Outscope (“Outscope,” “we,” “us,” or “our”) is operated by Diverse Media Systems LLC, a California limited liability company. We respect your privacy. We are committed to transparency about how information is collected, used, disclosed, and protected when you use the Outscope platform and its related services.
1. Purpose of the Service
Outscope is an email testing and quality assurance platform designed for development, testing, staging, and other non-production environments. The Service is intended to help users evaluate email deliverability, formatting, authentication, content quality, and related testing functions.
Outscope is not for routine processing of production customer data, protected health information (PHI), payment card data, or other regulated and sensitive personal information.
Users are responsible for ensuring that information submitted to the Service is appropriate for the intended testing purpose.
2. Information We Collect
Account Information
When you create an account, we collect:
- Email address
- Account creation date and status information
- Subscription and billing status information
- Records of your acceptance of our Terms of Service and this Privacy Policy (version and timestamp)
- Referral information, if you participate in our referral program (your referral code, referral counts, and the code you applied)
If you purchase a paid subscription, payment processing is handled by Stripe. Outscope does not store payment card numbers.
Email Testing Data
When emails are submitted to Outscope testing domains, we may process:
- Sender and recipient addresses
- Subject lines
- Email headers
- Email body content (HTML and plain text)
- Attachments, as part of the raw email message we receive and store for the retention period below (attachments are not separately analyzed)
- Technical metadata related to email transmission and authentication
- The country associated with the sending server’s IP address (derived for security and legal-compliance screening and stored with the analysis record)
Feature Data You Provide
Depending on the features you use, we also store:
- Messages you exchange with our AI chat assistant (stored encrypted, associated with your account)
- QA-agent configurations you create — persona names, instructions, and run settings — and the resulting run records
- Custom analysis rules you author
- Scenario names and groupings you create to organize test traffic
- Support ticket content you submit
Team and Invitation Information
If you create or join a team, we store organization details, membership, and roles. If you invite a teammate, we process the email address you provide in order to deliver and honor the invitation. If you were invited, the person who invited you provided us your email address for that purpose.
Sender Interaction Records
Our testing domains receive email from senders who may not hold an Outscope account. To operate our automated reply service, honor opt-out requests, prevent abuse, and understand use of our testing domains, we keep records about senders, including: the sender address and its domain, the time of first contact, whether our automated reply was received or its links were used, opt-out status, and aggregate send counts per sending domain.
Interest Form
If you submit our sign-up interest form, we store the email address you provide so we can contact you about availability.
Usage and Security Information
We may collect:
- IP address information
- Browser and device information
- Authentication and account activity logs
- Service usage statistics
- Security and fraud-prevention logs
3. Cookies and Similar Technologies
We use only first-party, strictly necessary cookies: a session cookie that keeps you signed in (HttpOnly and transmitted only over HTTPS), a security token used to protect against request forgery, and short-lived cookies used to complete the sign-in process. We do not use third-party analytics, advertising, or tracking cookies, and we do not embed third-party trackers in the Service.
The Service also uses a small amount of browser storage (localStorage) on your device: interface preferences (for example, dismissing the product tour or turning off guided help) that never leave your browser, and an identifier for your currently open chat conversation, which is sent to our servers only to load and continue that conversation. None of this storage is used for advertising, analytics, or cross-site tracking.
For information about how the Service responds to opt-out preference signals, including Global Privacy Control and “Do Not Track” browser signals, see Section 10 (Your Privacy Rights).
4. How We Use Information
We use information to:
- Operate and provide the Service
- Analyze email quality, formatting, authentication, and deliverability
- Generate reports and testing feedback
- Operate our automated reply service for senders to our testing domains, including honoring opt-out requests
- Provide the AI chat assistant and QA-agent features
- Detect abuse, fraud, security incidents, or unauthorized activity
- Enforce geographic and sanctions-related access restrictions
- Improve Service functionality and reliability
- Manage subscriptions and customer support
- Comply with legal obligations
5. Artificial Intelligence Processing
Certain features — including email content analysis, the AI chat assistant, and QA-agent runs — utilize artificial intelligence services hosted through Amazon Web Services (AWS) Bedrock. Information submitted to those features may be processed by AI models operating within the AWS Bedrock environment to generate testing insights, quality assessments, and responses.
Outscope does not use customer-submitted email content to train its own AI models. To the best of our knowledge and based on AWS service commitments, prompts and outputs processed through AWS Bedrock are not used to train foundation models.
Automated analysis and AI-generated outputs are used to assist, not replace, decisions that materially affect a user’s access to the Service (for example, account status determinations). If you are notified of such a determination, you may contact us at privacy@outscope.ai.
6. Sensitive Information
Outscope is intended for test and quality assurance purposes. Users should not submit:
- Protected Health Information (PHI)
- Payment card information
- Social Security numbers
- Government identification numbers
- Production customer datasets
- Other regulated or highly sensitive personal information
Outscope may identify some sensitive information categories through automated analysis. However, such controls cannot guarantee detection of all sensitive data. Users remain responsible for the content they submit.
When the Service’s automated analysis detects a potential sensitive identifier (such as a Social Security number) within submitted content, the Service records only a description of the type of data detected (for example, “potential U.S. Social Security number detected”) and does not extract or retain the underlying value beyond the ordinary retention period for the associated message.
7. Data Retention
We retain information only as long as reasonably necessary to provide the Service and support legitimate business operations. Current retention periods include:
Raw email content (including attachments): Up to 90 days.
Email analysis results and metadata: Up to 90 days for all plans. (Your plan determines how much of that history is visible in your dashboard — currently 3 days on the free tier and 90 days on paid plans.)
Chat assistant conversations: Deleted approximately 14 days after your last activity in a conversation; conversations you archive are kept up to 180 days.
QA-agent data: Run records are deleted after approximately 7 days; personas and their instructions are kept until you delete them or your account closes.
Sender interaction records: Approximately 90 days from first contact, extended up to one year after the most recent contact; aggregate reply counts up to one year; domain-level usage records for approximately 6 months (180 days), retained longer where an active business relationship exists, after the last activity.
Account information: While the account remains active; deleted within 30 days of account closure.
Security and audit logs: Typically up to 1 year. Certain administrative audit records may be retained longer where reasonably necessary for security, fraud prevention, dispute resolution, or legal compliance.
Billing and transaction records: 7 years from the date of the transaction, subject to any applicable legal hold.
Information may be deleted sooner in response to an authorized deletion request, subject to legal and operational requirements. Two limited exceptions apply after account deletion: we retain a salted, one-way hashed identifier (not your readable email address) to prevent free-trial abuse, and deleted data may persist in encrypted backups for up to 60 days before those backups age out.
8. How Information Is Stored and Protected
Outscope uses administrative, technical, and physical safeguards designed to protect information from unauthorized access, disclosure, alteration, or destruction. These safeguards include:
- Encryption in transit (TLS 1.2+)
- Encryption at rest (AES-256)
- Role-based access controls
- Authentication and authorization controls
- Infrastructure monitoring
- Security logging and alerting
No security system can guarantee absolute protection. Users acknowledge that transmission of information over the Internet carries inherent risks.
9. Sharing of Information
We do not sell personal information, and we do not share personal information with third parties for cross-context behavioral advertising. We may disclose information to:
Service Providers — including providers that support the operation of the Service, such as Amazon Web Services (AWS), Stripe, and authentication, infrastructure, and security vendors. These providers receive information only as needed to perform services for us.
Your Team or Organization — analysis history and Email Testing Data are private to your individual account by default. Where this capability is available, you may authorize specific individuals, identified by email address, to access shared History or Team views for your account. History is not shared automatically based on a shared email domain or organizational affiliation alone. Team owners and members can see membership information for their team.
Automated Replies to Senders — when an individual emails a testing address and the submission is associated with a business customer’s account, that customer will receive information about the sender’s message as part of the automated reply and the resulting analysis report. The customer’s own privacy practices (not solely this Privacy Policy) govern how that customer uses the information it receives. This is separate from Outscope’s own use of the data, which is described elsewhere in this Policy.
Mobile/SMS Opt-In Data — if you provide a mobile phone number to receive operational SMS alerts (for example, as an account operator), your phone number and SMS consent status are used solely to deliver those alerts. We do not sell, rent, or share mobile opt-in data or SMS consent information with third parties for marketing or promotional purposes. Standard message and data rates may apply; reply STOP to any message to opt out.
Legal Requirements — we may disclose information when required to comply with applicable laws, respond to lawful requests from governmental authorities, enforce our agreements, or protect the rights, safety, and security of Outscope, our users, and others.
Business Transactions — information may be transferred as part of a merger, acquisition, financing, reorganization, or sale of assets.
10. Your Privacy Rights
Depending on your jurisdiction, you may have rights regarding your personal information. Residents of California may have rights under the CCPA/CPRA, and residents of other U.S. states with comprehensive privacy laws (including but not limited to Virginia, Colorado, Connecticut, Utah, and Texas) may have similar rights. These rights may include the rights to:
- Access — request a copy of the personal information we maintain about you
- Correction — request correction of inaccurate information
- Deletion — request deletion of your personal information (“Right to be Forgotten”)
- Portability / Export — receive certain information in a portable format
- Opt-Out — opt out of certain data processing activities where applicable, including further automated replies from our testing domains
- Non-Discrimination — we will not discriminate against you for exercising these rights
- Object / Restrict — object to or restrict certain processing activities where required by law
- Limit Sensitive Personal Information — request that we limit the use of your sensitive personal information. Outscope does not knowingly collect sensitive personal information and processes it only in limited circumstances, such as security and fraud-prevention screening (e.g., security protocols that detect and delete sensitive personal information), and does not use it to infer characteristics about you.
To exercise these rights, contact us at privacy@outscope.ai. We may need to verify your identity before acting on a request. We will respond within the timeframe required by applicable law — within 30 days under the GDPR, and within 45 days (extendable as permitted) under the CCPA.
Appeals. If we deny your request, you may appeal by contacting us at privacy@outscope.ai with the subject line “Rights Request Appeal.” We will review your appeal and inform you in writing of our decision, and the reasons for it, within the timeframe required by applicable law. If your appeal is denied, we will provide information about how you may contact the relevant regulator or attorney general.
Authorized Agents. You may use an authorized agent to submit a rights request on your behalf. We may require the agent to provide proof that you have authorized them to act for you, and we may still ask you to verify your own identity directly with us.
Global Privacy Control and Do Not Track. Outscope honors user-enabled Global Privacy Control (GPC) signals as a valid opt-out request where applicable. Because there is no common industry standard for interpreting “Do Not Track” browser signals, the Service does not currently respond to them; however, as described in Section 3, we do not use third-party analytics, advertising, or tracking cookies.
Additional Rights Under the GDPR. If you are located in a jurisdiction governed by the GDPR, you also have: the right to withdraw your consent at any time where our processing is based on consent (without affecting the lawfulness of processing before withdrawal); the right to lodge a complaint with your local supervisory authority; and the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects concerning you. Where automated processing is used in such a decision, you may request human review of the decision and contest it by contacting us at privacy@outscope.ai.
11. Notice of Financial Incentive
Our referral program (described in Section 2) offers promotional credits when you refer another person to the Service. The only category of personal information involved is the referred individual’s email address, which you provide when you send a referral. Participation is voluntary: you opt in by choosing to use your referral code or by applying another user’s code, and you may withdraw at any time by contacting us at privacy@outscope.ai or by discontinuing use of the program. We do not sell this information or collect it for its independent value. We reasonably estimate the value of the data involved to be equal to or less than the value of the promotional credit provided, calculated by reference to our costs in offering the program.
12. International Users
Outscope is operated from and hosted within the United States. If you access the Service from outside the United States, your information may be transferred to, stored, and processed in the United States, and may also be processed in other jurisdictions where our service providers operate. Outscope does not currently direct the Service to, or maintain a legal basis for processing the personal data of, individuals located in the European Economic Area, the United Kingdom, Switzerland, or other jurisdictions with data transfer restrictions. If this changes, Outscope will implement an appropriate transfer mechanism (such as the EU Standard Contractual Clauses or the UK International Data Transfer Addendum) before undertaking such processing.
13. Children’s Privacy
The Service is not directed to children and, under our Terms of Service, is available only to individuals 18 or older. We do not knowingly collect personal information from children. If we learn that such information has been collected, we will take reasonable steps to delete it.
14. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. For non-material updates, we will update the “Last updated” date, and your continued use of the Service after the changes become effective constitutes acceptance of the revised Privacy Policy. For changes required by new or amended privacy or data protection law, we will provide the same notice described in the “Changes to These Terms” section of our Terms of Service - including email notice, a website banner, and, where applicable, a request that you re-consent - before those changes take effect.
15. Contact Information
For privacy-related questions, requests, or concerns, contact:
Diverse Media Systems LLCCalifornia, United States