Privacy Policy
Last updated: April 1, 2026
1. Introduction
OutreachPilot ("we," "our," or "us") operates the OutreachPilot platform, an AI-powered outreach and sales automation service. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform, including our website, dashboard, and all related services.
By accessing or using OutreachPilot, you agree to this Privacy Policy. If you do not agree, please discontinue use of the platform.
2. Information We Collect
Account Information
When you sign in via Google OAuth, we receive your name, email address, and profile picture from your Google account. We do not collect or store your Google password.
Outreach & Campaign Data
You may upload or provide the following data to power your outreach campaigns:
- Contact lists (names, email addresses, phone numbers, LinkedIn profile URLs, job titles, company information)
- Campaign content including email templates, SMS messages, LinkedIn messages, and call scripts
- Ideal Customer Profile (ICP) criteria and targeting preferences
- Knowledge base documents and company information you upload for AI personalization
Usage Data
We automatically collect information about how you interact with the platform, including:
- Pages visited, features used, and actions taken within the dashboard
- Campaign performance metrics (open rates, reply rates, click rates)
- Credit usage and activity logs
- Browser type, device information, and IP address
Communication Data
When you use our outreach features, we process email content, SMS messages, LinkedIn messages, and phone call metadata to deliver and track your campaigns.
3. How We Use Your Information
We use your information to:
- Provide, operate, and improve the OutreachPilot platform
- Execute outreach campaigns across email, LinkedIn, SMS, and phone channels
- Power AI features including message personalization, lead scoring, sentiment analysis, and the AI Pilot auto-responder
- Generate research reports and competitive analysis through our Research Suite
- Track campaign analytics and provide performance insights
- Process credit usage and manage your account billing
- Communicate with you about your account, updates, and support requests
- Detect, prevent, and address technical issues or abuse
4. Third-Party Services
OutreachPilot integrates with the following third-party services to deliver our platform:
- Google OAuth — for secure authentication
- Supabase — for data storage and real-time services
- OpenAI — for AI-powered features including message generation, lead research, and sentiment analysis
- Email delivery providers — for sending and tracking outreach emails
- SMS & telephony providers — for SMS messaging and power dialer functionality
- LinkedIn — for LinkedIn automation features (connection requests, messages, engagement)
- Slack — for optional notification integrations
- Stripe — for payment processing
Each third-party service has its own privacy policy governing their use of your data. We encourage you to review their policies.
4a. Google API Services User Data Policy
OutreachPilot's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We only use Google user data to provide and improve features the user explicitly authorized within OutreachPilot.
- We do not use Google user data to develop, improve, or train generalized AI or ML models.
- We do not allow humans to read your Google user data unless you explicitly grant us permission or we are required by law.
- We do not sell Google user data to third parties.
5. Data Sharing & Disclosure
We do not sell your personal information. We may share data in the following circumstances:
- Service providers: With trusted third parties who help us operate the platform (as described above)
- Legal requirements: When required by law, subpoena, or legal process
- Safety: To protect our rights, privacy, safety, or property, or that of our users or the public
- Business transfers: In connection with a merger, acquisition, or sale of assets
6. Data Retention
We retain your account data for as long as your account is active or as needed to provide services. Campaign data, contact lists, and analytics are retained for the duration of your account. If you delete your account, we will delete or anonymize your personal data within 30 days, except where we are legally required to retain it.
7. Data Security
We implement industry-standard security measures to protect your data, including encryption in transit (TLS/SSL), row-level security policies in our database, and secure authentication via OAuth. However, no method of electronic transmission or storage is 100% secure, and we cannot guarantee absolute security.
8. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data
- Export your data in a portable format
- Opt out of certain data processing activities
- Withdraw consent where processing is based on consent
To exercise any of these rights, contact us at support@useoutreachpilot.com, or if you are not an OutreachPilot customer but your information appears in a customer's outreach records, submit a data erasure request directly.
9. Cookies & Tracking
OutreachPilot uses essential cookies for authentication and session management. We may also use analytics tools to understand how the platform is used. We do not use third-party advertising cookies.
10. Chrome Extension
OutreachPilot offers an optional Chrome browser extension ("OutreachPilot Connect") that enables one-click connection of your LinkedIn, Reddit, and Twitter/X accounts to the platform.
What the Extension Accesses
- Authentication cookies: The extension reads session cookies from LinkedIn (li_at), Reddit (reddit_session), and Twitter/X (auth_token) only when you explicitly click "Connect" for each platform.
- Link token: The extension reads a temporary authentication token from the OutreachPilot settings page to securely associate your browser with your account.
How Cookie Data Is Used
Session cookies are transmitted securely to OutreachPilot servers solely to enable automated outreach actions you configure (sending LinkedIn connection requests, Reddit engagement, Twitter interactions). Cookie values are stored encrypted and are never shared with third parties, used for advertising, or accessed for any purpose other than executing your configured outreach campaigns.
Data Storage & Control
- You can disconnect any platform at any time from the extension popup or the OutreachPilot settings page.
- Disconnecting removes the stored session cookie from our servers.
- Uninstalling the extension removes all locally stored data (link tokens, connection status).
Permissions
This list is generated from the extension's own manifest (version 2.6.5) so it cannot drift from what is actually shipped. The extension requests the following Chrome permissions:
- cookies — Reads your session cookies for LinkedIn, X (Twitter), and Reddit (e.g. li_at, ct0/auth_token, reddit_session) to detect that you're logged in and to authenticate the actions you take through OutreachPilot.
- storage — Stores your connection status, link token, and extension settings locally in your browser.
- tabs — Reads basic information about your LinkedIn, X, and Reddit tabs (URL, load state) and opens platform pages such as login and setup when needed.
- alarms — Schedules periodic background checks — for example, refreshing proxy health and connection status, and polling for queued actions — while your browser is open.
- scripting — Injects OutreachPilot's widget and request interceptor into LinkedIn, X and Reddit pages you visit.
- webRequest — Observes network requests on those sites to capture actions you take — for example, confirming that a connection request or reply was actually sent.
- webNavigation — Detects page navigation on LinkedIn, X, and Reddit (including in-page/SPA navigation) so the widget and OutreachPilot stay in sync with the page you are viewing.
- proxy — Routes some LinkedIn/X/Reddit requests through OutreachPilot's proxy — a residential IP assigned by our servers to your account — using a PAC script. Everything else you browse goes direct and is unaffected.
- declarativeNetRequest — Applies request rules to LinkedIn/X/Reddit traffic — for example, a consistent per-account browser identifier (User-Agent) — as directed by OutreachPilot's servers.
The extension also declares the following optional permissions, which are not requested at install and are only asked for — with a separate Chrome prompt naming the permission — if you turn on a specific feature that needs them:
- privacy — Optional, off by default. If you grant it, blocks WebRTC from leaking your real IP address while OutreachPilot's proxy is active.
- browsingData — Optional, off by default. If you grant it, clears cached site data (local storage, IndexedDB, cache) for a platform when switching between accounts on a proxied connection, so data does not bleed between accounts.
- webRequestAuthProvider — Optional, off by default. If you grant it, lets the extension silently supply your assigned proxy credentials when the browser asks for authentication, so you do not see a login prompt.
Websites the Extension Can Access
The extension's host permissions are scoped to the following sites only — it cannot read or act on any other website:
https://*.linkedin.com/*https://*.reddit.com/*https://*.twitter.com/*https://*.x.com/*https://useoutreachpilot.com/*https://*.useoutreachpilot.com/*http://localhost/*http://127.0.0.1/*
Scripts Injected Into Pages
The extension injects the following content scripts. Each runs only on the listed sites (and never on the excluded login/logout/authentication pages listed alongside it), to render the in-page OutreachPilot widget, sync with your OutreachPilot dashboard tab, and — for the request interceptor below, which runs at page-load start in the page's own JavaScript context — observe the page's own network and navigation calls so the widget and your OutreachPilot account stay accurate:
- content-dashboard.js on
https://useoutreachpilot.com/*, https://*.useoutreachpilot.com/*, http://localhost/*, http://127.0.0.1/* - content-widget.js on
https://*.linkedin.com/*, https://*.twitter.com/*, https://*.x.com/*, https://*.reddit.com/*, https://old.reddit.com/*, https://chat.reddit.com/*(excluding login/logout/authentication URLs on those sites) - route-interceptor.js on
https://*.linkedin.com/*, https://*.twitter.com/*, https://*.x.com/*, https://*.reddit.com/*, https://old.reddit.com/*(excluding login/logout/authentication URLs on those sites) — runs in the page's own JavaScript context (document_start)
11. Children's Privacy
OutreachPilot is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us and we will promptly delete it.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the "Last updated" date. Your continued use of the platform after changes constitutes acceptance of the updated policy.
13. Contact Us
If you have questions about this Privacy Policy or our data practices, please contact us at:
Email: support@useoutreachpilot.com