SDR Autopilot Privacy Policy

Last updated: 2026-09-09

1. What this covers

This policy describes how SDR Autopilot (the "Service") handles personal data — yours as a waitlist signup or account holder, and the recipients' whose contact details flow through a campaign you run on a paid plan.

2. Waitlist & account data

  • Waitlist: email address and optional metadata needed to invite you (for example signup source and timestamps). We use this to manage the private beta queue and notify you when seats open — not to run outreach on your behalf.
  • Technical network data on public waitlist and similar abuse-sensitive flows: IP address and related network metadata, used for security, fraud prevention, abuse detection, rate limiting, and bot mitigation — not to profile you for marketing.
  • Account details: name, email, password hash, and billing email when you create an account.
  • Payment method metadata via Stripe when billing is configured (we never see or store full card numbers).
  • Project content you provide: domain, offer, docs, uploaded files, targeting preferences.
  • Website and product analytics: when Google Analytics is configured for a deployment, we use it for aggregate website/product analytics. Google acts as a third-party processor / service provider for that measurement.
  • Product telemetry needed to operate, secure, and improve the Service (not sold to third parties).

3. Free Explore previews vs paid identities

On Free Explore, prospect and company identities stay redacted in the product — you can evaluate ICPs and outreach previews without receiving raw contact details. Paid Founder and Growth plans unlock prospect identities and sending within your included (and optional top-up) capacity. Public API and MCP access to identities and outbound execution require a current active paid entitlement; historical identities that were reached while paid may remain readable in the authenticated app UI under the product's entitlement rules.

4. Data about the leads you contact

Company and contact records (name, title, email, company info) come from connected lead-data providers when configured, or from deterministic demo data in zero-config / guest-demo environments. You are the data controller for the outreach your account sends — see the anti-spam section of our Terms of Use. Automated cold outreach and follow-up sequences include a one-click unsubscribe that adds the recipient to your project's suppression list (and suppression is re-checked immediately before each send). Conversational reply drafts you send from the inbox do not add unsubscribe headers.

5. How we use data

  • To operate the Service: research, targeting, drafting, sending (on paid plans), and reporting.
  • To bill paid subscriptions and optional prospect-capacity top-ups via Stripe when configured.
  • To understand aggregate website and product usage via Google Analytics when that measurement ID is configured for the deployment.
  • To detect abuse and enforce rate limits on public waitlist, contact form, and login-free demo flows (including via IP address and technical network data where needed).
  • To improve the product — never to sell your data or your recipients' data to third parties.

6. Sending infrastructure

On paid plans, outbound mail typically goes through managed warmed sending (a shared pool of managed mailboxes) when that infrastructure is configured for the deployment. Connecting your own mailbox (Gmail, Outlook, or SMTP) may be available as an optional, configuration-dependent path. Either way, you remain responsible for the content and compliance of messages sent for your account.

7. Third-party processors

Depending on what is configured for a deployment and what you connect, processing may involve: an AI vendor (for example Anthropic, OpenAI, Mistral, or Google), Stripe (billing), Google Analytics (when configured, for aggregate website/product analytics), managed sending / email-infrastructure providers, optional BYO mailbox providers (Google, Microsoft, or your SMTP host), lead-data and email-finder vendors when keys are present, transactional email for account messages, bot-detection on public forms when enabled, cloud hosting, and our database. Each only receives what it needs to perform its function. We do not list processors we are not using.

8. Retention, security & rights

We retain project and campaign data for as long as your account is active, and waitlist emails until you ask to be removed or the waitlist purpose ends. You can request deletion of your account and associated data via the public contact form (account holders may also use in-product support); suppressed contacts stay suppressed even after other data is deleted, so a removed lead is not re-contacted by mistake. Passwords are hashed; mailbox credentials and similar secrets are encrypted at rest when stored. Access to production data is limited to what's needed to operate the Service.

Depending on where you're located, you may have rights to access, correct, export, or delete your personal data, and recipients may have corresponding rights over contact data a campaign holds about them. Use the public contact form to exercise any of these; account holders can also use in-product support.

9. Abuse prevention

We apply rate limits, bot checks (when configured), and other safeguards on public waitlist, contact form, and demo flows to reduce automated abuse. That may include processing IP addresses and technical network data for security, fraud prevention, abuse detection, rate limiting, and bot mitigation. We may refuse, suspend, or terminate access that appears fraudulent, harmful to recipients, or otherwise in violation of these policies.

10. Changes to this policy

We may update this policy from time to time. Continued use of the Service after a change takes effect constitutes acceptance of the updated policy.

11. Contact

Questions about this policy — including from waitlist visitors, account holders, or outreach recipients — use the public contact form. Account holders can also use in-product support when available.