Privacy
Last updated 10 August 2026
Who we are
RivalScout is owned and operated by GRAVITY115™. GRAVITY115™ is the data controller for any personal information processed in connection with your use of RivalScout.
What we collect
Account data. Your email address, profile name, organisation membership and role, sign-in metadata, and billing identifiers held by our payment processor.
Monitoring data. Watchlists and the competitor domains you name, the compressed page snapshots each run stores, the observations and scored changes derived from them, digests, alert rules and alert history, and any deals you import for win/loss analysis.
Operational data. Fetch logs, export records, AI usage and cost records, and an audit log of significant actions taken in your organisation.
What we do not collect
We do not collect data from behind logins or paywalls, we do not buy personal data, and we do not sell or share your watchlists, runs or digests with anyone outside your team.
How we use it
Your data is used to run your watchlists, generate digests and alerts, and to operate and support the service. Aggregate, non-identifying usage statistics help us improve reliability.
Who can see it
Only you and the people you invite. Access is enforced at the database level with per-row rules and owner, editor and viewer roles, so an invitation grants exactly the access you chose and nothing more.
Sub-processors
These providers process data on our instructions and only to deliver the service. We update this list before adding a new one.
- Lovable Cloud — application database, authentication and snapshot storage. Data is held in the European Union.
- Lovable AI Gateway — the language models used for extraction, summarisation and recommendations. Content sent for processing is redacted of personal identifiers first and is not used to train models.
- Cloudflare — application hosting, request routing and the egress our crawler uses.
- Stripe — payment processing and sales tax. Card details go to Stripe directly and never reach our systems.
- Resend — transactional and digest email.
- DataForSEO — search estimates, and only for organisations that have connected their own provider key. If you have not connected one, no data goes there.
Competitor data
Data about the domains you name is collected from publicly available sources only. We do not pass a login, we obey robots.txt, and we do not gather personal profiles of a competitor’s staff. The crawler page describes exactly how our fetcher behaves, and the methodology page lists every source we read and every figure we derive from it.
Retention
Runs are kept as an immutable history for as long as your organisation is active, because comparison over time is the product. Raw page snapshots are kept for 180 days and then removed; the observations derived from them remain. Delete a watchlist and its runs go with it. Delete an organisation and everything belonging to it is removed immediately.
Your choices
You can export everything at any time, correct your profile at any time, and delete your data yourself. In Settings, Delete an organisation exports the whole organisation as a file first, then removes the organisation, its watchlists, competitors, runs, stored snapshots, digests, deals, alerts and keys, and every team member’s access — and reports back that nothing was left behind. Delete accountremoves your sign-in and your memberships. Per-run CSV and PDF exports are available on every report. If you would rather we did it, write to privacy@rivalscout.io and we respond within 30 days.
Security
Data is encrypted in transit and at rest. API keys are stored only as hashes, so a leak of our database does not reveal a usable key. Credentials you supply for third-party providers are encrypted with AES-GCM before storage. Scheduled jobs authenticate with private tokens, and every read is checked at the database level against your organisation and role.
Changes
If this policy changes materially we will tell account owners by email before the change takes effect.