Privacy policy
Last updated 12 August 2026
Outreach is a small, personally-run tool for writing, sending and tracking your own cold email through your own Gmail account. This page explains what it collects, why, and how to make it stop.
What we collect
Your Google account. Signing in with Google gives us your name, email address and profile picture, and asks for a few Gmail permissions:
- Send email — so the app can send a draft on your behalf. Nothing is ever sent automatically; every email is reviewed and dispatched by you, one at a time.
- Read email — used only to notice replies on threads this app started, so it never emails someone who has already written back. It does not read the rest of your inbox.
- Calendar (optional) — if you turn on reminders, upcoming events are mirrored in so the app can nudge you about follow-ups. You can leave this off entirely.
What you add yourself. Your outreach targets and contact lists, any resume or profile details you upload (used to help draft emails, and deletable at any time from Settings), and message templates you write.
Your AI key. If you use AI drafting, you paste in your own Gemini API key. It is kept only in your browser for that session and is never sent to or stored on our server — there is no server-side key.
Payment proof. If you buy access to the shared contact pool, the UPI reference and screenshot you upload are stored so a human can verify the payment. Nothing else about a purchase is collected — there is no card or bank data involved.
What we don't do
- We don't sell or rent your data to anyone.
- We don't send email without you pressing send.
- We don't use your Gmail access for anything but sending and reply-detection.
- We don't share your Gemini key — it never leaves your browser.
Where it's stored
Your Google refresh token is encrypted at rest and only decrypted server-side, per request, to make an API call on your behalf. Resumes and payment screenshots are stored in object storage used only for this app. Resume data is deleted immediately when you use the "Delete my resume and parsed data" control in Settings.
Third parties involved
Google (sign-in, Gmail, Calendar), Google's Gemini API (only if you supply a key), QuickEmailVerification (checks whether an address you're about to email looks real, before you send to it), and Cloudflare R2 (file storage). Each only sees what it needs to do its one job.
Deleting your data
You can delete your uploaded resume and everything extracted from it at any time from Settings. To remove your account and everything else tied to it, email support@example.com and it will be handled directly.
Changes
If this policy changes in a way that matters, the "last updated" date at the top of this page will move. There is no mailing list announcing revisions.
Questions
Reach out any time at support@example.com, or use "Report an issue" in the app footer or in Settings.