Privacy
Privacy policy
Scout finds restaurants and requests Resy reservations for you. This page says what Scout stores, which services it talks to, and how you take it all back. Last updated 11 September 2026.
What Scout stores
Your account. Your email address and name from sign-in, your timezone, and your saved searches, favorites, and notification settings.
Your Resy connection. When you connect Resy, Scout keeps an encrypted session token for your Resy account so it can check availability and, only after you approve a request, book a table. Scout stores the display name of your Resy payment method (for example the card brand and last four digits) so you can see which card a restaurant would use. Scout never stores your Resy password or full card numbers. The one-time code Resy emails you is used once and discarded.
Reservations and requests. The restaurants, dates, party sizes, and time windows you ask for; the availability Scout observed; and the reservations it booked or found in your Resy account, so it can show status and avoid double booking.
Your Beli connection, if you add one. Scout signs in to Beli with the email and password you enter, keeps only the resulting Beli session tokens and account name, encrypted, and never stores your Beli password. Scout uses it to show your Beli ratings next to restaurants. Disconnecting deletes the session.
Assistants you connect. The name of each assistant or personal access token, what it is allowed to do, and the requests it created. Tokens are stored only as hashes. An assistant sees only the requests it made.
Operational records. Which routes were called, when, and with what outcome, kept to run and secure the service. Scout does not keep the text of your conversations with an assistant.
Services Scout uses on your behalf
- Resy, using your own account, to search availability and book. Resy's terms prohibit automated access, and Resy may deactivate accounts it identifies as automated. You accept that risk when you connect Resy.
- WorkOS for sign-in. WorkOS handles your email login and passes Scout your email and a session identifier.
- Anthropic and OpenAI models to read the free-text description of a dinner you type or that an assistant sends, and to summarize public restaurant information. Scout sends the text of the request and public restaurant data. It does not send your Resy credentials, payment details, or conversation history.
- Google Places for restaurant addresses, photos, ratings, and reviews.
- Beli, using your own Beli account, only if you connect it.
- Residential proxy providers to route requests to Resy. The proxy sees the request traffic to Resy, not your Scout account.
- Web push through your browser's push service, if you turn on notifications.
Scout does not sell your data, show advertising, or share your data with restaurants beyond what a reservation requires.
Assistants and AI agents
When you connect an assistant, whether through a personal access token or an OAuth connection, it acts within the permissions you chose. Automatic booking never happens until you approve the exact request in Scout. You can revoke any assistant on the Assistants page; its open requests stop at once.
Your controls
- Disconnect Resy or Beli in Settings at any time. Scout deletes the stored session, and for Resy stops all booking work.
- Revoke any assistant or token on the Assistants page.
- Ask for a copy of your data or deletion of your account by writing to the address on the support page. Scout deletes account data within 30 days of a verified request, except records it must keep to resolve a booking already in progress.
Retention and security
Resy sessions are encrypted at rest and are deleted when you disconnect or when they expire. Short-lived operational data such as availability checks is pruned on a rolling basis. Scout runs on a single cloud host in the United States.
Changes
If this policy changes in a way that matters, Scout will say so on this page with a new date.