Last updated: September 2026.
Account data: name, email, OAuth identifier — only if you log in. Your content: queries, saved lists, drafts, sent mail metadata. People results: professional information already public on the source sites (name, role, employer, public profile links). We do not buy private data and we do not infer sensitive attributes.
Contract (running your account), legitimate interests (B2B discovery of publicly shared professional data, balanced against privacy — hence suppression on request), consent (marketing, optional), legal obligation (abuse/fraud handling).
Today: lists/outbox persist in your browser's localStorage; server logs are minimal and ephemeral. With accounts: workspace data retained for the account lifetime + 30 days after deletion. Backups roll off within 90 days.
Processors only, to run the service: LLM inference (Groq), web search (Tavily), code/research profiles (GitHub, OpenAlex, Stack Exchange, Wikipedia, DEV.to), email delivery (Resend), auth (GitHub/Google OAuth). Full list in the DPA. No sale of personal data, no ad-tech trackers.
Access, correct, delete, port, restrict, object — email requests are honored within 30 days. Not our user but listed in results? File a removal/suppression request: we suppress matching public-profile URLs from future results and confirm in writing.
Processors are primarily US-based; transfers rely on SCCs plus each processor's DPA. EU users: same rights, same SLA.
TLS everywhere, least-privilege API keys, no passwords stored (OAuth only), prompt patching. No system is perfect — report issues via the abuse contact and we respond within 72 hours.
Privacy questions and rights requests: see contact & removal.