the marketing site or in the app.

The only cookies we set are strictly necessary:

  • An authentication cookie that keeps you signed in.
  • A cookie recording that you entered the pre-launch site password, while that gate is in place.

Because there is nothing to consent to, there is no cookie banner. If that ever changes, this section changes with it.

Do Not Track

We do not track visitors across third-party websites, so there is nothing for a Do Not Track signal to switch off. We do not respond to DNT signals differently, because our behavior is already the behavior DNT asks for.

We do not sell or share personal information

We do not sell personal information, and we do not share it for cross-context behavioral advertising, as those terms are used under California law. We never have.

Who else processes your data

We use a small number of service providers to run ScopeDiff. Each one is listed, with what it handles and why, on our sub-processors page. We give 30 days’ notice on that page before adding a new one.

We never see your card details.Payments go through Stripe’s own hosted checkout. We store only the identifiers Stripe gives us for your customer and subscription.

How long we keep things

We describe this the way it actually works rather than promising a schedule we don’t run:

  • Your projects and records are kept until you delete them. We do not automatically purge data after a period of inactivity or after you cancel a subscription. Cancelling returns you to the free plan; it does not erase anything.
  • Deleting a project deletes it immediately and permanently — every version, deliverable, milestone, acknowledgment, uploaded logo, and the share link itself. It cannot be undone.
  • Deleting your account removes your profile, projects, records, GitHub connection, and usage rows. See below for how to ask.
  • Records of your consent to subscription billing are kept even after account deletion, and are unlinked from your account when it goes. California law requires us to retain proof of what you agreed to be charged for.
  • Backups and server logs are retained by our hosting and database providers on their own schedules, so deleted data can persist in backups for a short window after it is gone from the live system.

Your choices

Email hello@scopediff.com and we will action any of these within 30 days:

  • Get a copy of what we hold about you.
  • Correct anything inaccurate.
  • Delete your account and its data. (Most of it you can already delete yourself, project by project, from the app. Account deletion is by email for now.)

We honor these requests as a matter of policy. We are a very small business and do not currently meet the thresholds that make the California Consumer Privacy Act apply to us — we would rather say so than imply a compliance program we don’t have. If that changes, this page changes first.

If you are a client viewing a shared record and want the name you entered removed, ask the studio that sent you the link — it is their record and they can remove it. You can also write to us and we will help.

Where we operate

ScopeDiff is operated from the United States and our providers store data in the United States. We do not currently offer the service to customers in the European Economic Area or the United Kingdom, and this policy is not written to satisfy the GDPR.

Age

ScopeDiff is a business tool, not intended for anyone under 18, and we do not knowingly collect information from children.

Changes

If we change this policy we will update the date at the top. For a change that materially affects how we handle your information, we will email account holders before it takes effect.

Contact

hello@scopediff.com

TermsPrivacySecuritySub-processorshello@scopediff.com© 2026 ScopeDiff