What we process
We process account data, the professional profile chosen by the candidate, job briefs, introduction interactions, meetings, and security records required to provide the service. Protected attributes are not used for matching.
Pilot waitlist
To manage an access request, we retain the name, email address, selected product, language, consent, and, for Sentry, the company. A Scout candidate may attach an optional CV. The file remains private and is neither extracted nor sent to a model until the person has verified their email and confirmed its use in Scout. A request does not automatically create an account.
Optional LinkedIn import
If you connect LinkedIn, you authorize Scout & Sentry to retrieve and store the portability data you select: profile, experience, education, skills, and languages. LinkedIn limits this feature to eligible members in the EEA and Switzerland, and our application must be approved. The data pre-fills a private draft and is never published without your review. OAuth tokens are encrypted, and raw LinkedIn responses are not retained. You can disconnect LinkedIn without changing your profile or request deletion of imported sources and unchanged values from the privacy center.
Optional Google Calendar connection
If you connect Google Calendar, you authorize Scout & Sentry to read busy periods from your primary calendar and create meeting events organized through the service. We use this data only to propose mutually available times, send invitations associated with introductions, and create the related Google Meet link. Busy periods are used to calculate availability; event content is not imported. OAuth tokens are encrypted. This data is not sold or used for advertising. You can disconnect Google Calendar in your settings and revoke access through Google.
Protection and limited use of Google data
Data obtained through Google Workspace APIs is encrypted in transit with TLS. OAuth tokens are encrypted at rest. Server-side access is limited to the authenticated user and authorized calendar operations, with minimal permissions, authorization controls, and revocation support. Busy periods are processed in memory to calculate availability and are not retained. We retain only the identifiers and times of meetings created by Scout & Sentry that are required for synchronization or deletion. Google Workspace data is not transmitted to an AI or machine-learning service and is never used to create, train, or improve a model. AI features unrelated to Google Calendar use Vercel AI Gateway with zero data retention enabled for every request. Use of information received from Google Workspace APIs complies with the Google API Services User Data Policy, including Limited Use requirements.
Microsoft 365 Calendar — coming soon
If you connect Microsoft 365 Calendar, you authorize Scout & Sentry to read the start time, end time, and availability status of events in your primary calendar and to create or delete meetings organized through the service. We use Microsoft Graph data only to propose mutually available times and manage invitations associated with introductions. Titles, descriptions, participants, and content from existing events are not imported. Data is encrypted in transit with TLS, and OAuth tokens are encrypted at rest. Availability periods are processed in memory and are not retained. We retain only the identifiers and times of meetings created by Scout & Sentry that are required for synchronization or deletion. Microsoft Calendar data is not transmitted to an AI or machine-learning service. You can disconnect Microsoft 365 Calendar in your settings and revoke access through Microsoft.
Optional Slack connection
When an organization connects Slack, we process the workspace identifier and name, associated member identifiers, role-channel identifiers and names, and commands, messages, and interactions addressed to Sentry in configured private channels or direct messages. A Slack email address may be used only to associate a verified Sentry member. OAuth tokens are encrypted and never exposed to users. Sentry does not request access to files or public channels. Disconnecting revokes future access and starts cleanup of channels created by Sentry.
Artificial intelligence
Scout & Sentry uses generative models to produce drafts, summaries, explanations, and suggestions. These outputs may be inaccurate and remain subject to human review. They do not make recruiting decisions on their own. Slack data is not sold, used for advertising, or used to train models.
Purposes
This data is used to create profiles, calculate explainable professional matches, arrange consented introductions, secure access, and meet legal obligations. The legal basis depends on the operation: performance of the service, explicit consent for identity disclosure, documented legitimate interest for security, or a legal obligation.
Visibility and recipients
A profile remains private until it is published. Before an introduction, only authorized anonymized projections are visible. Identity and contact details are disclosed only to the named organization after the candidate agrees, with limited and audited access.
Retention and rights
An optional CV attached to a request but never claimed is deleted within 30 days; an invalid or abandoned transfer is deleted sooner. Introduction access expires or is revoked according to its lifecycle. From the privacy center, you can export your data, delete data imported from LinkedIn, request account deletion, correct your profile, or revoke future access. Legally required audit evidence is minimized and pseudonymized.
Contact
For questions or data-related requests, contact privacy@scoutandsentry.com. A copy already received by an organization cannot be technically recalled; revocation blocks future access and updates.