TsType Scout
PrivacyTermsCookiesContactOpen app ↗

Trust / Data stewardship

Privacy,
in plain type.

This policy explains what Type Scout handles when you build a type system, create an account, audit a public website, or allow advertising.

Effective dateAugust 9, 2026OperatorType Scout
On this pageScopeInformation handledHow it is usedSharingRetentionYour choicesSecurityContact

Optional product research. Pricing votes remain anonymous daily aggregates. Separately, you may explicitly volunteer for a 20-minute interview; that private recruiting queue stores only your email, professional role, consent record, signup time, and recruiting status for up to 90 days.

1. Scope and operator

This policy applies to the Type Scout web application operated by Type Scout. It does not control the privacy practices of websites you choose to audit, font providers, Google, or other third parties.

Type Scout is a typography decision tool. A website audit may read up to five ordinary same-origin public pages in a temporary, isolated browser session; it does not sign in to the audited site or follow account, checkout, administration, download, or mutation-like routes.

DOCX and PDF document audits run locally in your browser. Selected files and extracted results are not uploaded or saved automatically; they remain in the active page until you clear the audit, reload, or close it. Optional OCR also runs locally after its worker, language model, and processing components are downloaded.

2. Information Type Scout handles

CategoryExamplesWhen
Device-local project dataBriefs, project names, font roles, palettes, saved directions, settings, and privacy choices.Stored in your browser as you use the app.
Optional account dataEmail address, verification status, salted password hash, session token hash, short-lived verification or password-recovery token hash, and an explicit server copy of your projects.When you create or verify an account, request account recovery, or save a server copy.
Public direction reportsProject name, brief, decision note, font roles, scores, rationale, source and license labels, and the latest recipient approval or revision request. A recipient name is optional; a revision note is required only when requesting changes.Report content and response status are available to anyone with the unguessable link until you revoke it. Response names and notes are stored with the owner’s report and disclosed before submission. Email verification is required before publishing.
Optional feedbackA rating, category, message, and a reply email only if you provide one.When you submit the feedback form.
Anonymous analyticsDaily aggregate counts for coarse actions such as opening a feature or completing an audit. Project content, audited URLs, account identifiers, IP addresses, and individual event histories are not stored in this analytics dataset.Only after you allow analytics.
Website-audit inputs and resultsThe public URL you submit; rendered text, computed typography, font resources, colors, and a viewport image returned to your browser.When you run an audit. The service processes the page transiently and does not intentionally retain the audit result.
Operational dataRequest time, request identifier, route, response status, duration, security events, and diagnostic logs. Application request logs are designed to omit query strings, project content, IP addresses, and full user-agent strings.When the service receives requests or protects against abuse.
Advertising dataCookies, IP addresses, device identifiers, ad impressions, and interactions handled by Google or approved advertising partners.Only after advertising is enabled and subject to applicable consent requirements.

3. How information is used

  • Provide font discovery, project management, saved systems, and account features.
  • Run requested public-page typography audits and return evidence to your browser.
  • Contact people who explicitly volunteer for product-research interviews and manage that recruiting queue.
  • Protect accounts, prevent abuse, diagnose failures, and maintain service reliability.
  • Show and measure advertising only when configured and permitted.
  • Respond to support, privacy, or legal requests.

4. When information is shared

Information may be processed by infrastructure, security, database, email, analytics, consent-management, and advertising providers used to operate Type Scout. Google and other approved ad vendors may process identifiers when advertising is enabled. Type Scout may also disclose information when legally required, to protect users or the service, or as part of a business transfer subject to appropriate safeguards.

Type Scout does not sell project briefs or font decisions as a standalone data product.

5. Retention

Browser projects remain on your device until you clear them or browser storage. Account sessions are designed to expire after 30 days, unused email-verification links after 24 hours, and unused password-recovery links after 30 minutes. Research-interview volunteer records automatically leave the active recruiting queue after 90 days and may be removed sooner on request or by the operator. Requesting a fresh verification link invalidates the earlier link. Account and project copies remain until deleted or until the service applies a documented retention limit. The self-hosted account-store configuration keeps up to 14 days of checksum-verified daily recovery snapshots on the configured protected data volume; a managed host may use a different documented backup schedule. Saved audit records remain private by default and omit screenshots; records and any published audit or direction links remain until you remove, privatize, or revoke them, or delete the owning account. Transient website-audit browser sessions close after each audit. Document-audit files and results remain only in the active browser page unless you choose to download a report. Operational logs should be retained only as long as needed for security, reliability, and legal obligations.

6. Your choices and rights

You can use core project tools without enabling analytics or advertising, keep projects only in your browser, avoid creating an account, decline research invitations, or change optional choices. Interview volunteers may withdraw at any time. Signed-in users can download a JSON copy of their account, server projects, shared directions, and saved audits; make audit links private; revoke direction links; delete individual records; or permanently delete the account from the Project Manager. You may also request access, correction, deletion, portability, or restriction where applicable. Advertising personalization can be controlled through Google’s ad settings.

To withdraw from research or submit a privacy request, contact Privacy email will be published before launch. Identity verification may be required before fulfilling a request.

7. Security and international processing

Type Scout uses measures such as password hashing, opaque session and verification tokens, verified email before public sharing, secure cookies in production, request-size limits, same-origin checks, private-network blocking for audits, and rate limits. Email links use the configured public application origin rather than an incoming host value. Temporary delivery failures may be retried using one message identifier to help the email provider prevent duplicate sends. Delivery monitoring records category, timing, attempt count, and coarse outcome without recording the recipient, message contents, account identifier, or verification token in application events. Signed-in users can review active browser sessions, revoke an individual session, sign out everywhere, and change a password; a password change rotates the current session and ends all others. Session labels use only a coarse browser and device category. No system is completely secure. Service providers may process information in countries different from yours, subject to applicable contractual or legal safeguards.

Children

Type Scout is not directed to children under 13 and is not intended to knowingly collect their personal information. Advertising settings must be configured appropriately for the intended audience before launch.

8. Contact and updates

Questions or requests: Privacy email will be published before launch. Material policy updates will be reflected by changing the effective date and, where appropriate, presenting an additional notice.

This operational template should be reviewed by qualified counsel before public launch and updated with the final legal entity, jurisdiction, vendors, retention schedule, and contact address.

© Type Scout
AppTermsCookiesContact