Privacy Policy

Website: skuascout.com · Last updated: 3 September 2026

NoteThis Privacy Policy is written to comply with the EU General Data Protection Regulation (GDPR) and Romanian data-protection law. It explains the personal data we process, why, and the rights you have over it.

1. Who We Are

This Privacy Policy explains how SKUA LABS SRL (a limited liability company registered in Romania, registered office at 85 Uverturii Boulevard, Building O14, Entrance A, Floor 4, Apartment 16, District 6, 060935 Bucharest, Romania, Trade Register number J2026049926004, sole registration code (CUI) 55428943) ("SKUASCOUT," "we," "us," or "our") collects and uses your personal data when you use the website at skuascout.com and the SKUASCOUT application and services (together, the "Service").

For the purposes of the EU General Data Protection Regulation ("GDPR"), we are the data controller of the personal data described in this Policy. Our contact details for privacy matters are in Section 12.

2. The Data We Collect

We collect the following categories of personal data:

  • Account data. Your name (if provided), email address, password (stored in hashed form), and, if you sign in with a third-party provider such as Google, the basic profile information that provider shares with us.
  • Payment data. When you subscribe or buy Credits, payment is processed by our payment processor. We receive limited billing information (such as your plan, transaction status, and partial card details), but we do not store your full payment card number ourselves.
  • Content you submit. The inputs you provide to the Service, such as keywords, ASINs, niches, and the data we read from files you upload (such as CSV exports, from which we keep only the columns we use, not the file itself), and the outputs generated from them.
  • Usage and technical data. Information about how you use the Service, such as features used, Credit activity, log data, device and browser type, IP address, and approximate location derived from it.
  • Communications. Messages you send us (for example, support requests) and your preferences for marketing communications.
  • Feedback you send from inside the app. When you use the in-app feedback button to report a problem or suggest an improvement, we receive the message you write, the type you chose, and, only if you attach one, a screenshot or image you choose to include (you see it before it is sent, and you can remove it). We also record the page you were on, your browser and app version, your screen size, language and time zone, your plan, and the last few error messages the app itself caught, so we can reproduce what you saw. The message and the image reach the two founders by email and are kept as described in Section 9.
  • Referral data. If you participate in the referral program, the referral codes used and the link between referring and referred accounts, to apply discounts and rewards and prevent abuse.

3. How We Collect It

  • Directly from you when you create an account, subscribe, upload content, or contact us.
  • Automatically as you use the Service, through logs, cookies, and similar technologies (see Section 6).
  • From third parties, such as your chosen sign-in provider and our payment processor.

4. Why We Use Your Data and Our Legal Basis

Under the GDPR we must have a legal basis for processing your personal data. We rely on the following:

  • To provide the Service (create your account, run analyses, store your work), legal basis: performance of our contract with you.
  • To process payments and manage subscriptions, Credits, and referrals, legal basis: performance of our contract and our legitimate interests.
  • To keep invoices and accounting records, legal basis: compliance with a legal obligation (Romanian tax and accounting law).
  • To secure, maintain, and improve the Service, including preventing fraud and abuse, legal basis: our legitimate interests.
  • To communicate with you about your account, changes, and support, legal basis: performance of our contract and our legitimate interests.
  • To send marketing (where applicable), legal basis: your consent, which you can withdraw at any time.

5. Automated Processing and AI

To generate your niche and product analyses, the inputs you submit (such as search terms and product details) are processed by our AI provider, Anthropic PBC (United States), acting as our processor. Under our commercial terms with Anthropic, your inputs are not used to train Anthropic's models.

These analyses are decision-support outputs. They do not produce legal or similarly significant effects on you within the meaning of Article 22 of the GDPR, and we do not use them to make solely-automated decisions about you.

6. Cookies and Similar Technologies

We use cookies and similar technologies to operate the Service and to remember your session. Essential cookies, which are necessary for the Service to work, are set without asking, in line with the ePrivacy rules and Romanian Law 506/2004.

We do not set non-essential, analytics, or marketing cookies without your consent. A cookie banner on our website lets you accept or decline them, and you can change your choice at any time via the Cookie settings link in the footer. You can also manage cookies through your browser settings.

The cookies and similar browser storage our website uses:

  • skua_consent (essential, 180 days). Records your cookie choice, including refusals, so we do not ask again. It stores only your decision, the time you made it, the banner version, and a random identifier for the consent record below.
  • Cookies beginning ph_ (analytics, set only if you accept, up to 365 days). PostHog analytics: usage measurement that does not use your name or email and, if you later create an account, attribution of your signup to your earlier visit. PostHog also sets matching entries in your browser's local storage; we clear these when you withdraw your consent.
  • hero_revealed (essential, current tab only). Remembers that the homepage intro has already played so it does not replay during your visit. It is cleared when you close the tab.

We keep a record of your consent choice (a random identifier, the time, your choice, the banner version, the policy date it was given under, whether you made it on the website or in the app, and your browser's user agent string) to meet our legal obligation to demonstrate consent. We do not store your IP address with this record. We keep the record of your current choice for as long as that choice stands, and delete a record you have replaced once it is 3 years old.

7. How We Share Your Data

We do not sell your personal data. We share it only with the sub-processors below, who act on our instructions under data-processing agreements, and with professional advisers or authorities where required by law:

  • Stripe, payment processing, subscriptions, and invoicing. Region: United States (with EU entity Stripe Payments Europe).
  • Supabase, database, authentication, and storage. Region: European Union.
  • Vercel, application hosting and serverless functions. Region: European Union edge.
  • PostHog, product analytics on our website and app, only where you consent. Region: European Union (Frankfurt).
  • Resend, transactional and (where you consent) marketing email delivery. Region: European Union (Resend is a US company).
  • Anthropic, AI processing of the inputs you submit, to generate analyses. Region: United States.
  • Apify, runs the Alibaba supplier searches behind the sourcing and cost figures in a Profitability analysis, from search terms built out of the inputs you submit. Region: European Union (Czech Republic).
  • Cloudflare, Turnstile bot protection on the account security screens in the app: signing in, signing up, resetting or changing your password, and asking for a new confirmation email. It receives your IP address and browser details to tell people from bots. Region: global network; Cloudflare, Inc. is a US company.
  • Sentry, error monitoring. When something in the app fails, it receives the diagnostic details of the fault so we can fix it. We do not send it your name or email, and your account reaches it only as an internal identifier. Region: European Union (Germany); Sentry is a US company.
  • Zoho, hosting for our own mailboxes, so anything you send to an address at skuascout.com, such as a support message or a request about your data, is received and stored there. Region: European Union.

Each of these providers is bound by a data-processing agreement that requires them to protect your data and process it only on our instructions. We keep this list current as our providers change.

8. International Transfers

We store our core database and application infrastructure in the European Union. Some of our sub-processors (such as Stripe and Anthropic) are located in the United States, so your personal data may be transferred outside the European Economic Area (EEA).

Where we make such a transfer, we ensure an appropriate level of protection using the European Commission's Standard Contractual Clauses (SCCs) incorporated into our agreements with these providers, and, where the provider is certified, the EU-US Data Privacy Framework. You can request a copy of the safeguards we rely on by contacting us at hello@skuascout.com.

9. How Long We Keep Your Data

We keep your personal data only as long as necessary for the purposes described in this Policy.

  • Account and content data are kept while your account is active, and for 30 days after you ask us to delete your account, or after we terminate it. Where you asked us to delete it yourself, those 30 days are your window to change your mind. We then erase or anonymize them, normally within 24 hours of that 30-day mark. If you would rather not wait, ask us at hello@skuascout.com and we erase them sooner.
  • Billing and tax records (invoices and accounting records) are kept for as long as Romanian tax and accounting law requires (currently 5 years for invoices, and up to 10 years where a longer fiscal-limitation period applies). We keep only the records the law requires, under restricted access, and delete them once the period ends.
  • Log data is kept for up to 90 days, then deleted or anonymized.
  • Feedback you send from inside the app is kept for 24 months so that we can act on it; a screenshot or image you attached is deleted after 180 days. If your account is deleted, any attached image is deleted within 24 hours of the erasure and the message is kept without anything that identifies you.
  • A one-way hash of your email address is kept for 24 months after your account is permanently deleted. The 24 months run from that permanent deletion, not from the day you ask. It has one purpose: our free credit offers are a one-time welcome for a first account, and without it the same person could delete and register again indefinitely to claim them over and over. That covers the signup credits and the referral bonuses, including the reward someone else would earn for introducing you a second time. It is a keyed hash, not your address, and it cannot be turned back into one. We hold it on the legitimate-interests basis, to prevent abuse of a promotional offer (GDPR Article 6(1)(f), Recital 47). Nothing else about the deleted account is stored with it, and it is never shared with anyone, including a person whose referral link you used.

When you ask us to delete your account, nothing is erased on the day you ask. Your access ends immediately: you are signed out, and the content you submitted and the results generated from it stop being reachable through the Service. If you have credits left, that balance stays visible when you sign in, so you can see what is being held for you. We then hold the account for 30 days, so that a deletion you regret can be undone. Sign in again inside those 30 days and confirm the restore, and everything comes back as it was, including your credits and your subscription. We keep it so you can undo the deletion, and so we can still serve the rights that survive it, such as a refund claim under the 14-day right of withdrawal in our Terms. We do not use it for anything else while the window runs.

If you do not come back, an automated job erases the account. That job runs once a day, so erasure normally happens within 24 hours of the 30-day mark rather than at the exact moment it passes. A run that is delayed, or that has a backlog of accounts to work through, can push it to one of the following days. Once it has run, the deletion is final and we cannot reverse it. You do not have to wait for the window: email us at hello@skuascout.com and we erase the account sooner.

Until it is erased, the account and everything in it is still stored, which is what makes those 30 days recoverable. After erasure, what stays is limited to the following: the invoices and accounting records we are legally required to keep, on the legal-obligation basis (GDPR Article 17(3)(b)); the records that show what you agreed to and what we have already refunded, which we keep with your account identifier removed so that a claim by either side remains provable (Article 17(3)(e)); the one-way email hash described above; and a log of the notices we are required to send you, which keeps the address each one went to, because proving we sent it means proving where. That log holds no message content. We keep it for three years after the account is erased, and it is not used to contact you.

One thing sits outside that list. We take routine backups of our database so we can recover the Service after a failure, and a backup taken before your erasure still contains what was in your account at the time. We do not read those backups, and we do not use them to restore an individual account, so an erased account does not come back from one. The copy goes when the backup it sits in is overwritten on our normal rotation, which is a matter of days rather than months.

10. Your Rights

Under the GDPR, you have the following rights regarding your personal data:

  • Access, to obtain a copy of the data we hold about you.
  • Rectification, to correct inaccurate or incomplete data.
  • Erasure, to ask us to delete your data in certain circumstances.
  • Restriction, to ask us to limit how we use your data.
  • Portability, to receive your data in a portable format, or have it sent to another provider where technically feasible.
  • Objection, to object to processing based on our legitimate interests, and to direct marketing at any time.
  • Withdraw consent, where we rely on consent, to withdraw it at any time without affecting prior processing.

To exercise any of these rights, contact us using the details in Section 12. We respond within one month. You also have the right to lodge a complaint with a supervisory authority; in Romania this is the National Supervisory Authority for Personal Data Processing (ANSPDCP), Bd. G-ral Gh. Magheru 28-30, Sector 1, Bucuresti 010336, anspdcp@dataprotection.ro.

11. Security and Children

We use reasonable technical and organizational measures to protect your personal data, such as encryption in transit, hashed passwords, and access controls. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

The Service is not directed to children, and you must be at least 18 (or the age of majority in your jurisdiction) to use it. We do not knowingly collect data from children.

12. Changes and Contact

We may update this Privacy Policy from time to time. If we make material changes, we will provide notice (for example, by email or an in-app notice). The "Last updated" date at the top shows when it was last revised.

For any privacy questions or to exercise your rights, contact us at hello@skuascout.com, or by post to SKUA LABS SRL, 85 Uverturii Boulevard, Building O14, Entrance A, Floor 4, Apartment 16, District 6, 060935 Bucharest, Romania.