Privacy

Privacy Policy

This policy explains what LeadAtomic collects from the public site, waitlist, and product, and how that information is used to operate, secure, and improve the service.

1. Scope

This Privacy Policy applies to LeadAtomic's public website, waitlist flow, account onboarding, authenticated product experience, and related support or operational communications.

It covers information we collect directly from you, information generated when you use the service, and limited technical information used for security, analytics, and abuse prevention.

It does not replace the privacy terms of third-party services you choose to connect, such as Google or Microsoft mailbox providers.

2. Information We Collect

Depending on how you interact with LeadAtomic, we may collect the following categories of information:

  • Account and waitlist information. Name, work email, workspace name, company website, feature-interest selections, and other information you submit during waitlist signup, sign-up, sign-in, or account recovery.
  • Workspace and onboarding information. Company and ICP inputs such as industry targets, buyer roles, geography, exclusions, competitors, keywords, notes, send-window settings, approval defaults, and other profile fields used to configure your workspace.
  • Mailbox and communications information. Sender email, display name, provider type, reply-to settings, signature text, mailbox connection status, OAuth scopes, encrypted provider credentials, outreach drafts, sent-message records, inbound replies, and related delivery or health diagnostics.
  • Security and operational information. Password hash, password-update timestamps, verification and reset token records, login timestamps, rate-limit records, session state, and error or activity logs needed to operate and protect the service.
  • Public-site analytics information. Page path, referrer, campaign parameters, device type, viewport width, country where available, and an anonymous visitor hash used for aggregate analytics. LeadAtomic's public-site analytics pipeline does not store raw IP addresses in marketing event rows.
  • Browser-stored state. Theme preference, onboarding draft state, analytics session state, UTM/referrer data, and temporary mailbox OAuth handoff state stored in your browser through cookies, local storage, or session storage.

3. How We Use Information

  • Create and secure accounts, maintain authenticated sessions, and prevent abuse.
  • Set up and operate your workspace, including ICP configuration, mailbox setup, and sending controls.
  • Generate or support product workflows such as onboarding finalization, website-based profile extraction, enrichment, scoring, and outreach drafting.
  • Send transactional emails such as verification links, password-reset links, and operational notices.
  • Measure public-site usage, waitlist demand, and conversion trends at an aggregate level.
  • Investigate errors, monitor system health, enforce rate limits, and maintain auditability for support and security.

4. How We Share Information

We do not currently sell personal information or run third-party advertising trackers on the public site.

We may share information in the following limited cases:

  • With service providers that help us operate LeadAtomic, such as transactional email infrastructure and operational tooling.
  • With the mailbox providers you choose to connect, such as Google or Microsoft, to complete OAuth, refresh credentials, and process mailbox activity you authorize.
  • With model or API providers used to perform requested product workflows, such as profile extraction, enrichment, scoring, or draft generation.
  • When required for legal compliance, fraud prevention, security response, or to protect LeadAtomic, our users, or the public.
  • As part of a merger, acquisition, financing, or asset sale involving LeadAtomic, subject to this policy or a successor policy.

4b. Google User Data

If you connect a Gmail mailbox, LeadAtomic requests two Google permissions and uses them for one purpose only: sending the outreach you approve, and detecting the replies to it.

  • Sending (gmail.send) — sends the messages you have reviewed and approved, from your own mailbox.
  • Reading (gmail.readonly) — detects replies to those messages, so the conversation appears in LeadAtomic, the sequence stops, and bounced addresses are retired. Every Gmail permission that allows reading a message is classified by Google as restricted; this is the narrowest one that supports the feature, and we never modify, label, or delete anything in your mailbox.

We store only mail related to outreach you sent through LeadAtomic. Our reply checker decides before anything is written down. It keeps a message if it matches outreach sent from your mailbox, if it comes from someone you have sent outreach to — so a reply that loses its threading, or an unsubscribe sent as a fresh email, still reaches you — or if it is a delivery failure notice about one of your sends. Everything else, including mail from anyone you have never contacted through LeadAtomic, is discarded in memory and never reaches our database, our product, or any third party.

No LeadAtomic employee reads your mailbox content. Message content is not available in any internal or operational tool we use, and our test suite fails if a change would reintroduce that access.

We never use Google user data to train AI models — ours or anyone else's — and never for advertising, profiling, credit decisions, or resale.

LeadAtomic's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.

You can disconnect a mailbox at any time in Settings, which revokes our access at Google and destroys the stored credentials. You can also revoke it directly from your Google account permissions.

4c. Sub-processors

These are the third parties that may process data on our behalf, and what they receive. We do not sell personal information to anyone, and none of these are advertising platforms or data brokers.

  • OpenAI — receives reply text and the message it responds to, solely to classify the reply and draft a suggested response for you to edit and approve. Sent through the OpenAI API, which is not used to train their models. Never used to develop or improve any AI model.
  • Google / Microsoft — your connected mailbox provider, for sending and reply detection you authorised.
  • Resend — email delivery for account notices (verification, password resets) and for the alerts we send you. A reply alert includes a short excerpt of the reply so you can act on it without opening the app, so Resend carries that excerpt in transit. You can switch reply alerts to a daily digest or off entirely in Settings.
  • MillionVerifier (EU) — checks whether a prospect’s email address exists before we draft or send to it, so we protect your sending reputation. It receives the email address on its own — no name, company, score or research — and never any content from your mailbox.
  • Render — application and database hosting, in encrypted storage.
  • Paddle (Paddle.com Market Limited, UK) — our payment provider and the merchant of record for every purchase, meaning Paddle is the seller on the transaction rather than a processor acting on our instructions. It receives your billing name, email, country, and payment details, which you give to Paddle directly at checkout — we never see or store your card number. Paddle handles invoicing, tax, and refunds, and is an independent controller of that billing data under its own privacy notice. It receives nothing about your prospects, your research, or your mailbox.

5. Cookies, Local Storage, and Analytics

LeadAtomic uses a small number of browser-side storage mechanisms for distinct purposes:

  • Session cookie. Authenticated workspace sessions use an HTTP-only session cookie so the app can keep you signed in securely.
  • Local and session storage. We store theme preference, onboarding draft state, analytics session data, UTM/referrer data, and temporary OAuth handoff state in browser storage.
  • Public-site analytics. The public site records anonymous usage events to help us understand visits, waitlist conversions, and campaign performance. The client-side tracker honors browser Do Not Track when it is explicitly enabled.

6. Security

LeadAtomic uses technical and operational safeguards intended to reduce risk, including salted password hashing, mailbox credentials encrypted at rest with AES-256-GCM under keys held outside the database, encrypted transport throughout, rate limiting, HTTP-only session controls, and audit-oriented operational records.

No system can promise absolute security. You remain responsible for protecting your own devices, mailbox accounts, and account credentials.

7. Data Retention

We keep information for as long as it is reasonably needed to operate the service, maintain security, support legitimate business records, and comply with legal obligations.

  • Reply content. The text of replies received in a connected mailbox is cleared after 180 days. We keep the record that a reply happened and how it was classified, so your conversation history stays intact, but the message text itself does not persist indefinitely.
  • Browser-stored values generally remain until they expire, are overwritten, or you clear them.
  • Verification and reset-token records remain in our systems as security records even after they expire or are consumed.
  • After you delete your workspace, we retain only financial records we are legally required to keep, and company research records that carry no link to you (see section 8).
  • Backups. Deletions apply to our live systems immediately. Backup copies are not rewritten; they expire on a 30-day cycle, after which no copy remains.

8. Your Choices, and Deleting Your Data

  • You can update certain account and workspace information from within the product.
  • You can disconnect a mailbox at any time in mailbox settings, which revokes our access at the provider.
  • You can sign out at any time and clear browser storage locally from your browser.
  • You can permanently delete your workspace yourself, from Settings. It asks for your password and for you to type your workspace name, so it cannot happen by accident.

When you request deletion, your mailboxes are disconnected and all processing stops immediately. The data itself — your accounts, conversations, messages, mailboxes, settings and workspace — is permanently deleted after 30 days. You can cancel at any point during that window, and we email you the exact date and a link to stop it.

Two things survive, neither of which identifies you: financial records we are legally required to retain, and the company research records in our shared database. Those describe businesses, not you, and other customers rely on the same records — after deletion they carry no link back to your workspace.

If you would rather we did it for you, or you need help with an access or correction request, contact hello@leadatomic.com.

9. If You Received Outreach Through LeadAtomic

LeadAtomic customers use the platform to run business-to-business outreach to other organisations. If you received an email sent through LeadAtomic, the following applies to you as the recipient.

  • What data is involved. Business-contact information — such as a work email address, role, and the company it belongs to — sourced from publicly available business listings and the company's own website, used to send relevant, human-reviewed outreach on behalf of the LeadAtomic customer.
  • Who is responsible. The LeadAtomic customer that contacted you is the party deciding to reach out. LeadAtomic operates the sending infrastructure on their behalf. Every message identifies the sender and the business they represent.
  • How to opt out. Every outreach email includes an unsubscribe link and a List-Unsubscribe header, and you can simply reply with "unsubscribe". Any of these permanently stops that customer from contacting that address through LeadAtomic.
  • Your other rights. To ask what data is held about you, correct it, or have it deleted, contact hello@leadatomic.comand we will route the request to the relevant customer and assist as the operator of the platform.

10. Changes to This Policy

We may update this Privacy Policy from time to time. If we make a material change, we will update the effective date on this page and use reasonable notice appropriate to the change.