Privacy Policy

Effective September 27, 2026

This policy explains how ProspectFlow ("we", "us") handles personal data when you visit prospectflow.app, use the ProspectFlow application at app.prospectflow.app, or connect your accounts to it.

1. Who this policy covers

  • Customers and users: people who sign up for ProspectFlow and members of their teams. For this data we are the controller.
  • Prospects: people whose details our customers upload, import, find or contact through ProspectFlow. For this data our customer is the controller and we process it on their instructions. Questions about how a customer uses your details should go to that customer; we will help them respond.
  • Website visitors: people who browse prospectflow.app.

2. What we collect

Account data

Your name, email address, password (stored only as a salted hash), team and role, and settings. If you sign in with Google, we receive your name, email address and profile picture.

Connected accounts

When you connect a mailbox (Gmail, Microsoft 365/Outlook, or IMAP/SMTP), a LinkedIn account, or another integration, we store the access credentials needed to act on your behalf. OAuth tokens and mailbox passwords are encrypted at rest. We also store the email messages, threads and LinkedIn messages that ProspectFlow sends or receives for your outreach, so we can show them in your inbox, detect replies and run your sequences.

Customer content

Contacts, companies, sequences, templates, tasks, notes, documents you upload for AI features, and anything else you create in the app.

Billing data

Payments are processed by Stripe. We receive your billing name, email, plan and payment status, and the last four digits and expiry of your card. We never see or store full card numbers.

Usage and technical data

IP address, browser type, request logs and error logs, used to run, secure and debug the service. Emails sent through ProspectFlow may include open tracking and unsubscribe links, which record when a recipient opens a message or unsubscribes.

Cookies

The application uses strictly necessary cookies to keep you signed in. We do not use advertising cookies, and the marketing site does not load third-party analytics.

3. Google user data

If you connect a Gmail account, ProspectFlow requests access to the Gmail API with the gmail.modify scope and to your email address. Here is exactly what we do with that access:

  • What we access: messages and threads in the connected mailbox, the mailbox's labels, and notifications that new mail has arrived.
  • How we use it: only to provide features you use in ProspectFlow: sending the emails in your sequences from your address, detecting and showing replies to them in your ProspectFlow inbox, stopping a sequence when a prospect replies, applying labels you choose, and, if you turn them on, AI features that classify replies or draft responses.
  • How we store it: OAuth tokens are encrypted at rest. Messages we sync are stored in our database and are visible only to members of your ProspectFlow team.
  • Who we share it with: only the service providers listed in section 5 that need it to run the features above (for example, our hosting provider, and an AI model provider when you use an AI feature on a message). We do not sell Google user data, use it for advertising, or let people read it except with your consent, for security purposes, to comply with the law, or when it has been aggregated and anonymized for internal operations.
  • No AI training: we do not use Google user data to develop, improve or train generalized artificial intelligence or machine learning models.
  • Removing access: you can disconnect a Gmail account in ProspectFlow at any time, which deletes its stored tokens, or revoke access at myaccount.google.com/permissions. See section 7 to delete the messages we synced.

ProspectFlow's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

4. How we use personal data

  • To provide, maintain and support ProspectFlow, including the features you choose to use.
  • To process payments and manage credits and subscriptions.
  • To send service emails: account verification, password resets, team invitations and billing notices.
  • To secure the service, prevent abuse and spam, and investigate incidents.
  • To comply with legal obligations.

Where the GDPR or a similar law applies, we rely on performance of our contract with you, our legitimate interests in running a secure service, your consent where we ask for it, and legal obligations.

5. Service providers

We share personal data only with providers that help us run ProspectFlow, under contracts that limit their use of it to providing their service to us:

  • Hosting and infrastructure: Railway (application servers and databases), Vercel (marketing site), and cloud file storage.
  • Email and messaging: Google, Microsoft, and your own email provider for connected mailboxes; Resend for our service emails; Unipile for connected LinkedIn accounts.
  • AI: AI model providers (such as OpenAI, Anthropic and Google, directly or through OpenRouter) when you use AI features, and a vector database (Pinecone) for documents you upload for AI use.
  • Data enrichment and verification: providers we query when you ask to find or verify an email address or research a company, such as FindyMail, Prospeo, MillionVerifier, Bounceban and TheirStack.
  • Payments: Stripe.
  • Integrations you connect: Composio and the apps you authorize through it.

We may also disclose data if required by law, to protect the rights and safety of our users or others, or as part of a merger or acquisition, in which case this policy will continue to apply to your data.

6. International transfers

Our providers may process data in the United States and other countries. Where required, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.

7. Retention and deletion

  • We keep account data and customer content for as long as your account is active.
  • Disconnecting a mailbox or LinkedIn account deletes its stored credentials immediately.
  • To delete your account and all associated data, including synced email, email support@prospectflow.app from your account's email address. We will complete the deletion within 30 days and confirm when it is done. Copies in backups are removed as those backups expire.
  • We keep billing records for as long as tax and accounting law requires.

8. Security

We encrypt data in transit with TLS and encrypt connected-account credentials at rest. Access to production systems is limited to the people who need it and protected with multi-factor authentication. Each team's data is isolated from other teams. No system is perfectly secure; if we become aware of a breach affecting your personal data, we will notify you without undue delay and within 72 hours where the law requires.

9. Your rights

Depending on where you live, you may have the right to access, correct, delete or export your personal data, to object to or restrict certain processing, and to withdraw consent. To exercise any of these rights, email support@prospectflow.app. You may also complain to your local data protection authority. We do not sell or share personal data for cross-context behavioral advertising.

10. Children

ProspectFlow is a business tool and is not intended for anyone under 16. We do not knowingly collect their data.

11. Changes

We will post any changes on this page and update the effective date. If a change is material, we will tell you by email or in the app before it takes effect.

12. Contact

ProspectFlow
support@prospectflow.app