Privacy Policy
Last updated: July 8, 2026
OutreachOS (“we,” “us”) operates the agentic outreach application at outreachos.app. This policy explains what data we collect, how we use it, and the choices you have. Questions: danielganjali09@gmail.com.
Information we collect
- Account data. The email address and password you use to create an account, and the profile details you provide (name, role, bio, proof points).
- Mission content. The campaigns, target companies, contacts, evidence, and email drafts you create or that the app generates on your behalf.
- Replies, on the professional sending path only. If you send from an address on one of our domains, mail sent back to that address arrives at our servers, is stored against the conversation, and is forwarded to your own inbox. See the section below.
How your email is sent
There are two ways, and neither gives OutreachOS access to your mailbox. On the manual path we open a pre-filled compose window in your own mail app and you press send yourself; nothing leaves our servers and we cannot see what happens next. On the professional path we send on your behalf from an address on a domain we own, using Amazon SES.
We do not connect to Gmail or any other mailbox, hold OAuth tokens for one, or request any mailbox scope. We cannot read, search, or store the contents of your mail on either path.
Replies on the professional path
We receive inbound mail only at the address we assigned you on our own domain, and only because that domain’s mail servers are ours. We store the reply and forward it to your inbox so you can answer it. This applies to that one address; we have no access to any other mailbox of yours, and the manual path produces no inbound mail for us at all.
Where your data lives
Account, profile, and mission data are stored in our database (MongoDB Atlas). Email is sent through Amazon SES, or by you from your own mail app. We use third-party AI providers to draft and analyze outreach content; only the content needed for a given task is sent to them, and they are not permitted to train on your data.
How we protect your data
We use industry-standard safeguards to protect your data. All traffic between your browser and the app is encrypted in transit using TLS/HTTPS, and access to production systems is restricted to authorized personnel. We hold no credential to any mailbox of yours, so a compromise of this service cannot expose the contents of your mail.
Sharing
We do not sell your data. We share it only with infrastructure subprocessors that run the service (cloud hosting, database, email delivery, AI drafting) and only as needed to operate the app, or when required by law.
Your choices
- Switch to the manual sending path at any time in Settings, or stop using your professional address entirely. Either one ends inbound mail reaching us.
- Request deletion of your account and associated data by emailing danielganjali09@gmail.com.
Retention and deletion
We keep your data only for as long as your account is active. When you delete your account (or request deletion by email), we delete your personal data, mission content, and stored replies within 30 days, except where a specific retention period is required by law.
Changes
We may update this policy; material changes will be reflected by the “Last updated” date above. Continued use after a change means you accept the updated policy.
