ScavoPrivacy Policy
Privacy Policy
What Scavo collects, where it is stored, which processors touch it, and how long it is kept. Written against the systems the product actually runs on.
Effective 8 August 2026
01Scope
This policy explains how Scavolution handles personal data in Scavo, the private Instagram revenue operating system. It covers the marketing site and the operator workspace.
Two groups are involved. Operators are the people who hold Scavo accounts. Leads are the people your team converses with on Instagram. For operator accounts we act as the data controller. For lead conversations we act as a processor on your behalf, and you remain the controller.
02What we collect
Operator accounts
- Name, email address, and a scrypt-hashed password. We never store the password itself.
- Workspace name, timezone, role, and membership status.
- Session records, sign-in attempt counts, and lockout timestamps.
- An audit trail of workspace decisions, member changes, approvals, and tag edits.
Lead conversations
- Instagram user id, username, and display name as supplied by Meta.
- Message content, direction, timestamps, and platform message ids.
- Fields your team or the system extracts: goal, current reality, main struggle, importance, stage, intent score, tags, and owner.
- Appointment and stage-change events used for attribution.
Configuration
- Your playbook, framework, voice, offer, knowledge base, guardrails, and automation rules.
03Instagram data
When an Instagram account is connected, Scavo receives message events through Meta's webhooks and sends replies through Meta's APIs. We request only the permissions needed to read and reply to conversations for the connected account.
We do not scrape Instagram, buy contact lists, or collect data about people who have not contacted you or been contacted by you through the connected account.
Your use of these integrations is also governed by Meta's terms and platform policies.
04How we use it
- Authenticating operators and keeping workspaces separate.
- Presenting conversations with their context so your team can respond.
- Generating suggested replies from your playbook.
- Running keyword automations and scheduled follow-ups you configure.
- Producing analytics and attribution for your own workspace.
- Diagnosing faults, preventing abuse, and meeting legal obligations.
We do not sell personal data. We do not use your conversations or playbook to train models for anyone else's benefit.
05AI processing
To draft a suggested reply, the relevant conversation transcript and your playbook configuration are sent to Google's Gemini API. The response is returned, checked against your guardrails, and stored with the generation record.
If no AI credentials are configured, or the request fails, times out, or produces a reply that breaks an evidence rule, Scavo falls back to a deterministic response and no external call is relied upon.
Conversations are sent to a third-party model provider to produce drafts. If that is not acceptable for your use case, the AI drafting features can be left unconfigured and the product still operates.
06Where data is stored and who touches it
We keep the processor list short and specific:
- Turso hosts the libSQL database holding workspaces, accounts, conversations, messages, and events.
- Vercel hosts and serves the application.
- Google processes transcripts submitted to the Gemini API for draft generation.
- Meta delivers and receives Instagram messages.
These providers operate infrastructure in multiple regions, so data may be processed outside your country. We share data with them only to run the service, and otherwise disclose it only where required by law or to protect our rights.
07Retention
- Sessions expire after 14 days, and expired records are cleared.
- Conversations, contacts, and events are kept for as long as the workspace is active.
- After a workspace closes, data may be exported within 30 days and is then scheduled for deletion.
- Audit records may be kept longer where needed for security or legal obligations.
If you need a shorter retention period for lead data, that is set in the agreement between you and Scavolution.
08Your rights
Depending on where you live, you may have the right to access, correct, delete, restrict, or port your personal data, to object to processing, and to complain to a supervisory authority.
Operators can exercise these rights by contacting us. If you are a lead who has messaged a business using Scavo, that business controls your conversation data. Contact them first, and we will support their response.
Requests go to [privacy contact email]. We will respond within the period required by applicable law.
09Security
- Passwords are scrypt-hashed with a per-account salt and compared in constant time.
- Sessions are database-backed, stored as hashes, delivered in HTTP-only cookies, and expire.
- Sign-in throttling locks an account for 15 minutes after five failed attempts.
- Workspace scope and role are derived from the server session on every protected request.
- Incoming Meta webhooks are signature-verified, echo-filtered, and deduplicated.
No system is perfectly secure. If we become aware of a breach affecting your data, we will notify you without undue delay and as required by law.
11Children
Scavo is a business tool and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child's data has reached us, contact us and we will remove it.
12Changes to this policy
We may update this policy. The effective date above will change, and material updates will be communicated to workspace owners.
13Contact
Privacy questions can go to [privacy contact email], or by post to [registered business name and address]. Where required, the data controller for operator accounts is [registered legal entity].
Open your revenue room.
Scavo is a private workspace. Request access and the Scavolution team will approve your account and set the playbook up with you.
Request access