Privacy Policy

Orgscout (orgscout.io), operated by Roshco Advisory. Updated August 10, 2026.

What we collect

How we use it

Solely to provide the service: authenticating you, rendering your engagement's workforce analytics, and answering questions you ask the built-in assistant. We do not sell personal information, serve ads, or use your data to train models.

Service providers

Data is processed by the infrastructure the service runs on: Railway (hosting and database), Cloudflare (DNS, CDN, file storage), Google and WorkOS (sign-in), and Anthropic (the Cal assistant; only the question you ask and the engagement context needed to answer it).

Retention and deletion

Engagement data persists until an engagement owner deletes it in the app. Mobile users can permanently delete their own account in Settings under Account. Account deletion immediately removes sign-in access, memberships, onboarding preferences, and direct account identifiers. A restricted queue temporarily retains the identity-provider user ID until deletion at WorkOS succeeds; failures are automatically retried. Shared business records remain available to the organization with the deleted user's identity replaced by an anonymous identifier. Orgscout retains only a one-way hash of the deleted email address to prevent a configured allowlist from accidentally restoring the account; an administrator can remove that tombstone only by explicitly inviting the person again.

Contact

[email protected]