Privacy Policy
ScopeHunter — professional & trust network for security practitioners
This describes what ScopeHunter actually collects, who else sees it, and what you control — written to be specific about this product rather than generic. If a data flow below sounds unusual for a "networking" app, that's because ScopeHunter is also a compliance workspace: several sections cover that half of the product specifically. See our Security Policy for how the data described here is protected, and our Terms of Service for the account agreement itself.
Account and profile data
Creating an account requires an email address and password, or Google sign-in. Authentication is handled by a dedicated, self-hosted auth service (Supabase Auth / GoTrue) — ScopeHunter's own backend never sees or stores a raw password. Your session is kept in your browser's local storage, not a cookie.
Profile fields you fill in (name, bio, employer, skills, links) are visible to other members per your privacy settings, same as any professional network. Ghost Mode, if enabled, hides your activity and exempts you from analytics entirely — see below.
Payments and identity verification — handled by Stripe, not us
Pro subscriptions, one-time donations, and credential-scan credit packs are processed by Stripe. We never see or store your card number — Stripe's Customer Portal handles that directly.
If you complete identity verification, it runs through Stripe Identity: the government ID and selfie you submit go straight to Stripe and are never persisted in ScopeHunter's own database. We receive back a verified/not-verified result, not the documents.
Resume uploads
A resume you upload (PDF or DOCX) is stored in Google Cloud Storage, encrypted at rest, and scanned for malware before it's used anywhere else in the product. To extract structured data from it (skills, work history) we send its text content to Anthropic's Claude API — a third-party AI vendor. That's the one place in the product where document content is sent to an external AI model; we don't do this with any other content you post.
Analytics — opt-in only, not opt-out
We use Google Analytics (GA4), but the tracking script is not loaded into the page at all until you explicitly consent — not loaded-then-restricted, not "opt in to storage while a ping already went out." Nothing reaches Google before you say yes. You can change this choice any time from your Profile's Privacy settings. Ghost Mode overrides your choice unconditionally: a Ghost Mode account is never tracked, even if analytics was previously accepted.
Ads — no tracking, no cookies
Free-plan accounts see in-feed ads served by EthicalAds, chosen specifically because it doesn't track individual users or set cookies — it loads without consent-gating for that reason. Pro subscribers and admin/owner accounts never see ads.
Compliance workspace — data about your infrastructure
If your organization uses the CMMC / SOC 2 / ISO 27001 workspace, additional data flows apply, scoped to that org and visible only to members of it:
- OS-hardening evidence. The hardening automation is a Salt formula that runs on your own infrastructure. By default it doesn't call home — ScopeHunter never sees what's on those hosts. Reporting results back to this platform is opt-in and off by default; see how it works. If you turn reporting on, check results (pass/fail plus free-text detail — process names, ports, file paths, account names as observed on your host) are stored against your org.
- Cloud integration. Connecting Google Cloud requires uploading a GCP service-account key. It's stored encrypted at rest (envelope encryption, unique per-record key) and used only to read the configuration/asset data needed to generate compliance evidence — never displayed back in plaintext after you save it.
- Credential scanner. Scans a URL only after you've verified you own the domain it's on. Results are encrypted at rest; viewing a decrypted result requires a fresh MFA check, not just a valid session.
Security bulletins
The vulnerability/breach feed on your dashboard is pulled from public sources — CISA's known- exploited-vulnerabilities catalog, NVD, and Have I Been Pwned's public breach list. This is a one-way read of public data; your email address is never sent to any of these services to check whether you personally were breached.
Transactional email (signup confirmation, billing receipts, notifications) is sent through an authenticated Gmail relay. We don't use your email for marketing beyond what you'd reasonably expect from using the product, and we don't sell or rent it to anyone.
Who sees your data
| Vendor | What they get | Why |
|---|---|---|
| Stripe | Payment details; ID + selfie if you verify identity | Billing and identity verification — never touches our database |
| Anthropic (Claude API) | Resume text content | Structured data extraction, only when you upload a resume |
| Google Cloud Storage | Uploaded resume files, compliance letterhead images | File storage, encrypted at rest |
| Google Analytics | Page views/events, only after opt-in | Product usage analytics |
| EthicalAds | Nothing personal — no tracking, no cookies | Ad serving for free-plan accounts |
| Google (Gmail relay) | Transactional email content and your address | Sending account/billing email |
We don't sell personal data to anyone, for any reason.
Your controls
- Ghost Mode — hide your activity and exempt yourself from analytics, from your Profile.
- Analytics opt-out — change your consent choice any time in Profile > Privacy.
- Two-factor authentication — enroll from Profile > Security.
- Export or delete your data — from your Profile, tracked end-to-end. On deletion, your identifying data is purged; content it's referenced from (a reply in someone else's thread, for example) remains structurally intact but disassociated from you, the same as described in our Security Policy.
Children's privacy
ScopeHunter is not directed at anyone under 18. Account creation requires confirming you meet that age requirement, per our Terms of Service.
Changes to this policy
If we materially change what we collect or who we share it with, we'll update the date below and, for a significant change, let existing members know.
Questions about any of this: security@scopehunter.io. This page describes our actual practices in plain language; it isn't a substitute for your own legal advice if you need a formal compliance determination for your organization.
Last updated: 2026-08-23.