Privacy Policy
Last updated: July 6, 2026
Scaffold's data management practices are as follows:
- Scaffold's website is hosted on Render, using exclusively U.S. servers.
- Users' prompts and responses are funnelled through Anthropic, via Claude API. Per Anthropic's privacy policy, Anthropic will not use these inputs—nor the Claude/Anthropic-generated outputs—in model training (“Is my data used for model training?”). However, Anthropic may store these inputs and outputs on their back-end for up to 30 days after receipt or generation and subject them to trust and safety screenings. If an interaction is found to violate Anthropic's Usage Policies, it may be stored beyond the 30-day period (“How long do you store my organization's data?”).
- User profile creation and log-in is managed by Google OAuth. Scaffold has access to users' email address, but not password.
- When users create a user profile, the information contained within their profile is stored on Supabase, in U.S. servers.
- Specifically, Supabase stores information on: user inputs, Scaffold outputs, interaction titles, interaction takeaways, interaction sticky notes, interaction timestamps, and organizational folders.
- If the user deletes an interaction, that interaction will be immediately and permanently removed from Supabase.
- Without explicit and verifiable permission from the user, Scaffold's founders, Brendan and Hillary, will not access any user information stored on Supabase.
- If users use Scaffold without creating a user profile, the information from the interaction is not saved in Supabase and is inaccessible to Brendan and Hillary. However, since the interaction is processed via Claude API, it would be subject to Anthropic's 30-day storage policy as described above.
Except upon request for a legal process, Scaffold will not share any of the data that it collects with third-parties unrelated to the delivery of its services.
The terms above may be subject to change. The last updated date will be indicated at the beginning of this policy.