Scout

Legal

Privacy

Scout reads ads, not people. This page says what it collects to do that, who else sees it, how long it stays, and how to get rid of it.

Last updated Aug 26, 2026

Who this covers

This policy covers Scout: the Instagram account @scout.wiki, the website at scout.wiki, and the analysis cards it produces. Scout is the data controller for the information described here.

It does not cover Instagram itself, the shops whose listings Scout reads, or any site you reach by following a link from a card. Those have their own policies and Scout has no control over them.

What Scout collects

Three things, and nothing that is not on this list.

  • What you send. The screenshots, links, forwarded ads and messages you put in the DM thread, plus anything you type alongside them. This is the raw material for the analysis and there is no way to run a check without it.
  • Your account. An email address, the Instagram username you messaged from, the display name you choose, and the date you joined. The email exists so sign-in links have somewhere to go.
  • What you do with a card. Which checks you saved, the star ratings and written reviews you post, and the two answers in the feedback bar — whether a card helped, and whether you bought the thing. The second one is what makes the figure on your stats page mean anything.

Scout does not ask for your address, your phone number, your date of birth or any payment details, because it never sells you anything and never ships you anything.

What comes from Instagram

Scout replies to DMs through Meta’s Messenger platform. When you message the account, Meta passes Scout a page-scoped identifier for your conversation, your public username and profile name, and the contents of the messages you send.

That is the whole of it. Scout cannot read your other conversations, cannot see who you follow, cannot post to your account and cannot reach your email address through Instagram — the email in your Scout account is one you gave the website directly.

Your handle is linked to your Scout account by the fact that you messaged from it, which is why it is read-only in settings. Scout never asks you to type a handle in, because a handle anyone can type is a handle anyone can claim.

Why Scout holds it

  • To run the check you asked for and send the card back. This is the performance of what you asked Scout to do.
  • To keep your feed, your saved list and your stats, so a check you ran last month is still there this month.
  • To publish community reviews, which is the point of writing one.
  • To find out where Scout is wrong. Aggregate accuracy — how often a product was identified, how often a check failed — is read across all users, never as a profile of one.

Scout does not build advertising profiles, does not do behavioural targeting, and has nothing to sell you. There is no advertising business here to feed.

How automated analysis is used

Producing a card involves large language models and automated retrieval. The content you send — the screenshot, the listing text, the link — is passed to third-party model providers to do that work, under contracts that forbid using it to train their models.

Anything on a card that a model wrote is labelled with the model’s name, the number of sources behind it and the date it was written. If it is not labelled that way, a person or a deterministic check produced it.

No decision Scout makes has a legal effect on you. A card is an opinion with its working attached; the buying decision is entirely yours.

Who else sees it

Scout does not sell your data, and never has. It is shared only with the services needed to run the product, each of which gets the minimum required:

  • Hosting and infrastructure providers, who store the data at rest.
  • Model and search providers, who receive the contents of a submission in order to analyse it.
  • An email provider, which receives your address in order to deliver a sign-in link.
  • Meta, which necessarily carries the DM thread, because that is where you sent the message.

Scout may also disclose information where the law requires it, or where it is needed to investigate abuse of the service. If Scout is ever acquired, this policy travels with the data and you will be told before anything changes.

What is public, and what is not

Every card has two addresses. The private one is tied to your account and only opens for you. The public one — the link the share button copies — contains the analysis and nothing about who asked for it. No username, no handle, no timestamp of your request.

A public card can be indexed by search engines. Your feed, your saved list, your stats and your settings never are.

Community reviews are public by design: the star rating, the text you wrote, and the display name on your account appear next to the product for anyone who opens it. Do not put anything in a review you would not put on a public page.

Cookies and local storage

Scout sets no cookies at all. What it keeps is held in your browser's local storage, on your own device, and is never sent anywhere except back to Scout.

  • Your sign-in tokens, which are what keep you signed in. Signing out deletes them and revokes them on our side.
  • Your name and email, kept beside them so the header can render the signed-in state immediately instead of flashing a signed-out one.
  • Whether you chose light or dark.

There are no third-party analytics cookies, no advertising pixels and no cross-site trackers. Video reviews embedded on a card load from youtube-nocookie.com and only after you tap play, so opening a card does not report you to Google.

How long it is kept

  • Sign-in links last 15 minutes and work once.
  • Your checks and saved items are kept while your account is open. Checks you have neither saved nor shared may be cleared after 24 months of inactivity.
  • Your account is kept until you close it, then deleted permanently 30 days later.
  • Community reviews are kept indefinitely, detached from your account if you delete it. See deleting your data for why.

Your choices

You can ask for a copy of what Scout holds on you, ask for it to be corrected, ask for it to be deleted, or object to it being processed. Depending on where you live, these may be legal rights; Scout honours them either way.

Email privacy@scout.wiki from the address on your account, or message @scout.wiki from the handle linked to it. Expect a reply within 30 days. If you are not satisfied, you can complain to your local data protection authority.

Deleting everything

There is a page for this with three routes on it, including one that does not require signing in: how to delete your Scout data.

Security

Traffic is encrypted in transit, data is encrypted at rest, and access to production data is limited to the people who need it to keep the service running. There are no passwords to leak because Scout does not use any.

No service can promise it will never be breached. If one happens and it affects you, you will be told directly rather than through a changelog.

Children

Scout is not intended for anyone under 13, and Instagram sets its own minimum age. If you believe a child has sent Scout information, email privacy@scout.wiki and it will be deleted.

Where the data sits

Scout’s providers operate in several countries, so your information may be processed outside the one you live in. Where that happens, transfers are covered by standard contractual clauses or an equivalent safeguard.

Changes to this policy

The date at the top is the date of the last substantive change. If a change materially affects what Scout does with your information, you will be told in the DM thread before it takes effect, not after.

Contact

Privacy questions go to privacy@scout.wiki. Anything else can go straight into the thread with @scout.wiki.