← Back to home

Privacy Policy

Last updated: October 2026

1. What we collect

Account data: your name, email address, and password hash. Profile data: the freelancer profile you fill in. Outreach data: leads you save, campaigns, templates, and messages you send. Mailbox data: the SMTP host, port, and username of mailboxes you connect — the password itself is encrypted at rest and never returned by our API. Usage data: basic product analytics and error logs.

2. How we use it

To run the service: store your leads, send the emails you compose, schedule follow-ups, and show your pipeline. To keep the service safe: rate limiting, abuse detection, and audit logs. To support you: responding to support requests and, if you opt in, product updates. We do not sell your data or your prospects' data, and we do not use your outreach content to train models.

3. Mailboxes you connect

When you connect an email account, we use those credentials only to send email on your behalf and to report delivery events. SMTP passwords are encrypted with AES-256-GCM using a key derived from server secrets; you can disconnect a mailbox at any time, which deletes its stored credentials.

4. Subprocessors and transfers

We use vetted subprocessors to deliver the service: a hosting and tunnel provider for the application, Stripe for payments, an email provider for password-reset mail, and an error-monitoring service. Each is bound by contract to process data only on our instructions. Where data crosses borders, we rely on standard contractual clauses or equivalent safeguards.

5. Retention

We keep account data while your account is active and for a short backup window after deletion. Suppression-list entries are kept indefinitely even after you delete your account, because an opt-out must outlive the account that requested it. Audit logs are retained for 12 months.

6. Your rights

Depending on where you live, you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. You can export and delete your data from Settings, or contact us to exercise these rights. We respond within 30 days and never charge for a first request.

7. Cookies

ClientFinder uses a single session cookie to keep you signed in. There are no third-party advertising or cross-site tracking cookies on the app.

8. Security and contact

Data is transmitted over TLS, passwords are hashed with Argon2, mailbox credentials are encrypted at rest, and access to production data is limited and audited. No system is perfectly secure, but we design for defense in depth. Privacy questions can be sent through the contact details on the landing page.