Legal

Privacy Policy

Version 2026-07-23Current published documentScout Crew LLC · Wisconsin

1Data We Collect

We collect and store the information needed to run Scout Crew:

  • Account data — your login credentials (hashed, never stored in plaintext) and account

settings.

  • Venue API keys — if you connect a venue (e.g. Kalshi, Polymarket US), the API key or

credential you provide, stored using the envelope encryption described in Section 2.

  • Trading and betting activity — positions, orders, fills, tags, notes, and P&L you record

or that we observe through a connected venue account, so the Service can track performance and power History, Bet Analysis, and calibration features.

  • Usage data — pages viewed, features used, and request logs, so we can operate, debug, and

improve the Service.

  • Chat and notes content — messages you send to the in-app AI ("crew chat"), game notes,

and durable "crew memory" facts you choose to save.

  • Technical data — IP address, device/browser metadata, and error logs, collected

automatically for security and reliability purposes.

We do not knowingly collect more than is necessary to operate the Service. We never fabricate or infer a data point we don't actually have — where we lack data (e.g. an unplayed game's score), the Service shows "no data yet" rather than a synthetic value, and the same honesty principle applies to data we tell you about ourselves.

We use only essential cookies (a signed session cookie that keeps you logged in). We do not use advertising trackers or third-party analytics cookies, and we do not sell or rent your personal information to anyone.

2API-Key Handling

Venue API keys are protected with envelope encryption, not stored in plaintext anywhere in the system:

  • Each user is issued a random, per-user 256-bit Data Encryption Key (DEK).
  • Your API key (and other secrets) are sealed under your DEK using AES-256-GCM, an

authenticated encryption cipher.

  • The DEK itself is never stored in the clear. It is stored wrapped — encrypted under a

separate Key-Encryption Key (KEK), the application's master key, which is held outside the application database and outside the source repository.

  • This "wrap the key that wraps the secret" design (envelope encryption) means your API key is

never persisted unencrypted, while still letting the server decrypt it when needed to run scheduled scouting or push notifications on your behalf, even when you are not actively using the app.

  • No plaintext secret is ever written to logs.
  • As stated in the Terms of Service, your API key is never shown to anyone, including

administrators — administrators can see your usage, bets, notes, and chats for support and operations purposes, but not your decrypted credential.

3How We Use Your Data

We use the data above to: provide and personalize the Service (reads, grades, tracking, calibration); make requests to venues you have connected, using your own key, on your behalf; generate AI commentary and chat responses; monitor, secure, and debug the Service; enforce eligibility and the Terms of Service; and communicate with you about the Service. We do not use your data for third-party advertising, and we do not sell it.

4Sharing & Service Providers

We share personal data only with the service providers needed to run Scout Crew, and only the data each one needs:

  • Cloud hosting & backup providers — the Service's servers, database, and encrypted

backups run on third-party cloud infrastructure.

  • AI (large-language-model) providers — when you use crew chat or AI-generated reads, the

relevant content (your chat message and the game/market context needed to answer it) is sent to a third-party AI provider to generate the response. We do not commit to a single AI provider or model: to balance cost and output quality, the operator may route requests among multiple providers and models (e.g., Anthropic or similar commercial AI providers) and may change them at any time without notice. Whichever provider is used receives this content only to process the request, through its commercial API and under its own terms. If you connect your own AI provider key, that content goes to your chosen provider instead, under your own agreement with them. Venue API keys are never sent to AI providers.

  • Connected venues and data sources — requests to a venue you connect (e.g., Kalshi) are

made with your credential, and necessarily disclose to that venue the fact and content of those requests. Public market and sports data sources receive only ordinary technical request data, never your identity or portfolio.

  • Legal compulsion — we may disclose data if required by law, subpoena, or court order, or

to protect the rights, safety, or property of Scout Crew or others. Where lawful, we will attempt to notify you before disclosing your data.

Aggregated, de-identified statistics (Section 5) are not personal data and may be shown to other users only under the floors described below.

5Crew-Wide Aggregation

Some features (the "Crew-Wide Edge Lab") show aggregated, anonymized statistics computed across multiple users' betting activity — for example, win rates broken out by strategy facet. To protect individual privacy, a facet cell is only displayed when data from at least three (3) distinct user accounts contributes to it (in addition to a minimum-sample-size floor on the number of decided bets). Cells that don't clear this floor are withheld rather than shown with too few contributors. No individual user's bets, amounts, or identity are exposed through this feature — only aggregate statistics for cells that meet the floor.

6Data Retention

We retain different categories of data for different periods, driven by product need and storage limits. Configured defaults, in days, are:

DataDefault retentionWhat it covers
Cross-venue price/line snapshots45 daysHistorical price data powering line-movement charts, closing-line-value (CLV), and calibration statistics.
Position snapshots180 daysObserved book/position history powering the book-value chart.
Crew chat history7 daysSaved turns of your conversations with the in-app AI (per game thread and the general board thread). Durable facts you explicitly save to "crew memory" are excluded from this window and do not expire on this schedule.
HTTP call log7 daysInternal telemetry of outbound calls to third-party data providers, used for budget/rate-limit monitoring.
Error log30 days (also capped at 1,000 rows, newest kept)Unhandled application error records, used for debugging.

Older rows in each category are pruned automatically once they age out of the window above. Retention windows are operator-configurable; if a default above changes materially, we will update this document's version date.

Account data, venue API keys, and trading/betting records (positions, fills, tags, notes) are retained for as long as your account is active, because they are the product's core record. When you disconnect a venue key, the stored wrapped key is deleted immediately. When your account is deleted (Section 7), this data is deleted within thirty (30) days, except for minimal records we are legally required to keep, records needed for active security or fraud-prevention purposes, and the aggregated, de-identified statistics described in Section 5. Encrypted backups age out on their own rotation schedule shortly thereafter.

7Your Rights: Access, Correction, Deletion, Export

Regardless of which state you live in, you may: access the personal data we hold about you; correct inaccurate data; delete your account and associated data (notes, chats, saved bets, and settings); export your data in a portable format; and disconnect any venue API key at any time from within the Service (disconnecting removes the stored wrapped key so it can no longer be decrypted or used).

Send requests to the contact in Section 11. We will verify the request using your account email and respond within forty-five (45) days. We will not discriminate against you for exercising any of these rights. Deletion is subject to the narrow exceptions in Section 6.

8Breach Notification

If we become aware of unauthorized acquisition of your personal information, including an API key, we will investigate and notify affected users without unreasonable delay — and in any event within forty-five (45) days, consistent with Wis. Stat. § 134.98 — unless law enforcement asks us to delay notification to protect an investigation. If a breach affects more than 1,000 individuals, we will also notify the nationwide consumer reporting agencies as the statute requires. Where users in other states are affected, we will follow those states' notification laws as applicable. Notice will describe what happened, what data was involved, and what we are doing about it — including immediate revocation guidance if a venue key may have been exposed.

9Children

The Service is not directed to, and may not be used by, anyone under 18. We do not knowingly collect personal information from anyone under 18; if we learn we have, we will delete it and close the account.

10Security

Beyond the API-key envelope encryption in Section 2: passwords are hashed with a modern memory-hard algorithm (argon2id); sessions are signed and server-side revocable (logging out invalidates every outstanding session for your account); administrative access is limited and logged; and no plaintext secret is ever written to logs. No system is perfectly secure — if you believe your account or key has been compromised, revoke the key at the venue first, then contact us.

11Contact

Questions about this Privacy Policy, or requests to access, correct, export, or delete your data, can be directed to Scout Crew LLC at info@scoutcrew.com.

12Changes

We may update this Policy; material changes will be reflected by an updated version date at the top of this document and notice in the Service. If a change materially reduces your rights under this Policy, we will ask you to re-accept before it applies to you.