Most privacy pages are written to reassure. This one is written to be accurate, which sometimes means saying the less comfortable thing first: Scoop is not end-to-end encrypted, and it cannot be. The entire product is software reading your work conversation to find the commitments in it. That is impossible if nobody but the participants can read the messages. So we don't claim it, and if you ever see us imply it, we've made a mistake.
What that actually means in practice
“Not end-to-end encrypted” is a precise statement, and it's worth separating from things it doesn't mean.
| Claim | True? | Detail |
|---|---|---|
| Messages are encrypted where they're stored | Yes | Each conversation has its own key; nothing sits in plain text on disk. |
| Only members of a conversation can read it in the app | Yes | Access is per conversation, not per organisation. |
| Nobody but the participants can ever read a message | No | The server holds the keys, because the model has to read messages to find tasks. |
| We read your messages for advertising, or sell them | No | There is no ad product, and there is nobody to sell them to. |
| Your whole phonebook is uploaded | No | See below — this one is a deliberate design choice. |
Contacts: the restraint that costs us something
Most messengers upload your entire address book. It makes the product better — every contact who joins later can be matched instantly — and it means the company holds a social graph for people who never signed up for anything.
We keep only the people you actually connect with: somebody you share a group with, somebody you've messaged, somebody you invited. Your phone matches the rest locally and tells us nothing about them. This is genuinely worse for us — some matching is slower, and some people you know won't show up until there's a real connection. We think holding a graph of people who never chose us is not ours to hold.
Where we said no to a log
Here is a decision we think is worth explaining, because from the outside it looks like an omission. We record the IP address a person signs in from, signs out from, changes their name from, and closes their account from. We do not record one against a message.
It would have been easy to log it — one line of code, and every product analytics guide recommends it. But an IP on every message is a location trail on every person in every group, in an app whose whole premise is a server reading work conversations. Knowing that Imran sent three messages from a different part of the city on Tuesday is not information we need to run this product, and it is exactly the sort of thing that makes people write less honestly in a work group. The account-level events, which are the ones that matter for a lawful request or a security incident, are kept for 180 days and then deleted.
The point isn't that we couldn't collect it. It's that a product built on reading conversations should be unusually careful about everything else it touches.
Where the AI runs, said plainly
The model that reads messages to find commitments is Anthropic's. That makes Anthropic a data processor for us, and because the endpoint isn't in India, it makes it a cross-border transfer under the DPDP Act, 2023. We name that in our privacy notice rather than leaving it implied, and we won't describe Scoop as processing your messages only in India, because that would not be true.
There's a second, smaller thing worth knowing about how that reading works. The model is fed a conversation's recent messages — not one message at a time — because context is what lets it tell a commitment from a comment. Messages that record an event (“Arvind marked this as done”) are excluded from what the model reads, deliberately: otherwise every completed task would breed a new one.
Closing your account
You can close your account from inside the app, and it takes two steps with a one-time code — because a phone gets picked up off a table, and the one action there's no way back from should ask you to prove the number again.
- Your account closes on day zero. You're signed out everywhere, and your number is freed immediately, so you can sign up again later as a new account rather than being locked out for months.
- Your messages are not deleted. A message you sent in a group is also the other members' record of a conversation they were part of. Deleting it rewrites their history to settle your request. You are anonymised in it instead, which is what every messenger does and what our terms promise.
- The registration record is kept for 180 days — your number, name and signup date, in a separate table from everything else — because India's IT Rules require it after cancellation. Then it's purged.
We'll name the gap in that too: if you want the words themselves gone rather than anonymised, per-message deletion is something we owe you and haven't finished building. It's on the list, and until it's there we won't pretend otherwise.
Why write this at all
Because the honest version is a competitive advantage with the people we're building for. A factory owner putting his shift group into an app, or a CA partner putting client names into one, has a reasonable and specific worry, and a page of reassuring adjectives doesn't answer it. A precise account of what's stored, what isn't, and what we refuse to collect does. If any of it changes, we'd rather update this page than let it quietly become untrue.
Written by Team Scoop, Founding team, Scoop. General guidance on running a team, not professional or legal advice for a specific situation.
