This Privacy Policy explains what information ScrapedIn ("ScrapedIn", "we", "us", "our") collects when you use our application at app.scrapedin.com and this website, how we use and protect that information, how long we keep it, and how you can delete it or withdraw your consent.

ScrapedIn is a cold-email outreach CRM. It imports or collects sales leads, drafts personalized emails using AI, sends those emails through your own Gmail account, tracks engagement, and runs follow-up sequences. Because the product operates on your mailbox and your spreadsheets, we've written this policy to be specific rather than generic.

The short version

We only touch the Google data needed to run the features you asked for: sending your emails, saving your drafts, noticing replies to threads you sent, and reading the lead sheet you select. We never sell your data, never use it for advertising, and never use it to train generalized AI or machine learning models. You can revoke our access and have your data deleted at any time.

1. Who we are

ScrapedIn is operated from India. For the purposes of the EU/UK General Data Protection Regulation, we act as the data controller for the account information you give us directly, and as a data processor acting on your instructions for the mailbox content, spreadsheet content and lead records you connect to the service.

For any privacy question, request or complaint, contact deepj.work@gmail.com.

2. Information we collect

2.1 Account information

When you sign in with Google, we receive and store your name, email address, Google account identifier and profile picture. We use this to create your account, keep you signed in, and show you which mailbox is currently connected.

2.2 Google authorization credentials

When you grant permission, Google issues us an access token and a refresh token for your account. These are stored encrypted and are used solely to perform the actions described in section 3 on your behalf. We never receive, see or store your Google password.

2.3 Content you connect to the service

  • Lead records — the names, job titles, companies, email addresses, public profile URLs and other business-contact fields you import, scrape or enter.
  • Spreadsheet data — the rows and columns of the specific Google Sheet you select for a campaign.
  • Campaign content — your offer descriptions, prompts, templates, tone settings, generated drafts and sent messages.
  • Reply metadata — for threads ScrapedIn sent, whether a reply exists, when it arrived and enough of the message to attribute it to the right lead and campaign.

2.4 Engagement and usage data

We record when a message was sent, whether it was opened, whether tracked links were clicked, and whether a reply was detected. We also keep basic technical logs — IP address, browser type, timestamps and error traces — to operate the service, debug problems and prevent abuse.

2.5 What we do not collect

We do not collect payment card numbers (any payment processing is handled by a third-party processor and card details never reach our servers), and we do not use advertising cookies or third-party tracking pixels on this website.

3. Google user data and the scopes we request

ScrapedIn requests the following Google OAuth scopes. This list is complete and matches what you see on the Google consent screen when you connect your account.

Scope What it allows Why ScrapedIn needs it
gmail.send Send email on your behalf To deliver your outreach emails and follow-ups from your own mailbox. This scope cannot read your mail.
gmail.compose Create and manage drafts To save AI-generated emails as drafts in your Gmail account so you can review, edit or send them from your inbox.
gmail.readonlyRestricted Read messages and settings Solely to detect replies to threads ScrapedIn sent, so a lead who responds is marked as replied and automatically removed from the follow-up sequence. We query for the specific threads we sent; we do not index, mine or export your mailbox.
spreadsheets See, edit and create Google Sheets To read lead rows from the specific sheet you choose, and to write send status and reply status back into that same sheet.
drive.metadata.readonly See file names and metadata in Drive To list your spreadsheets by name in the file picker so you can choose one. Metadata only — this scope does not give us the contents of any Drive file.
userinfo.email
userinfo.profile
Basic account identity To create your account, sign you in, and display which Google account is connected.

Gmail data is used only to provide the features described above, to you. We do not use it for any secondary purpose. Specifically, we do not sell Gmail data, we do not use it for advertising or profiling, we do not transfer it to data brokers or information resellers, and we do not use it to develop, improve or train generalized AI or machine learning models.

Human access to Gmail data is prohibited except in the narrow cases Google permits: with your explicit prior consent for a specific issue (for example, when you ask us to investigate a support problem), where necessary for security purposes such as investigating abuse, to comply with applicable law, or where the data has been aggregated and de-identified for internal operations.

4. Limited Use disclosure

Google API Services User Data Policy

ScrapedIn's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In practice this means: we use Google user data only to provide or improve the user-facing features that are prominent in ScrapedIn's interface; we do not transfer it except as necessary to provide those features, to comply with applicable law, or as part of a merger or acquisition following your notification; we do not use it for serving advertisements; we do not allow humans to read it except in the limited circumstances listed above; and we do not use it to develop, improve or train generalized or non-personalized AI and/or ML models.

5. How we use information

We use the information described above only to:

  • create and secure your account and authenticate you;
  • import, de-duplicate and organise your leads;
  • generate personalized email drafts for the leads in your campaigns;
  • send those emails and follow-ups from your connected mailbox;
  • detect replies so sequences stop and your pipeline stays accurate;
  • show you engagement statistics for your own campaigns;
  • write status back to the spreadsheet you selected;
  • provide customer support you request;
  • maintain security, prevent abuse, and meet legal obligations.

Where GDPR applies, our legal bases are: performance of a contract (running the service you signed up for), consent (the permissions you grant on the Google consent screen, which you may withdraw at any time), legitimate interests (securing the service and preventing abuse), and legal obligation where applicable.

6. AI processing

To draft personalized emails, ScrapedIn sends the relevant lead information and your campaign instructions to a third-party large language model provider acting as our subprocessor. That processing happens only to produce your draft and return it to you.

We use these providers under terms that prohibit them from using submitted content to train their models. We do not use your Gmail content, your lead data or your campaign content to train any AI or machine learning model, our own or anyone else's.

7. Sharing and disclosure

We do not sell your personal information, and we never have.

We share data only with service providers who help us run ScrapedIn, and only to the extent needed:

  • Cloud hosting and database providers — to store your account and campaign data.
  • Google APIs — to send mail and read the sheets and threads you authorised.
  • An AI model provider — to generate drafts, as described in section 6.
  • A payment processor — if and when you pay for a plan.

These providers are bound by contract to process data only on our instructions and to keep it confidential. Beyond them, we disclose information only where we are legally required to (for example a valid court order), where it is necessary to protect our rights or the safety of others, or in connection with a merger or acquisition — in which case we will notify you before your information is transferred and becomes subject to a different policy.

8. Data retention

Data How long we keep it
Account details For as long as your account is open; deleted within 30 days of account closure.
Google OAuth tokens Until you disconnect the account or revoke access, at which point they are deleted immediately.
Lead records and campaign content Until you delete them, or within 30 days of account closure.
Reply detection data We store only what identifies the reply and links it to a campaign; it is deleted with the campaign.
Engagement statistics Retained with the campaign; deleted with it.
Technical and security logs Up to 90 days, then deleted or de-identified.

We may retain a limited record for longer only where necessary to comply with a legal obligation, resolve a dispute or enforce our agreements. Backups are cycled out on a rolling basis and deleted data disappears from them within 90 days.

9. Deleting your data and revoking access

9.1 Revoke ScrapedIn's access to your Google account

Go to myaccount.google.com/permissions, select ScrapedIn, and choose Remove access. Our tokens stop working immediately and we lose all ability to read or send anything in your account. You can also disconnect the account from within ScrapedIn's settings, which deletes our stored tokens.

9.2 Delete your ScrapedIn data

You can delete individual leads and campaigns from within the app at any time. To delete your entire account and all associated data, email deepj.work@gmail.com from the address you signed up with, with the subject "Delete my account". We will confirm and complete the deletion within 30 days, and it removes your account record, tokens, leads, campaigns, generated content and engagement history.

Note that emails already sent from your mailbox live in your own Gmail account and in your recipients' inboxes. Deleting your ScrapedIn data does not and cannot retract them.

10. Security

All traffic to ScrapedIn is encrypted in transit with TLS, and data is encrypted at rest. OAuth tokens are held encrypted and separately from general application data. Access to production systems is restricted to the operator of the service and protected by multi-factor authentication. We request the minimum scopes needed and store the minimum data needed.

No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify you and any applicable regulator without undue delay and, where required, in any case within 72 hours of becoming aware.

11. Data about the people you contact

ScrapedIn processes business-contact information about your leads on your behalf. You are the controller of that data and you are responsible for having a lawful basis to hold and email it, for honouring opt-out and unsubscribe requests promptly, and for complying with the anti-spam and data protection laws that apply to you and your recipients — including GDPR, the UK GDPR, CAN-SPAM, CASL and India's Digital Personal Data Protection Act as applicable.

If someone you contacted through ScrapedIn wants their data removed, they may write to deepj.work@gmail.com and we will route the request to the relevant account holder and assist in fulfilling it.

12. Your privacy rights

Depending on where you live, you may have the right to:

  • access the personal data we hold about you and receive a copy;
  • correct inaccurate or incomplete data;
  • delete your data ("right to erasure");
  • restrict or object to certain processing;
  • receive your data in a portable, machine-readable format;
  • withdraw consent at any time, without affecting processing already carried out;
  • not have your personal information sold or shared — which we do not do in any case;
  • lodge a complaint with your local data protection authority.

Exercise any of these by emailing deepj.work@gmail.com. We respond within 30 days and will not discriminate against you for making a request.

13. International data transfers

ScrapedIn is operated from India and uses cloud infrastructure and service providers that may store or process data in other countries, including the United States and the European Union. Where we transfer personal data out of the EEA or UK, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.

14. Children

ScrapedIn is a business tool and is not directed at anyone under 18. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.

15. Changes to this policy

We may update this policy as the product changes. When we do, we'll revise the "Last updated" date at the top. If a change materially affects how we handle your data — for example if we request an additional Google scope — we will notify you by email or through the app before it takes effect, and where required we will ask for your consent again.

16. Contact us

ScrapedIn

Privacy, data requests and support: deepj.work@gmail.com

Website: https://scrapedin.com


ScrapedIn is an independent product and is not affiliated with, endorsed by, or connected to Google LLC or LinkedIn Corporation. Gmail, Google Sheets and Google Drive are trademarks of Google LLC.