Scopy is a messaging assistant used by restaurants, spas, salons, and clinics to handle customer messages on WhatsApp. This page explains what data we hold, why we hold it, and how to remove it. It is intentionally short. If anything is not clear, email privacy@scopy.help and we will answer plainly.
When you message a business through WhatsApp, that business is the data controller, meaning they decide why your data is collected, so they can serve you. Scopy is the data processor, meaning we hold the data on their behalf and run the Scopy software. Both of us have responsibilities under privacy laws: GDPR in Europe, UU PDP in Indonesia, similar laws elsewhere.
Your WhatsApp number and display name: Sent to us automatically by WhatsApp when you message the business. We need this to reply to you.
The messages you send: To understand what you want and respond.
Photos you choose to send in the chat:stored so the business's staff can see them, for example a screenshot proving a payment. We only keep real photos. Videos, voice notes, and documents you send are not downloaded or stored.
Your reservation details: If you book: date, time, party size, and any notes you share.
For business staff who sign in to the Scopy app: an email address for sign-in and a display name you choose. No password, we email you a sign-in code or link instead.
Your WhatsApp contacts or other chats.We only see messages and photos you choose to send to the business's number, nothing else on your phone.
Payment information.If you pay the business, that happens outside Scopy, in person or through their own payment processor. Businesses pay Scopy's own subscription by card through Stripe. Stripe holds the card details and we never see the full card number.
Tracking cookies.The Scopy staff app uses only a session cookie to keep you signed in. No third-party analytics, no ads, no fingerprinting. The signup form uses Cloudflare's human-check to block bots; it does not track you across sites.
The business you're messaging. Their staff can read your messages and reservations through the Scopy app, and they use this to serve you. They cannot see customers of other businesses.
Scopy's infrastructure providers.Your data is stored on Supabase, hosted in Singapore, and processed through n8n on Hetzner, with servers in Singapore. The AI replies are generated by Anthropic. The staff app runs on Vercel, emails are delivered by Resend, and our domain and email routing run through Cloudflare. These providers process data on Scopy's behalf and cannot use it for their own purposes.
Google Calendar (optional).If a business connects its own Google Calendar, its reservations are copied there. That copy lives in the business's Google account, under Google's terms.
Nobody else. We do not sell or share your data with marketers, advertisers, or third parties.
Conversations: Deleted automatically 90 days after your last message, unless you have a future reservation. Conversations tied to upcoming reservations stay until the visit happens. Photos you sent in the chat are deleted at the same time as the conversation.
Reservations: Kept as long as the business keeps you as a customer, typically for their accounting and follow-up. Ask the business if you want yours removed.
Scopy mistakes or complaints (rare): kept longer if needed for safety or audit purposes. We will document it if we ever do this.
The fastest way: message Scopy the word /forget, or “delete my data”, or “supprime mes données”. Scopy confirms, then deletes all your conversations, messages, and any photos you sent, on that business's account within 24 hours. You lose past chat context if you message them again, but your future visits are not affected.
If you want to be removed from a business's reservation records too, ask the business directly. Those records belong to them, not to Scopy.
Prefer email? Write to privacy@scopy.help with the WhatsApp number you messaged from. We process the request within five business days.
Business owners can delete their whole Scopy account, and all of its data, themselves in the app under Settings, then Account.
You have the right to:
See what data we hold about you.
Correct anything inaccurate.
Object to how we process your data.
Complain to your local data protection authority.
Email privacy@scopy.help for any of these.
Your data is encrypted in transit with HTTPS and TLS, and at rest through Supabase and Hetzner disk encryption. Access to the Scopy staff app requires an emailed sign-in code or link, so there is no password to steal. We keep daily backups, retained for 30 days.
We are a small team. If a security incident affects your data, we will email you and the affected business within 72 hours of discovering it.
If we make material changes, we will update the date at the top of this page and email anyone affected. The current version always lives at scopy.help/privacy.
Privacy questions: privacy@scopy.help
General support: support@scopy.help
Scopy is operated by SAI Prime LLC, United States. This page is written in plain English in good faith. It is not legal advice. If you need a binding interpretation under your local law, talk to a lawyer. Our terms of service are at scopy.help/terms.
Message Scopy the word /forget and everything on that business's account goes within 24 hours.