Trust & data handling
What this actually does with your data
Last updated: 1 August 2026
Not a compliance-department page — a plain answer to the question anyone doing their own outreach should ask before connecting a real mailbox to a tool: what does it actually do with my data, and the data it finds on my behalf?
Where prospect data comes from
Every prospect is sourced from People Data Labs, a licensed B2B data provider — never scraped, never invented, never bought as a static list. We only ever show you real people who match the ideal-client profile you described.
How the AI drafting is grounded
Every fact a draft uses has to trace back to something actually supplied — either your own offer and proof points, or a real, verified detail about the prospect. The model is instructed to never invent an achievement, a shared connection, or a reason it "noticed" something. It's also restricted to professional-context facts: the kind of thing visible on a company site or a professional profile in under 30 seconds. It will not use anything that would require digging into someone's personal life or social activity, even if that information happened to be available.
Every draft lists exactly which supplied facts it used, right in the review panel, so you can check its work before you approve anything.
What we never do
- We never send anything automatically. Every single email — whether it's a first-touch draft or a scheduled nurture step — requires your explicit review and approval before it goes out.
- We never read, search, or modify your inbox. The Google permission this app requests is send-only
(the
gmail.sendscope) — there is no code path that touches an existing message, thread, or label in your mailbox. - We never fabricate a case study, a testimonial, or a statistic to make this look more effective than it's been for you specifically.
How your connected mailbox is protected
Connecting Gmail goes through Google's own OAuth consent screen — we never see or store your Google password. The token that lets us send on your behalf afterward is encrypted at rest (AES-256-GCM) and only decrypted at the moment a send you've approved actually goes out. You can disconnect it at any time, which revokes that access with Google directly.
Every email we send includes a real one-click unsubscribe link. Once someone unsubscribes, or an address bounces, we keep a record of that specifically so we never contact them again from your account — even if you later delete the original prospect.
Who else touches your data
We use a small number of service providers to run this product. Each acts strictly on our instructions:
- People Data Labs — the source of prospect data.
- Anthropic — used to draft outreach copy and structure your described ICP, grounded only in the facts described above. It never sends anything and never acts on a reply on its own.
- Supabase — hosts the application database.
- Railway — hosts the application server.
- Google — sends outreach email through your own connected mailbox, and nothing else.
Your control over your own data
You can delete every saved ICP, prospect, draft, outcome, and intake session tied to your account yourself, at any time, from Settings — no support ticket required. We keep contact and outreach records only until you delete them or the associated prospect opts out.
Questions
If anything here isn't specific enough for what you need to decide, ask — we'll answer plainly or say we don't know, not deflect. contact@abstractglitch.com.