ScopeHunter

Privacy Policy

ScopeHunter — professional & trust network for security practitioners

This describes what ScopeHunter actually collects, who else sees it, and what you control — written to be specific about this product rather than generic. If a data flow below sounds unusual for a "networking" app, that's because ScopeHunter is also a compliance workspace: several sections cover that half of the product specifically. See our Security Policy for how the data described here is protected, and our Terms of Service for the account agreement itself.

Account and profile data

Creating an account requires an email address and password, or Google sign-in. Authentication is handled by a dedicated, self-hosted auth service (Supabase Auth / GoTrue) — ScopeHunter's own backend never sees or stores a raw password. Your session is kept in your browser's local storage, not a cookie.

Profile fields you fill in (name, bio, employer, skills, links) are visible to other members per your privacy settings, same as any professional network. Ghost Mode, if enabled, hides your activity and exempts you from analytics entirely — see below.

Payments and identity verification — handled by Stripe, not us

Pro subscriptions, one-time donations, and credential-scan credit packs are processed by Stripe. We never see or store your card number — Stripe's Customer Portal handles that directly.

If you complete identity verification, it runs through Stripe Identity: the government ID and selfie you submit go straight to Stripe and are never persisted in ScopeHunter's own database. We receive back a verified/not-verified result, not the documents.

Resume uploads

A resume you upload (PDF or DOCX) is stored in Google Cloud Storage, encrypted at rest, and scanned for malware before it's used anywhere else in the product. To extract structured data from it (skills, work history) we send its text content to Anthropic's Claude API — a third-party AI vendor. That's the one place in the product where document content is sent to an external AI model; we don't do this with any other content you post.

Analytics — opt-in only, not opt-out

We use Google Analytics (GA4), but the tracking script is not loaded into the page at all until you explicitly consent — not loaded-then-restricted, not "opt in to storage while a ping already went out." Nothing reaches Google before you say yes. You can change this choice any time from your Profile's Privacy settings. Ghost Mode overrides your choice unconditionally: a Ghost Mode account is never tracked, even if analytics was previously accepted.

Ads — no tracking, no cookies

Free-plan accounts see in-feed ads served by EthicalAds, chosen specifically because it doesn't track individual users or set cookies — it loads without consent-gating for that reason. Pro subscribers and admin/owner accounts never see ads.

Compliance workspace — data about your infrastructure

If your organization uses the CMMC / SOC 2 / ISO 27001 workspace, additional data flows apply, scoped to that org and visible only to members of it:

Security bulletins

The vulnerability/breach feed on your dashboard is pulled from public sources — CISA's known- exploited-vulnerabilities catalog, NVD, and Have I Been Pwned's public breach list. This is a one-way read of public data; your email address is never sent to any of these services to check whether you personally were breached.

Email

Transactional email (signup confirmation, billing receipts, notifications) is sent through an authenticated Gmail relay. We don't use your email for marketing beyond what you'd reasonably expect from using the product, and we don't sell or rent it to anyone.

Who sees your data

VendorWhat they getWhy
StripePayment details; ID + selfie if you verify identityBilling and identity verification — never touches our database
Anthropic (Claude API)Resume text contentStructured data extraction, only when you upload a resume
Google Cloud StorageUploaded resume files, compliance letterhead imagesFile storage, encrypted at rest
Google AnalyticsPage views/events, only after opt-inProduct usage analytics
EthicalAdsNothing personal — no tracking, no cookiesAd serving for free-plan accounts
Google (Gmail relay)Transactional email content and your addressSending account/billing email

We don't sell personal data to anyone, for any reason.

Your controls

Children's privacy

ScopeHunter is not directed at anyone under 18. Account creation requires confirming you meet that age requirement, per our Terms of Service.

Changes to this policy

If we materially change what we collect or who we share it with, we'll update the date below and, for a significant change, let existing members know.

Questions about any of this: security@scopehunter.io. This page describes our actual practices in plain language; it isn't a substitute for your own legal advice if you need a formal compliance determination for your organization.

Last updated: 2026-08-23.

ScopeHunter is built and operated by L-IT Technical Solutions, a Texas IT consultancy — the same people who run the CMMC automation described here against their own production infrastructure.