Privacy Policy

Last updated: 1 October 2026

What we store

  • • Account data — name, email, company, language, plan and status.
  • • Your campaign data — lead lists you import, email templates, campaigns and their results.
  • • Replies — only if you connect your own mailbox; messages are read over IMAP with credentials you supply.
  • • Credentials — Portal access keys are stored only as a one-way hash. Customer AI-provider keys, billing configuration and connected mailbox credentials are encrypted at rest and never displayed back to you. SMTP credentials are also provided securely to the sending provider to connect your mailbox.

Traffic analytics

We measure our own pages with a first-party collector. It records the page path, a random per-tab session id, the referring site, a general device class and — for usability — where visitors click and how far they scroll. It sets no advertising cookies, runs no third-party analytics script, and does not build a cross-site profile. Operator and API paths are excluded from capture.

Cookies and similar storage

We keep this to a minimum:

  • • cp_session (necessary) — a signed, HttpOnly cookie that keeps you signed in. It cannot be read by scripts.
  • • cp_lang (necessary) — remembers your language choice.
  • • cp_consent_v1 (local storage) — remembers the cookie choice described below.
  • • cp_traffic_sid (session storage) — a random per-tab id for our first-party traffic statistics. It is cleared when you close the tab.

Marketing measurement — off unless you opt in

If you accept marketing, we load the Meta Pixel (Meta Platforms Ireland Ltd., pixel id 1219153286899205) to measure which advertising brings visitors to this site. It is off by default: no request is made to Meta, and no advertising cookie is set, until you choose “Accept marketing” in the banner.

When it is enabled it records a page view for each page you open and a registration event when an account is actually created. We do not send your name, email address or any other personal detail with those events, and we never report a signup or a page redirect as a purchase. When marketing consent is present, a verified paid invoice is reported once to Meta through the Conversions API, with its value, currency and a stable transaction identifier. Trial accounts, unpaid invoices and complimentary admin grants are not purchases.

What Meta receives. As with any web request, Meta sees the address of the page you opened, the referring page, standard technical data such as your IP address and browser type, and the pixel cookie that identifies your browser to Meta. Meta uses this to attribute visits and conversions to advertising campaigns and to build advertising audiences. For consented payment measurement, we also send a SHA-256 hash of your normalized account email, available Meta browser/click identifiers, and checkout IP address and browser type. The hash remains personal data; it is not anonymous. Checkout attribution is encrypted at rest. Withdrawing consent while signed in disables future server purchase reporting. Meta is an independent controller for that processing under its own privacy terms.

You can change or withdraw your choice at any time using Cookie settings in the footer. We also honour Global Privacy Control and Do Not Track: if your browser sends either signal, marketing measurement stays off regardless of any earlier choice.

Who processes data

We use a database provider to store the records above, a mail platform to send campaigns from managed mailboxes, and a language model provider to assist with drafting and to interpret assistant requests. Passwords, API keys and mailbox credentials are never sent to the language model.

AI assistance and payments

Public questions are sent to the included AI provider through Teable. Signed-in assistant conversations and summaries are stored with your account. If you select your own AI connection, assistant prompts are sent to that provider and its terms and charges apply. Keep credentials out of chat; use the secure connection forms. For public-chat usage limits, we store a keyed daily digest of the visitor’s network address, not the original address or prompt, in the usage ledger.

Payments use hosted Stripe or Cryptomus pages. We store order identifiers, amounts, payment status, subscription references and plan expiry. Card details and crypto wallet secrets are not collected by this app. Verified provider callbacks are used to activate or update your plan.

Legal basis and your rights

We process your data to perform our agreement with you. Depending on where you live you may have the right to access, correct, export or delete your data, and to object to certain processing. We do not sell personal data.

Retention and deletion

Account and campaign records are kept while your account is open. You can delete lead lists and email templates from your workspace, and you can ask us to export or erase your account and its data through the contact page; we will verify the request and action it within 30 days.

Contact

Privacy questions and requests: Contact support.