Privacy Policy
Last updated: September 10, 2026
OutreachOS (“we,” “us”) operates the agentic outreach application at outreachos.app. This policy explains what data we collect, how we use it, and the choices you have. Questions: danielganjali09@gmail.com.
Information we collect
- Account data. The email address and password you use to create an account, and the profile details you provide (name, role, bio, proof points).
- Goal content. The campaigns, companies, contacts, evidence, and email drafts you create or that the app generates on your behalf.
- Replies, when reply tracking is on. On a mailbox you connected, we open that inbox to find replies to mail we sent for you and store those replies against the conversation. See the section below for exactly what that reads.
How your email is sent
Two ways, and neither of them sends from a server of ours. On the manual path we open a pre-filled compose window in your own mail app and you press send yourself; nothing leaves our servers and we cannot see what happens next. On the your own mailbox path you give OutreachOS an app password for your own mail account and we send through it, so the mail leaves your provider, from your address, on your own quota and under your own contract with them.
That app password is the only credential we hold for a mailbox, and we hold it only for a mailbox you explicitly connect. It is stored encrypted with a key held outside the database, is never returned by any part of the app, and is destroyed when you disconnect. On the manual path we have no access to your mailbox at all.
We use it for two things: submitting your outgoing messages to your mail provider, and, when reply tracking is on, opening your inbox read only to find replies to mail sent from here. The section below says exactly what that reads. Be aware that an app password is issued by your mail provider for the whole account rather than for sending alone, so you should revoke it in your mail account if you stop using this path. Disconnecting here destroys our copy of it.
Reading replies in a mailbox you connected
If the app password you gave us can also open your inbox, reply tracking is on, and a scheduled job opens that inbox read only. It looks at who each new message is from, fetches only the messages that answer mail we sent for you, and stores those replies against the conversation so follow-ups stop when somebody answers. It reads nothing else in the mailbox and never marks, moves, files or deletes anything. If your provider does not allow it, or your organisation has switched IMAP off, reply tracking stays off and we never open the inbox at all. Disconnecting the mailbox ends this, and so does revoking the app password with your provider.
Where your data lives
Account, profile, and goal data are stored in our database (MongoDB Atlas). Email is sent through your own mailbox if you connected one, or by you from your own mail app: we operate no mail server and send nothing from a domain of ours. A reply we read from a connected mailbox is stored in the same database, against the conversation it answers. We use third-party AI providers to draft and analyze outreach content; only the content needed for a given task is sent to them, and they are not permitted to train on your data.
How we protect your data
We use industry-standard safeguards to protect your data. All traffic between your browser and the app is encrypted in transit using TLS/HTTPS, and access to production systems is restricted to authorized personnel. Any mailbox credential you have given us is encrypted with a key held outside the database, is never sent back to your browser and never appears in a log or an error message.
Sharing
We do not sell your data. We share it only with infrastructure subprocessors that run the service (cloud hosting, database, AI drafting) and only as needed to operate the app, or when required by law.
Your choices
- Switch to the manual sending path at any time in Settings, or disconnect the mailbox you connected. Either one ends our access: disconnecting destroys the stored credential, and with it any ability to send or to read replies.
- Request deletion of your account and associated data by emailing danielganjali09@gmail.com.
Retention and deletion
We keep your data only for as long as your account is active. When you delete your account (or request deletion by email), we delete your personal data, goal content, stored replies and any mailbox credential within 30 days, except where a specific retention period is required by law.
Changes
We may update this policy; material changes will be reflected by the “Last updated” date above. Continued use after a change means you accept the updated policy.
