Launch date: Saturday 1st of August 2026

Privacy Policy

Last updated: March 2026

Introduction

This Privacy Policy explains how scomm.ai ("Company," "we," "us," or "our") collects, uses, discloses, and protects personal information when you use the scomm.ai website (https://scomm.ai).

By using our website, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree with this policy, please do not use our website.

Who Are We

scomm.ai is operated by:

Legal Entity Name: Media Routes Inc.

Registered Address: 86-50 Burnhamthorpe Rd., W., Mississauga ON L5B 3C2

Province/Territory: Ontario

Country: Canada

Contact Email: privacy@scomm.ai

Website: https://scomm.ai

For data protection purposes, we act as a Data Controller for personal information collected through our website.

Information We Collect

Information You Provide Directly

When you interact with our website, we may collect:

Account Information:

  • Name
  • Email address
  • Account credentials (username and encrypted password)
  • Profile information

Payment and Billing Information:

  • Billing name and address
  • Payment method details (processed by third-party payment processors)
  • Transaction history
  • Invoice information

Affiliate Program Information:

  • Business name
  • Tax identification numbers (if applicable)
  • Payment details
  • Marketing website URLs
  • Promotional materials

Communications:

  • Support inquiries and help requests
  • Feedback and survey responses
  • Email correspondence with our team
  • Any other information you choose to provide

Automatically Collected Information

When you use our website, we automatically collect:

Technical Information:

  • IP address
  • Browser type and version
  • Device type and identifiers
  • Operating system
  • Screen resolution
  • Language preferences

Usage Information:

  • Pages visited and features used
  • Time and date of visits
  • Referring website or source
  • Click-through and navigation paths
  • Search queries within our website
  • Error logs and diagnostic information

Tracking Technologies:

  • Cookies and similar technologies
  • Pixel tags and web beacons
  • Session identifiers
  • Affiliate tracking parameters

Application Version Information

When our desktop or mobile applications check for updates:

  • Version checking requests are sent to https://scomm-ai.github.io/version/index.json
  • This is an HTTPS GET request
  • No customer data, personal information, or identifiable information is transmitted in these requests
  • Only the application's current version number is compared against the latest available version

Information from Third Parties

We may receive information about you from:

  • Payment processors (transaction confirmations)
  • Analytics providers (aggregated usage statistics)
  • Affiliate networks (if you join through a third-party platform)
  • Public databases (for fraud prevention)
  • Third-party identity providers (Google, Microsoft, etc.) when you use Single Sign-On (SSO) for authentication

How We Use Your Information

We use the information we collect for the following purposes:

Service Delivery and Management:

  • Provide, maintain, and improve our website services
  • Process transactions and send transaction notifications
  • Manage your account and preferences
  • Provide customer support and respond to inquiries
  • Authenticate users and maintain account security
  • Issue and manage authentication tokens (refresh tokens and access tokens) for secure access to paid features
  • Verify subscription status and deliver paid add-on features

Payment Processing:

  • Process payments and subscription billing
  • Generate invoices and transaction records
  • Prevent payment fraud

Affiliate Program Administration:

  • Track referrals and calculate commissions
  • Process affiliate payments
  • Provide performance reports and analytics
  • Communicate program updates and opportunities

Communications:

  • Send service-related announcements and updates
  • Respond to support requests
  • Send marketing communications (with your consent where required)
  • Notify you of changes to our services or policies
  • Notify you of application version updates and security patches

Analytics and Improvement:

  • Analyze usage patterns and trends (aggregated data only)
  • Conduct research and development
  • Test new features and improvements
  • Generate aggregated statistical information

Legal Compliance:

  • Comply with applicable laws and regulations
  • Respond to legal requests and prevent harm
  • Protect our rights and property
  • Enforce our agreements

Cryptographic Key Management

Public Key Storage

For email encryption functionality:

  • We store public cryptographic keys on our servers associated with each email address
  • Public keys are used to enable encrypted communication
  • Public keys do not allow us to decrypt or read your encrypted content

Private Key Storage - User Control

Default (Recommended):

  • Your private cryptographic keys remain exclusively on your client device (desktop, iOS, or mobile)
  • We never have access to unencrypted private keys
  • You are solely responsible for backing up and securing your private keys

Optional Cloud Backup (User Choice):

  • You may optionally upload a symmetrically encrypted copy of your private key to our servers
  • Encryption uses AES-256-GCM algorithm (industry-standard encryption)
  • You choose the encryption password - we do not have access to this password
  • We cannot decrypt your private key without your password
  • This encrypted backup allows you to restore your private key on new devices using your password
  • You can delete this encrypted backup at any time

Important Security Note:

  • We employ a zero-knowledge architecture for private keys
  • Whether stored locally or as an encrypted backup, we cannot access your unencrypted private keys
  • If you lose your password for the encrypted backup, we cannot recover your private key

Authentication And Token Management

Single Sign-On (SSO) Authentication

For commercial add-ons and paid features:

  • We support Single Sign-On (SSO) ,through external identity providers including:
    • Google
    • Microsoft
    • Other third-party identity providers
  • Upon successful SSO authentication, the identity provider confirms your identity
  • We receive minimal information from the identity provider (typically email address and authentication confirmation)

Token-Based Access

After successful SSO authentication:

  • We issue our own long-term refresh token and access token
  • These tokens are used to:
    • Verify your subscription status
    • Access paid features
    • Retrieve billing information from our billing server (auth.scomm.ai)
  • No other personally identifiable information (PII) is transmitted beyond what is necessary for authentication

Token Refresh Process

  • Access tokens are short-lived for security
  • To obtain a new access token:
    • Your application sends the refresh token to auth.scomm.ai
    • Our authentication server verifies the refresh token
    • A new access token is issued, signed by our well-known authentication public key
    • No additional personal information is transmitted during token refresh

What We Do NOT Collect During Authentication

  • We do not collect browsing history from identity providers
  • We do not access your email content through SSO providers
  • We do not collect contacts, files, or other personal data from your SSO account
  • We only receive authentication confirmation and the email address associated with your account

Client-Side Architecture - Important Privacy Protection

Client-Side Processing

Our application operates with a privacy-by-design, client-side architecture:

Desktop Applications:

  • All core application processing occurs on your desktop device
  • Data processing happens locally without transmission to our servers

iOS and Mobile Applications:

  • All core application processing occurs on your mobile device
  • Data processing happens locally without transmission to our servers

Web Application (Desktop Platforms):

  • User login and authentication occur through the web application
  • After authentication, most processing occurs client-side in your browser
  • Minimal data is transmitted to our servers (only authentication tokens and subscription verification)

What Stays on Your Device

The following never leave your device:

  • Email content
  • Email metadata and headers
  • Private cryptographic keys (unless you choose encrypted backup)
  • Local application data and cache
  • User preferences and settings

What We Store on Our Servers

We only store:

  • Account information (name, email, encrypted password)
  • Public cryptographic keys (for encryption purposes)
  • Optionally: Symmetrically encrypted private keys (if you choose cloud backup with your own password)
  • Authentication tokens (refresh and access tokens)
  • Billing and subscription information
  • Application version information (for update notifications)

Legal Basis For Processing (PIPEDA & GDPR COMPLIANCE)

We process personal information on the following legal bases:

Consent:

  • Where you have given clear consent for specific processing activities
  • Marketing communications (you may withdraw consent at any time)
  • Optional cookies and tracking (beyond essential cookies)
  • Optional encrypted private key cloud backup (you choose to enable this feature)

Contractual Necessity:

  • To perform our contract with you (provide services you requested)
  • To process payments and deliver purchased products
  • To manage your account and fulfill our obligations
  • To authenticate users and provide secure access to paid features
  • To issue and manage authentication tokens

Legitimate Interests:

  • Service improvement and development
  • Fraud prevention in payment processing
  • Network and information security
  • Direct marketing to existing customers (where permitted)
  • Providing version update notifications for security and functionality

Legal Obligation:

  • Compliance with tax and accounting requirements
  • Response to legal processes and government requests
  • Prevention of fraud and criminal activity

Cookies And Tracking Technologies

Types of Cookies We Use

Essential Cookies:

  • Required for basic website functionality
  • Session management and authentication
  • Security features
  • Authentication token management
  • Cannot be disabled

Performance Cookies:

  • Analytics and usage statistics
  • Error tracking and diagnostics
  • A/B testing and optimization

Functional Cookies:

  • Remember your preferences
  • Personalization features
  • Language and regional settings

Marketing/Advertising Cookies:

  • Affiliate tracking and attribution
  • Interest-based advertising
  • Campaign performance measurement
  • Retargeting and remarketing

Cookie Management

You can control cookies through:

  • Browser settings (block all cookies or specific types)
  • Our cookie consent banner (on first visit)
  • Third-party opt-out tools
  • Do Not Track signals (where supported)

Note: Disabling essential cookies may impair website functionality and prevent authentication.

Third-Party Cookies

We use cookies from third-party services:

  • Google Analytics (usage statistics)
  • Payment processors (transaction security)
  • Advertising networks (campaign tracking)
  • Social media platforms (sharing features)
  • Third-party identity providers (for SSO authentication)

These third parties operate under their own privacy policies.

Data Retention

Retention Periods

We retain personal information for as long as necessary to fulfill the purposes described in this Privacy Policy:

Account Information:

  • Active accounts: Duration of account relationship
  • Inactive accounts: 2 years after last login
  • Deleted accounts: 30 days for recovery, then permanently deleted

Cryptographic Keys:

  • Public keys: Duration of account relationship
  • Encrypted private key backups: Until you delete them or close your account
  • Permanently deleted within 30 days of account deletion

Authentication Tokens:

  • Refresh tokens: Until revoked or account deleted
  • Access tokens: Short-lived (typically hours), then automatically expired
  • Token logs: 90 days for security monitoring

Payment Information:

  • Transaction records: 7 years (tax and accounting requirements)
  • Payment method details: Until subscription ends or updated

Communications:

  • Support tickets: 3 years
  • Marketing preferences: Until you unsubscribe

Website Usage Data:

  • Analytics data: 26 months (aggregated)
  • Server logs: 90 days

Affiliate Data:

  • Active affiliates: Duration of program participation
  • Inactive affiliates: 3 years after last commission payment

Version Check Logs:

  • No personal data stored from version check requests
  • Anonymous version check statistics: 12 months (aggregated)

Deletion and Anonymization

After retention periods expire:

  • Personal information is permanently deleted or anonymized
  • Anonymized data may be retained indefinitely for statistical purposes
  • Backup copies are deleted within 90 days of primary deletion
  • Cryptographic keys (public and encrypted private) are permanently deleted
  • Authentication tokens are immediately revoked and deleted

Data Security

Security Measures

We implement industry-standard security measures:

Technical Safeguards:

  • Encryption in transit (TLS/SSL for all communications)
  • Encryption at rest for sensitive data
  • Secure password hashing (bcrypt or equivalent)
  • AES-256-GCM encryption for optional private key backups
  • Cryptographic signing of authentication tokens
  • Public key cryptography for secure communications
  • Regular security updates and patches
  • Firewall protection and intrusion detection
  • Access controls and authentication

Organizational Safeguards:

  • Employee confidentiality agreements
  • Access limited to authorized personnel
  • Regular security training
  • Incident response procedures
  • Third-party security audits

Payment Security:

  • PCI DSS compliance for payment processing
  • Tokenization of payment data
  • No storage of full credit card numbers

Authentication Security:

  • Short-lived access tokens to limit exposure
  • Secure token refresh mechanism via auth.scomm.ai
  • Well-known public key infrastructure for token verification
  • Protection against token theft and replay attacks

Client-Side Security:

  • Zero-knowledge architecture - we cannot access your unencrypted private keys
  • Client-side encryption before any data leaves your device
  • Local storage of sensitive data on your device only

Data Breach Notification

In the event of a data breach:

  • We will notify affected users within 72 hours
  • Notification includes nature of breach and steps taken
  • We will notify relevant authorities as required by law
  • We will provide guidance on protective measures
  • For cryptographic key compromises, we will provide immediate guidance on key rotation

Limitations

While we employ robust security measures:

  • No system is 100% secure
  • Internet transmission carries inherent risks
  • You are responsible for protecting your account credentials
  • You are responsible for protecting your private key encryption password (if using cloud backup)
  • Loss of your private key encryption password means permanent loss of access to encrypted data
  • Report suspicious activity immediately

Data Sharing And Disclosure

Service Providers

We share information with trusted third-party service providers:

Payment Processors:

  • Stripe, PayPal, or other payment gateways
  • Purpose: Process transactions
  • Data shared: Billing information, transaction details

Analytics Providers:

  • Google Analytics, Mixpanel, or similar
  • Purpose: Usage analysis and website optimization
  • Data shared: Anonymized usage data, IP addresses

Infrastructure Providers:

  • Cloud hosting and storage services
  • Purpose: Host website and databases
  • Data shared: Account data, public keys, encrypted private key backups (encrypted with your password)

Communication Services:

  • Email service providers
  • Purpose: Send transactional and marketing emails
  • Data shared: Email addresses, names, communication preferences

Affiliate Networks:

  • Third-party affiliate platforms
  • Purpose: Manage affiliate program
  • Data shared: Referral data, commission information

Third-Party Identity Providers:

  • Google, Microsoft, and other SSO providers
  • Purpose: User authentication via SSO
  • Data shared: Authentication requests, email address for account matching

All service providers are contractually bound to:

  • Use data only for specified purposes
  • Maintain confidentiality and security
  • Comply with applicable privacy laws

What We NEVER Share

  • Private cryptographic keys (we don't have access to them)
  • Private key encryption passwords (you choose these, we never see them)
  • Decrypted authentication tokens from third-party providers
  • Email content or communications
  • Browsing history outside our website

Business Transfers

In the event of:

  • Merger or acquisition
  • Asset sale or reorganization
  • Bankruptcy or insolvency

Your personal information may be transferred to the acquiring entity. You will be notified of any such transfer, and the new entity will be bound by this Privacy Policy.

Note: Encrypted private key backups would transfer encrypted (the acquiring entity still cannot decrypt without your password).

Legal Requirements

We may disclose information when required to:

  • Comply with court orders or legal processes
  • Respond to government requests
  • Protect our rights and property
  • Prevent fraud or criminal activity
  • Protect safety of users or the public

We will notify you of legal requests unless prohibited by law.

Note: We cannot disclose private keys or decrypt private key backups as we do not have access to the decryption passwords.

Aggregate and Anonymous Data

We may share aggregated or anonymized data that cannot identify you:

  • Industry reports and statistics
  • Research and publications
  • Public presentations
  • Aggregate version adoption statistics (no user identification)

International Data Transfers

Transfer Mechanisms

Your information may be transferred to and processed in countries other than your country of residence:

Primary Data Storage: Canada

Potential Transfer Locations:

  • United States (cloud services)
  • European Union (support services)
  • Other countries where our service providers operate

Safeguards

For transfers outside Canada/EU/UK:

  • Standard Contractual Clauses (EU Commission approved)
  • Privacy Shield certification (where applicable)
  • Adequacy decisions by relevant authorities
  • Contractual commitments from recipients
  • End-to-end encryption for sensitive data (private key backups remain encrypted during transfer)

Your Rights

You have the right to:

  • Object to international transfers
  • Request information about safeguards
  • Obtain copies of transfer agreements

Your Privacy Rights

Rights Under PIPEDA (Canada)

Access:

  • Request copies of your personal information
  • Receive information about how it's used
  • Request information about stored public keys and encrypted private key backups

Correction:

  • Update inaccurate or incomplete information
  • Request corrections to your records

Withdrawal of Consent:

  • Withdraw consent for processing at any time
  • May limit service availability
  • Delete encrypted private key backups
  • Revoke authentication tokens

Complaint:

  • Lodge complaints with Privacy Commissioner of Canada

Rights Under GDPR (EU/UK)

Access (Article 15):

  • Obtain confirmation of processing
  • Receive copy of your data

Rectification (Article 16):

  • Correct inaccurate data
  • Complete incomplete data

Erasure (Article 17) - "Right to be Forgotten":

  • Request deletion of your data
  • Subject to legal retention requirements
  • Includes deletion of public keys, encrypted private key backups, and authentication tokens

Restriction of Processing (Article 18):

  • Limit how we use your data
  • Applicable in specific circumstances

Data Portability (Article 20):

  • Receive data in machine-readable format
  • Transfer data to another provider
  • Export your public keys and encrypted private key backups

Objection (Article 21):

  • Object to processing based on legitimate interests
  • Object to direct marketing at any time

Automated Decision-Making (Article 22):

  • Right not to be subject to automated decisions
  • We do not use automated decision-making

Rights Under CCPA (California)

Right to Know:

  • Categories of personal information collected
  • Sources and purposes of collection
  • Third parties with whom information is shared

Right to Delete:

  • Request deletion of personal information
  • Subject to exceptions

Right to Opt-Out:

  • Opt out of sale of personal information (we do not sell data)

Right to Non-Discrimination:

  • Not be discriminated against for exercising rights

How to Exercise Your Rights

To exercise any of these rights:

Email: privacy@scomm.ai

Subject Line: Privacy Rights Request - [Type of Request]

Include:

  • Your full name
  • Email address associated with account
  • Specific right you wish to exercise
  • Verification information (for security)

Response Time:

  • Acknowledgment within 5 business days
  • Complete response within 30 days (GDPR/PIPEDA)
  • 45 days for CCPA requests
  • Extensions communicated if needed

Verification: We may request additional information to verify your identity before fulfilling requests.

No Fee: Requests are processed free of charge (unless manifestly unfounded or excessive).

Special Note on Cryptographic Data:

  • We can provide your public keys and encrypted private key backups
  • We cannot decrypt your private key backups (you control the encryption password)
  • We can delete all cryptographic data upon request

Children's Privacy

Age Restriction:

  • Our website is not intended for children under 13 (16 in EU)
  • We do not knowingly collect information from children

Parental Notification: If we discover we have collected information from a child:

  • We will delete it immediately
  • We will notify parents/guardians if possible

Parental Rights: Parents may:

  • Request access to their child's information
  • Request deletion of information
  • Refuse further collection

Contact us immediately if:

  • You believe a child has provided information
  • You are a parent seeking to exercise rights

Do Not Track Signals

Browser DNT Settings:

  • Some browsers offer "Do Not Track" (DNT) signals
  • There is no industry standard for responding to DNT

Our Response:

  • We currently do not respond to DNT signals
  • You can control tracking through cookie settings
  • Third-party tracking may continue unless blocked

Alternative Controls:

  • Browser privacy settings
  • Cookie management tools
  • Ad blocker extensions
  • Privacy-focused browsers

California Privacy Disclosures

California Shine the Light Law: California residents may request information about sharing personal information with third parties for direct marketing purposes.

Our Disclosure:

  • We do not share personal information with third parties for their direct marketing
  • You may still request this information annually

CCPA Rights: See Section 13.3 for California-specific rights.

Third-Party Links And Services

External Links

Our website may contain links to third-party websites, including:

  • Partner services
  • Social media platforms
  • External resources and tools
  • Affiliate websites
  • Third-party identity providers (for SSO authentication)

We are not responsible for:

  • Privacy practices of third-party sites
  • Content on external websites
  • Security of third-party services

Third-Party Integrations

We may integrate with third-party services (e.g., payment processors, analytics, identity providers). These services operate under their own privacy policies. We recommend reviewing their policies before providing information.

Third-Party Identity Providers

When using SSO authentication:

  • You are redirected to the identity provider's authentication page
  • The identity provider's privacy policy governs their data collection
  • We only receive authentication confirmation and email address
  • Review the privacy policies of Google, Microsoft, or other providers you use for SSO

Social Media Features

Social media features (share buttons, embedded content) may collect:

  • IP address
  • Page you're visiting
  • Cookies to enable functionality

These features are governed by the privacy policies of the social media companies.

Marketing Communications

Types of Communications

We may send:

Transactional Emails (cannot opt out):

  • Purchase confirmations
  • Account notifications
  • Security alerts
  • Service updates
  • Application version update notifications
  • Authentication and token-related alerts

Marketing Emails (can opt out):

  • Product announcements
  • Promotional offers
  • Newsletters
  • Affiliate program updates

Consent and Opt-Out

CASL Compliance (Canada):

  • We obtain express or implied consent before sending commercial electronic messages
  • Every marketing email includes an unsubscribe link
  • We honor opt-out requests within 10 business days

You can opt out by:

  • Clicking "unsubscribe" in any marketing email
  • Emailing privacy@scomm.ai with "Unsubscribe" in the subject
  • Updating preferences in your account settings

Opting out of marketing does not affect transactional or service-related communications.

Changes To This Privacy Policy

Updates and Modifications

We reserve the right to update this Privacy Policy at any time to reflect:

  • Changes in our practices
  • Legal or regulatory requirements
  • New features or services
  • Feedback and improvements
  • Updates to authentication mechanisms or cryptographic protocols

Notice of Changes

When we make changes:

Material Changes:

  • We will provide prominent notice (email notification, website banner)
  • Effective 30 days after notice
  • You may review changes before they take effect

Non-Material Changes:

  • Updated "Last Updated" date
  • Effective immediately upon posting
  • Continued use constitutes acceptance

Review and Acceptance

We encourage you to review this Privacy Policy periodically.

Continued use of our website after changes become effective constitutes acceptance of the updated policy.

If you do not agree with changes, you should discontinue use and may request deletion of your account.

Contact Information

Privacy Inquiries

For privacy-related questions, concerns, or requests:

Email: privacy@scomm.ai

Subject Line: Privacy Inquiry

Mailing Address:
scomm.ai
Media Routes Inc.
86-50 Burnhamthorpe Rd W,
Mississauga, ON L5B 3C2
Canada

Data Protection Officer

If required by applicable law, you may contact our Data Protection Officer at: dpo@scomm.ai

Regulatory Authorities

You have the right to lodge a complaint with relevant supervisory authorities:

Response Time

We strive to respond to all inquiries within:

  • 5 business days for acknowledgment
  • 30 days for complete response
  • 60 days for complex requests (with notification of extension)

Accessibility

We are committed to ensuring this Privacy Policy is accessible to everyone.

If you have difficulty accessing this policy or require it in an alternative format:

  • Contact privacy@scomm.ai
  • Request formats: large print, audio, plain language summary

We will provide reasonable accommodations within 10 business days.

Language

This Privacy Policy is provided in English.

If translated versions are made available, the English version prevails in case of conflicts or discrepancies.


Summary Of Our Privacy Commitments

Client-Side Architecture:

  • ✓ Core processing happens on your device (desktop, iOS, mobile)
  • ✓ Private keys stay on your device (unless you choose encrypted cloud backup)
  • ✓ You control your encryption password - we cannot decrypt your private key backups

What We Collect:

  • ✓ Account information (name, email, encrypted password)
  • ✓ Billing information (for purchases)
  • ✓ Website usage data (pages visited on scomm.ai)
  • ✓ Technical information (IP address, browser type)
  • ✓ Public cryptographic keys (for email encryption)
  • ✓ Optionally: Encrypted private key backups (encrypted with YOUR password using AES-256-GCM)
  • ✓ Authentication tokens (for secure access to paid features)

What We Never Collect:

  • ✗ Unencrypted private cryptographic keys
  • ✗ Your private key encryption passwords
  • ✗ Email content or communications
  • ✗ Personal data during version update checks

Your Rights:

  • ✓ Access your data (including cryptographic keys)
  • ✓ Correct inaccurate information
  • ✓ Delete your account and data (including all keys and tokens)
  • ✓ Export your data
  • ✓ Opt out of marketing
  • ✓ File complaints with regulators

Security Measures:

  • ✓ Zero-knowledge architecture for private keys
  • ✓ AES-256-GCM encryption for optional key backups
  • ✓ Short-lived access tokens for enhanced security
  • ✓ Cryptographically signed authentication tokens
  • ✓ TLS/SSL encryption for all communications

Acknowledgment

By using the scomm.ai website, you acknowledge that you have read, understood, and agree to this Privacy Policy.

If you do not agree with this policy, please do not use our website.

Last Updated: March 2026

Version: 2.0


END OF PRIVACY POLICY