Privacy Policy
This policy explains what personal data [TBD: legal entity name] ("Outsquid", "we") collects when you use Outsquid, why, and the choices you have. It also explains how we handle data about the people you email with Outsquid.
1. Data we collect about our users
- Account data: your name, email address and password (stored only as a
salted hash). If you sign in with Google, we receive your name, email address
and profile picture from Google (scopes
openid,email,profile). - Organization data: organization and project names, members and their roles.
- Billing data: your plan and invoices. Card details are collected and stored by Stripe; we never see or store full card numbers.
- Connected mailbox data: see section 3.
- Usage data: server logs (IP address, request times, errors) used to keep the service secure and working.
- Website analytics: aggregate, cookieless statistics about visits to our website (pages viewed, referring site, country, browser and device type) and a few product milestones, such as signing up or launching a first campaign. These are not tied to your name or email address. See section 9.
2. Data you upload (Customer Data)
Prospects and their details (names, email addresses, companies, custom fields and so on), the emails you write, and the replies you receive are Customer Data. You decide what goes in and why; for this data you are the controller and we act as your processor (see the Data Processing Agreement). We only process it to provide Outsquid to you.
3. Google and Microsoft mailbox data
When you connect a mailbox, we ask only for the permissions needed to send your campaigns and bring in their replies:
| Provider | Permissions | Why |
|---|---|---|
| Gmail / Google Workspace | gmail.send | Send the emails in your campaigns from your mailbox |
gmail.readonly | Find replies to your campaign emails and show them in your Outsquid inbox | |
userinfo.email | Identify which mailbox you connected | |
| Microsoft 365 / Outlook | Mail.Send | Send the emails in your campaigns |
Mail.ReadWrite | Find replies to your campaign emails and show them in your Outsquid inbox | |
User.Read, offline_access | Identify the mailbox and keep it connected without asking you to sign in again |
Access and refresh tokens are encrypted at rest (AES-256-GCM). You can disconnect a mailbox at any time in Outsquid, or revoke access from your Google or Microsoft account.
Google API Services User Data Policy. Outsquid's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular, we:
- use Gmail data only to send your campaign emails and show replies to them in Outsquid;
- do not use it for advertising, and do not sell it;
- do not let humans read it, except with your permission for support, for security investigations, or where the law requires it;
- do not use it to develop, improve or train generalised AI or machine learning models.
We apply the same rules to data received from Microsoft Graph.
4. People who receive emails sent with Outsquid
If you received an email sent through Outsquid, the sender (our customer)
uploaded your details and is responsible for having a lawful basis to contact
you. Every campaign email includes an unsubscribe link and a one-click
List-Unsubscribe header; unsubscribing stops all further campaign emails
from that sender's organization. Campaign emails may contain an open-tracking
pixel and tracked links that record when the email is opened or a link is
clicked. To ask about your data, contact the sender, or write to us at
[TBD: privacy@ address] and we will forward your request.
5. How we use data and our legal bases
- To provide the service you signed up for (contract).
- To bill you (contract, legal obligation).
- To keep Outsquid secure and prevent abuse, including enforcing our Acceptable Use Policy (legitimate interests).
- To send account emails such as verification, password resets and alerts about disconnected mailboxes (contract).
- To understand, in aggregate, how people find and use Outsquid so we can improve it (legitimate interests).
We do not sell personal data and do not use it for advertising.
6. Sub-processors
We use these providers to run Outsquid:
| Provider | Purpose | Location |
|---|---|---|
| [TBD: hosting provider] | Application servers and database | [TBD] |
| Stripe | Subscription billing and payments | [TBD] |
| Sign-in with Google; Gmail sending and reply sync for connected mailboxes | [TBD] | |
| Microsoft | Outlook / Microsoft 365 sending and reply sync for connected mailboxes | [TBD] |
| Umami | Cookieless website analytics | EU / US |
| [TBD: transactional email provider] | Account emails (verification, password reset, alerts) | [TBD] |
7. Retention
We keep account and Customer Data while your account is active. After you delete your account, we delete it within [TBD: retention period after account deletion], except where the law requires us to keep it longer (for example invoices).
8. Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal data, and to object to or restrict its processing. You can export your prospects from the app at any time. For anything else, contact [TBD: privacy@ address]. You can also complain to your local data protection authority.
9. Cookies
Outsquid uses a single essential cookie to keep you signed in. We don't use advertising or analytics cookies.
Our website analytics (Umami) work without cookies or similar identifiers stored on your device and don't track you across other websites. Query strings and links containing tokens are stripped before anything is sent.
10. Security
We encrypt data in transit (HTTPS) and encrypt mailbox credentials at rest, keep each organization's data separate, and limit internal access to what is needed to run the service.
11. Changes and contact
We will post changes to this policy here and notify account Owners by email if they are significant. Contact: [TBD: privacy@ address], [TBD: legal entity name], [TBD: registered address].
Last updated 2026-10-04