RMMM Holdings, LLC d/b/a ScoutLane ("ScoutLane," "we," "us") operates the ScoutLane application at www.scoutlane.app. This policy explains what we collect, why, and your choices. ScoutLane is built on a simple principle: your application materials are yours. We use source checks and user review to reduce fabrication, and we do not sell or misuse those materials.
What we collect
Account data: your email address, and, if you sign in with Google, the basic profile Google returns to authenticate you. Content you provide: your resume text and uploads, job descriptions, role preferences, saved applications and drafts, and any feedback or support request you submit. Generated content: the packets, documents, and Interview Kit materials, and Debrief output we produce for you. Purchase records: credit-pack purchases and remaining credit balance, processed through Stripe. Usage data: product analytics events and error and diagnostic data, plus standard technical data such as browser type and IP address. Once you are signed in, we link your analytics events to your account using an opaque internal account ID only, so we can tell that the same signed-in visitor returned or moved an application forward. That ID is never your email, name, or any content of your resume, job descriptions, or generated documents. Waitlist and referral data: if you join the waitlist, we collect your email address, any note you add, and a referral code we generate for you. If you joined through another person's referral link, we store their referral code on your waitlist entry, which links the two entries, and therefore the two email addresses, in our records, and lets us credit a referral count and a capped credit counter on the referrer's entry. That link is stored by code rather than by email address, and we do not show either person the other's identity; a referrer sees only their position in line and a count. Self-referrals are rejected, and unrecognized codes are discarded rather than stored.
How we use it
To create your requested application packets and Interview Kit materials, to operate, secure, and improve the service, to process payments and track your credit balance, to manage the waitlist and referral program, and to communicate with you about your account. We produce two distinct kinds of AI output. Your application materials, resume, cover letter, fit assessment, outreach messages, and LinkedIn kit, are generated from information you provide about yourself. Before documents are delivered, code blocks tailored claims, skills, and quantified metrics that fail their source checks. Other prose and profile details still require your review. Interview Kit company intel is different: it is research about a prospective employer, drawn from public web-search results and cited back to its public source, not from your personal data. This same distinction, and the disclaimers, liability, and review obligations that go with it, extend to any additional AI-generated or web-derived feature we add later, and not only to the features named here.
Service providers we share with
We share information only with service providers that help us run the product, organized here by category so that changing a specific vendor within a category does not require rewriting this policy: only updating the list below:
- Hosting: Vercel.
- Storage and authentication: Supabase (database and authentication, hosted in the US), and Google (basic profile data, only if you choose Google sign-in).
- AI generation: Anthropic (the AI model that generates your application materials and Debrief from the text you provide, and your Interview Kit brief from that text together with public search results).
- Public web-search research: Brave Search, a server-side public web-search API that powers Interview Kit company intel. It processes search queries about the employer you are researching, not your personal data, and it never scrapes a gated site or logs into anyone's account, consistent with our no-scraping, no-account-login policy.
- Payment processing: Stripe (your card details are handled by Stripe, not stored by us).
- Email delivery: Amazon Web Services SES.
- Analytics: PostHog (product analytics, keyed to an opaque account ID once you are signed in, never your email or document content; hosted in PostHog's US cloud region).
- Error monitoring: Sentry.
- Bot protection: Cloudflare.
Current as of August 1, 2026. We add or change vendors within these categories from time to time as our product evolves; this list reflects our then-current vendors, and we will note material changes as described under "Changes" below.
We do not sell your personal information, and we do not use your resume, job descriptions, Debrief notes, or search results to train third-party models beyond generating your requested output. We may also disclose information if required by law or legal process, to protect our rights, users, or the public, or in connection with a merger, acquisition, or sale of assets.
Business customers seeking a data processing addendum for their own compliance needs may contact us at the address below; at ScoutLane's current stage, serving individual job-seekers, a standalone DPA program is not yet necessary, and we will revisit this if that changes.
Your rights
Depending on where you live, you may have rights to know what personal information we collect, to access, correct, delete, or port it, and to opt out of certain uses such as targeted advertising or the "sale" or "sharing" of personal information, as those terms are defined by applicable law, for example under California's CCPA/CPRA and similar laws in other states. We do not sell personal information and do not knowingly engage in cross-context behavioral advertising. To exercise any of these rights, contact us at the address below; we will not discriminate against you for exercising them. Ohio, where ScoutLane's operating entity is based, does not currently have a comprehensive consumer privacy law of this kind; Ohio's existing data-protection statute (commonly called the Ohio Data Protection Act) is a cybersecurity safe-harbor law that gives qualifying businesses an affirmative legal defense if they maintain a reasonable security program, and it does not itself grant consumers rights to access, delete, or opt out. ScoutLane is currently invite-only and pre-launch and does not meet the applicability thresholds of most state comprehensive privacy laws, but we are providing these baseline disclosures now and will update this section as our user base and legal obligations grow.
Retention and deletion
We keep your data while your account is active. You can delete your own account and data at any time from Account settings, no admin help required. Deletion signs you out right away, and within 7 days we permanently delete your stored packets, Interview Kit and Debrief materials, feedback, resume profile, and waitlist entry. Support requests you filed at Support are kept as a resolution record and are not included in that automatic sweep; contact privacy@scoutlane.app if you want a past support request deleted too. To ask a privacy question, or to stop a recent deletion inside that 7-day window, contact privacy@scoutlane.app. If you joined the waitlist without creating an account, that entry is not reachable from Account settings; email privacy@scoutlane.app to have it deleted.
Separately, each packet you generate carries its own retention window for reopening it byte-for-byte as originally shipped: 90 days from creation for a packet from your free allotment, 365 days for a packet paid for with a credit. Inside that window, reopening or re-downloading a packet reads the stored snapshot exactly as generated, no new model call. After the window, a daily housekeeping job sweeps the detailed snapshot and keeps only lightweight metadata (status, scores, dates, and the role title and company); reopening a packet past its window requires generating it again.
Purchase and transaction records. Deleting your account does not delete our record of your purchase transactions. We retain a de-identified transaction record (with the identifier linking it to your deleted account removed, but the underlying Stripe transaction reference retained) for as long as required by our accounting, tax, and other legal recordkeeping obligations (generally up to seven years). This lets us meet those obligations without keeping any of your account content or personal profile after deletion.
Unused credit balance. If you have an unused credit balance when you delete your account, that balance is forfeited at the time of deletion. If you want a refund of an unused balance, request it at privacy@scoutlane.app before you delete your account, or within the 7-day window above if you act quickly after deleting.
Your choices
You can delete your account and data yourself, at any time, from Account settings, and you can turn off optional analytics from that same page. Turning analytics off stops new events from being sent, and signing out clears the link between your account ID and any further analytics activity in that browser.
Security
We use industry-standard measures, including encryption in transit, access controls, and row-level database security. No system is perfectly secure, but we design to minimize what we collect and expose.
Children
ScoutLane is not directed to children under 16, and we do not knowingly collect their data.
Changes
We may update this policy, including the sub-processor list above. We will post the new effective date here, and for material changes, provide notice as appropriate (for example, by email or an in-product notice).
Contact
privacy@scoutlane.app for privacy and deletion questions, support@scoutlane.app for everything else. RMMM Holdings, LLC d/b/a ScoutLane, Ohio.