Privacy Policy

Understand how Scopture, a product of Ducflair, collects, uses, and protects your personal data.

Introduction

This Privacy Policy explains how we process your personal data when you use Scopture’s services. Some processing is necessary for us to provide you with our services (see Section 3A), while other processing may be based on your explicit consent, which you can give or withdraw at any time (see Section 3B). By using Scopture, you acknowledge that you have read and understood this Privacy Policy.


1. Important Information and Who We Are

Purpose of This Privacy Policy

This policy provides information about how Scopture, a product of Ducflair, collects, processes, and safeguards your personal data when you use our services, including this website and our CAD tools.

Data Controller

Ducflair, based in Portugal, is the controller responsible for your personal data. For the purposes of this Privacy Policy, references to “Scopture,” “we,” “us,” or “our” refer to Ducflair.

Contact Information

If you have any questions or concerns about this Privacy Policy or your personal data, please contact us:


2. The Data We Collect About You

We collect and process various types of data to provide and improve our services. The categories of personal data we may collect include:

  • Identity Data: First name, last name, username, or similar identifiers.
  • Contact Data: Email address, telephone number, billing address, and delivery address;
  • Payment and Billing Data: Payments are processed by Stripe. Scopture does not receive or store complete payment-card or bank-account details where those details are collected directly by Stripe. We may receive limited billing and transaction information, such as your billing name and address, subscription status, payment status, amount, currency, invoice information, and Stripe customer or transaction identifiers;
  • Technical Data: IP address, browser type and version, device information, operating system, approximate time zone, authentication status, session identifiers, security logs, and technical information required to operate and protect the service. We do not receive or store your password from third-party assistant platforms, and Scopture MCP tools must not be used to submit passwords, API keys, one-time authentication codes, or other authentication secrets;
  • Usage Data: Information about how you use our services, including interaction with features and user behavior;
  • Design Data: Drafts and models you create using Scopture’s CAD tools;
  • Connected Assistant and MCP Data: When you connect Scopture to a compatible third-party assistant or application, such as ChatGPT or Claude, we may receive the information that you or the third-party service intentionally provide to a Scopture MCP tool. This may include tool instructions, selected project or document identifiers, project content required to perform the requested action, account identifiers, and the results of authentication or authorization checks.

Scopture does not request or attempt to obtain your complete conversation history. We process only the specific tool inputs, referenced resources, and other information made available to the Scopture integration for the action you requested.

Providing your Identity and Contact Data is a contractual requirement necessary to create an account and access Scopture’s services. If you do not provide this data, we will be unable to register your account or provide access to the platform. Providing Payment Data is required only if you subscribe to a paid plan. All other data collection is either technically necessary for the functioning of the service or entirely voluntary.


3. How We Use Your Personal Data

We only process your personal data when we have a valid legal basis to do so. Most commonly, we use your data under the following categories:

A. Performance of a Contract

We process the following data because it is necessary to perform the contract we have with you (i.e., our Terms of Service) or to take steps at your request before entering into such a contract:

  • Account Creation: To register you as a new user and manage your secure profile;
  • Service Delivery: To provide access to Scopture’s CAD tools, project management features, and technical support;
  • Subscriptions and Payment Processing: To create and manage paid subscriptions, receive payment status information, provide access to purchased services, and coordinate transactions and refunds processed by Stripe;
  • Connected Integrations: To authenticate your Scopture account, respond to MCP tool requests, retrieve or modify Scopture content according to your instructions, return the requested result to the connected service, and maintain the security and reliability of the integration.

We rely on your explicit, freely given consent for the following activities:

  • Marketing Communications: To send you newsletters, promotional offers, or updates about new features where you have opted in to receive them. You may withdraw your consent at any time by using the unsubscribe link included in each marketing email or by contacting us at [email protected]. Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal.

C. Legitimate Interests

We process your data when it is necessary for our legitimate interests (or those of a third party), provided your fundamental rights do not override those interests:

  • Platform Security: To detect and prevent fraud, unauthorized access, or malicious activity;
  • Service Analytics: To analyze how users interact with our interface so we can fix bugs and improve the user experience.

Where required, we enter into appropriate data-processing agreements with service providers that process personal data on our behalf.

We may process your data where it is necessary for compliance with a legal obligation to which we are subject, such as:

  • Tax & Accounting: Keeping records of financial transactions for Portuguese tax authorities;
  • Regulatory Requests: Responding to valid legal requests from government or law enforcement bodies.

Connected Assistants and MCP Integrations

Scopture may be made available through compatible third-party assistants and applications using the Model Context Protocol (MCP) or other supported integration mechanisms.

Information received by Scopture

When you invoke a Scopture tool through a connected service, that service may send Scopture the information necessary to perform your requested action. Depending on the tool, this may include:

  • The specific instruction or parameters provided to the tool;
  • Your Scopture account or organization identifier;
  • The project, file, document, or other resource you selected;
  • Content required to read, create, update, or otherwise process that resource;
  • Technical and security information necessary to authenticate the request and prevent abuse.

Scopture does not require access to your complete conversation history. We process only the information that the connected service makes available to the Scopture tool for the requested operation.

Information returned to the connected service

Scopture returns only the information reasonably necessary to respond to the requested tool operation. Depending on the request, this may include selected project information, operation results, generated previews, validation errors, or confirmation that a requested action was completed.

Scopture does not intentionally include internal diagnostic identifiers, security logs, or unrelated account information in MCP tool responses unless they are strictly necessary to complete or troubleshoot the requested operation.

Read and write operations

Some Scopture MCP tools may only retrieve information. Other tools may create, update, export, or delete content in your Scopture account. The available operation and its effects will be described by the relevant tool, and actions that change external data may require confirmation by the connected service.

Third-party processing

The connected service separately processes information under its own terms and privacy policy. OpenAI, Anthropic, and any other compatible service are independent providers and are not acting as Scopture’s data processors merely because you choose to connect Scopture to their service.

Information you submit to the connected service before it is sent to Scopture is governed by that service’s privacy practices. Information received and processed by the Scopture MCP server is governed by this Privacy Policy.

Purpose and use

We process information received through an MCP integration only to:

  • Authenticate and authorize access;
  • Perform the operation requested by you;
  • Return the requested result;
  • Protect the integration and Scopture against fraud, abuse, and unauthorized access;
  • Diagnose errors and maintain service reliability.

MCP request content is not used for advertising, behavioral profiling, or training general-purpose artificial intelligence models. This includes private project and design content received through MCP.

Permissions and user control

Access is limited to the permissions granted through the connection and to the resources available to your Scopture account. You have the right to manage and revoke your MCP integration access at any time. To do so, you can:

  • Disconnect Scopture directly within the connected third-party service (such as ChatGPT or Claude);
  • Revoke OAuth access from your Scopture account settings, where that functionality is available;
  • Delete your Scopture data separately, disconnecting the integration prevents new MCP requests from accessing your account, however it does not automatically delete information previously stored in your Scopture account or information independently retained by the third-party service.
  • Contact us at [email protected] or [email protected] for assistance with managing your integrations or data.

MCP request retention

MCP request content is processed transiently to perform the requested operation and is not ordinarily retained. Request bodies, prompts, project content, and tool outputs are excluded from operational logs. We may retain limited operational metadata, such as request timing, tool usage, latency, and error information, where necessary to maintain security, monitor performance, and troubleshoot issues. Integration authorization data is retained only for as long as the integration remains authorized. Session information retained independently by the connected third-party service is subject to that provider’s own retention practices. The applicable Scopture retention periods are described in Section 5.


4. Disclosures of Your Personal Data

We share your data only with trusted third-party providers to the extent necessary for the purposes described in this Privacy Policy, including Stripe for payment processing, Amazon Web Services (AWS) for cloud infrastructure and hosting, Grafana Cloud for system monitoring and performance analytics, and a self-hosted version of Umami for cookieless website analytics (page views, referrer, browser type, and screen resolution — no personally identifiable information is collected by us).

Where you choose to connect Scopture to a third-party assistant or application, such as ChatGPT or Claude, information necessary to execute a requested tool operation may be exchanged with the relevant provider. These providers separately process information under their own terms and privacy policies. Scopture does not disclose information to such a service unless the integration is connected and a relevant operation is requested.


5. Data Retention

We retain personal data only for the periods described below, unless a longer period is required by law or necessary for an active legal claim, security investigation, or legal hold.

Account and Project Data

Account information, project data, and content intentionally saved to your Scopture account are retained while your account remains active. Following a verified account-deletion request, access is disabled and the data is deleted or irreversibly anonymized within 30 days.

Project Files, Previews, and Exports

Project files and generated previews follow the retention period of the associated project or account. Temporary exports are deleted within 7 days after creation.

OAuth Tokens and MCP Connections

OAuth tokens and integration credentials are retained while the integration remains connected or authorized. When authorization is revoked, future MCP requests using that authorization are rejected, and stored credentials are removed within 24 hours.

Disconnecting Scopture through a connected service prevents that service from making future MCP requests. Where Scopture receives or processes a revocation, the associated credentials are invalidated.

MCP Request Content

MCP request content is processed only to perform the requested operation and is not ordinarily retained in application or operational logs. Content intentionally saved to a Scopture project is treated as project data.

MCP Operational Metadata

Limited MCP operational metadata is retained for 30 days after the request. This may include the request time, invoked tool, account or organization identifier, outcome, latency, and error category.

Security and Audit Logs

Security and audit logs are retained for 90 days after creation. Records associated with an active security investigation may be retained until the investigation is completed.

Backups

Data removed from active systems may remain in encrypted backups until those backups are removed through their normal rotation, no later than 90 days after deletion from the active systems.

Support Cases and Attachments

Support correspondence and associated attachments are retained for 24 months after the support case is closed, unless they form part of a financial record, security investigation, or legal dispute.

Billing, Invoices, and Tax Records

Billing, invoice, transaction, subscription, refund, and tax records received or maintained by Scopture are retained for the period required under applicable Portuguese accounting and tax law. Payment-method details and other payment information processed independently by Stripe are subject to Stripe’s own privacy, retention, and legal obligations.

Refund Records

Records necessary to document or process a refund are retained according to the applicable billing and tax retention period. Other refund correspondence follows the support-record retention period.

Records relevant to a legal dispute, regulatory matter, investigation, or legal hold may be retained until the matter is resolved and the applicable limitation or enforcement periods have expired.

Irreversibly Anonymized Statistics

Information that has been irreversibly anonymized so that it can no longer reasonably identify an individual may be retained without a fixed retention period.


Under General Data Protection Regulation and other applicable laws, you have the following rights:

  • Access: Request a copy of the personal data we hold about you;
  • Correction: Correct any inaccuracies in your data;
  • Erasure: Request the deletion of your data where applicable;
  • Restriction: Restrict the processing of your data in certain circumstances;
  • Portability: Request a copy of your data in a structured, commonly used format;
  • Objection: Object to the processing of your data for specific purposes, such as direct marketing.

To exercise your rights, contact us at [email protected].

You also have the right to lodge a complaint with a data protection supervisory authority. In Portugal, this is the Comissão Nacional de Proteção de Dados (CNPD). You can find their contact details at www.cnpd.pt.


Our website and services may contain links to external sites or third-party applications. We are not responsible for the privacy practices of these entities. Please review their privacy policies before providing personal data.


8. Cookies

Scopture uses only strictly necessary cookies to ensure the proper functioning of the platform. These cookies are essential for features such as user authentication. They are temporary, session-based, and are not used to track, profile, or collect any personal data for marketing or analytical purposes. No third-party cookies are used on the platform.

For website analytics, we use Umami, a privacy-friendly, cookieless analytics tool. Umami does not use cookies, does not collect personally identifiable information, and does not track users across sessions or websites. The aggregate analytics data collected (page views, referrer, browser type, screen resolution) cannot be used to identify you individually.


9. Children’s Privacy

Scopture’s services are not directed at individuals under the age of 13. We do not knowingly collect personal data from children under 13. If you are a parent or guardian and believe that your child has provided us with personal data, please contact us at [email protected]. If we become aware that we have collected personal data from a child under 13 without appropriate parental consent, we will take steps to delete that data promptly.


10. Changes to This Privacy Policy

We may update this Privacy Policy periodically to reflect changes in our practices, legal requirements, or operational needs. The updated version will be published on our website with its effective date. Where changes materially affect how we process your personal data, we will provide reasonable advance notice by email or through a prominent notice on the platform before the changes take effect. Where required by law, we will obtain your consent before applying the changes.


11. Contact Us

If you have any questions, concerns, or wish to exercise your rights, you can reach us at:

Alternatively, you may write to us at:

Ducflair
Rua Padre Antídio Coelho Sousa, nº 264
4575-281 Oldrões, Penafiel, Portugal

Copyright © 2026 Scopture. All rights reserved.