Privacy
What Scout collects, what it shares, and what it never touches.
Last updated 29 August 2026.
The short version
Scout records what retailers are selling and for how much — prices, stock and seller identity on retailer product pages you visit. Those readings are shared with everyone using Scout, because that is what makes it work: you get told about restocks your own browser never looked at.
Scout does not record your browsing beyond those product pages, and never receives your retailer login or your card number.
If you switch it on, Scout can also buy things for you — within a limit you set, on a card you name by its last four digits. That is off until you turn it on, and there is a section below about exactly what it stores.
What the extension reads
The extension runs only on product pages at the retailers Scout covers, and on the marketplace product pages it tracks prices from. It does not run on search pages, category pages, your cart, your account, or any other site — nothing is read from a page outside that list, because the extension is never loaded there.
The exact list is the one your browser shows you: it is declared in the extension’s own permissions, which you are shown before you install it and again whenever it changes. That is the authoritative version and it cannot fall out of date the way a list written here would.
What is sent to PackFresh
For each product page: the retailer, the listing id, the product title, the price, whether it is in stock, who is selling it, and the time. Also which node sent it, so contributions can be credited to the person running it.
Your watches — the products you are chasing, your price limit, your quantity — are stored against your account so alerts can reach you.
Your search area is stored too, and it is the one piece of location we keep. When you give Scout a postcode we look up its centre and save the postcode, that centre point and how far around it you want us to look. It is what “near you” means when your phone has not told us where you are, and it is why the shop lists work with location switched off entirely. A postcode centre is a town, not an address — we never derive it from where your phone actually is. You can change it or clear it on the You tab.
Which games you collect, if you picked any when you set the app up. It only decides what order things are listed in. Nothing is hidden from you because of it and it is not shown to anyone else.
The extension periodically checks in (a “heartbeat”) to report that it is still running, and the network address that check-in arrives from is recorded — cryptographically scrambled with a server-side key before it is stored, not kept as a plain address. Scrambled this way, it cannot be turned back into your address by anyone reading our database, but it still lets us tell “same network as before” from “different network”. That is what stops removing and reinstalling the extension from being counted as a brand new browser every time, and it is also how we can tell you when another Scout account is checking in from your network — see the next section.
Buying on your behalf
Scout can add a watched product to your cart, and — separately, and only if you switch it on — complete the order. Both run in your own browser, in your own signed-in session, the same way you would do it yourself.
Automatic checkout is off until you do four separate things:turn on the switch, set the most a single order may cost, enter the last four digits of the card you want used, and grant permission for the retailer’s checkout pages. Miss any one and Scout carts the item and stops, and tells you which one is missing.
The last four digits stay on your machine. They are never sent to PackFresh. They exist so Scout can compare them against the card the checkout page is actually about to charge, and refuse if the two do not match — the realistic mistake is not a wrong item, it is a default card that quietly expired and a different one taking its place.
Your spending limits are counted on your own machine too, so a limit cannot be raised by anything other than you, and cannot be lost to a network problem at the moment it matters. If you run Scout on more than one computer, each keeps its own count.
What does reach PackFresh is a record of what was attempted: the retailer, the listing, the product, how many, what it cost, whether it worked, and the retailer’s own order number when an order completed. Kept against your account, so that a purchase made while you were asleep can be explained afterwards — which is the whole reason to trust something that spends money without asking.
Scout Relay, if you install it
Relay is a separate application you install on your own computer. It is optional, most installations do not have it, and the extension works normally without it — it keeps watching while your browser is closed.
The extension talks to Relay through a small local channel on your machine. Nothing about that conversation goes to PackFresh.
What Relay itself sends is deliberately thin: that it is running. A machine identifier it generates, when it was last seen, its version, and whether it can raise a notification on that computer. That is what lets Scout send an alert to a machine that is actually awake rather than one that is not. The row expires on its own once Relay stops reporting.
What is shared with other people
Observations are shared. Your watches are not. A reading that a product is back in stock at $49.99 is available to everyone; the fact that you are watching it, and the price you are willing to pay, is not shown to anyone else.
The contributor leaderboard shows a username — or the part of an email before the @ — beside a count of readings contributed. It never shows what somebody watches or buys.
If another Scout account checks in from the same network as you — a shared office, a campus, a household, or just an ISP that puts many customers behind one address — you are told a count. Not who: not a name, not an email, not anything about what that account does. We often cannot tell whether it is a second profile of yours, somebody else in the building, or an unrelated stranger sharing the same address, so the message says only what was observed. This has never caused a problem for anyone using Scout — it is shown as information, not a warning, and nothing is disabled or suggested because of it.
Your browser also checks places you did not ask about
Some retailers only answer questions about one shop at a time. For those there is no national stock number — only what a particular store has on its shelf, and the only way anyone knows whether a shop has something is if a browser somewhere asks that shop.
So alongside the listings you are watching, Scout occasionally checks one place nobody has looked at recently — a town chosen by us, not by you, somewhere the network has no coverage. It is one extra request roughly every five minutes, it uses no more of your connection than your own watches do, and it is what makes the map exist for the person who joins tomorrow. Every reading it produces is shared, in the same way and under the same terms as everything above.
You will not usually notice it. It is not a visible tab, it never signs in as you, and it never touches a cart. If you would rather not contribute, turn Scout off — the switch in Settings stops all of it, yours and ours together.
The phone app: where you are
The PackFresh app reads your precise location for two things, and they are worth telling apart.
Sorting shops by how far away they are.The lists of shops near you — Nearby, the store directory, a shop’s own page — measure from where you are standing, because “which of these is closest” is the question they exist to answer. The coordinate is sent with the request so the search can be centred on it. It is not stored against your account, and no record is kept of which shops you looked at. These screens never raise the permission prompt themselves: they read your location only if you have already allowed it, and otherwise they measure from the search area saved on your account — and say at the top of the list which of the two they used.
Filing a Rover report — a photograph of a shelf you are standing at. Here the location is the evidence, so it is read more than once, and all of it while the reporting screen is open: when the screen opens, to work out which shop you are at; and continuously while the camera is up, so each photograph is stamped with where it was taken. Your position is read once more when you press send. What is stored with the report is the coordinate from the first photograph, the coordinate of each of the others, the place you sent it from — labelled as that, and never used as the evidence — and the distance between the shop and the photograph.
Only while you are using it.The app asks for “when in use” permission and nothing else — there is no background location, no tracking between visits, and no record of anywhere you go that you did not file a report from. Decline the permission and every part of the app still works, measuring from your saved search area instead; the one thing you cannot do is file a report.
The phone app: photographs
Rover photos are taken in the app, with the camera. There is no library picker and there will not be one — a photo chosen from a camera roll has unknown age and unknown provenance, and could not be told apart from evidence once stored.
Every photo is uploaded to PackFresh and is invisible to everyone until a person reviews it. If it is approved, the photograph becomes public — attached to that shop, visible to anyone using Scout. That is the point of filing one, and it is the part worth reading twice.
So: a shelf photograph taken in a busy shop can contain other people. Reviewers reject photos with recognisable faces, but the safest thing is not to take them. Along with the photo we store the coordinate above, the time, and your account id — a report is attributable, because an anonymous claim about a shop is not worth publishing.
Ask us and we will take a photograph down.
What Scout never has
Your retailer login. Fetch runs in your own browser, in your own signed-in session. PackFresh never receives those credentials and could not use them if it did.
Your card number. Scout never receives it, never stores it and never sends it anywhere. Your card lives with the retailer, exactly as it does when you check out by hand.
This section used to say Scout “adds items to your cart and stops—it cannot check out”. That was true when it was written and stopped being true in August 2026, when automatic checkout shipped. It is corrected here rather than quietly deleted, because a privacy page that silently drops a promise is worse than one that never made it. See Buying on your behalf above for what actually happens now.
Who you are, to us
Sign-in is handled by Auth0. Scout stores the resulting account id, your email address and your display name. Passwords are never seen by PackFresh — Auth0 handles authentication and Scout only ever receives a token. Signing in with Apple or Google means we see whatever that provider tells us, which is your email address and, on the very first sign-in only, your name. If you use Apple’s Hide My Email, the relay address is the only one we ever have.
This dashboard sets two cookies and no others. One keeps you signed in. The other is short-lived and only remembers which page you were heading for while you sign in, so you land back on it. There is no advertising cookie, no analytics tracker and no third-party script on this site, and nothing here follows you to another one.
Notifications
There are three ways an alert reaches you, and which ones you get depends on what you have installed.
On your phone, through Apple’s own push service. When you allow notifications we store the device token Apple issues, so we can send to that phone. It identifies the app on that device, not you and not your location, and it stops working when you delete the app.
By email, through our email provider.
To the browser extension, through ntfy, on a topic derived from your account id. This one comes with a warning worth reading: ntfy has no accounts on the free tier, so the topic name is the only thing protecting it. It is long and random for that reason, and anyone who has it can subscribe to your alerts — treat it like a password. It is being retired as testers move to the phone app, and it will stop being used entirely once nobody depends on it.
Turning it off
Remove a watch and it stops being tracked for you. Sign out in the extension and it stops contributing readings. Uninstall it and nothing further is collected. In the phone app, turning off location or notifications in iOS Settings stops each of those immediately — the shop lists fall back to the search area saved on your account, and filing a Rover report is the one thing that cannot be done without location.
Deleting your account
In the app: You → Delete account. It asks once, and then it is done and cannot be undone. You can also email support@packfresh.com and we will do it.
What goes: your reports and every photograph attached to them, your watches, your alerts, your notification tokens, your saved search area, and the account itself.
What stays: the shelf readings you contributed. Those record what a shop was selling at a moment in time, they carry no link to you, and they are the shared record everyone using Scout depends on — the same reason your readings were useful to other people while you were here. This is the one thing deletion does not reach, and it is deliberate.
Two honest limits. An account holding orders or payouts is refused rather than half-deleted, because those carry retention obligations we cannot override — email support@packfresh.comand we will sort it out. And deleting the account does not yet delete the sign-in identity held by our authentication provider: signing in again gives you a new, empty account rather than the old one.
Getting in touch
support@packfresh.com, for anything on this page — what we hold about you, a correction, a deletion we have not honoured, or a question about a Rover photograph you filed.
It is the same address on the support page and in the phone app under You, and it reaches a person rather than a queue.