Effective September 3, 2026
This policy applies specifically to the Refore Scout browser extension (“Scout”, “the extension”), published by Refore (“we”, “us”). It describes every category of data the extension handles, why we handle it, how long we keep it, and every party it is shared with. For our other products and our website, see the Refore Privacy Policy.
Contact for any privacy question or request: [email protected].
Scout keeps the following in your browser’s local extension storage. This data stays on your device, is not synced by us, and is never transmitted to us:
| Data | Purpose |
|---|---|
| Your watch list: the address and title of each page you added, and which block of it you selected | To re-check the right block on the right page |
| Content snapshots of the selected blocks and the values extracted from them, with history | To show you what changed — deltas, new items, and text diffs |
| Topics you follow, items discovered for them, and their scores | To surface new content matching what you follow |
| Your settings: check frequency, notification channels and their credentials, rules and thresholds, interface language, diagnostics preference | To run Scout the way you configured it |
| Sign-in state, if you choose to sign in | To keep you signed in for optional online features |
| Your own AI endpoint, model name and API key, if you configure one | So Scout can call your model provider directly |
| A random installation identifier generated on your device | To rate-limit and de-duplicate diagnostic reports (Section 3.5) |
You can delete all of it at any time by removing the watches and topics in the dashboard, or by uninstalling the extension, which permanently deletes the extension’s local storage.
Signing in is optional — local monitoring works fully without an account. If you sign in, Scout authenticates you against Refore’s servers and receives an access token. Your account identifier and the email address of your Refore account are transmitted to and stored on Refore’s servers, to authenticate you, to determine which features your plan includes, and to enforce per-account usage limits. Scout never asks for or handles your password.
Recipient: Refore.
Scout uses AI only to help you set up and rank what you already asked it to watch: to identify which value in the block you selected is worth tracking and to name it, to turn a rule you typed into a condition, to score how relevant a discovered item is to a topic you follow, and to summarize such an item. AI never posts, replies, or acts on any site for you.
If you are signed in and have not configured your own model, these requests go to Refore’s servers, which pass them to a third-party AI model provider acting as our processor — currently Google (Gemini models) and OpenAI. Each request contains only what that task needs, truncated in length: the title of the page you are watching and the text of the block you selected; the candidate values found in that block; the topic you typed together with the titles and short snippets of the items being scored; and, for the setup assistant, the visible text and link structure of the page you are adding.
It does not contain your email address, your credentials, your browsing history, or content from pages you did not add. Neither we nor our model providers use this content to train models, and we retain it only as long as needed to return a response.
If you configure your own model instead, the same content is sent directly from your browser to the endpoint you specified and does not pass through Refore at all. Your API key is stored only on your device and is never sent to us. The operator of that endpoint is a party of your choosing, governed by its own privacy policy.
If you are not signed in and have not configured your own model, Scout makes no AI requests at all.
Recipients: Refore, and our third-party AI model providers, Google and OpenAI (see Section 4).
Websites change their markup, so Scout can record how a given kind of page on a given site is laid out and reuse that for future checks. When it does, it sends Refore’s servers structural metadata only: the site’s domain, the URL path pattern (never the query string or fragment), the identifiers of the page elements involved, one sample address of the page it was derived from, and your installation identifier.
This describes a public site’s layout. It does not include your snapshots, your extracted values, your history, your topics, or the content of what you are monitoring.
Recipient: Refore.
Browser (system) notifications are generated locally and are not transmitted anywhere.
If you add a notification channel — Feishu, Telegram, or a custom webhook — then when something you watch changes, Scout sends that channel a message containing the card title, a label for the page type, the link to the watched page, and the values or text that changed. It goes from your browser directly to the endpoint you configured, using the token or webhook address you supplied.
Recipients: the messaging service you chose — for example Feishu, Telegram, or the operator of your custom webhook. These are third parties selected by you and governed by their own privacy policies. Scout sends nothing to any channel you did not add.
To find and fix failures — a check that could not read a page, a site that refused the request, a storage or notification failure, an uncaught error — Scout sends error and health events to our diagnostic logging service. An event may contain the event type and severity, an error code and stack trace, the address of the page involved with its query string and fragment stripped, the page title, the extension version, your interface language, your browser’s user-agent string, your installation identifier, and your account identifier if you are signed in.
These reports do not contain the content of the pages you monitor, your snapshots, your topics, your notification credentials, or your own-model configuration. Text taken from a page is included only if you separately enable the “include page text in diagnostics” setting, which is off by default.
You can turn diagnostics off entirely in Scout’s settings.
Recipients: Refore, the cloud infrastructure providers that host our servers and logs on our behalf, and Cloudflare, which handles network delivery. Reports are kept only as long as needed to investigate and fix the underlying problem, then deleted.
Scout can expose your local Scout data to an AI assistant running on your own computer over a connection that never leaves your machine. It is off by default, the data is never sent to us, and only local applications you installed and authorized can read it.
The complete list:
We may also transfer data as part of a merger, acquisition, or sale of assets; if that happens we will notify you, and the data will remain subject to this policy or a successor policy no less protective.
We never share your data with data brokers, advertising networks, or analytics resellers, and we never sell or rent it.
All transmission uses HTTPS. Credentials are stored only where they are needed — your model API key and notification tokens never leave your device. On our servers we apply access controls and encryption at rest. No system is perfectly secure; if a breach affects your personal information we will notify you and the relevant regulators as required by law.
Scout is not directed to children under 13, or under the minimum age in your jurisdiction, and we do not knowingly collect their personal information.
We may update this policy. Material changes will be reflected in the effective date above and, where significant, announced in the extension or by email. Continuing to use Scout after an update means you accept the updated policy.
Copyright © 2026 refore.ai All rights reserved.