OpenScout
Privacy Policy
Last updated September 30, 2026. This policy covers the OpenScout marketing site at openscout.app, the early-access endpoint at api.openscout.app, the hosted MCP gateway at mcp.oscout.net, and the Scout desktop and iOS apps.
Local-first by default
OpenScout is designed so conversations, broker state, local databases, paired-device state, and day-to-day agent activity primarily live on your own machines and paired bridge rather than in a developer-run cloud account.
Limited website collection
If you only use the website, the data we receive is limited to website analytics and anything you choose to send through the early-access form.
Website Data We Collect
Website analytics
The marketing site at openscout.app uses Google Analytics in production to measure page visits and site interactions such as navigation clicks, CTA clicks, command copy events, and lead-form activity.
Contact and early-access form submissions
If you submit the contact form or the early-access form, we collect your email address, the intent you select, any note you add, basic source metadata, and a spam-prevention field. That submission is sent to api.openscout.app and stored in private blob storage.
Optional OpenScout Network And Push Relay
You can pair Scout directly with your Mac by QR code without an OpenScout Network account. If you choose to sign in with GitHub or Apple, we receive the provider account identifier and the account details the provider makes available, such as a name, handle, and verified email address. We use that identity to authenticate you and route your own devices; we do not use it to track you across other apps or websites.
If you enable remote notifications, Scout sends a paired-device identifier, encrypted Apple Push Notification service token, app and build version, device model, system version, and notification authorization state to the OpenScout push relay. Notifications sent through Apple contain generic alert text and opaque Scout record identifiers—not prompts, agent output, file paths, or commands.
The relay keeps delivery results, account and device rate counters, and limited security logs such as IP address and user agent. Push audit records are pruned after 30 days. OpenScout uses Cloudflare for hosted service infrastructure, Apple for notification delivery and optional sign-in, and GitHub for optional sign-in.
Hosted MCP Gateway
The gateway at mcp.oscout.net lets an MCP client such as Claude reach the Scout broker on your own Mac. You connect by signing in with GitHub and approving the client. When you approve, we store an OAuth grant: the client's name, the agent name you chose, your account identifier, the granted scope, and hashes of the issued tokens. Access tokens expire after one hour and refresh tokens after 30 days unless renewed. Pre-issued agent tokens are stored only as SHA-256 hashes with their agent name, label, and creation and revocation times.
When you connect a Mac with scout mesh bridge connect, we store a bridge credential for your account: a SHA-256 hash of it, your account identifier and GitHub login, the node name, the machine label your Mac sends (its hostname unless you choose another), and creation, last-use, and revocation times. The credential itself stays in your Mac's keychain. To apply the daily call limit, the gateway keeps a count of tool calls per account for the current day. It does not record which tools were called.
Tool calls and their results pass through the gateway to your Mac's bridge in memory. The gateway does not store tool arguments, results, or message content; those records are kept by the Scout broker on your own machine. The gateway only receives what your client sends in a tool call. It does not read your conversations, memory, or files in the client.
One tool, feedback_send, sends a redacted note about Scout to api.openscout.app when an agent or you choose to report a problem. The report names the sending agent, harness, project, and host, and may include bounded, redacted service logs when diagnostics are requested. We keep these reports for support until they are no longer needed.
To stop access, disconnect the connector in your client, revoke the agent token, or run scout mesh bridge disconnect on your Mac. To delete your grants and account data, contact us using the details below.
App Permissions And Local Processing
Camera
Scout iOS asks for camera access only to scan a pairing QR code from your bridge.
Microphone
Scout iOS asks for microphone access when you want to send voice input.
Speech recognition
Scout iOS uses speech recognition for transcription. The current app is configured to require on-device recognition.
Notifications
Scout iOS asks for notification permission so it can alert you about approvals, replies, and other events that need attention.
How We Use Information
- We use website analytics to understand how people find and use the marketing site.
- We use early-access submissions to respond to interest, prioritize product work, and manage access requests.
- We use optional account and device data to authenticate you, connect your devices, deliver notifications you enable, prevent abuse, and troubleshoot delivery.
- We do not sell personal information and we do not run third-party advertising profiles for OpenScout.
Infrastructure And Retention
The public marketing site is served from GitHub Pages. Early-access submissions are written to private blob storage. Day-to-day agent state stays on your own devices and paired bridge. Optional account discovery and notification delivery use the hosted services described above. We keep website submissions for product and support operations until they are no longer needed.
Questions
You can turn off notifications in system settings, sign out of OpenScout Network, or continue using local QR pairing without an account. If you have a privacy question or want us to remove an early-access submission or hosted account data, use the contact page.
Contact OpenScout