FFanoutBack

Legal

Privacy Policy

Last updated: [Date]

This policy explains what Fanout collects, who processes it, and what you can do about it.

What we collect

Account data: the email address you use to sign up or sign in, and basic profile fields associated with your account.

Gmail OAuth tokens: when you connect a Gmail account, Fanout stores the OAuth access and refresh tokens for the send and read scopes it needs, along with their expiry and the scopes you granted.

Content you enter: the recipient lists you paste or import, the base message you write, the AI-generated messages in your account, and the campaign metadata that organizes them.

Campaign and reply data: recipient statuses, sent timestamps, and the replies Fanout detects so it can show them in your inbox.

Third parties your data passes through

Google (Gmail API and OAuth): sending your approved messages, reading thread and message identifiers, and detecting replies. Google receives the content of messages sent through your account because they are sent from your account.

Groq (AI message generation): when you generate messages, the base message and the personalization context for each recipient are sent to Groq's API to produce drafts. Groq processes this message content to return generated text.

Apollo (lead search, optional): if you use the lead search feature, your search criteria and the contact data Apollo returns (names, positions, companies, email addresses) pass through Apollo's API and are stored in your account when you save them.

Supabase (database and authentication hosting): Fanout's database, authentication, and data storage run on Supabase infrastructure.

We do not sell your data. We do not share your data with advertisers, and we do not run advertising on Fanout.

Gmail data, specifically

Gmail data obtained through the Gmail API is used only to provide Fanout's sending and reply-tracking features. It is not used for advertising, not sold, not shared with data brokers, and not used to train AI models. Fanout's use and transfer of information received from Google APIs adheres to Google's API Services User Data Policy, including its Limited Use requirements.

How long we keep data

Campaigns, recipients, messages, and replies are kept for as long as your account is active so the app can function. OAuth tokens for a connected Gmail account are kept while the connection is active, and are refreshed as needed to keep sending and reply tracking working.

If you disconnect a Gmail account, its stored tokens are removed. If you delete your account, your campaigns, recipients, messages, replies, connections, and settings are deleted. You can also delete individual campaigns yourself at any time from the dashboard.

Note that email you have already sent exists in your recipients' inboxes and in your own Gmail account; deleting data from Fanout does not remove already-delivered email.

Your rights

You can request access to, correction of, or deletion of the personal data we hold about you. Because your content lives in your account, you can export or delete most of it directly in the app. For anything else, contact us at [privacy@yourdomain.com] and we will respond within a reasonable time.

Depending on where you live, you may have additional rights under laws such as the GDPR, including the right to object to or restrict processing and the right to data portability.

Cookies and tracking

Fanout uses only the essential browser storage needed to keep you signed in. We do not use third-party analytics cookies, advertising cookies, or cross-site trackers.

Contact

Questions or requests about this policy can be sent to [privacy@yourdomain.com].

See also our Terms of Service.