Privacy Policy
Last updated: July 31, 2026
1. Who We Are
This Privacy Policy describes how Emaissary (the "Service") collects, uses, and protects information in the course of operating an AI outreach copilot that researches accounts and drafts personalized outreach for your approval. Emaissary ("we", "us") is operated by its founder. By using the Service, you agree to the practices described below.
2. Two Kinds of Data
Emaissary handles two distinct categories of data, and our role is different for each:
- (a) Your account data. This is information about you as a user of the Service: your email address, name, authentication provider details (for example, a Google or Microsoft sign-in, or a hashed password), account settings, and service usage data. For your account data, Emaissary is the data controller — we determine why and how this data is processed, subject to this policy.
- (b) Prospect data. This is contact and company information about the people and organizations you research and contact through the Service — data you add manually, import from CSV, or that the Service gathers through integrations we provide (such as Apollo.io for prospect discovery) and from public web sources. For prospect data, you are the data controller, and Emaissary acts as your data processor: we handle it strictly on your instructions to research accounts, draft outreach, and track the resulting activity.
3. What We Collect & Why
We collect account data (as described above) to create and secure your account, operate the Service, provide support, and measure product usage against your plan's limits. We collect and process prospect data at your direction to identify accounts worth contacting, draft personalized messages, and track outreach status. We do not use your account data or your prospect data to train models for the benefit of other customers, and we do not sell either category of data.
4. Retention
We retain your account data for as long as your account remains active, and for a reasonable period afterward as needed for legal, tax, or fraud-prevention purposes. Prospect data is likewise retained while your account is active. Self-service export and deletion tools are planned; until they ship, you can request deletion of your account or prospect data at any time by emailing hello@emaissary.com, and we will respond promptly.
5. Sub-processors
We rely on a small number of third-party providers to operate the Service, each acting as a sub-processor for the data categories above. The current list, including each provider's purpose and location, is maintained on our Subprocessors page.
6. Google User Data (Sign-In and Gmail Connection)
You can sign in to Emaissary with your Google account, and you can optionally connect your Gmail account so that outreach emails you approve are sent from your own address. Here is exactly what we access and how we use it:
- Google Sign-In. When you sign in with Google, we receive your basic profile information (name and email address) to create and secure your account. Nothing else.
- Gmail connection. If you choose to connect Gmail, we request the
gmail.sendpermission only. We use it solely to send outreach emails that you have individually reviewed and approved in Emaissary, from your own address. We cannot and do not read your inbox, your contacts, or any existing messages — the permission we request does not allow it. - What we store. An encrypted OAuth refresh token (encrypted at rest with AES-256) and the email address of the connected account, so we can send on your behalf until you disconnect. We do not store your Google password. Google user data is protected in transit with TLS and at rest with encryption, under the same access controls described in the Security section below.
- Sharing. We do not transfer, sell, or share Google user data with any third party, and we do not use it for advertising. No humans read this data except with your explicit consent for support, where required for security or legal compliance, or as needed to operate the sending feature you enabled.
- Retention & deleting it. We retain the stored token and connected address only while your Gmail connection is active. Disconnect Gmail at any time from Settings → Integrations in the app — this immediately deletes the stored token and revokes our access at Google; deleting your account does the same. You can also revoke access from your Google Account permissions page.
- AI/ML. Google user data is never used to develop, improve, or train artificial-intelligence or machine-learning models — neither ours nor any third party's — and is never transferred to third-party AI services. The outreach drafts Emaissary generates are produced from prospect research data and your own instructions, not from any Google user data.
Emaissary's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
7. Cookies & Analytics
We use Google Analytics (GA4) to understand aggregate traffic and usage patterns on our marketing site, implemented with Google Consent Mode v2. Analytics storage defaults to denied until you actively accept our cookie banner; if you decline, no analytics cookies are set and no analytics request is made. Full details on the cookies we use and how consent is stored are on our Cookies page.
8. Your Rights
Depending on your jurisdiction, you may have rights to access, correct, or request erasure of your account data. Until self-service export and deletion tools ship, you can exercise these rights by emailing hello@emaissary.com from the address associated with your account, and we will respond promptly.
9. Prospect Rights
Because prospect data is controlled by the Emaissary user who added it, a prospect who wishes to exercise a privacy right (such as requesting access or erasure) may email us at hello@emaissary.com. We will relay the request to the controlling user, and we will purge the relevant data on that user's instruction, or where we are otherwise legally required to do so.
10. Security
We use industry-standard security measures to protect both account data and prospect data, including encryption in transit and at rest, hashed credentials, and access controls, all hosted on Microsoft Azure infrastructure. No system is completely secure, so we cannot guarantee absolute security, but we work to protect your data from unauthorized access and disclosure.
11. Children
The Service is not directed to, and is not intended for use by, anyone under 16 years of age. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will remove it.
12. Changes
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email or through the Service. The "Last updated" date at the top reflects the most recent revision.
13. Contact
Questions about this Privacy Policy or how we handle your data? Reach us at hello@emaissary.com or visit our Contact page.