Privacy Policy
Last updated: fill in the date you publish this. This is a starting draft written to match how the product actually behaves — have it reviewed by counsel in your jurisdiction before relying on it as your live policy.
What we collect
Account and profile data you provide directly: name, contact details, current role, experience, target designations, employment status, and an uploaded CV if you choose to provide one. We also store the outreach activity run on your behalf — which jobs you started outreach on, which contacts were reached, message content, and any classified response.
Company contact data — a shared cache
To make referral targeting affordable and fast, verified contact information at a given company (a name, title, and work email) is stored in a cache shared across all users targeting that company, rather than kept privately per user. This cache is not paired with which specific user contacted that person, or when. The first time we resolve a contact at a new company, it comes from a paid, real lookup through a third-party email-discovery provider; every contact after that at the same company is derived by inferring the company's email naming pattern from the first, then verified before any message is sent.
Retention: contact cache entries persist until they're superseded by a fresher lookup (e.g. after a bounce), invalidated after repeated verification failures, or removed on request. They are not tied to an individual user's account in a way that makes them part of that user's personal data for deletion purposes — see below.
What we don't do
- We don't read your email inbox beyond monitoring for replies to messages sent on your behalf.
- We don't sell personal data to third parties or use it for advertising.
- We don't use your data to build a profile of you beyond what your stated preferences and CV provide.
Third parties we share data with
Sending outreach requires working through LinkedIn/Gmail automation infrastructure (Unipile), an email-discovery vendor for contact lookups, and payment processors (Razorpay for India, Stripe internationally) for billing. Each only receives the specific data needed to perform its function — Unipile receives message content and recipient details to send on your behalf; payment processors receive billing details, never your outreach activity.
Your rights
You can request deletion of your personal account data — profile, outreach history, message content specific to you — at any time via a support ticket from Settings. Shared company-contact cache entries you contributed are not personally tied to your account by the time they're shared, so a deletion request removes your personal data cleanly without needing to unwind the shared cache.
If a contact you reached out to asks not to be contacted again, that request is honored across all future outreach to that person, from any user.
Data retention
Account data is retained for as long as your account is active, plus a reasonable period after account closure for legal, billing, and dispute-resolution purposes. Specify your exact retention windows here once decided.
Contact
Questions about this policy: add your support/legal contact email here before publishing.