PRIVACY POLICY
Your private OweScout workspace.
Effective August 6, 2026
OweScout is operated by Carr Identity Group LLC. This policy explains what data OweScout collects, why it is used, who processes it, and the choices available to you. It applies to the OweScout website, iOS and Android apps, and related services.
Information you provide
- Account information: email address, internal user identifier, authentication provider, and a name when you choose to share one through Apple or Google sign-in.
- Mission and financial organization data: creditor or collector names, balances, account references, dates, status, notes, activities, plans, reminders, payment records, recovery-fund entries, and other details you choose to save.
- Documents and scans: private files, PDFs, images, and document metadata you explicitly select, upload, or scan.
- Support communications: information you include when you contact OweScout for help.
Credit-report imports
PDF and screenshot text extraction runs locally in your browser or supported mobile app. OweScout does not send complete credit-report text to an AI provider. OweScout saves only the collection-account drafts you review and explicitly submit, plus any original document you separately choose to upload.
Information processed automatically
OweScout and its infrastructure providers may process limited technical information needed to operate and secure the service, such as IP address, request time, app or browser type, device platform, authentication events, error details, and security logs. OweScout does not use advertising SDKs and does not track you across other companies' apps or websites.
Website analytics
On public OweScout website pages, OweScout uses first-party analytics to understand site traffic, improve page usefulness, and detect abuse. Analytics may include random visitor and session identifiers, event type and time, public page and landing paths without query strings, referring website hostname, coarse country, device, browser, and operating-system categories, CTA source and destination categories, engagement time, and scroll-depth milestones. A connection address is used transiently to create a server-keyed identifier that rotates daily for abuse prevention; the address itself is not written to the analytics database, and the rate-limit identifier is deleted after one day. OweScout does not put mission details, account references, document names, balances, email addresses, or complete IP addresses into this analytics event store.
The random visitor identifier expires after 90 days, sessions expire after 30 minutes of inactivity, and stored analytics events are automatically deleted after 90 days. OweScout honors enabled Global Privacy Control and browser Do Not Track signals by not collecting these first-party analytics events.
How information is used
- Authenticate you and maintain your private account.
- Store, sync, export, and delete the workspace you request.
- Provide document import, scanning, and malware screening.
- Verify purchases, subscriptions, and feature access.
- Protect accounts, prevent abuse, troubleshoot, and support users.
- Comply with law and enforce OweScout's Terms of Use.
OweScout does not sell personal information, use it for targeted advertising, pull data directly from credit bureaus, hold or move money, or report activity to creditors or collection agencies.
Service providers
OweScout shares information only as needed to provide the service, comply with law, or protect users. Current providers include:
- Supabase for authentication, database, and private file storage.
- Vercel for website, API, and infrastructure hosting.
- Apple for Sign in with Apple, iOS distribution, and App Store purchases.
- Google for Google sign-in, Android distribution, and Google Play purchases.
- Stripe for purchases made on the OweScout website.
These providers process data under their own privacy terms and only for the functions used by OweScout. OweScout may also disclose data when legally required or when reasonably necessary to prevent fraud, abuse, or harm. OweScout does not give providers permission to use private workspace data for advertising.
Billing
Apple handles purchases made in the iOS app, Google handles purchases made in the Android app, and Stripe handles web purchases. OweScout receives purchase status, product, transaction identifiers, dates, and entitlement state, but does not receive your full payment-card number or store-account password. Apple, Google, and Stripe may retain transaction records under their own legal obligations.
Storage, security, and retention
OweScout uses encrypted transport, private access controls, and platform security features intended to protect your data. Uploaded documents may pass through OweScout's private malware scanner before encrypted cloud storage. No system can guarantee absolute security.
Account and workspace data is retained while your account is active or until you delete it. Security records, backups, support records, and transaction evidence may remain for a limited period when needed for recovery, fraud prevention, dispute handling, or legal compliance, after which they are deleted or de-identified under provider and operational retention practices.
Your choices and controls
- Access and correct workspace information directly in OweScout.
- Export allowlisted account data from web Account settings.
- Delete missions, documents, and other content through available workspace controls.
- Revoke camera access in your device settings; OweScout requests camera access only when you start a scan.
- Sign out to end the local session or permanently delete your account from Account settings in either mobile app or the website.
Account deletion removes your OweScout authentication identity, database workspace, and private uploaded files after required billing and storage cleanup. Deleting OweScout does not automatically cancel an active App Store or Google Play subscription; manage it in the subscription settings for the store where you purchased it.
Children
OweScout is intended for adults and is not directed to children under 13. OweScout does not knowingly collect personal information from a child under 13. Contact support if you believe a child provided data.
Changes to this policy
This policy may be updated as OweScout's services or legal obligations change. Material changes will be reflected here with a new effective date and, when appropriate, an in-product notice.
Contact
Questions, privacy requests, or account-deletion help can be sent to dcarr@carridentitygroup.com. You can also visit the OweScout Support page.