Privacy Policy
Effective date: 2026-09-26
1. Introduction & Scope
This Privacy Policy explains how Persoon.ai Inc. ("scm.cc", "we", "us") collects, uses, discloses, and safeguards personal data when you visit our websites, create an account, or use the scm.cc platform and related services (the "Services"). It applies to personal data we process as a controller - for example, account data and website-visitor data.
When a customer uses the Services to process personal data contained in their connected sources (for example, repository, cloud, or scanner data ingested through our connectors), the customer is the controller of that data and we act as a processor on their behalf. Our processing in that role is governed by the customer agreement and, where executed, a Data Processing Agreement (DPA) rather than by this Policy.
2. Personal Data We Collect
We collect the categories of personal data below, depending on how you interact with the Services. Connected-source content is processed under the customer agreement, not as data we collect for our own purposes.
- Account data - name, work email, organization, role (owner, admin, member, viewer). Provided by you or your administrator at signup.
- Authentication data - hashed credentials, OAuth identifiers, multi-factor enrollment status. From you or your identity provider.
- Usage, device & log data - pages viewed, feature usage, IP address, browser/device type, timestamps, security and audit logs. Collected automatically.
- Billing data - plan selection and billing status. Payment-card details are collected and processed by Stripe; we never see or store card numbers.
- Communications - support requests, emails, and feedback you send us.
- Connector content (processor role) - compliance evidence from sources you connect: repository and cloud metadata, scanner posture findings naming the affected resource, and derived coverage metrics. The free repository secrets scanner clones the target repository transiently to perform the scan and deletes the clone immediately when the scan completes; source code is not retained.
3. How We Use Personal Data
- Creating and administering accounts, organizations, and role-based access.
- Authenticating users and enforcing tenant isolation via row-level security.
- Processing subscription payments through Stripe.
- Delivering transactional and service email (for example, sign-in verification, invitations, and alerts) through our email provider.
- Operating AI-assisted features that summarize, score, or generate analyses from customer data; inputs are sent to our AI subprocessor (Anthropic) solely to return a result. Under Anthropic's current commercial terms those inputs and outputs are not used to train their foundation models, and we do not use them to train any model of our own; we hold no separate Zero Data Retention agreement, so retention follows the provider's then-current terms.
- Monitoring, debugging, securing, and improving the Services, including aggregated and de-identified analytics.
- Communicating with you about support, security, and material changes to the Services.
- Complying with legal obligations and enforcing our agreements.
4. Legal Bases for Processing
Where the GDPR, UK GDPR, or similar laws apply, we rely on the following legal bases: providing the Services under your agreement (performance of a contract); security, fraud prevention, and product improvement (legitimate interests); marketing emails and non-essential analytics (consent, where required); tax and regulatory records (legal obligation).
5. How We Share Personal Data
We do not sell personal data. We share personal data only as described below:
- Subprocessors: vetted vendors that host, secure, or support the Services - Supabase (database, authentication, and storage), Hetzner (application hosting), Stripe (payment processing), Anthropic (AI features, on demand), and GitHub (source connector, only when you connect it).
- Within your organization: with administrators and other members of your tenant, according to the role-based access controls you configure.
- Legal and safety: where required by law, regulation, legal process, or to protect rights, safety, and the integrity of the Services.
- Business transfers: in connection with a merger, acquisition, or sale of assets, subject to the protections of this Policy.
Subprocessors are bound by contractual confidentiality and data-protection obligations consistent with this Policy.
6. International Data Transfers
Our infrastructure and subprocessors process personal data primarily in the United States, and may process it in other regions. Where personal data is transferred across borders from jurisdictions that restrict such transfers, we rely on appropriate safeguards such as the EU Standard Contractual Clauses (and the UK Addendum where applicable) as made available through our subprocessors' data-processing terms. We have not appointed an EU or UK representative under Article 27; EU/UK users with questions about that posture can reach us at info@persooninc.com.
7. Data Retention
We retain personal data for as long as needed to provide the Services and for legitimate business and legal purposes. Account data is retained for the life of the account and deleted or anonymized after account closure; security logs and audit-trail entries are retained per our internal retention schedule. Connector content processed on a customer's behalf is retained while the source remains connected and is deleted under the customer agreement on disconnection or account deletion.
Deletion is applied to live systems immediately. Copies can persist in vendor-managed backups for a limited period until those backups expire on the provider's schedule; erasure is re-applied after any recovery from backup.
8. Your Privacy Rights
Depending on your jurisdiction (for example, under the GDPR/UK GDPR or U.S. state privacy laws), you may have the right to access, correct, delete, port, or restrict processing of your personal data, to object to certain processing, and to withdraw consent. You may also have the right to lodge a complaint with a supervisory authority.
To exercise these rights - including requesting deletion or export of your account and personal data - contact us at info@persooninc.com. Where we act as a processor for connected-source data, please direct requests to the relevant customer (controller); we will assist them as required. We will verify your identity before acting on a request and will respond within the timeframes required by applicable law.
9. U.S. State Privacy Laws & Do Not Track
Comprehensive state privacy laws apply only above defined thresholds. We do not currently meet the applicability thresholds of the CCPA/CPRA (California) or the Virginia, Colorado, Connecticut, Utah, or similar state statutes (for example, 100,000+ consumers or the revenue tests those laws set). We say that plainly rather than pretending otherwise - and we voluntarily extend the access, correction, deletion, and portability rights in Section 8 to all users regardless of state.
For California residents (CalOPPA): this Policy identifies the categories of personal data we collect (Section 2), how we use and share it (Sections 3 and 5), and how to review or request changes to your information (Section 8). We do not respond to browser "Do Not Track" signals; no third-party advertising trackers run on authenticated pages.
We do not sell or share personal data for cross-context behavioral advertising, and we do not use or disclose sensitive personal information outside the purposes these laws permit without an opt-out.
10. Email, Breach Notice & Accessibility
Service email (sign-in verification, security alerts, receipts) is transactional. Any marketing email we send includes a working unsubscribe link honored promptly and our physical postal address, as the CAN-SPAM Act requires; unsubscribing never affects service email.
If a breach of our systems results in unauthorized acquisition of your personal data, we will notify affected users consistent with applicable state breach-notification laws (including Wyoming's) without unreasonable delay, and will notify regulators where the law requires it.
We strive to keep the Services usable with current assistive technologies (WCAG 2.1 AA as our target) and treat accessibility barriers as bugs; report them to info@persooninc.com.
11. Security, Children & Changes
We apply administrative, technical, and organizational safeguards designed to protect personal data, including encryption in transit (TLS) and at rest, role-based access controls, and append-only audit logging. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
The Services are intended for business use and are not directed to children; we do not knowingly collect personal data from anyone under 16, and never from a child under 13 (COPPA). If we learn we hold a child's data, we delete it.
We may update this Policy from time to time. Material changes will be communicated through the Services or by email, and the effective date above will be updated. Questions may be directed to Persoon.ai Inc. at info@persooninc.com.