Scout by DR CV

YOUR SEARCH. YOUR CONTROL.

Privacy built for
an active job search.

This notice explains the additional information Scout uses when it searches, prepares, communicates, and applies on your behalf. Updated 13 September 2026.

Scout acts only from your account and rules.

Scout uses the DR CV account you sign in with, the CV or career profile you select, and the search rules, limits, application mode, answers, approvals, mission objectives, follow-up instructions, and optional memory entries you save. Memory entries are labelled goals, preferences, boundaries, or verified facts and remain editable by you. For a mission, Scout may use AWS Bedrock to build a short plan from that information and select only the career tools registered by DR CV. The server checks every planned step against your account, rules, limits, connector state, and human-only boundaries before it can run. It records the mission, plan, messages, workflow status, and bounded receipts so you can see what it found, prepared, sent, or stopped. Pausing a mission prevents another step from starting; pausing Scout stops new sourcing, applications, and outreach. Work already delivered to an employer or provider cannot be recalled.

Job sourcing and applications

Scout reads public job listings and job links you send. When an application is permitted, the employer or its application provider receives the information needed for that application, such as your selected CV and verified answers. Scout does not invent missing facts, solve CAPTCHAs, or answer legal, work-authorisation, compensation, or assessment questions for you. Those steps are placed in Needs you.

Cold outreach

Scout discovers roles from public company boards and attributed remote-job feeds, including RemoteJobs.org and Jobicy. Scout can discover and verify additional direct employer boards from published application links, which appear in Connections and can be removed. It keeps the original vacancy link, uses bounded cached feed data and does not represent an aggregator listing as a DR CV or employer-authored posting. You can remove a source at any time. Scout may prepare outreach using public business contact details with a recorded source and your truthful career evidence. It checks the vacancy and may follow a small, clearly labelled trail to the company’s public website and its contact, careers, recruiting, people, team or about pages. Scout does not invent email addresses, scrape social profiles, submit contact forms or treat a domain’s mail settings as proof that a mailbox exists. The exact page publishing the selected address remains visible with the draft. Messages remain subject to your configured mode, caps, approval state, duplicate checks, and opt-out handling. Recruiters can see the information in an outreach message you approve or permit Scout to send. If you explicitly enable follow-up for Outreach Autopilot, Scout may send no more than one follow-up in the original Gmail thread after the delay you select. Follow-up is off by default, shares your outreach limits, can be cancelled while scheduled, and is suppressed when Scout detects a human reply, bounce or automatic response. Scout does not create multi-message sequences.

Responses remain in the connected mailbox. Scout requests only From, Reply-To, Subject, Message-ID, automation headers and timestamps for reconciliation; it does not request or copy the response body into the workspace. It records limited delivery, human-reply, bounce, automatic-response and workflow metadata. If explicit Subject metadata such as a suspected-spam marker indicates a recipient system may be rejecting Scout outreach, Scout stores only a risk code, timestamp and source record—not the subject—and places a profile-wide hold on new cold outreach and follow-ups. Scheduled follow-ups are cancelled. Job sourcing, applications and candidate-approved recruiter replies continue, and only you can release the hold after reviewing Gmail. Automatic-response classification can be imperfect, so Scout surfaces the Gmail thread for your review and continues watching for a later human reply. Scout checks thread metadata again immediately before a scheduled follow-up. A response arriving in the brief interval after that check may not be detected before delivery, which is an unavoidable mailbox race.

When Scout detects a human reply, you can open the Gmail conversation, choose a saved DR CV, and review or edit the exact response before approving it. Scout then sends that candidate-approved copy with the selected CV attached in the existing Gmail thread. The recipient, subject, approved body, selected CV title, outcome and bounded receipt are kept in Scout’s activity history. Scout never automatically resends when Gmail delivery is uncertain; it asks you to check Gmail Sent once.

Research and exact-message review

Scout stores candidate-owned research tasks, inspected public-page links, contact provenance, attempt counts and retry reasons. Research may continue within bounded limits without asking you to supply every missing contact. Evidence-backed drafts retain a snapshot of the relevant CV excerpts and job text, source fingerprints, model version, exact message and your approval or rejection. Relevant excerpts and job text are processed using AWS Bedrock; the drafting request excludes separate recipient-address and candidate-name fields, although information you place inside career text may still be included. Changing the source CV or job invalidates an old draft before delivery. Generated follow-up ideas are not automatically scheduled. Unattended generated outreach is currently disabled; exact-message approval uses the existing delivery limits and safeguards.

Employer sign-in sessions

When a supported application needs employer sign-in, you may explicitly permit a temporary sign-in handoff and then choose to save its session. The handoff presents only observed employer sign-in fields and controls, not a general remote computer. Information you enter passes through Scout to that employer. Input commands are encrypted, cannot execute after thirty seconds, and are scheduled for deletion by the twenty-second cleanup cycle; they are not sent to an AI model or written into application logs. A handoff expires after ten minutes. Scout does not retain your password as an account credential.

If you choose Save, Scout retains encrypted employer cookies and local storage for up to seven days, bound to your account and that employer scope, to resume permitted applications. Identity-provider sessions are excluded. You can revoke a saved employer session in Connections or erase it with your Scout workspace. Expired or revoked sessions cannot be reused. Backups may retain encrypted historical data under their separate retention period. This feature does not bypass CAPTCHA, legal attestations or unsupported sign-in flows; those remain manual.

Connected accounts

Gmail access is used for approved application and outreach delivery and limited response reconciliation. Telegram and WhatsApp are optional command and notification channels: you can send a public job link, check status, pause or resume Scout, and answer a referenced blocked step. Free-text requests become saved Scout missions and appear in your workspace conversation, where they are processed using AWS Bedrock. Routine commands are handled directly. Scout does not import your general Telegram or WhatsApp history; provider message identifiers, outcome, and error category are retained for reliability and abuse prevention. An answer you deliberately send for a blocked step is saved with that step.

OAuth tokens and messaging destinations are encrypted at rest. Disconnecting a connector revokes Scout’s saved connection and cancels undelivered alerts; use the provider’s own security controls as well if you believe an account or token is compromised.

AI processing and service providers

Scout may use AWS Bedrock to interpret public application-page navigation, plan a mission, compare job requirements with the career information you provide, and draft truthful application or outreach material. A model cannot directly submit an application, send a message, invent a new tool, or override the server’s rules. Automated output can be wrong, so consequential or missing facts are designed to stop for your review. The service also uses Neon for authentication, self-hosted PostgreSQL and Redis for workflow data, AWS-hosted infrastructure, Cloudflare for delivery, and the connector providers you choose, including Google, Telegram, or Twilio’s WhatsApp service.

Retention, deletion, and your rights

Scout retains your rules, candidate-authored memory, mission objectives, plans, mission messages, workflow records, applications, outreach records, actions, and connector state while needed to run your account and maintain an auditable history. Short-lived connector codes expire after ten minutes. Messaging receipt metadata is scheduled for deletion after 30 days; delivered or cancelled outbound notification receipts after 90 days. Backups and records already delivered to employers or providers may have separate retention periods.

The Your data workspace page lets you pause new work, disconnect individual channels, or permanently erase Scout rules, sources, matches, applications, outreach, contacts, connector data, notifications, and activity history. Erasing Scout does not delete your DR CV résumés or identity. Private-beta admission and objective usage totals remain to prevent invitation replay and limit evasion. If an application or message is crossing an irreversible provider boundary, Scout pauses immediately and waits for its bounded receipt before allowing erasure. It cannot recall information an employer, mailbox, or messaging provider has already received.

The main DR CV privacy policy explains account information, contact details, and how to request access or deletion. This Scout notice adds product-specific detail; it does not replace that policy. Use Scout only for accounts, CVs, mailboxes, phone numbers, and application information you are authorised to use.