Privacy Policy
BearScope is a customer-experience operations platform, built on Fibric. This page explains what data we collect, how we use it, who we share it with, and the rights you have. We try to say it plainly.
We process the support data you bring on your behalf, as a processor. We do not sell it, and we do not use it to train models for anyone else.
Every record carries a tenant. The database scopes every read to the caller, so one customer's data cannot be read by another.
You can access, export, and delete your data, and we will help your end customers exercise their rights through you.
1. Overview and roles
This policy describes how Fibric ("Fibric," "we," "us") handles personal data in connection with BearScope, our AI-native customer-experience operations platform where your people and their AI agents run support together on one system. BearScope is a Fibric product.
We act in two different roles, and the distinction matters:
- We are a controller of account and website data.
- For information about the people who sign up for and administer a BearScope account, and visitors to bearscope.com, we decide why and how that data is used. This policy governs that data.
- We are a processor of your support-conversation data.
- When you connect your support systems and run conversations through BearScope, the conversation content and the customer records inside it belong to you. We process that data only on your behalf and under your instructions, as set out in our terms and any data processing agreement. You are the controller of that data; your end customers should look to you for their privacy notice and rights.
This policy is a clear template describing our practices. It is not legal advice, and it does not replace a signed agreement between us.
2. Data we collect
Account data
When you create or administer an account, we collect the information needed to set it up and keep it secure: your name, work email, the company or tenant name, your role, authentication identifiers, and (for paid plans) billing contact details. Payments are handled by our billing provider; we do not store full card numbers.
Usage and device data
When you use the app or visit the site, we collect technical and usage information: pages and features used, actions taken in the product, timestamps, IP address, browser and device type, and approximate location derived from IP. We use this to operate the service, keep it secure, fix problems, and understand how it is used.
Support-conversation data (processed on your behalf)
To do its job, BearScope ingests and processes the customer-support data you connect: conversations and messages, the customer records attached to them, order and account context you bring through your integrations, voice transcripts where enabled, and the scores, coaching notes, and receipts the product produces. This data may contain personal data about your end customers. We process it as your processor, to provide the service to you, and not for our own purposes.
Communications
If you contact us, request a demo, or subscribe to updates, we keep the messages and contact details you send so we can respond and, where you have asked or where permitted, send you relevant information.
3. How we use data
We use the data described above to:
- provide, operate, and maintain BearScope and the website;
- authenticate users, enforce tenant isolation, and keep the service secure;
- process and resolve support conversations on your behalf, including scoring, coaching, and producing the receipts that record what was done;
- check every AI-proposed action against your policy before it runs, and record the result;
- provide support to you, respond to your requests, and manage billing;
- monitor, debug, and improve the reliability and performance of the service;
- comply with legal obligations and enforce our terms.
We do not sell personal data. We do not use your support-conversation data to train AI models for other customers or for our general model development. Any AI processing of your data is to provide the service to you.
4. AI processing
BearScope uses AI agents to read conversations, reason about what a customer needs, and propose actions. To do this, relevant conversation content is sent to the AI models we use as sub-processors so the model can produce a response or a proposed plan. The model providers we use are contractually bound not to train their models on your data. Every action an AI agent proposes is checked against your policy before it runs, runs once even if retried, and leaves a receipt you can audit. Sensitive actions wait for a person on your team.
5. Legal bases (where applicable)
Where data-protection law such as the GDPR or UK GDPR applies, we rely on these legal bases for processing the account and website data we control: performance of a contract (to provide the service you signed up for), our legitimate interests (to secure, operate, and improve the service and to communicate with you), consent (for optional cookies and marketing where required), and compliance with legal obligations. For support-conversation data we process as your processor, you are responsible for the legal basis as the controller.
6. Sub-processors
We use a small set of vetted vendors to run the service. Each is bound by a contract that requires appropriate security and limits their use of data to providing their service to us. Our principal sub-processors are:
- Amazon Web Services (AWS)
- Cloud infrastructure: hosting, databases, storage, and networking for the application and your data.
- AI model providers
- The base models that power AI agents and the Radar analyst. These providers process conversation content to return responses and are contractually prohibited from training on your data.
- Billing provider
- Subscription billing and payment processing for paid plans. Card details are handled by the provider, not stored by us.
- Operational tooling
- Email delivery, error monitoring, and analytics used to operate and support the service.
We will keep a current list of sub-processors available and give notice of material changes as required by your agreement, so you have the opportunity to object where your contract allows.
7. Data residency and transfers
BearScope runs primarily on AWS in the United States. If you are located elsewhere, your data may be transferred to and processed in the United States and other countries where we or our sub-processors operate. Where required, we put appropriate safeguards in place for international transfers, such as standard contractual clauses. If you have specific residency requirements, contact us to discuss what we can support.
8. Security
Protecting your data is built into how the platform works, not bolted on:
- Encryption. Data is encrypted in transit and at rest.
- Walled-off tenancy. Every record carries a reseller and a tenant identifier, and the database enforces row-level scoping so each query is limited to the caller's tenant. One customer's data cannot be read by another.
- Checked actions and receipts. Actions are checked against policy before they run, run once even on retry, and leave an audit receipt recording what was done, by whom or what, on whose authority, and on which data.
- Access controls. Access to production systems is limited to authorized personnel on a need-to-know basis and is logged.
- Real data only. Live views render real data or nothing; fallbacks are tagged and withheld so a guess never passes as a fact.
No system can promise perfect security, but we work to a high bar and continue to improve it. You can read more on our security page.
9. Data retention
We keep account and website data for as long as your account is active and as needed to provide the service, then for a limited period afterward to meet legal, accounting, and security obligations. Support-conversation data we process on your behalf is retained according to your configuration and your agreement with us; when your agreement ends, we delete or return that data within the timeframe set out in your contract, except where law requires us to keep it. Backups are purged on a rolling schedule.
10. Your rights and choices
Depending on where you live, you may have rights to access, correct, export, delete, or restrict the use of your personal data, and to object to certain processing. For the account and website data we control, you can exercise these rights by contacting us at the address below; we may need to verify your identity first.
If you are an end customer of a business that uses BearScope, the business is the controller of your support data. Please direct your request to that business; we will support them in honoring it.
Account administrators can access and export their organization's data through the product, and can request deletion of a tenant. We will not discriminate against you for exercising a privacy right.
11. Cookies and tracking
We use a small number of cookies and similar technologies. Strictly necessary cookies keep you signed in and the app working. Where used, analytics cookies help us understand how the site and product are used so we can improve them. We do not use third-party advertising cookies to track you across other sites. Where consent is required, we ask for it, and you can manage cookies through your browser settings.
12. Children
BearScope is a business product and is not directed to children. We do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact us and we will delete it.
13. Changes to this policy
We may update this policy as the product and the law change. When we make material changes, we will update the date at the top and, where appropriate, notify account administrators. Your continued use of BearScope after an update means you accept the revised policy.
14. Contact us
Questions about this policy or about your data? We are happy to help. Reach us through the contact page, and for data-specific requests please say so in your message and we will route it to the right place.
An honest note: this is a clear, generic-correct template, not legal advice. When we have a signed data processing agreement with you, that agreement governs the support data we process on your behalf.
Safe by design, plain to read, easy to audit.
The same rules that keep your data walled off and every action checked are the rules the whole product runs on. See how it works.
Read our Terms of Service, browse pricing, or read the blog.