Privacy Policy
Effective Date: April 24, 2026 · Last Updated: August 20, 2026
1. Introduction
Scott Applications LLC ("we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains what information we collect, how we use it, who we share it with, and what choices you have — when you visit www.scottapplications.com, buy a website template, or buy a Scott Skill Pack (including install through our MCP server at mcp.scottapps.com).
We operate our own first-party analytics on this website. Page views are recorded only if you accept optional analytics on the cookie banner. We do not use Facebook Pixel or advertising trackers. Skill packs and their checkers never phone home — they do not contain analytics, beacons, or account gates.
2. Information We Collect
A. Information You Give Us Directly
When you fill out a contact form, buy a website template, buy a skill pack, or join our newsletter, we collect:
- Name and business name
- Email address
- Phone number
- Project details and message
- Budget range (if provided)
- Service(s) of interest
- City or region (if provided)
- Purchase email and the license key we issue for a skill pack (the key is hashed at rest)
- Optional pack-improvement notes you type in your locker after ticking the consent box — never your source code or AI prompts
B. Information Collected Automatically
If you choose "Accept all" on the cookie banner, our first-party analytics records the following. If you choose essentials only or decline, we do not write page views.
- IP address — used to derive city-level location only (we do not store street-level or precise GPS location). Your IP is stored temporarily and used to map general visitor geography.
- City-level location — derived from your IP address via a geolocation lookup. We record city and region, not your exact address.
- Device type, operating system, and browser — parsed from your User-Agent string (e.g., "mobile / iOS / Safari").
- Pages visited and session path — we track which pages you view and in what order, to understand how visitors navigate the site and which pages lead to contact form submissions. This data is linked to an anonymous session ID, not your name or email.
- CTA and link clicks — we record when visitors click call buttons, email links, or other key actions on the site. These events are linked to the same anonymous session ID.
- Referrer URL — the page or search engine that brought you to our site, if your browser sends this information.
C. Cookie Consent Record
When you respond to our cookie consent banner, we record your choice (accepted or declined), along with your device type, browser, and the page you were on when you responded. This record is stored so we can honor your preference and demonstrate compliance.
D. reCAPTCHA v3
Our contact forms are protected by Google reCAPTCHA v3, which analyzes visitor behavior to detect bots. reCAPTCHA operates under Google's Privacy Policy. We store the reCAPTCHA score on each lead submission for spam auditing purposes. We do not have access to any additional data reCAPTCHA may collect on Google's end.
E. Skill Packs and MCP
A purchased skill pack is installed through our MCP with your SSK- key. The files your agent writes locally do not contact us. They do not see your repository. They do not upload prompts. There is no tracker, beacon, or analytics SDK inside any pack.
To deliver the product we do collect:
- The email used at Stripe Checkout
- A license key we generate (SSK-…), stored hashed
- That you opened the locker or asked MCP to install a pack you paid for
When your coding agent talks to mcp.scottapps.com, that is an HTTPS request to our server so we can deliver the product. We retain operational records of that use:
- Which tool ran (for example install, load a pack, fetch a reference)
- Which pack slug was requested, when one was named
- Whether the call succeeded, and a short error code if it did not
- A hash of your license key — never the key itself
- Which kind of coding app called us (Claude, Cursor, Copilot, Grok, or other), taken from the request's user-agent family — not the full string
We do not receive, store, or read the files on your disk, the prompt you typed, your source code, .env files, repository paths, or how many tokens your agent used. Those never leave your machine.
We use the operational records to run and secure the service, and — when we choose to — to decide which pack to upgrade next. Daily counts (tool, pack, success or fail) can be copied into our internal factory inbox. Same company. Not sold. Not shown on the public site. A count is a hypothesis for a later edition; the copy already on your disk does not change by itself.
If you send an improvement note from the locker, you must tick a box first. We store whether the pack helped on that task, an optional short note, which pack you named, and your locker email so we can delete the note if you ask.
3. Cookies and Local Storage
We use a small number of cookies and browser storage values:
- Session ID cookie — an anonymous random identifier generated when you first visit the site. This is used to stitch together your page views and interactions into a single session for analytics. It does not identify you by name or email and is not shared with any third party.
- Cookie consent cookie (
sa_consent) — stores your response (full / essential / declined) so we don't ask you again. - Skill locker cookie — httpOnly, set after you paste a license key or enter an email code. Lets you download and send an optional improvement note. It is not an analytics cookie.
- Poll deduplication cookie — if you participate in an on-site poll, a short-lived HTTP-only cookie prevents your vote from being counted more than once. This cookie contains only your vote choice and expires after 30 days.
We do not set any advertising cookies, cross-site tracking cookies, or cookies from social media networks. Third-party services we use (Mapbox for maps, Google for reCAPTCHA, Stripe for payments) may set their own cookies — please refer to their respective privacy policies linked in Section 5.
4. How We Use Your Information
- To respond to your inquiry — we use your name, email, phone, and project details to follow up on contact form submissions and proposal requests.
- To process payments — website templates and skill packs are paid through Stripe. We do not store your card number or full payment details — Stripe handles all payment data.
- To deliver skill packs — we use your purchase email and license key so you can open the locker or install through MCP. We use MCP operational records (tool, pack slug, success or fail, hashed key) to keep the host running and to decide which packs to upgrade when we choose to. Optional locker notes are used the same way, and only after you opt in. Your email stays with the order; it is not copied into that upgrade inbox.
- To secure the MCP host — rate limits, fault codes, and hashed-key check-ins help us stop abuse and keep paying seats working. We do not use this to read your projects.
- To send transactional emails — we use SMTP2GO to deliver confirmation emails, approval or rejection notices for template applications, and project-related communications. We do not send unsolicited marketing emails.
- To send our newsletter — if you opt in, we use your email address to send occasional business tips and updates. You can unsubscribe at any time by replying to any newsletter email or contacting us directly.
- To understand how our site is used — if you accepted analytics, first-party page views, session paths, and device/browser breakdown help us improve the site. This data is never sold or shared with advertisers, and it is never written by a skill pack.
- To detect and prevent spam — reCAPTCHA scores and IP-based dev/test flags help us filter automated form submissions from real inquiries.
5. Third-Party Services We Use
The following third-party services process data on our behalf. Each operates under its own privacy policy:
- MongoDB Atlas — cloud database where all lead, analytics, and consent data is stored. Hosted in the United States. MongoDB Privacy Policy
- SMTP2GO — transactional email delivery for contact form confirmations and admin notifications. SMTP2GO Privacy Policy
- Stripe — payment processing for website template reservations. We do not store payment card details. Stripe is PCI DSS compliant. Stripe Privacy Policy
- Google reCAPTCHA v3 — bot detection on contact forms. Google Privacy Policy
- Mapbox — map tiles rendered on our service area and analytics map components. Mapbox receives your IP address when map tiles are loaded. Mapbox Privacy Policy
We do not use Google Analytics, Meta/Facebook Pixel, TikTok Pixel, or any advertising network trackers.
6. Data Retention
- Lead submissions — retained indefinitely for business records and project history unless you request deletion.
- Analytics data (page views, events, journey sessions) — retained for up to 24 months for trend analysis, then purged.
- Cookie consent records — retained for 12 months.
- Newsletter subscribers — retained until you unsubscribe, at which point your email is removed from the active list within 7 days.
- Template waitlist entries — retained until the template launches or you request removal.
- Skill-pack orders and hashed license keys — retained as business records of the sale so we can re-issue access. Ask us to close a key and we will mark it revoked.
- Opt-in pack feedback — retained up to 24 months, or deleted sooner if you ask.
- MCP operational events (tool, pack slug, success or fail, hashed key, client family) — retained 90 days, then purged.
- MCP daily counts (how often a tool or pack ran, success or fail — no hashed key) — retained up to 24 months so we can plan upgrades, then purged.
7. Your Rights and Choices
You have the right to:
- Access — request a copy of the personal information we hold about you.
- Correct — ask us to correct inaccurate information.
- Delete — request that we delete your personal information. Note that some data may need to be retained for legal or business record purposes.
- Opt out of the newsletter — reply to any newsletter email or contact us directly and we'll remove you within 7 days.
- Withdraw cookie consent — you can clear your cookies at any time through your browser settings. Non-essential tracking will stop if you have previously declined consent on our banner.
- Skill-pack notes — locker feedback is optional. Do not tick the box if you do not want the note stored. Email us to delete a note you already sent.
- MCP usage — ask us to close a key and we delete the hashed operational events for that key. Daily counts have no key on them and stay as de-identified totals until they age out.
To exercise any of these rights, contact us at contact@scottapps.com or call (254) 900-2520. We'll respond within 10 business days.
8. Children's Privacy
Our website is not directed at children under 13. We do not knowingly collect personal information from children. If you believe a child has submitted information to us, please contact us and we will delete it promptly.
9. Changes to This Policy
We may update this Privacy Policy as our services evolve. When we do, we'll update the "Last Updated" date at the top of this page. Continued use of the site after changes are posted constitutes acceptance of the updated policy.
10. Contact Us
Scott Applications LLC
212 Dallas St, Waco, TX 76704
contact@scottapps.com
(254) 900-2520