Introduction
This Privacy Policy explains how scomm.ai ("Company," "we," "us," or "our") collects, uses, discloses, and protects personal information when you use:
- Desktop applications and software programs
- Mobile applications (iOS and Android)
- Add-ons and paid features
- Related services and applications
By using our services, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree with this policy, please do not use our services.
Who Are We
scomm.ai is operated by:
Legal Entity Name: Media Routes Inc.
Registered Address: 86-50 Burnhamthorpe Rd., W., Mississauga ON L5B 3C2
Province/Territory: Ontario
Country: Canada
Contact Email: privacy@scomm.ai
Website: https://scomm.ai
For data protection purposes, we act as a Data Controller for personal information collected through our applications and related services.
Information We Collect
Information You Provide Directly
When you interact with our services, we may collect:
Account Information:
- Name
- Email address
- Account credentials (username and encrypted password)
- Profile information
Payment and Billing Information:
- Billing name and address
- Payment method details (processed by third-party payment processors)
- Transaction history
- Invoice information
Communications:
- Support inquiries and help requests
- Feedback and survey responses
- Email correspondence with our team
- Any other information you choose to provide
Automatically Collected Information
When you use our services, we automatically collect:
Technical Information:
- IP address
- Browser type and version
- Device type and identifiers
- Operating system (Windows, macOS, Linux, iOS, Android)
- Screen resolution
- Language preferences
Usage Information:
- Features used
- Time and date of usage
- Interactions with our services
- Error logs and diagnostic information
Tracking Technologies:
- Cookies and similar technologies
- Session identifiers
Application Version Information:
When our desktop or mobile applications check for updates:
- Version checking requests are sent to https://scomm-ai.github.io/version/index.json
- This is an HTTPS GET request
- No customer data, personal information, or identifiable information is transmitted in these requests
- Only the application's current version number is compared against the latest available version
- No logs of individual user update checks are maintained
Extension & Security Processing — IMPORTANT PRIVACY PROTECTIONS
WHAT WE DO NOT COLLECT OR ACCESS:
We want to be absolutely clear about what we DO NOT do:
- We DO NOT have access to your emails or their content
- We DO NOT read, store, or process email headers, metadata, subject lines, or sender information
- We DO NOT access your email accounts on Gmail, Microsoft, or any other email service
- We DO NOT store emails on our servers
- We DO NOT transmit email data to our servers
- We DO NOT track your email communications
Your emails remain stored exclusively on your email service provider (Gmail, Microsoft, etc.) and are never transmitted to or stored on scomm.ai servers.
HOW OUR SERVICES WORK:
Client-Side Processing Only:
Our applications operate with a privacy-by-design, client-side architecture:
- All spam filtering, phishing detection, and AI-powered search operate entirely on your own device (client-side)
- No email content, metadata, or identifiable information is sent to our servers
- Processing happens locally on your device using anonymous, non-traceable methods
- Search and filtering results remain on your device
Platform-Specific Processing:
- Desktop Applications (Windows, macOS, Linux): All core processing occurs on your desktop device
- Mobile Applications (iOS, Android): All core processing occurs on your mobile device
- Web Application: User login and authentication occur through the web application, but email processing remains client-side
Anonymous Threat Detection:
- Our security features may use anonymous, aggregated threat intelligence data that cannot be traced back to individual users
- Pattern matching and threat detection occur on your device without transmitting personal data
- Any threat intelligence shared is fully anonymized and does not contain user-identifiable information
What We Actually Store:
- Public cryptographic keys (for encryption of emails on your device)
- Billing and payment information
- Account signup details (name, email, encrypted password)
- Service preferences and settings
- Authentication tokens (for secure access to paid features)
Note: Private keys are the user's responsibility and are not stored on our servers. We employ a privacy-by-design approach where your email data never leaves your device and never reaches our servers.
Cryptographic Key Management
Public Key Storage:
- We store public cryptographic keys on our servers associated with each email address
- Public keys are used to enable encrypted communication
- Public keys do not allow us to decrypt or read your encrypted content
Private Key Storage — User Control:
Default (Recommended):
- Your private cryptographic keys remain exclusively on your client device (desktop, mobile)
- We never have access to unencrypted private keys
- You are solely responsible for backing up and securing your private keys
Optional Cloud Backup (User Choice):
- You may optionally upload a symmetrically encrypted copy of your private key to our servers
- Encryption uses AES-256-GCM algorithm (industry-standard encryption)
- You choose the encryption password — we do not have access to this password
- We cannot decrypt your private key without your password
- This encrypted backup allows you to restore your private key on new devices using your password
- You can delete this encrypted backup at any time
Important Security Note:
- We employ a zero-knowledge architecture for private keys
- Whether stored locally or as an encrypted backup, we cannot access your unencrypted private keys
- If you lose your password for the encrypted backup, we cannot recover your private key
Authentication and Single Sign-On (SSO)
For commercial add-ons and paid features:
We support Single Sign-On (SSO) through external identity providers including: Google, Microsoft, and other third-party identity providers.
What We Receive from Identity Providers:
- Email address (for account matching)
- Authentication confirmation
- We do NOT receive: Browsing history, Email content or access, Contacts, files, or other personal data from your SSO account
Token-Based Access:
After successful SSO authentication:
- We issue our own long-term refresh token and access token
- These tokens are used to: verify your subscription status, access paid features, retrieve billing information from our billing server (auth.scomm.ai)
- No other personally identifiable information (PII) is transmitted beyond what is necessary for authentication
Token Refresh Process:
- Access tokens are short-lived for security
- Your application sends the refresh token to auth.scomm.ai
- Our authentication server verifies the refresh token
- A new access token is issued, signed by our well-known authentication public key
- No additional personal information is transmitted during token refresh
Information from Third Parties
We may receive information about you from:
- Payment processors (transaction confirmations)
- Analytics providers (aggregated usage statistics)
- Public databases (for fraud prevention)
- Third-party identity providers (Google, Microsoft, etc.) when you use Single Sign-On (SSO) for authentication
Client-Side Architecture — Important Privacy Protection
Our applications operate with a privacy-by-design, client-side architecture:
Desktop Applications:
- All core application processing occurs on your desktop device
- Private keys stored using your OS secure store (Windows Credential Locker, macOS Keychain)
- Updates downloaded securely via HTTPS
iOS and Mobile Applications:
- All core application processing occurs on your mobile device
- Data stored in sandboxed application containers
- Diagnostic crash reporting may be handled by platform tools (e.g., Apple CrashReporter) unless you opt out in device settings
What Stays on Your Device
- Email content
- Email metadata and headers
- Private cryptographic keys (unless you choose encrypted backup)
- Local application data, cache, and user preferences
What We Store on Our Servers
- Account information (name, email, encrypted password)
- Public cryptographic keys
- Optionally: Symmetrically encrypted private keys (encrypted with your own password)
- Authentication tokens (refresh and access tokens)
- Billing and subscription information
- Application version information (for update notifications)
Email Service Providers (Gmail, Microsoft, etc.)
Our applications integrate with third-party email services using OAuth or modern authentication:
- We do not store your email provider passwords
- You manage access through your email provider's security settings
- You can revoke our application's access at any time through your Google Workspace, Microsoft 365, or other provider's account settings
- Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements
How we Use Your Information
We use the information we collect for the following purposes:
Service Delivery and Management:
- Provide, maintain, and improve our services across all platforms (desktop, mobile)
- Process transactions and send transaction notifications
- Deliver purchased add-ons and premium features
- Manage your account and preferences
- Provide customer support and respond to inquiries
- Authenticate users and maintain account security
- Issue and manage authentication tokens (refresh tokens and access tokens) for secure access to paid features
- Verify subscription status and deliver paid add-on features
Payment Processing:
- Process payments and subscription billing
- Generate invoices and transaction records
- Prevent payment fraud
Communications:
- Send service-related announcements and updates
- Respond to support requests
- Send marketing communications (with your consent where required)
- Notify you of changes to our services or policies
- Notify you of application version updates and security patches
Analytics and Improvement:
- Analyze usage patterns and trends (aggregated data only)
- Conduct research and development
- Test new features and improvements
- Generate aggregated statistical information
Security (Client-Side Only):
- Enable local spam and phishing detection on your device
- Provide AI-powered search capabilities on your device
- Maintain encrypted authentication credentials
- All security processing occurs on your device without data transmission to our servers
Legal Compliance:
- Comply with applicable laws and regulations
- Respond to legal requests and prevent harm
- Protect our rights and property
- Enforce our agreements
Legal Basis For Processing (PIPEDA & GDPR COMPLIANCE)
We process personal information on the following legal bases:
Consent:
- Where you have given clear consent for specific processing activities
- Marketing communications (you may withdraw consent at any time)
- Optional cookies and tracking (beyond essential cookies)
- Optional encrypted private key cloud backup (you choose to enable this feature)
Contractual Necessity:
- To perform our contract with you (provide services you requested)
- To process payments and deliver purchased products
- To manage your account and fulfill our obligations
- To authenticate users and provide secure access to paid features
- To issue and manage authentication tokens
Legitimate Interests:
- Service improvement and development
- Fraud prevention in payment processing
- Network and information security
- Direct marketing to existing customers (where permitted)
- Providing version update notifications for security and functionality
Legal Obligation:
- Compliance with tax and accounting requirements
- Response to legal processes and government requests
- Prevention of fraud and criminal activity
Cookies & Tracking Technologies
Types of Technologies We Use
Essential Session Data:
- Required for basic application functionality
- Session management and authentication
- Security features
- Authentication token management
- Cannot be disabled
Performance Tracking:
- Analytics and usage statistics
- Error tracking and diagnostics
- Feature optimization
Functional Data:
- Remember your preferences
- Personalization features
- Language and regional settings
Management
You can control tracking through:
- Application settings
- Device privacy controls
- Platform-specific privacy settings (iOS, Android, desktop OS)
Note: Disabling essential session data may impair application functionality and prevent authentication.
Third-Party Technologies
We may use technologies from third-party services:
- Analytics services (usage statistics)
- Payment processors (transaction security)
- Third-party identity providers (for SSO authentication)
These third parties operate under their own privacy policies.
Data Retention
Retention Periods
We retain personal information for as long as necessary to fulfill the purposes described in this Privacy Policy:
Account Information:
- Active accounts: Duration of account relationship
- Inactive accounts: 2 years after last login
- Deleted accounts: 30 days for recovery, then permanently deleted
Cryptographic Keys:
- Public keys: Duration of account relationship
- Encrypted private key backups: Until you delete them or close your account
- Permanently deleted within 30 days of account deletion
- Private keys (local): Never stored on our servers (user responsibility)
Authentication Tokens:
- Refresh tokens: Until revoked or account deleted
- Access tokens: Short-lived (typically hours), then automatically expired
- Token logs: 90 days for security monitoring
Payment Information:
- Transaction records: 7 years (tax and accounting requirements)
- Payment method details: Until subscription ends or updated
Communications:
- Support tickets: 3 years
- Marketing preferences: Until you unsubscribe
Usage Data:
- Analytics data: 26 months (aggregated)
- Error logs: 90 days
Version Check Logs:
- No personal data stored from version check requests
- Anonymous version check statistics: 12 months (aggregated)
Deletion and Anonymization
After retention periods expire:
- Personal information is permanently deleted or anonymized
- Anonymized data may be retained indefinitely for statistical purposes
- Backup copies are deleted within 90 days of primary deletion
- Cryptographic keys (public and encrypted private) are permanently deleted
- Authentication tokens are immediately revoked and deleted
Data Security
Security Measures
We implement industry-standard security measures:
Technical Safeguards:
- Encryption in transit (TLS/SSL for all communications)
- Encryption at rest for sensitive data
- Secure password hashing (bcrypt or equivalent)
- AES-256-GCM encryption for optional private key backups
- Cryptographic signing of authentication tokens
- Public key cryptography for secure communications
- Regular security updates and patches
- Firewall protection and intrusion detection
- Access controls and authentication
- Client-side encryption for email processing
Organizational Safeguards:
- Employee confidentiality agreements
- Access limited to authorized personnel
- Regular security training
- Incident response procedures
- Third-party security audits
Payment Security:
- PCI DSS compliance for payment processing
- Tokenization of payment data
- No storage of full credit card numbers
Authentication Security:
- Short-lived access tokens to limit exposure
- Secure token refresh mechanism via auth.scomm.ai
- Well-known public key infrastructure for token verification
- Protection against token theft and replay attacks
Privacy-by-Design Architecture:
- Email processing occurs entirely on your device
- No email content transmitted to our servers
- End-to-end encryption for sensitive operations
- Zero-knowledge architecture for email data and private keys
- Client-side processing across all platforms (desktop, mobile)
Data Breach Notification
In the event of a data breach:
- We will notify affected users within 72 hours
- Notification includes nature of breach and steps taken
- We will notify relevant authorities as required by law
- We will provide guidance on protective measures
- For cryptographic key compromises, we will provide immediate guidance on key rotation
Limitations
While we employ robust security measures:
- No system is 100% secure
- Internet transmission carries inherent risks
- You are responsible for protecting your account credentials and private keys
- You are responsible for protecting your private key encryption password (if using cloud backup)
- Loss of your private key encryption password means permanent loss of access to encrypted data
- Report suspicious activity immediately
Data Sharing And Disclosure
Service Providers
We share information with trusted third-party service providers:
Payment Processors:
- Stripe, PayPal, or other payment gateways
- Purpose: Process transactions
- Data shared: Billing information, transaction details
Analytics Providers:
- Analytics services
- Purpose: Usage analysis and service optimization
- Data shared: Anonymized usage data, IP addresses
Infrastructure Providers:
- Cloud hosting and storage services
- Purpose: Host services and databases
- Data shared: Account data, public keys, encrypted private key backups (encrypted with your password), service preferences (NOT email content)
Communication Services:
- Email service providers
- Purpose: Send transactional and marketing emails
- Data shared: Email addresses, names, communication preferences
Third-Party Identity Providers:
- Google, Microsoft, and other SSO providers
- Purpose: User authentication via SSO
- Data shared: Authentication requests, email address for account matching
All service providers are contractually bound to:
- Use data only for specified purposes
- Maintain confidentiality and security
- Comply with applicable privacy laws
What We NEVER Share:
- Email content or communications
- Email metadata or headers
- Private cryptographic keys (we don't have access to them)
- Private key encryption passwords (you choose these, we never see them)
- Decrypted authentication tokens from third-party providers
- Email account credentials for third-party services
Business Transfers
In the event of:
- Merger or acquisition
- Asset sale or reorganization
- Bankruptcy or insolvency
Your personal information may be transferred to the acquiring entity. You will be notified of any such transfer, and the new entity will be bound by this Privacy Policy.
Note: Encrypted private key backups would transfer encrypted (the acquiring entity still cannot decrypt without your password).
Legal Requirements
We may disclose information when required to:
- Comply with court orders or legal processes
- Respond to government requests
- Protect our rights and property
- Prevent fraud or criminal activity
- Protect safety of users or the public
We will notify you of legal requests unless prohibited by law.
Note: We cannot disclose private keys or decrypt private key backups as we do not have access to the decryption passwords.
Aggregate and Anonymous Data
We may share aggregated or anonymized data that cannot identify you:
- Industry reports and statistics
- Research and publications
- Threat intelligence (anonymized security patterns)
- Aggregate version adoption statistics (no user identification)
International Data Transfers
Transfer Mechanisms
Your information may be transferred to and processed in countries other than your country of residence:
Primary Data Storage: Canada
Potential Transfer Locations:
- United States (cloud services)
- European Union (support services)
- Other countries where our service providers operate
Note: Email content is NEVER transferred anywhere as it remains on your device and your email provider's servers.
Safeguards
For transfers outside Canada/EU/UK:
- Standard Contractual Clauses (EU Commission approved)
- Privacy Shield certification (where applicable)
- Adequacy decisions by relevant authorities
- Contractual commitments from recipients
- End-to-end encryption for sensitive data (private key backups remain encrypted during transfer)
Your Rights
You have the right to:
- Object to international transfers
- Request information about safeguards
- Obtain copies of transfer agreements
Your Privacy Rights
Rights Under PIPEDA (Canada)
Access:
- Request copies of your personal information
- Receive information about how it's used
- Request information about stored public keys and encrypted private key backups
Correction:
- Update inaccurate or incomplete information
- Request corrections to your records
Withdrawal of Consent:
- Withdraw consent for processing at any time
- May limit service availability
- Delete encrypted private key backups
- Revoke authentication tokens
Complaint:
- Lodge complaints with Privacy Commissioner of Canada
Rights Under GDPR (EU/UK)
Access (Article 15):
- Obtain confirmation of processing
- Receive copy of your data
Rectification (Article 16):
- Correct inaccurate data
- Complete incomplete data
Erasure (Article 17) — "Right to be Forgotten":
- Request deletion of your data
- Subject to legal retention requirements
- Includes deletion of public keys, encrypted private key backups, and authentication tokens
Restriction of Processing (Article 18):
- Limit how we use your data
- Applicable in specific circumstances
Data Portability (Article 20):
- Receive data in machine-readable format
- Transfer data to another provider
- Export your public keys and encrypted private key backups
Objection (Article 21):
- Object to processing based on legitimate interests
- Object to direct marketing at any time
Automated Decision-Making (Article 22):
- Right not to be subject to automated decisions
- We do not use automated decision-making
Rights Under CCPA (California)
Right to Know:
- Categories of personal information collected
- Sources and purposes of collection
- Third parties with whom information is shared
Right to Delete:
- Request deletion of personal information
- Subject to exceptions
Right to Opt-Out:
- Opt out of sale of personal information (we do not sell data)
Right to Non-Discrimination:
- Not be discriminated against for exercising rights
How to Exercise Your Rights
To exercise any of these rights:
- Email: privacy@scomm.ai
- Subject Line: Privacy Rights Request - [Type of Request]
Include:
- Your full name
- Email address associated with account
- Specific right you wish to exercise
- Verification information (for security)
Response Time:
- Acknowledgment within 5 business days
- Complete response within 30 days (GDPR/PIPEDA)
- 45 days for CCPA requests
- Extensions communicated if needed
- Verification: We may request additional information to verify your identity before fulfilling requests.
- No Fee: Requests are processed free of charge (unless manifestly unfounded or excessive).
Special Note on Cryptographic Data:
- We can provide your public keys and encrypted private key backups
- We cannot decrypt your private key backups (you control the encryption password)
- We can delete all cryptographic data upon request
Children's Privacy
Age Restriction:
- Our applications and services are not intended for children under 13 (16 in EU)
- We do not knowingly collect information from children
Parental Notification:
If we discover we have collected information from a child:
- We will delete it immediately
- We will notify parents/guardians if possible
Parental Rights:
Parents may:
- Request access to their child's information
- Request deletion of information
- Refuse further collection
Contact us immediately if:
- You believe a child has provided information
- You are a parent seeking to exercise rights
Email Service Providers
Third-Party Email Services
Your emails are stored on third-party email services (Gmail, Microsoft, etc.):
- We do not control their privacy practices
- Your email data is subject to their privacy policies
- We do not access or retrieve your emails from these services
- Email content remains exclusively with your email provider
Our Integration
- Our applications connect to your email service using OAuth authentication
- We receive only the permissions you grant
- All processing happens on your device (desktop, mobile)
- No email content is transmitted to our servers
Your Responsibilities
- Review privacy policies of your email service provider
- Understand what permissions you grant to our applications
- Maintain security of your email account credentials
- Keep your private encryption keys secure
Platform-Specific Information
Desktop Applications (Windows, macOS, Linux)
Our desktop applications:
- Install locally on your computer
- Process all email operations on your device
- Store private keys locally (unless you enable encrypted cloud backup)
- Connect to auth.scomm.ai only for subscription verification
- Check for updates via https://scomm-ai.github.io/version/index.json (no personal data transmitted)
Mobile Applications (iOS, Android)
Our mobile applications:
- Install on your mobile device
- Process all email operations on your device
- Store private keys in device secure storage (unless you enable encrypted cloud backup)
- Connect to auth.scomm.ai only for subscription verification
- Check for updates via https://scomm-ai.github.io/version/index.json (no personal data transmitted)
- Follow platform-specific security and privacy guidelines
Marketing Communications
Types of Communications
We may send:
Transactional Messages (cannot opt out):
- Purchase confirmations
- Account notifications
- Security alerts
- Service updates
- Feature announcements
- Application version update notifications
- Authentication and token-related alerts
Marketing Messages (can opt out):
- Product announcements
- Promotional offers
- Newsletters
- Tips and tutorials
Consent and Opt-Out
CASL Compliance (Canada):
- We obtain express or implied consent before sending commercial electronic messages
- Every marketing email includes an unsubscribe link
- We honor opt-out requests within 10 business days
You can opt out by:
- Clicking "unsubscribe" in any marketing email
- Emailing privacy@scomm.ai with "Unsubscribe" in the subject
- Updating preferences in your account settings
- Adjusting notification settings in the application
Opting out of marketing does not affect transactional or service-related communications.
California-Specific Disclosures
Categories of Personal Information Collected
In the past 12 months, we have collected the following categories of personal information (as defined by CCPA):
- Identifiers (name, email, IP address)
- Commercial information (purchase history, payment details)
- Internet activity (service usage patterns, feature interactions)
- Geolocation data (approximate location from IP)
We do NOT collect:
- Email content or communications
- Email metadata or headers
- Biometric information
- Sensitive personal information beyond what is necessary for account security
Sources of Information
We collect personal information from:
- Directly from you (account registration, purchases)
- Automatically through your use of our services
- Third parties (payment processors, analytics providers, identity providers)
Business Purposes
We use personal information for purposes described in Section 3 (How We Use Your Information).
Sharing for Business Purposes
We share information with service providers for business purposes as described in Section 8 (Data Sharing).
No Sale of Personal Information
We do not sell personal information as defined by CCPA.
We do not share personal information for cross-context behavioral advertising.
Shine the Light Law
California residents may request information about disclosure of personal information to third parties for direct marketing purposes. We do not share personal information with third parties for their direct marketing purposes.
Changes To This Privacy Policy
Updates and Modifications
We reserve the right to update this Privacy Policy at any time to reflect:
- Changes in our practices
- Legal or regulatory requirements
- New features or services
- Feedback and improvements
- Updates to authentication mechanisms or cryptographic protocols
- New platform support (additional operating systems or devices)
Notice of Changes
When we make changes:
Material Changes:
- We will provide prominent notice (email notification, in-app notification)
- Effective 30 days after notice
- You may review changes before they take effect
Non-Material Changes:
- Updated "Last Updated" date
- Effective immediately upon posting
- Continued use constitutes acceptance
Review and Acceptance
We encourage you to review this Privacy Policy periodically.
Continued use of our services after changes become effective constitutes acceptance of the updated policy.
If you do not agree with changes, you should discontinue use and may request deletion of your account.
Contact Information
Privacy Inquiries
For privacy-related questions, concerns, or requests:
Email: privacy@scomm.ai
Subject Line: Privacy Inquiry
Mailing Address:
scomm.ai (Media Routes Inc.)
86-50 Burnhamthorpe Rd W,
Mississauga, ON L5B 3C2
Canada
Data Protection Officer
If required by applicable law, you may contact our Data Protection Officer at: dpo@scomm.ai
Regulatory Authorities
You have the right to lodge a complaint with relevant supervisory authorities:
- Canada: Office of the Privacy Commissioner of Canada (www.priv.gc.ca)
- EU/UK: Your local data protection authority
- California: California Attorney General (oag.ca.gov)
Response Time
We strive to respond to all inquiries within:
- 5 business days for acknowledgment
- 30 days for complete response
- 60 days for complex requests (with notification of extension)
Accessibility
We are committed to ensuring this Privacy Policy is accessible to everyone.
If you have difficulty accessing this policy or require it in an alternative format:
- Contact privacy@scomm.ai
- Request formats: large print, audio, plain language summary
We will provide reasonable accommodations within 10 business days.
Language
This Privacy Policy is provided in English.
If translated versions are made available, the English version prevails in case of conflicts or discrepancies.
Summary Of Our Privacy Commitments
Privacy-First Architecture:
- ✓ All email processing happens on YOUR device (desktop, mobile), not our servers
- ✓ We never access, read, or store your email content
- ✓ We never see email headers, metadata, or sender information
- ✓ Your emails stay with your email provider (Gmail, Microsoft, etc.)
- ✓ Client-side architecture across all platforms
What We Actually Collect:
- ✓ Account information (name, email, encrypted password)
- ✓ Billing information (for purchases)
- ✓ Service usage data (features used)
- ✓ Public cryptographic keys (for email encryption)
- ✓ Optionally: Encrypted private key backups (encrypted with YOUR password using AES-256-GCM)
- ✓ Authentication tokens (for secure access to paid features)
What We Never Collect:
- ✗ Email content or communications
- ✗ Email metadata or headers
- ✗ Your email provider data
- ✗ Unencrypted private cryptographic keys
- ✗ Your private key encryption passwords
- ✗ Personal data during version update checks
Your Rights:
- ✓ Access your data (including cryptographic keys)
- ✓ Correct inaccurate information
- ✓ Delete your account and data (including all keys and tokens)
- ✓ Export your data
- ✓ Opt out of marketing
- ✓ File complaints with regulators
Security Measures:
- ✓ Zero-knowledge architecture for private keys
- ✓ AES-256-GCM encryption for optional key backups
- ✓ Short-lived access tokens for enhanced security
- ✓ Cryptographically signed authentication tokens
- ✓ TLS/SSL encryption for all communications
- ✓ Client-side processing on all platforms
Acknowledgment
By using scomm.ai applications and services, you acknowledge that you have read, understood, and agree to this Privacy Policy.
If you do not agree with this policy, please do not use our services.
Effective Date: February 06, 2026
Last Updated: March 29, 2026
Version: 2.0
END OF PRIVACY POLICY