Back to OutboundFlow

Public legal page

Privacy Policy for OutboundFlow

This page is the public privacy statement for the OutboundFlow application on https://outbound-flow.vercel.app/. It explains how OutboundFlow accesses, uses, stores, protects, and discloses personal information, including Google and Microsoft mailbox data connected through the product.

Effective date: March 28, 2026Applicable domain: outbound-flow.vercel.appContact: solankijay01@gmail.comRelated page: Terms & Conditions

Mailbox permissions

OutboundFlow requests only the Google Workspace Gmail and Microsoft 365 Outlook permissions needed to connect a mailbox, send outbound email, sync replies, and keep campaign state accurate.

Security controls

OAuth credentials are stored in encrypted form, access is limited to the service functions required to operate the product, and workspace access is scoped by account membership and product permissions.

Data handling limits

OutboundFlow does not sell Google or Microsoft user data, does not use mailbox data for advertising, and does not use Google Workspace API data to develop, improve, or train generalized AI or machine learning models.

Workspace records

The app stores workspace, contact, campaign, message-thread, and operational event data so teams can launch campaigns, monitor delivery, sync replies, and collaborate from one shared system.

1. Scope and service identity

This Privacy Policy explains how OutboundFlow handles personal information when you access or use the OutboundFlow application and public website located at https://outbound-flow.vercel.app/. In this policy, "OutboundFlow," "we," "our," and "us" refer to the OutboundFlow service and the service operator responsible for providing it, where applicable.

This policy is intended to support public-facing product use, Google Auth Platform verification, and Microsoft Entra branding and consent verification. It applies to information collected on the public site, within the product, and through connected services such as Google Workspace Gmail and Microsoft 365 Outlook.

2. Information we collect

We collect and process information needed to operate the service, authenticate users, run outbound campaigns, synchronize replies, and secure the product. The information we collect depends on how you use OutboundFlow and which integrations you connect.

  • Account and workspace data, such as your name, email address, role, workspace membership, and account authentication records.
  • Campaign and contact data, including contact lists, imported records, campaign drafts, templates, send schedules, reply disposition, unsubscribe status, and related operating notes.
  • Mailbox integration data, including connected mailbox address, provider account label, OAuth scopes, encrypted access and refresh credentials, token expiry, message-thread identifiers, headers, snippets, message bodies, and send or reply timestamps.
  • Operational and security data, such as IP-derived logs, error traces, audit events, usage counters, job status, webhook events, and diagnostics needed to maintain the platform.

3. How we use information

We use personal information to provide, maintain, secure, and improve the user-facing functionality of OutboundFlow. That includes creating workspaces, authenticating users, connecting mailboxes, sending outreach, synchronizing replies, suppressing follow-ups after a response, updating campaign analytics, and troubleshooting product issues.

We may also use information to prevent abuse, investigate security incidents, comply with law, enforce our Terms and Conditions, and communicate operational notices related to your use of the service.

4. Google user data and Gmail permissions

When you connect a Google account, OutboundFlow requests the Gmail scopes https://www.googleapis.com/auth/gmail.send, https://www.googleapis.com/auth/gmail.readonly, and https://www.googleapis.com/auth/gmail.modify. We also use the Gmail profile endpoint to identify the connected mailbox email address.

We use Gmail data only to provide or improve the user-facing features of OutboundFlow. In practical terms, that means connecting a mailbox, sending campaign emails or manual replies, reading thread and message data to synchronize replies back into the workspace, updating campaign state when a recipient replies, and showing the team accurate inbox and thread history inside the product.

OutboundFlow's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell Google user data, use Google user data for targeted advertising, or use Google Workspace API data to develop, improve, or train generalized or non-personalized AI or machine learning models.

  • Google user data is accessed only after you authorize the mailbox connection.
  • Google OAuth credentials are stored in encrypted form.
  • Google mailbox content is processed so the service can send messages, synchronize threads, classify replies, and keep campaign records accurate.
  • If you revoke Google's access to the app or disconnect the mailbox, future Google API access stops once valid credentials are no longer available to the service.

5. Microsoft user data and Outlook permissions

When you connect a Microsoft account, OutboundFlow requests the scopes openid, profile, email, offline_access, User.Read, Mail.Send, and Mail.ReadWrite through the Microsoft identity platform and Microsoft Graph.

We use Microsoft data to identify the connected mailbox, send email, create or continue reply threads, synchronize inbox activity back into OutboundFlow, update campaign and inbox records, and display workspace-visible thread history. We do not access Microsoft mailbox data for unrelated analytics, advertising, resale, or profiling outside the product features a user has asked us to provide.

  • Microsoft account profile data is used to identify the mailbox owner and connected mailbox address.
  • Microsoft mailbox data is used to send outbound mail, create replies, read synchronized messages, and keep reply-aware campaign state accurate.
  • Microsoft OAuth credentials are stored in encrypted form and refreshed only as needed to keep the connected mailbox working.

6. Sharing and disclosure

We do not sell personal information, Google user data, or Microsoft user data. We disclose information only when necessary to run the service, comply with law, protect rights and security, or complete an instruction authorized by the workspace.

  • Service providers that host, secure, or support the infrastructure used by OutboundFlow.
  • Authorized workspace users who need shared visibility into campaigns, replies, contacts, and mailbox-connected activity.
  • Integration endpoints or third-party services you intentionally configure, such as CRM adapters, webhooks, calendars, or similar connected tools.
  • Regulators, law enforcement, or other parties when disclosure is legally required or necessary to investigate fraud, abuse, or security incidents.

7. Security protections

We use administrative, technical, and organizational measures designed to protect personal information against unauthorized access, loss, misuse, or disclosure. These measures include encrypted storage for OAuth credentials, access controls, logging, and environment-based secrets management.

No service can guarantee absolute security. You are responsible for securing your account credentials, limiting access to authorized team members, and connecting only mailboxes and data sources you are permitted to use.

8. Retention and deletion

We retain personal information for as long as it is needed to provide the service, maintain workspace history, enforce agreements, resolve disputes, comply with legal obligations, and protect the security and integrity of OutboundFlow.

Campaign, contact, inbox, and workspace records may remain available until they are deleted by the workspace or removed during account closure or administrative cleanup. OAuth credentials remain stored only while a mailbox connection is maintained and are removed when no longer needed, revoked, or deleted as part of account or integration cleanup.

If you want mailbox access to stop immediately, you can disconnect the mailbox in the product or revoke the app's access from your Google or Microsoft account settings. If you need a deletion request handled at the service level, you may contact OutboundFlow using the details provided below.

9. Your choices and rights

Depending on your location and relationship to the workspace, you may have rights to access, correct, export, restrict, or delete certain personal information. Many workspace records can also be updated or removed directly through the product by an authorized user.

If you are using OutboundFlow through an employer, client, or private workspace, that organization may control some of the information processed in the service and may need to handle your request first.

10. Policy changes

We may update this Privacy Policy from time to time to reflect product changes, legal requirements, security practices, or changes in how connected services are used. When we make a material change, we will update the effective date on this page and, where appropriate, provide an in-product notice or other reasonable notification.

11. Privacy requests and contact

If you need to submit a privacy, access, correction, deletion, or verification-related request, you may contact OutboundFlow at solankijay01@gmail.com. This contact channel may be used for Google Auth Platform verification, Microsoft Entra review, and user privacy inquiries relating to the public OutboundFlow service at https://outbound-flow.vercel.app/.

If you use OutboundFlow through an employer, client, or private workspace, that organization may control some of the information processed within the service and may need to review or coordinate your request before it can be completed.