ScoltoBack to home
Legal · Privacy

Privacy Policy

Last updated · September 19, 2026

Scolto (“Scolto”, “we”, “us”) is a business-to-business software service that helps brand, marketing, and insights teams research public social-media conversation. This policy explains what personal information we collect, how we use it, and the choices you have. Scolto is operated from Israel; for our full operator and registration details, contact support@scolto.com.

1. Information we collect

Account information

We use Single Sign-On with Google or Microsoft. When you sign in we receive your name, email address, and profile picture from that provider. We do not receive or store your Google/Microsoft password.

Content you submit

The briefs, questions, prompts, and configuration you enter, and the reports, dashboards, and other outputs Scolto generates for you. This is your workspace content.

Usage and device data

Log data such as IP address, browser type, pages viewed, feature usage, and timestamps, collected to operate, secure, and improve the service.

Billing data

Payments are processed by our merchant of record, Lemon Squeezy (Lemon Squeezy, LLC). We receive order and subscription details (e.g. plan, usage balance, country for tax) but we do not collect or store your full card number.

Publicly available content we analyse for you

To fulfil your research requests, Scolto retrieves and analyses content that is publicly available on social platforms and the open web (for example public posts, videos, comments, reviews, and press), together with content from licensed data providers. We do not access private messages, DMs, or non-public accounts.

2. How we use information

  • To provide, maintain, and secure the service and your account.
  • To run the research you request and deliver briefs, dashboards, and reports.
  • To process payments, meter and manage your plan usage, and prevent fraud and abuse.
  • To respond to your support requests at support@scolto.com.
  • To analyse and improve product performance and reliability.
  • To comply with legal obligations and enforce our terms.

We do not sell your personal information. We do not use your workspace content (your briefs or generated outputs) to train our or third parties’ general-purpose AI models.

3. Legal bases

Where the GDPR or similar laws apply, we process personal data on the bases of performance of our contract with you, our legitimate interests in operating and improving the service, your consent where required, and compliance with legal obligations.

4. Service providers and sharing

We share data with vetted providers who process it on our behalf under contract, including:

  • Google Cloud Platform & Firebase - hosting, database, authentication.
  • Google Vertex AI / Gemini - AI model processing.
  • Lemon Squeezy - payments and billing (merchant of record).
  • Licensed data providers - supply of public social and web content.
  • Langfuse and Google Cloud Trace - AI tracing, so we can diagnose a failed or slow answer. Traces carry a sample of prompts and model responses, with email addresses, phone numbers and credentials removed automatically before they leave our systems.
  • Sentry - error monitoring.
  • PostHog (EU-hosted) and Google Analytics 4 - product and marketing analytics. See section 5.
  • Infrastructure providers - performance and security.

We may also disclose information to comply with law, to protect our rights and users, or as part of a merger or acquisition (with notice where required).

5. Analytics, cookies, and session recording

We measure how the site and the product are used so we can find what is broken or confusing and fix it. Two tools do that, and what each is allowed to store on your device depends on the choice you make in the cookie banner.

Before you choose, and if you decline

PostHog runs in a cookieless mode: it counts page views and product events without storing anything on your device - no cookies, no local storage - and session recording stays switched off. Google Analytics does not load at all. We measure this way so that our usage numbers describe every visitor, instead of only the people who accept.

If you accept

PostHog may then keep a first-party analytics identifier on your device, so that a returning visit can be recognised as the same journey, and it records your session: the pages, clicks, and scrolling of your visit, replayed like a video. Session recording runs only if you accept. Every text input is masked before the recording leaves your browser, so what you type is not captured by it. Google Analytics 4 also loads, for marketing measurement - which page, search, or campaign brought you here.

Where this goes, and changing your mind

PostHog processes this data on our behalf and our project is hosted in the European Union. You can change your choice at any time: clear cookies and site data for this site in your browser, and the banner returns on your next visit.

Cookies that are strictly necessary - the ones that keep you signed in - are always set. They are not analytics, and the banner does not cover them.

6. International transfers

We and our providers may process data in countries other than yours. Where required, we rely on appropriate safeguards such as the EU Standard Contractual Clauses.

7. Data retention

We keep personal data for as long as your account is active and as needed to provide the service, then for a reasonable period to meet legal, accounting, and security obligations. You can ask us to delete your account and associated workspace content.

Records of agent design sessions

When anyone designs an agent with our setup assistant, we keep a record of that session - the brief that was typed, the questions our assistant asked and the answers given, and the plan it produced. This includes sessions from visitors who never created an account, because the brief is typed before any sign-in. We keep these records for as long as they are useful for understanding and improving the product, with no fixed expiry, and we do not use them to build a profile of you or for advertising. To have a session record deleted, email support@scolto.com and tell us roughly when you used it and what you were researching, so we can find it. If you delete your account, we keep the session record itself but cut you out of it: your account, the sign-in, how you arrived and the link to anything you created are removed, so what remains is an anonymous record of a design session with nothing pointing back to you.

8. Security

We use industry-standard measures including encryption in transit, access controls, and managed cloud infrastructure. No method of transmission or storage is completely secure, but we work to protect your information and to notify you of material incidents as required by law.

9. Your rights

Depending on your location, you may have the right to access, correct, export, or delete your personal data, to object to or restrict certain processing, and to withdraw consent. To exercise any right, email support@scolto.com. You also have the right to complain to your local data-protection authority.

10. Children

Scolto is a business tool and is not intended for anyone under 18. We do not knowingly collect personal data from children.

11. Changes to this policy

We may update this policy from time to time. We will post the new version here and update the “Last updated” date; material changes will be communicated where appropriate.

12. Contact

Questions or requests: support@scolto.com. Scolto is operated from Israel; full operator details are available on request.