Privacy Policy

Effective date: June 3, 2026  ·  LeadWithEmail.com

LeadWithEmail ("we", "us", "our") provides an AI-powered email outreach platform for wholesale and B2B suppliers. This policy explains what data we collect, how we use it, and your rights. We use plain language intentionally — if anything is unclear, email us at [email protected].

1. What data we collect

Account information

When you sign up via Google, we receive your name and email address from your Google account through Clerk (our authentication provider). We store this to identify your account.

Gmail OAuth tokens

When you connect your Gmail account, Google issues us an OAuth access token and refresh token. These tokens are encrypted at rest using Fernet (AES-128-CBC with HMAC authentication) and stored in our database. They are used to send emails from your Gmail account on your behalf and to detect replies from contacts you have emailed. We do not scan or analyze your wider Gmail mailbox, drafts, or messages from people you have not contacted through LeadWithEmail. See our Google Data Use page for full detail.

Contact lists

When you upload a CSV of buyers or contacts, we store the contact data (name, email, company, and any other columns you provide) in your account. This data belongs to you and is used only to send outreach emails on your behalf. You are responsible for having a lawful basis to upload and contact these recipients; we do not independently verify their consent (see our Terms of Service).

Email send logs & reply snippets

We store a record of each email sent through the platform, including the recipient email address, subject line, body, send timestamp, and Gmail message/thread ID, so you can review what was sent. When a contact you emailed replies, we also store a short preview of that reply (currently up to 500 characters, taken from the Gmail message snippet) along with its subject and message/thread ID, to power the conversation view and hot-lead detection.

Open and click tracking events

Each outgoing email contains a tracking pixel (your brand logo, or a 1×1 transparent image) and an optional click-tracking link. When a recipient opens the email or clicks a link, we record the timestamp and whether the open appears genuine or automated (see Section 4).

Billing information

Payment card details are handled entirely by Stripe and never pass through our servers. We store your Stripe customer ID and subscription status.

Cookies

We use only essential cookies. Our authentication provider (Clerk) sets a session cookie to keep you signed in, and we use a temporary session cookie to secure the Gmail connection (OAuth) flow. We do not use third-party advertising or cross-site tracking cookies.

2. How we use Gmail access

LeadWithEmail requests two Gmail scopes: https://www.googleapis.com/auth/gmail.send and https://www.googleapis.com/auth/gmail.readonly. gmail.send lets us send the emails you approve from your Gmail account; gmail.readonly lets us read replies from contacts you have emailed. We do not modify, label, archive, delete, or mark your Gmail messages as read.

We use Gmail access only to:

  • Send outreach emails from your Gmail account to contacts you specify
  • Check whether contacts have replied (by polling your inbox for messages from tracked contacts)
  • Show the reply/conversation and draft AI-assisted reply suggestions you review before sending

We do not use Gmail access to:

  • Read, scan, or analyze your wider mailbox, drafts, or messages from senders you have not contacted through LeadWithEmail
  • Access contacts, calendar, or any Google service other than Gmail
  • Sell your email data, or share it except with the AI provider that drafts a suggested reply (see Section 7) and as needed to operate the Service

Note: we do store a short snippet of replies from contacts you have emailed (see "Email send logs & reply snippets" above), and that snippet is sent to our AI provider to draft a suggested reply that you review before sending. AI never sends email automatically.

Google API Services User Data Policy

LeadWithEmail's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Data received through Google APIs is used only to provide and improve the features described in this policy. We do not use Google user data to serve advertising, and we do not sell Google user data.

3. Logo tracking pixel

Each email sent through LeadWithEmail contains a small image — either your uploaded brand logo or a 1×1 transparent pixel — hosted at leadwithemail.com/track/[token]. When a recipient's email client loads this image, we record that the email was opened.

This is standard email tracking practice. The pixel is embedded in the HTML version of the email. Recipients using plain-text email clients will not trigger tracking.

The tracking token links to the specific email sent. No personal data about the recipient's device, IP address, or location is collected beyond the open event timestamp.

4. Open tracking limitations

Apple Mail Privacy Protection (MPP), introduced in iOS 15 and macOS Monterey, causes Apple's mail servers to pre-fetch tracking pixels automatically — even if the recipient never actually opens the email. As of 2025, Apple Mail accounts for approximately 58% of all email client market share.

To reduce false positives, we apply the following filters:

  • Opens recorded within 45 seconds of send are flagged as likely automated (bot or MPP scan) and excluded from open rate calculations
  • Domains icloud.com, me.com, and mac.com receive automatic Apple MPP consideration

For this reason, all open data in LeadWithEmail is labeled "Estimated Opens" throughout the platform. Reply rate — not open rate — is the primary and most reliable success metric we emphasize.

5. Data isolation

Each LeadWithEmail account is completely isolated. Your contact lists, email send logs, campaigns, and tracking data are never visible to, shared with, or accessible by other LeadWithEmail users. All database queries are scoped to your account using a unique tenant identifier enforced at the application layer.

6. We do not sell your data

We do not sell, rent, or trade any personal data — yours or your contacts' — to any third party, for any purpose, at any price. This includes advertising networks, data brokers, and analytics companies.

7. Third-party services we use

Stripe (billing)

Payment processing is handled by Stripe. We never see or store your card number. Stripe's use of your data is governed by Stripe's Privacy Policy.

Clerk (authentication)

Sign-in and session management are handled by Clerk. Your account credentials are managed by Clerk under their Privacy Policy.

Anthropic / OpenAI / Google AI (email generation)

AI-generated email copy is produced by large-language model APIs (Anthropic Claude by default; OpenAI or Google Gemini if you select them). For outreach drafts, the prompt includes your brand context and a contact’s first name, company, and location. For suggested replies, it also includes the snippet of the reply you received. We do not send your full contact list to AI providers, and we do not use your data to train AI models. We keep an internal, metadata-only log of AI calls (provider, model, purpose, token counts, cost) that never stores prompt or email content. See Subprocessors.

Railway / Supabase (infrastructure)

Our application runs on Railway (hosting) and Supabase (database). Data is stored in the United States.

8. Data retention and deletion

We retain your data for as long as your account is active.

Delete it yourself: while signed in, go to Settings → Account → Delete account to permanently remove your account and tenant data (contacts, campaigns, sent-email and reply records, hot leads, tracking events, and stored Gmail tokens). You can also Disconnect Gmail from the same screen without deleting your account.

Or request deletion: email [email protected] with the subject "Data Deletion Request" and we will delete your account and associated data within 30 days. Some records may be retained for legal, billing, or security reasons — see our Data Deletion page.

You can also revoke Gmail access at any time from your Google account at myaccount.google.com/permissions. Revoking access does not delete your LeadWithEmail account, but it will stop email sends until you reconnect.

9. Security

Gmail OAuth tokens are encrypted at rest using Fernet symmetric encryption (AES-128-CBC). The encryption key is stored separately from the database.

All data is transmitted over HTTPS. Database access is restricted by network rules and authenticated credentials.

If you believe you have discovered a security vulnerability, please email [email protected] immediately.

10. Changes to this policy

We may update this policy as the platform evolves. If we make material changes, we will notify you by email or by a notice in the app. The "effective date" at the top of this page reflects the date of the most recent revision.

11. Contact

Questions about this policy or your data: [email protected]
LeadWithEmail.com  ·  New Jersey, USA

Related: Google Data Use · Security · Subprocessors · Data Deletion

Effective date: June 3, 2026 · Last updated: June 28, 2026