Privacy policy
Last updated: 11 August 2026
Scope Creep is the trading name of Thomas Matthews, a sole trader based in the United Kingdom ("we", "us"). This policy explains what personal data we collect when you use Scope Creep at scopecreep.agency, why we collect it, who else touches it, and the choices you have. It's written in plain English on purpose.
Questions about anything here: hello@scopecreep.agency.
What Scope Creep is, in one line
Scope Creep is an internal tool for agencies. You upload a signed statement of work, AI proposes the deliverable list, you confirm it, and it becomes a live monthly delivery dashboard. Your clients never log in — there is no client portal.
The data we collect
Account data. Your name, email address, and a password stored only in securely hashed form by our authentication provider — or, if you sign in with Google, your Google account email. We also record your workspace name and the date you joined.
Workspace content. Everything you and your team put into the product: client names and contact details, engagement terms such as fees and dates, deliverables and their monthly progress, notes, logged client requests, sentiment records, meeting details, and the names of team members you add. Some of this is personal data about people at your clients' businesses — see "Your clients' data" below.
Uploaded documents. The statement-of-work files you upload. These usually contain commercial terms and may contain names, signatures and contact details.
Billing data. Payments are handled by Stripe. We never see or store your card number. Stripe tells us only your subscription status, plan, billing dates and customer reference.
Contact form submissions. If you write to us through the contact page, we store your name, agency name, email address and message, together with a one-way cryptographic hash of your IP address. The hash exists solely to rate-limit the form and prevent abuse — we do not store your IP address itself and cannot recover it from the hash.
Technical basics. Standard server logs generated by hosting the service, including IP address, browser type and timestamps, used for security and keeping the product running.
We do not sell personal data to anyone, and we do not use advertising or remarketing cookies. See "Cookies and analytics" below for what we do use.
Cookies and analytics
We use cookies in two distinct ways, and they are treated differently.
Strictly necessary cookies keep you signed in and keep the service secure. These are set inside the app, cannot be switched off, and do not require your consent, because the product does not function without them.
Analytics cookies are used on our public website only — not inside the app once you are signed in. We use Google Analytics 4, loaded through Google Tag Manager, to understand how people find and move around the site so we can improve it. We do not use Google's advertising features, remarketing, or cross-site tracking.
Analytics cookies load only if you consent. We use Cookiebot to manage that consent: on your first visit you can accept or reject non-essential cookies, and you can change your mind at any time through the cookie settings link in the site footer. Until you consent, non-essential storage is denied by default, so no analytics cookies are set and no analytics data is collected.
Google may process analytics data outside the UK, under recognised transfer safeguards. Google Analytics 4 does not log or store full IP addresses.
We also use Google Search Console to see how the site performs in search results. It does not set cookies on your device and collects no personal data about you.
How AI extraction works with your documents
When you upload a SOW and request extraction, the document is sent once to Anthropic's Claude API, which reads it and proposes a deliverable list. Under Anthropic's commercial API terms, content sent to the API is not used to train their models. Anthropic is a US company, so this involves a transfer outside the UK, made under their data processing terms and recognised safeguards.
Two things worth being clear about. The extraction is assistive, not automatic: it proposes, and a person on your team reviews, edits and confirms every line before it becomes part of your record. Nothing in Scope Creep makes an automated decision that produces legal effects or similarly significant effects for anyone. And if you'd rather not send a particular document through extraction at all, you can skip the upload and enter deliverables manually — the product works either way.
Emails we send
Account emails — signup confirmation, password reset and similar — are sent from our own domain through our hosting provider's transactional email infrastructure. If you contact us through the form, your submission is emailed to us with your address set as the reply-to so we can answer you directly. We don't send marketing email.
Your clients' data
The SOWs and workspace content you upload will usually contain information about your clients and the people who work there. For that data, you are the data controller — you decide what goes in and why — and we act as your processor, handling it only to provide the service. By uploading content you confirm you're entitled to do so. We never contact your clients, and nothing in your workspace is visible to any other customer.
One exception worth knowing: the product includes a shared sample workspace ("North Peak Digital") that any account can load to explore the product with realistic fictional data. It is communal by design — anything entered there is visible to other accounts using it. Don't put real client information in the sample workspace.
Why we're allowed to process your data
We process account data, workspace content and billing data because it is necessary to perform our contract with you — to run the product you signed up for.
We process technical logs, hashed IP addresses and abuse-prevention records under our legitimate interests in keeping the service secure, available and free from abuse.
We process contact form submissions under our legitimate interests in responding to enquiries, or to take steps at your request before entering into a contract.
Where we ever need consent, we will ask for it clearly and you can withdraw it at any time.
Who else helps us run the service
- — Lovable Cloud — application hosting, database, file storage, authentication and transactional email, built on Supabase infrastructure.
- — Anthropic — AI extraction of uploaded SOWs, as described above.
- — Stripe — payment processing and subscription billing.
- — Google — sign-in, if you choose to use it; and Google Analytics, Tag Manager and Search Console on our public website, as described under "Cookies and analytics".
- — Cookiebot (Usercentrics) — cookie consent management on our public website.
Each processes data solely to provide their service to us, under contract. Some operate outside the UK; where they do, transfers take place under recognised safeguards such as the UK's international data transfer mechanisms and the providers' own data processing agreements. If we add or change a provider in a way that affects your data, we'll update this list.
How long we keep things
Your workspace data stays with us while your account is active.
If you close your account, or ask us to delete it, we delete your workspace content — including uploaded documents — within 30 days, allowing a short period for it to age out of routine backups.
You can ask us for a copy of your workspace data at any time while your account is active, and for up to 30 days after closure. Email us and we'll provide it. We're working on making that export available directly inside the app.
Contact form submissions, and the abuse-prevention records containing hashed IP addresses, are kept for up to 12 months and then deleted. We keep minimal billing records for as long as UK tax law requires.
Your rights
Under UK data protection law you can ask us to: give you access to the personal data we hold about you, correct it, delete it, restrict or object to how we use it, or provide it in a portable format. Email us and we'll respond within one month.
You also have the right to complain to the Information Commissioner's Office at ico.org.uk — though we'd appreciate the chance to put things right first.
If you're a client of one of our customers and your details appear in their workspace, your request is usually best directed to that agency, since they decide what is stored and why. Contact us and we'll help route it.
Security
Access to workspaces is controlled by authentication and enforced at the database level, so each workspace's data is isolated from every other customer's. Uploaded documents live in private storage scoped to your workspace and cannot be read by anyone outside it. Stored SOWs cannot be overwritten once uploaded, so the document behind your record stays as it was signed.
Connections to the service are encrypted in transit, passwords are stored only as hashes, and new passwords are checked against known breach databases. Administrative access to production data is limited to the sole trader named at the top of this policy.
If a personal data breach occurs that is likely to result in a risk to people's rights and freedoms, we will report it to the ICO within 72 hours of becoming aware of it, and tell affected customers without undue delay where the risk to them is high.
Children
Scope Creep is a business tool and is not intended for anyone under 18.
Changes to this policy
If this policy changes in any meaningful way, we'll update the date at the top and flag the change to signed-in users. Continuing to use the service after that means you accept the updated policy.
Contact
Thomas Matthews, trading as Scope Creep — hello@scopecreep.agency