Privacy Policy
Last updated: July 11, 2026
1. Introduction
ProspectFlow ("we", "our", or "us") operates the prospectflow.dev website and SaaS platform. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service.
2. Information We Collect
Account Information
When you create an account, we receive your account identifier, name, email address, profile image, and session information from Clerk. We also record the signup IP address in encrypted form and keep a keyed lookup hash. We use that IP signal to rate-limit signups and detect repeated free-account abuse; we do not use it for advertising.
Payment Information
Payment processing is handled by Stripe. We do not store credit card numbers on our servers. Stripe collects and processes payment information in accordance with their own privacy policy.
Business Data
When you use prospect research, we collect business names, addresses, reviews, public records, websites, and other business evidence to build the signal feed, explain fit and intent, and draft outreach. Depending on the workflow, we may also obtain professional contact details—such as a person's name, role, work or personal email, phone number, and public profile—from enrichment providers including Prospeo, Hunter, and RocketReach. Those prospects did not necessarily ask us to collect their information.
Usage Data
We collect pages and features used, timestamps, attribution parameters, errors, and device/request information. Public scorecards can record views, scroll depth, time on page, and CTA clicks. We hash network identifiers before storing a visitor identifier.
3. Google Account & Gmail Data
If you choose to connect your Google account, ProspectFlow requests access to the following Google API scopes:
- Full Gmail access (
https://mail.google.com/) — Used to send seller-approved outreach and to run reply detection. Reply detection connects to the inbox through Gmail or IMAP, searches a limited recent window for replies to ProspectFlow-sent messages, and reads the matching message metadata and content needed to distinguish a reply, auto-reply, bounce, or complaint. We do not use the inbox to build advertising profiles or scan unrelated mail for prospect data. - Email address (
https://www.googleapis.com/auth/userinfo.email) — Used to identify your connected account and display it in the dashboard. - Profile information (
https://www.googleapis.com/auth/userinfo.profile) — Used to display your name alongside the connected email account.
How We Use Google Data
Google user data is used to identify the connected account, send approved messages, count sending activity, and detect responses to those messages. We do not use Google mailbox data for advertising or unrelated market research.
Storage & Retention of Google Data
We store encrypted OAuth tokens and the connected address so the connection can work without re-authentication. We store our outbound message, delivery state, and derived reply classification. The reply scanner processes matching received messages in memory; it does not copy the connected inbox or retain attachments. You can revoke access at any time from your Google Account permissions page, or by disconnecting your email account in ProspectFlow settings.
Sharing of Google Data
We do not sell Google user data. Google and our hosting/database providers process the limited data needed to provide the connection. ProspectFlow staff do not read mailbox data except when you request support and authorize the access, or when necessary to investigate abuse or a security incident.
Compliance
ProspectFlow's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
4. How We Use Your Information
- Provide, operate, and maintain our platform
- Process your transactions and manage your subscription
- Find and rank business prospects, explain evidence, and generate outreach drafts
- Send transactional emails (account confirmation, password resets, billing receipts)
- Analyze usage patterns to improve our features and user experience
- Detect and prevent fraud or abuse
- Comply with legal obligations
5. Third-Party Services
This list is generated from the same typed processor register used by product code. A service marked optional receives data only when that integration or workflow is used.
- Clerk — Authentication and account management. Data: account identifiers, email, name, profile image, session and device information.
- Neon — Managed PostgreSQL database hosting. Data: account, prospect, outreach, billing-reference, and product records stored by the service.
- Vercel — Application hosting, edge delivery, feature configuration, and file storage. Data: requests, operational logs, uploaded feedback images, and application data needed to serve a request.
- Stripe — Subscriptions, invoices, and payment processing. Data: account and billing identifiers, plan, invoices, payment status; card details go directly to Stripe.
- Anthropic — Prospect research, scoring support, summaries, and outreach drafting. Data: seller instructions and the business/prospect evidence needed for the requested generation.
- OpenAI (optional) — Optional AI generation and analysis paths. Data: seller instructions and the business/prospect evidence needed for the requested generation.
- Google — Google sign-in, Gmail sending and reply detection, Places business research, and optional Ads conversion measurement. Data: OAuth profile, connected mailbox credentials/tokens, sent-message identifiers and limited received-message metadata/content for reply classification, business search queries, and—when a measurement ID is configured—public-site browser/conversion events.
- Microsoft (optional) — Microsoft sign-in, Outlook/Graph sending, and connected-mailbox access. Data: OAuth profile, connected mailbox credentials/tokens, and message data needed to send or detect replies.
- Resend — Transactional platform email and delivery webhooks. Data: recipient address, message content, and delivery events.
- Instantly (optional) — Optional mailbox warm-up and account-health integration. Data: connected sending address and mailbox configuration.
- Hunter (optional) — Business contact discovery. Data: business domain/name and returned professional contact data.
- RocketReach (optional) — Fallback business contact discovery. Data: business domain/name and returned professional contact data.
- Prospeo (optional) — Business contact enrichment. Data: business domain/name and returned professional emails, phone numbers, names, and profiles.
- NeverBounce (optional) — Email deliverability verification. Data: email addresses submitted for verification.
- Business research providers (optional) — Public-record and web research through providers such as Google Places, Yelp, Serper, ScraperAPI, Outscraper, WhoisXML API, Census, FRED, and government APIs. Data: business names, domains, locations, and public-record search terms.
- Upstash — Rate limiting and short-lived operational coordination. Data: hashed or internal request keys and short-lived coordination state.
- Sentry — Error and performance monitoring. Data: scrubbed error, request, device, and diagnostic context.
- Meta (optional) — Optional public-site advertising conversion measurement. Data: public-site browser, page, and conversion events when a Meta Pixel ID is configured.
- Cloudflare (optional) — Optional DNS management and generated-site deployment. Data: encrypted customer-supplied DNS credentials, domain configuration, and generated site files.
- NameSilo (optional) — Optional domain registration. Data: domain order and registration contact/configuration data.
- Social media creation and publishing providers (optional) — Optional Social OS research, media generation, and publishing through configured providers such as Apify, ScrapeCreators, Blotato, BytePlus, and Higgsfield. Data: public social URLs/content, creative prompts, generated media, and publishing instructions.
6. Cookies and Tracking
We use essential cookies for authentication, security, and first-touch attribution. Outreach email may contain an invisible open pixel and ProspectFlow-rewritten links. Loading the pixel or visiting a rewritten link records the related send, time, and delivery/engagement event. Public scorecards use a signed document context so the browser can report views, scrolling, time, and CTA clicks without accepting a client-supplied account identity. Browser and email-client privacy protections can make these measurements incomplete or inaccurate. When advertising measurement IDs are configured, public marketing pages can also send browser, page, and conversion events to Google Ads or Meta; those optional pixels are not required to use the app.
7. Data Retention
Account, connected-email, prospect, contact, and outreach records remain while your account is active unless you delete them sooner. Automated cleanup currently keeps product analytics for about 90 days, public-report events for about 180 days, prospect event history and usage records for about 365 days, and security events for about 730 days (operators may shorten these windows). Account deletion removes or irreversibly detaches your direct identifiers from user-owned records. Our account-linked usage and billing rows are deleted; Stripe can retain invoices, payment records, and dispute evidence under its legal and financial obligations. Security and product-audit records can remain for the stated windows to prevent fraud and investigate incidents, but account IDs, network address, user agent, and attached metadata are removed from those retained rows. Platform-wide suppression records remain as long as needed to honor an opt-out; they retain an encrypted/hash-protected recipient reference, not the deleted seller identity. Shared public business/source records may remain because they are not an account profile, but the deleted account's links, notes, contacts, and outreach are removed.
8. Data Security
We implement appropriate technical and organizational measures to protect your data, including encryption in transit (TLS), secure database access controls, and regular security reviews. However, no method of electronic transmission or storage is 100% secure.
9. Your Rights
You have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data and account
- Download a JSON account export containing your account and seller profiles, prospects, normalized contacts and channels, outreach sends and saved templates, document metadata (not document bodies), and usage records. Owned encrypted PII is decrypted in the export; credentials, OAuth tokens, API keys, encryption material, webhook secrets, and platform-wide suppression records are excluded.
- Withdraw consent for optional data processing
For a prospect contact we enriched, you may object to processing or request correction or removal. We rely on legitimate interests in helping business sellers identify relevant professional contacts, balanced against the prospect's privacy rights; we do not treat enrichment as consent. Contact us with the address or other identifier to remove. Sellers remain responsible for having a lawful basis for their own outreach.
10. Children's Privacy
Our service is not directed to individuals under 18 years of age. We do not knowingly collect personal information from children.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new policy on this page and updating the "Last updated" date.
12. Contact Us
If you have questions about this Privacy Policy or your data, contact us at: