1. Introduction
This Privacy Policy explains how Scotive (“we”, “us”) collects, uses, and shares information when you use scotive.com and the Scotive service (the “Service”). It is written to match how the product actually works today: Gmail-connected invoice tracking, optional QuickBooks Online connection, human-approved sending, and AI-assisted extraction and drafting.
By using the Service you acknowledge this Policy. Related terms are in our Terms of Service.
2. Who we are
The Service is operated under the brand Scotive(websites at scotive.com / www.scotive.com; API at api.scotive.com).
Privacy requests: privacy@scotive.com
General support: support@scotive.com
3. Information we collect
Account information. Email address, password (stored as a one-way hash), optional display name, and preferences such as timezone and digest settings.
Google / Gmail connection. When you connect Gmail we receive OAuth tokens, the connected mailbox email, profile display name (when available), granted scopes, and connection status. Access and refresh tokens are encrypted at rest before storage.
Intuit / QuickBooks Online connection (optional). When you connect QuickBooks Online we receive OAuth tokens, your QuickBooks company (realm) identifier, granted scopes (accounting API access), and connection status. Access and refresh tokens are encrypted at rest before storage. We may also receive company display metadata Intuit returns with the connection.
Invoice and payment-ops data we derive or import. We store a structured ledger and related records, which may include:
- Client name and email, invoice references, amounts, currency, and dates — from Gmail extraction and/or from QuickBooks invoice and customer records you authorize us to read
- QuickBooks identifiers (for example invoice Id, DocNumber, Balance) and paid / not-paid status we sync from QuickBooks
- Status (for example invoiced, overdue, promised, disputed, paid)
- Evidence snippets and quotes (for example a promise date or dispute phrase) and Gmail message/thread identifiers needed to reopen context
- Review-queue items when extraction confidence is low
- Chase drafts you generate or that the escalation ladder prepares for review
- Records of chase emails you chose to send (subject, body, timestamps)
- Optional suppressed-sender list and client-merge preferences
We do not store your entire mailbox or your entire QuickBooks company. We store extracted or imported facts needed for the ledger and drafts, evidence needed for tracking, and references so we can fetch conversation context from Gmail when you open an invoice and keep open / paid status in sync with QuickBooks when connected.
Usage and security data. We may process technical logs (for example IP address, timestamps, error diagnostics) and login-attempt records used for rate limiting and account security.
4. How we use information
We use information to:
- Provide, maintain, and secure the Service
- Detect invoices you sent via Gmail and, when connected, import open invoices from QuickBooks into your ledger
- Keep your open / paid ledger current, including syncing paid status from QuickBooks and matching Gmail conversations to QuickBooks-sourced invoices
- Interpret client replies (promises, disputes, payment claims, questions)
- Generate follow-up and reply drafts for your review
- Send email only when you explicitly approve (or send an optional daily digest you enabled), via your connected Gmail
- When you mark an invoice paid or confirm payment received in Scotive for a QuickBooks-linked invoice, update that invoice in QuickBooks (for example by creating a linked Payment) so Balance reflects what you confirmed
- Operate settings such as escalation timing and digests
- Respond to support requests and enforce our Terms
- Improve reliability and product quality using aggregated or de-identified insights where feasible
5. Artificial intelligence processing
To extract invoice details and draft emails, relevant content (for example message subjects, body excerpts, PDF text snippets, and ledger fields) may be sent to third-party AI infrastructure — currently via OpenRouter, which routes requests to model providers (for example OpenAI models). That processing is for inference to operate features you use.
Scotive’s policy: we do not use your email content to train Scotive’s own models. We configure and select providers with the intent that customer content is not used to train their foundation models where the provider offers such terms; provider policies may change, and you should review OpenRouter’s and the underlying model provider’s privacy terms as well.
AI outputs can be wrong. Always review drafts and ledger fields before acting.
7. Retention
We retain account and ledger data while your account is active. OAuth tokens are kept only while the related connection remains active (Gmail and/or QuickBooks), or until they expire or are revoked. Security logs are kept for a limited period needed for abuse prevention.
When you delete your account (Settings → delete account, with email confirmation), we delete your user record and associated Service data such as invoices, events, receipts, review items, chase drafts and sends, Gmail and QuickBooks connection and sync state, settings, merge prompts, and related tokens — subject to short-lived backups and legal retention requirements.
Disconnecting Gmail or QuickBooks removes stored tokens for that connection but does not by itself erase your ledger; delete your account if you want a full wipe.
8. Security
We use industry-standard measures appropriate to the sensitivity of the data, including encrypted transport (HTTPS), hashed passwords, and encryption of Gmail and QuickBooks OAuth tokens at rest. No method of transmission or storage is 100% secure; we cannot guarantee absolute security.
9. Your choices and rights
Depending on where you live, you may have rights to:
- Access or export personal data we hold about you
- Correct inaccurate account information
- Delete your account and associated Service data
- Disconnect Gmail and revoke Google access (also via your Google Account permissions)
- Disconnect QuickBooks and revoke Intuit access (also via your Intuit account connected apps)
- Object to or restrict certain processing, where applicable
You can update many settings in-product. For other requests, email privacy@scotive.com. We may need to verify your identity before responding. If you are in the EEA/UK, you may also lodge a complaint with your local supervisory authority.
10. International transfers
We and our processors may process data in the United States and other countries. Where required, we use appropriate transfer mechanisms (such as standard contractual clauses) with subprocessors.
11. Children
The Service is not directed to children under 16 (or the minimum age required in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided us data, contact us and we will delete it.
13. Changes to this Policy
We may update this Privacy Policy to reflect product or legal changes. We will post the revised Policy with a new “Last updated” date. Material changes may also be communicated in-product or by email when appropriate.
14. Contact
Privacy: privacy@scotive.com
Support: support@scotive.com