Privacy Policy
What we collect
- Account information. Your email address and an identity-provider user ID, used to sign you in and check workspace access. The mobile app sends your password securely through Orgscout to WorkOS for authentication; Orgscout does not store it. Web sign-in may use Google or WorkOS.
- Workforce data you upload. Engagement data (employee rosters, org structures, compensation figures, policy documents) that you or your organization import into the platform.
- Operational logs. Standard server logs (request paths, timestamps, status codes) used to operate and secure the service.
How we use it
Solely to provide the service: authenticating you, rendering your engagement's workforce analytics, and answering questions you ask the built-in assistant. We do not sell personal information, serve ads, or use your data to train models.
Service providers
Data is processed by the infrastructure the service runs on: Railway (hosting and database), Cloudflare (DNS, CDN, file storage), Google and WorkOS (sign-in), and Anthropic (the Cal assistant; only the question you ask and the engagement context needed to answer it).
Retention and deletion
Engagement data persists until an engagement owner deletes it in the app. Mobile users can permanently delete their own account in Settings under Account. Account deletion immediately removes sign-in access, memberships, onboarding preferences, and direct account identifiers. A restricted queue temporarily retains the identity-provider user ID until deletion at WorkOS succeeds; failures are automatically retried. Shared business records remain available to the organization with the deleted user's identity replaced by an anonymous identifier. Orgscout retains only a one-way hash of the deleted email address to prevent a configured allowlist from accidentally restoring the account; an administrator can remove that tombstone only by explicitly inviting the person again.