Scout

Privacy

Privacy policy

Scout finds restaurants and requests Resy reservations for you. This page says what Scout stores, which services it talks to, and how you take it all back. Last updated 11 September 2026.

What Scout stores

Your account. Your email address and name from sign-in, your timezone, and your saved searches, favorites, and notification settings.

Your Resy connection. When you connect Resy, Scout keeps an encrypted session token for your Resy account so it can check availability and, only after you approve a request, book a table. Scout stores the display name of your Resy payment method (for example the card brand and last four digits) so you can see which card a restaurant would use. Scout never stores your Resy password or full card numbers. The one-time code Resy emails you is used once and discarded.

Reservations and requests. The restaurants, dates, party sizes, and time windows you ask for; the availability Scout observed; and the reservations it booked or found in your Resy account, so it can show status and avoid double booking.

Your Beli connection, if you add one. Scout signs in to Beli with the email and password you enter, keeps only the resulting Beli session tokens and account name, encrypted, and never stores your Beli password. Scout uses it to show your Beli ratings next to restaurants. Disconnecting deletes the session.

Assistants you connect. The name of each assistant or personal access token, what it is allowed to do, and the requests it created. Tokens are stored only as hashes. An assistant sees only the requests it made.

Operational records. Which routes were called, when, and with what outcome, kept to run and secure the service. Scout does not keep the text of your conversations with an assistant.

Services Scout uses on your behalf

Scout does not sell your data, show advertising, or share your data with restaurants beyond what a reservation requires.

Assistants and AI agents

When you connect an assistant, whether through a personal access token or an OAuth connection, it acts within the permissions you chose. Automatic booking never happens until you approve the exact request in Scout. You can revoke any assistant on the Assistants page; its open requests stop at once.

Your controls

Retention and security

Resy sessions are encrypted at rest and are deleted when you disconnect or when they expire. Short-lived operational data such as availability checks is pruned on a rolling basis. Scout runs on a single cloud host in the United States.

Changes

If this policy changes in a way that matters, Scout will say so on this page with a new date.