Privacy Policy

Last updated: February 25, 2026

1. Introduction

Mythic Works LLC ("we", "us", or "our") respects your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the Mythic Scout platform ("the Service").

2. Information We Collect

Account Information

When you create an account, we collect:

  • Name and email address
  • Hashed password (we never store plaintext passwords)
  • Account preferences and settings

Usage Data

We automatically collect:

  • Scan parameters (categories, locations, search radius)
  • Feature usage events (scans created, leads viewed, exports downloaded)
  • IP address, browser type, and device information (via server logs)
  • Timestamps of account activity

Business Data

The Service collects and processes publicly available business information, including business names, website URLs, addresses, phone numbers, and website content. This data is sourced from third-party APIs (Google Places) and direct website crawling of publicly accessible pages.

3. How We Use Your Information

  • Provide the Service: Run scans, generate scores, extract contacts, and display results.
  • Improve the Service: Analyze usage patterns to improve scoring accuracy and user experience.
  • Communicate: Send account-related notifications, security alerts, and product updates.
  • Enforce Terms: Detect abuse, prevent fraud, and enforce our Terms of Service.
  • Billing: Process payments when paid plans are introduced.

4. Data Sharing and Disclosure

We do not sell your personal information. We may share data with:

  • Infrastructure providers: Vercel (hosting), Neon (database), Railway (worker processing), AWS (storage) — only as necessary to operate the Service.
  • Third-party APIs: Google Places API (business discovery), Anthropic (AI analysis) — query data is sent to these services as part of scan processing.
  • Legal requirements: When required by law, subpoena, or to protect our rights, safety, or property.

5. Business Data and Crawled Websites

Mythic Scout crawls publicly accessible websites to analyze their technical quality. We store extracted signals (performance, SEO, accessibility metrics), contact information found on public pages, and generated scores. This data is used to provide analysis results to our users.

Business owners: If your business appears in our system and you would like your data removed, contact us at privacy@mythicscout.com. We will process removal requests within 30 days.

6. Data Retention

  • Account data: Retained while your account is active. Deleted within 30 days of account deletion.
  • Scan results and lead data: Retained while your account is active. Shared business lead records may persist if linked to other users' scans.
  • Usage events: Retained for up to 24 months for analytics, then anonymized or deleted.
  • Server logs: Retained for up to 90 days.

7. Data Security

We implement industry-standard security measures including:

  • Encrypted data transmission (TLS/HTTPS)
  • Bcrypt password hashing
  • JWT-based session authentication
  • Database-level access controls
  • Regular security reviews

No system is 100% secure. We cannot guarantee absolute security but will notify affected users promptly in the event of a data breach.

8. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access: Request a copy of the data we hold about you.
  • Correction: Request correction of inaccurate data.
  • Deletion: Request deletion of your account and associated data.
  • Export: Download your data in a portable format (CSV export is available in the Service).
  • Objection: Object to certain processing activities.

To exercise these rights, contact privacy@mythicscout.com. We will respond within 30 days.

9. Cookies and Tracking

The Service uses essential cookies for authentication and session management. We do not use third-party advertising cookies or trackers. Analytics are collected server-side via usage events, not through client-side tracking scripts.

10. International Users

The Service is hosted in the United States. If you access the Service from outside the US, your data may be transferred to and processed in the US. By using the Service, you consent to this transfer. We process data in accordance with applicable privacy laws including GDPR where applicable.

11. Children's Privacy

The Service is not intended for individuals under 18. We do not knowingly collect data from children. If we learn we have collected data from a child under 18, we will delete it promptly.

12. Changes to This Policy

We may update this Privacy Policy periodically. Material changes will be communicated via email or in-app notification at least 14 days before taking effect. The "Last updated" date at the top reflects the most recent revision.

13. Contact Us

For privacy-related questions or requests, contact us at privacy@mythicscout.com.