Store of Scope / Legal

Privacy Policy

What Store of Scope processes, what it deliberately leaves out, and the controls available to you.

Effective date: August 29, 2026

01

Scope of this policy

This policy explains how Store of Scope processes information when you visit this website, subscribe to the editorial newsletter, or use the Store of Scope plugin and its hosted workflow service.

It does not govern third-party products that you connect to Store of Scope. Those services apply their own privacy policies to information they process.

02

Information we process

We process information you provide during setup, such as workspace preferences, newsletter sources, topic rules, cadence choices, and approval decisions.

When you connect Gmail, the workflow may process normalized message identifiers, sender and subject metadata, timestamps, labels, thread relationships, and short previews needed to determine workflow state. Generated scopes, delivery drafts, audit receipts, and connector status may also be processed so the service can complete and explain its work.

03

Information we deliberately exclude

Store of Scope does not store your Google OAuth tokens. Authentication credentials are handled by the connector and hosting infrastructure that provides the authorized connection.

We do not retain raw MIME messages, full message bodies by default, or attachment bytes after processing unless you deliberately enable a workflow that requires retained content. We do not sell inbox data or use it to build advertising profiles.

04

Why we process information

We use information to connect the sources you choose, identify newsletter material, prevent duplicate processing, prepare scopes, record approvals, deliver requested artifacts, maintain workspace state, diagnose failures, protect the service, and respond to support requests.

We use website request logs for security and operational reliability. This release does not use analytics, advertising cookies, or a first-party newsletter signup form.

06

Connected services

Gmail is required for the current plugin workflow. Calendar and Drive are optional. Each connection is authorized separately, and the product should explain the purpose of a requested connection before you approve it.

Gmail send access, when available, is optional and used only for a delivery workflow you choose. Store of Scope is designed to require approval before a proposed send is executed.

07

Service providers and infrastructure

Store of Scope relies on service providers to operate the website, hosted MCP service, connectors, and newsletter. These may include Codex and OpenAI services, Noodle Seed hosting, Google services, Substack, domain and infrastructure providers, and vendors used for security or support.

Providers process information under their own terms and privacy notices. Their systems may operate in countries different from yours.

08

When information is shared

We share information with service providers only as needed to operate the product, follow your instructions, protect users and the service, or comply with valid legal obligations. We may disclose information in connection with a corporate transaction, subject to appropriate protections and notice where required.

We do not sell personal information. We do not share inbox-derived content for cross-context behavioral advertising.

09

Retention and deletion

Workspace settings, normalized workflow state, generated artifacts, and audit receipts are retained only for as long as needed to provide the workspace, meet security or legal obligations, and resolve disputes. Retention periods may differ by data type and enabled workflow.

You can remove the plugin, disconnect connectors, and use workspace deletion controls to request deletion of retained Store of Scope workspace data. Some limited records may remain temporarily in backups, security logs, or records that must be preserved by law.

10

Security

We use technical and organizational measures intended to protect information, including authorization boundaries, access controls, transport security, and operational logging. No system can guarantee absolute security.

If you believe your workspace or connection has been compromised, revoke the relevant connector authorization and contact us using the privacy contact below.

11

International processing

Store of Scope and its providers may process information in multiple countries. Those countries may have data-protection rules different from the rules where you live. Where required, the responsible provider uses an appropriate transfer mechanism.

12

Your choices and rights

Depending on where you live, you may have rights to request access, correction, deletion, restriction, objection, portability, or withdrawal of consent. These rights can be subject to exceptions and identity verification.

You can also control the product directly by changing workspace preferences, pausing scheduled tasks, withholding approval, disconnecting Google services, or deleting the workspace.

You may also lodge a complaint with the data-protection supervisory authority responsible for your location. We encourage you to contact us first so we can try to address the concern directly.

13

Children

Store of Scope is not directed to children below the minimum age stated in the Terms. We do not knowingly collect personal information from children below that age. Contact us if you believe a child has provided information to the service.

14

Changes to this policy

We may update this policy as the product, providers, or legal requirements change. We will post the revised policy and update its effective date. Material changes may also be communicated through the website, product, or newsletter when appropriate.

15

Contact

Send privacy questions, rights requests, or complaints to the privacy contact listed below. Include enough information for us to understand the request, but do not email sensitive inbox content or credentials.

Last updated: August 29, 2026