Privacy Policy
This Privacy Policy explains what information SpamCipher ("SpamCipher", "we", "us", or "our") collects, how we use, store, share, protect, and delete it, and the choices and rights you have. It applies to spamcipher.com, the SpamCipher web application at app.spamcipher.com, our APIs, our browser extension, and the related services (together, the "Service"), including any Google or Microsoft mailbox you choose to connect.
1.Who We Are and Our Role
SpamCipher is a cold email platform for high-volume sending. We help senders send cold email at scale, warm mailboxes, verify email addresses, find and confirm business contacts, check domain health and email authentication, monitor blacklists and sender reputation, and analyze message content, so their email reaches the inbox.
The application this Policy covers
This Privacy Policy is published by SpamCipher Inc. ("SpamCipher"), the developer and operator of the Service. It is the privacy policy for the application presented to you on the Google OAuth consent screen as SpamCipher, and for the application presented on the Microsoft consent screen under the same name. It is hosted on spamcipher.com, a domain we own and control, and it is linked from the footer of every page on spamcipher.com and from inside the application.
You can reach us about anything in this Policy at privacy@spamcipher.com.
Controller and processor
We act in two different roles depending on the data involved:
- For information about your account and your use of the Service (such as your name, login details, billing data, and usage logs), we are the data controller. This Policy describes how we handle that information.
- For the email lists and contact data you submit to be verified or processed ("Customer Data"), and for the contents of any mailbox you connect, you are the controller and we are a data processor acting on your instructions. We process that data only to provide the Service to you. If you are a business customer subject to the GDPR or similar laws, our GDPR page and Data Processing Agreement govern that relationship.
By using the Service, you agree to this Policy. If you do not agree, please do not use the Service.
2.Information We Collect
Account and profile information
When you create an account we collect your name, email address, a password (which we store only in hashed form), and optionally your company name, role, and phone number. We may also collect information you provide when you contact support or respond to surveys.
Billing information
Payments are processed by our payment provider, Stripe. We do not store full payment card numbers on our systems. We retain billing details such as your billing contact, subscription plan, transaction history, and limited card metadata (for example, card brand and last four digits) returned to us by Stripe to manage your subscription and invoices.
Customer Data you submit for processing
To use the Service you submit data to be processed, such as email addresses and any associated fields in the lists you upload or send through our API or integrations, the names and domains you query with Email Finder, the campaigns and message templates you write, and the domains and sending IPs you add for monitoring. We process this Customer Data only to return results to you and to run the features you turn on (for example, validity status, deliverability signals, monitoring alerts, or a campaign send).
Authentication and monitoring data
If you use domain health, DMARC, blacklist, or reputation monitoring, we collect the domains and IP addresses you ask us to watch and the related public DNS and authentication records. If you route your DMARC aggregate (RUA) reports to us, we receive and parse those reports, which describe sources sending email on behalf of your domain.
Information from connected mailboxes and accounts (OAuth)
When you connect a third-party mailbox or account, such as a Google (Gmail or Google Workspace) or Microsoft (Outlook.com or Microsoft 365) account, you authorize us through OAuth to access specific data needed for the feature you enable. We receive and store an OAuth access token and, where applicable, a refresh token so the integration can run; these tokens are encrypted at rest. We request the minimum access each feature needs, you choose which features to enable, and you can disconnect at any time.
Depending on the feature you turn on, the access we request is used as follows:
- Inbox Warm-up (send, plus filing). To grow a connected mailbox’s sending reputation, we send a controlled volume of warm-up messages from your mailbox, on your behalf, to the seed inboxes we operate. With Google this uses
https://www.googleapis.com/auth/gmail.sendto send, plushttps://www.googleapis.com/auth/gmail.modifyif you ask us to file warm-up mail into a folder: filing has to find those messages in your mailbox and move them into the folder you named. We match them by a unique marker SpamCipher stamps on the messages it sent, so only our own warm-up mail is ever moved. With Microsoft, warm-up sending uses GraphMail.Send. - Outbound campaigns and the unified inbox (send, plus read). The outreach product sends the campaigns you create from the mailbox you connected, and gives you a unified inbox that surfaces the replies, bounces, and out-of-office responses that arrive in it. With Google this uses
https://www.googleapis.com/auth/gmail.sendto send andhttps://www.googleapis.com/auth/gmail.modifyto read inbound mail and to apply labels; with Microsoft, GraphMail.SendandMail.Read. What we store from your mailbox, and the setting that controls it, is described in the Google User Data section below. SpamCipher never deletes mail from your mailbox, and the only messages it ever moves are the warm-up messages it sent itself. - Reputation monitoring (read-only statistics). To report your domain and IP reputation, spam rate, and authentication results, we request Google’s read-only Postmaster Tools scope
https://www.googleapis.com/auth/postmaster.readonly. This returns aggregate reputation metrics for domains you own; it does not expose the contents of any email. - Basic profile. To identify the connected account we request
openidandemail(and, with Microsoft,offline_accessso the connection can refresh without re-prompting you). This gives us the email address of the connected mailbox, not your contacts and not your message content.
Our handling of Google data is described in full in the Google User Data section below, and our handling of Microsoft data immediately follows it.
Usage, device, and log data
Like most online services, we automatically collect technical information when you use the Service: your IP address, browser and device type, operating system, referring pages, the pages and features you use, and timestamps. We use this for security, fraud prevention, troubleshooting, and to understand and improve the Service.
Cookies and similar technologies
We use a small number of cookies and similar technologies, described in the Cookies section. We do not use advertising or cross-site tracking cookies.
3.How We Use Information
We use the information we collect to:
- Provide, operate, and maintain the Service, including verifying addresses, sending the campaigns you create, running monitoring, and returning results;
- Operate Inbox Warm-up, sending the controlled warm-up messages our system generates from a mailbox you connect, to grow its sending reputation (inbox placement is measured on our own receiving seed inboxes, not in your mailbox);
- Show you the replies, bounces, and out-of-office responses that arrive in a mailbox you connected, in the unified inbox;
- Create and secure your account and authenticate you;
- Process payments, manage subscriptions, and send invoices and receipts;
- Respond to your requests and provide customer support;
- Detect, prevent, and investigate fraud, abuse, and security incidents;
- Maintain and improve the Service, including diagnosing problems and developing new features;
- Send you service and administrative messages (such as security alerts, billing notices, and changes to our terms), which you cannot opt out of while you have an account;
- Send you optional product news and marketing, using only your account contact details and never Google user data, other connected-mailbox data, or Customer Data, which you can opt out of at any time; and
- Comply with our legal obligations, enforce our terms, and protect our rights and the rights and safety of others.
We do not sell your personal information. Customer Data and data obtained from connected accounts, including Google user data and Microsoft account data, are used only to provide and improve the user-facing features you enable. We do not use them for marketing or product news, for advertising of any kind (including targeted, personalized, retargeted, or interest-based advertising), for analytics or research unrelated to those features, to build or enrich any separate database or contact corpus, to determine credit-worthiness or for lending purposes, to develop, improve, train, or fine-tune any artificial-intelligence or machine-learning model, or for any other purpose.
4.Google User Data (Limited Use)
Three features let you connect a Google account. Inbox Warm-up sends warm-up messages on your behalf and, if you ask it to, files those same messages into a folder. Outbound sends the campaigns you create and provides a unified inbox for the replies that arrive in that mailbox. Reputation monitoring can optionally read your Gmail Postmaster Tools statistics. When you connect through OAuth, Google asks you to grant specific permissions (scopes). We request only the minimum scope each feature needs, and we use the access only to provide that feature.
The Google scopes we request, and what each one is for
https://www.googleapis.com/auth/gmail.send(shown to you as "Send email on your behalf") is used to send warm-up messages and the outreach campaigns you create, from your connected mailbox, on your behalf. This is a send-only scope: on its own it grants no read, search, label, or delete access. Whether a warm-up message reached the inbox or spam is determined on the receiving seed inboxes we operate, not in your mailbox.https://www.googleapis.com/auth/gmail.modifyis used for two things. First, Outbound reads the mail that arrives in the connected mailbox so the unified inbox can show you replies, bounces, and out-of-office responses to your campaigns. Second, Inbox Warm-up moves the warm-up messages SpamCipher itself sent out of the primary inbox into a folder you name, and applies the label for it, so they stay out of your way. We ask for this one scope rather than a read-only scope plus a second write scope because it is the narrowest single scope that covers both. It does not permit permanent deletion, and SpamCipher never deletes mail, and never moves mail to Trash. The only messages it moves or labels are the warm-up messages it sent itself, matched by a unique marker it stamped on them. We deliberately do not requesthttps://mail.google.com/, the full-access scope that would allow IMAP access and permanent deletion.https://www.googleapis.com/auth/postmaster.readonlyis used by reputation monitoring to read aggregate Gmail Postmaster Tools metrics (domain and IP reputation, spam rate, and authentication results) for domains you own. It returns statistics only and never the contents of any email.openidandemailare used to identify the connected mailbox by its email address, so we can show you which mailbox is connected and attach results to the right account.
What we store from your Gmail mailbox
The mailboxes customers connect to Outbound are, in practice, dedicated outreach mailboxes, and a reply that is not captured is lost business. So by default SpamCipher stores the messages that arrive in a connected mailbox, so that no reply, bounce, or out-of-office notice is missed. You control this:
- The setting "Capture all replies to this mailbox", in CRM under Preferences, then AI Automations, is on by default. With it on, we store the inbound messages that arrive in the mailbox you connected, including replies from addresses you have not emailed.
- Turn it off and we store only mail we can tie to your own outbound activity: a reply in a thread we sent, a reply from an address you emailed, an attributable bounce, or a reply to a test send.
- For each message we store, we keep the sender address, the subject, the message body and a short snippet of it, the provider message id, and the timestamps. We do not store attachments.
- We only ever read the mailboxes you connect, and only for this purpose. We do not read, index, export, or profile your mail for anything else.
- Deleting a message in the unified inbox (Outreach, then Unibox) removes it from SpamCipher only; it is never deleted from your mailbox.
Who we share Google user data with
We do not sell Google user data and we do not share it with any third party for that third party’s own purposes. Google user data is stored on servers we operate in the United States, hosted on Google Cloud Platform, which acts as our infrastructure provider under contract and processes it only on our instructions. Our network security and content-delivery provider, Cloudflare, may handle requests in transit but does not store Google user data. Those are the only two providers that Google user data reaches.
We transfer Google user data only where it is necessary to provide or improve the user-facing features you enabled, to comply with applicable law or valid legal process, or as part of a merger, acquisition, or sale of assets in which the recipient remains bound by commitments at least as protective as this Policy. We transfer it for no other reason.
AI-assisted features and Google user data
Some optional features use artificial intelligence, for example drafting a suggested reply or classifying a reply’s intent in the unified inbox. These run on SpamCipher’s own model inside our own infrastructure. We do not send Google user data, or any other connected-mailbox data, to any external artificial-intelligence or large-language-model provider. We do not use Google user data to develop, improve, train, or fine-tune any artificial-intelligence or machine-learning model, whether generalized, non-personalized, or specific to you. You can turn these features off at any time in CRM, under Preferences, then AI Automations, and turning them off stops any AI processing of your mail.
How we protect Google user data
We protect Google user data with encryption in transit (TLS) and encryption at rest. OAuth access tokens, refresh tokens, and any stored mailbox credentials are encrypted with authenticated encryption (AES-256-GCM) using keys held outside the database. Access is limited, on a need-to-know basis, to the systems that run the feature and to the small number of personnel who administer them, and we review our systems and dependencies regularly.
How long we keep Google user data, and how to have it deleted
- OAuth tokens are kept only while the mailbox is connected. Disconnecting the mailbox in SpamCipher, or revoking access at Google, deletes them.
- The messages we stored from the mailbox are kept while it is connected and are deleted when you disconnect it, or within 30 days if you delete your account instead. You can also delete individual messages, and whole mailboxes, from inside the application at any time.
- Postmaster Tools statistics are aggregate metrics with no message content, retained while monitoring is enabled and deleted when you disconnect it.
- Residual copies may persist in encrypted backups for a limited period before they are overwritten on the normal backup cycle.
You can review or revoke SpamCipher’s access at any time from your Google Account at myaccount.google.com/permissions, or by removing the mailbox inside SpamCipher (Outreach, then Email Accounts, then Remove). To have your Google user data deleted without waiting, or to ask us to confirm deletion, email privacy@spamcipher.com and we will action it and confirm within 30 days. See Deleting Your Data for the full procedure.
Limited Use
SpamCipher’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In practice that means we will use Google user data only to provide and improve the user-facing features described above and prominently disclosed at consent, and that we will not:
- transfer or sell Google user data to third parties such as advertising platforms, data brokers, information resellers, or contact-data providers;
- use or transfer Google user data for serving advertisements, including targeted, personalized, retargeted, or interest-based advertising;
- use or transfer Google user data to determine credit-worthiness or for any lending purpose;
- use Google user data to develop, improve, or train generalized or non-personalized artificial-intelligence or machine-learning models, or to train any model of any kind;
- add Google user data to, or use it to enrich, any contact database, lead corpus, or dataset we make available to anyone else; or
- allow humans to read your Google user data, unless we first obtain your consent to read specific messages or data, it is necessary for security purposes such as investigating abuse, it is required to comply with applicable law, or the data has been aggregated and anonymized.
If we ever want to use Google user data for a purpose not described here, we will ask for your consent first.
5.Microsoft Account Data
Inbox Warm-up and Outbound also let you connect a Microsoft account (Outlook.com or Microsoft 365). Warm-up needs send access; Outbound sends your campaigns and reads the mail that arrives in the connected mailbox for the unified inbox. Both go through Microsoft Graph, and it does not modify or delete your mail. When you connect through OAuth, Microsoft asks you to grant specific permissions, and we request only the minimum each feature needs.
Mail.Send(Microsoft Graph) to send warm-up messages and the outreach campaigns you create, from your connected mailbox, on your behalf.Mail.Read(Microsoft Graph) to read the mail that arrives in the connected mailbox for the unified inbox. This is a read-only permission: no modify and no delete.offline_accessto obtain a refresh token so the connection keeps working without re-prompting you.openidandemailto identify the connected mailbox by its email address.
We handle Microsoft account data on the same terms as Google user data throughout: the same storage and capture setting, the same in-house-only AI position, no sale, no sharing with advertising platforms or data brokers, no advertising use, no credit-worthiness or lending use, no model training, and no human reading except with your consent, for security, to comply with law, or in aggregated and anonymized form. OAuth tokens and any stored credentials are encrypted at rest (AES-256-GCM) and in transit (TLS). You can revoke SpamCipher’s access at any time from your Microsoft account at account.microsoft.com, or by disconnecting the mailbox inside SpamCipher; the same deletion applies.
7.How Long We Keep Information
We keep information only for as long as we need it for the purposes described in this Policy, unless a longer period is required or permitted by law.
- Customer Data (uploaded lists and results): we store it encrypted and retain it only as long as needed to provide your results. You can delete uploaded files and results at any time from your account, and we delete uploaded lists within 30 days unless you ask us to keep them longer.
- Connected-mailbox data (Google user data and Microsoft account data): kept while the mailbox is connected and deleted when you disconnect it, as described in the Google User Data section.
- OAuth tokens: kept only while the integration is connected; revoking access or disconnecting deletes them.
- Account and billing data: kept while your account is active and for a limited period afterward to meet legal, tax, accounting, and dispute-resolution requirements.
- Logs and usage data: retained for a limited period for security and operational purposes.
When we no longer need information, we delete it or anonymize it. Residual copies may remain in encrypted backups for a limited time before they are overwritten.
8.How We Protect Information
We use technical, administrative, and organizational measures designed to protect information against loss, misuse, and unauthorized access, disclosure, alteration, or destruction. These include:
- Encryption of data in transit using TLS, and encryption of sensitive data at rest;
- Authenticated encryption (AES-256-GCM) for OAuth tokens and connected-mailbox credentials, with keys held outside the database;
- Hashing of account passwords;
- Tenant isolation enforced in the database, so one customer’s data is not reachable from another customer’s session;
- Access controls that limit who can access systems and data, on a need-to-know basis;
- Secure, reputable cloud infrastructure (Google Cloud Platform) and security tooling (Cloudflare); and
- Monitoring, logging, and regular review of our systems, dependencies, and third-party security assessments where required.
No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If we become aware of a breach that materially affects your personal information, we will notify you and the appropriate authorities as required by law and without undue delay.
9.Cookies and Similar Technologies
Cookies are small files stored on your device. We use them sparingly:
- Strictly necessary cookies keep you logged in, secure your session, and enable core functionality. These cannot be turned off without breaking the Service.
- Analytics cookies help us understand how the Service is used so we can improve it. We use privacy-respecting analytics and do not use this data for advertising.
We do not use advertising, retargeting, or cross-site tracking cookies, and we never place cookies or similar identifiers based on anything in a connected mailbox. You can control or delete cookies through your browser settings; disabling strictly necessary cookies may prevent parts of the Service from working.
10.Your Privacy Rights
Depending on where you live, you may have some or all of the following rights regarding your personal information:
- Access a copy of the information we hold about you;
- Correct inaccurate or incomplete information;
- Delete your information;
- Object to or restrict certain processing;
- Receive your information in a portable format;
- Withdraw consent where processing is based on consent, including by disconnecting a mailbox; and
- Opt out of marketing communications at any time.
If you are in the European Economic Area, the United Kingdom, or Switzerland, these rights arise under the GDPR and equivalent laws; see our GDPR page for details, including the lawful bases on which we rely. If you are a California resident, you have rights under the CCPA and CPRA, including the right to know, delete, correct, and opt out of any "sale" or "sharing" of personal information; we do not sell or share personal information as those terms are defined, and we do not use or disclose sensitive personal information for any purpose other than providing the Service.
To exercise any of these rights, email us at privacy@spamcipher.com. We will respond within the time required by applicable law. We will not discriminate against you for exercising your rights. If the information at issue is Customer Data or connected-mailbox data for which one of our customers is the controller, we will refer your request to that customer.
11.Deleting Your Data
You can delete your data at any time, and most of it you can delete yourself without contacting us.
Disconnect a mailbox (deletes the Google or Microsoft data)
- In SpamCipher, open Outreach, then Email Accounts.
- Select the account and choose Remove.
- The OAuth access and refresh tokens and the messages we stored from that mailbox are deleted immediately.
- You can also revoke access from the Google side at any time at myaccount.google.com/permissions, or from the Microsoft side at account.microsoft.com. Revoking there stops all further access; disconnecting in SpamCipher deletes the stored data.
Delete individual items
Uploaded lists, verification results, campaigns, contacts, and individual stored messages can each be deleted from inside the application, and deletion there is permanent.
Delete your whole account
Email privacy@spamcipher.com from your account address and ask us to delete your account. We delete your account, your Customer Data, and all connected-mailbox data within 30 days, and confirm when it is done. We keep only what we are legally required to keep, such as invoices and tax records, and a minimal record that the account existed and was deleted.
Deleted data is removed from our live systems on the timelines above. Residual copies may persist in encrypted backups for a limited period before they are overwritten on the normal backup cycle, and are not restored into the live system.
12.International Data Transfers
SpamCipher is operated from, and hosts data in, the United States. If you access the Service from outside the United States, your information will be transferred to and processed in the United States and other countries where we or our sub-processors operate, which may have different data-protection laws than your country.
Where we transfer personal information out of the European Economic Area, the United Kingdom, or Switzerland, we rely on appropriate safeguards, such as the European Commission’s Standard Contractual Clauses and the UK Addendum, to protect that information. Business customers can request our Data Processing Agreement, which incorporates these clauses, at privacy@spamcipher.com.
13.Children’s Privacy
The Service is intended for businesses and adults. It is not directed to children, and we do not knowingly collect personal information from anyone under the age of 16. If you believe a child has provided us with personal information, contact us at privacy@spamcipher.com and we will delete it.
14.Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date at the top of this page. If the changes are material, and in particular if they change how we access, use, store, share, or delete Google user data or other connected-mailbox data, we will provide additional notice, such as by email or an in-product notice, before they take effect. Your continued use of the Service after an update means you accept the revised Policy.
15.Contact Us
If you have questions about this Privacy Policy or how we handle your information, or if you wish to exercise your rights, contact us at:
- Privacy, data, and deletion requests: privacy@spamcipher.com
- General support: support@spamcipher.com