Scopara

Privacy Policy

Version 2026-08-06-v1. Not legal advice -- see the project's internal compliance documentation for the full caveat. Have an attorney review this before it's relied on beyond the current prototype stage.

1. What we collect

Your email address and a hashed (never plaintext) password, to operate your account. The PDF files you upload, and the results of processing them (extracted text, suggested corrections, formatting flags). Metadata about your use of the Service -- timestamps of logins, uploads, views, downloads, sharing actions, and deletions -- kept in an append-only audit log.

2. How your transcript content is used

A transcript you upload is used only to run the proofreading pipeline you requested: text extraction, formatting checks against the jurisdiction you selected, and a proofreading pass (either a live call to an Anthropic Claude model, or a local heuristic fallback when no live model is configured). Extracted text is sent to Anthropic's API for that proofreading pass, routed to one of two API paths based on the local sensitivity classification described in the Terms of Service -- that classification and routing decision happen before any content leaves this product's own servers.

3. Who can see your documents

By default, only you. A document is visible to another account only if you explicitly grant that account view-only access, which you can revoke at any time. An administrator of the Service can view a document for support or investigation purposes; every such access is logged distinctly and separately from ordinary owner or shared-grant views, and is never hidden from the audit trail.

4. Retention

Documents and their processed results are retained until you delete them, or until a retention-purge policy removes them automatically. The exact automatic-retention window is still being finalized (it depends on confirmation from Anthropic's own HIPAA-readiness documentation, requested separately) and is not yet enforced automatically as of this version of the product -- until it is, retention is effectively "until you delete it yourself." When automatic retention is enabled, PHI-flagged documents are expected to have a longer retention window than standard documents, consistent with the flagged-content handling described in this project's internal compliance documentation.

5. Deletion

Deleting a document or your account permanently removes the stored file and any exported files. A minimal audit-trail stub is kept (that something existed and was deleted, by whom, when) -- it does not contain your transcript content. See Section 7 of the Terms of Service for the full description of what deletion does and doesn't remove.

6. Security

Passwords are hashed, not stored in plaintext. Sessions use random, server-side, HttpOnly session tokens. Access to every document goes through a single, centralized access-control check (owner, explicit share, or logged administrative override) rather than being re-implemented per feature. This version of the product runs without HTTPS termination built in -- any real deployment is expected to sit behind a reverse proxy that terminates TLS; do not rely on this version of the product being served without one.

7. Third parties

Transcript text you upload is sent to Anthropic (api.anthropic.com) to run the proofreading pass, when a live API key is configured. No other third party receives your transcript content through normal use of the Service.

8. Your choices

You can view everything recorded about your own account activity on the Audit Log page. You can delete any document you own, or your entire account, at any time -- see Section 5. You can revoke any sharing grant you've made at any time.

9. Changes to this policy

If this policy changes in a way that matters, we'll ask you to accept the updated version before you can continue using the Service. The version you accepted is recorded on your account.