← Scire

Draft · legal and operational review required before public launch

Privacy notice

Draft prepared 28 September 2026. The final operator must replace the contact and entity details and confirm all processor, retention, and jurisdictional obligations.

Information Scire uses

Scire uses Google account identity information to create and secure your account. Gmail connection is separate and optional. If you grant the read-only Gmail scope, Scire searches likely billing and cancellation messages within a bounded 90-day history and a configured message cap. It does not read attachments by default and does not request permission to send, change, or delete mail.

What is stored

Scire stores the mailbox address, the granted scope, an encrypted refresh token, sync cursors, and the normalized email text and metadata needed to support a detection. This can include message subject, sender, date, candidate amount and currency, source message identifiers, a short excerpt, and a small set of safe links. It also stores subscription summaries, your corrections, review decisions, and an account activity log.

How the information is used

Scire uses deterministic parsing and typed Jev/TypeSafe decisions to identify likely subscription events and route uncertain results to review. A receipt is evidence that an email reported a charge; it does not prove that a payment settled. Amounts remain in their original currency and billing cycle.

Service providers

Google provides sign-in, OAuth, and Gmail API services. TypeSafe may process a normalized email excerpt for classification when a server-side key is configured. The final operator must list current subprocessors, locations, safeguards, and contractual terms before launch. The draft data-flow record is available in the source repository.

Retention and controls

Email evidence is retained for 90 days and then deleted by a scheduled worker. Subscription summaries and correction history remain until you delete them or your account. You can disconnect Gmail, export your data, or delete your account in settings. Disconnect removes the saved refresh token and stops syncing. Google revocation can take longer or fail independently; account deletion removes Scire's data immediately.

Security and contact

Gmail refresh tokens are encrypted at rest. Access tokens are used in worker memory. Message bodies and credentials are not written to application logs. Before publication, the operator must add its legal name, privacy contact, applicable rights request process, jurisdictional disclosures, and a verified production domain.

This page is a product draft, not a final legal notice. Read draft terms.