Privacy Policy
Last updated 6 September 2026
This policy covers two different kinds of personal data, and it is worth separating them at the outset: information about you, the account holder, and information about the people your campaigns contact. The obligations are not the same.
Information about you
We hold, for as long as you have an account:
- Your email address and name, from signing up with Google, GitHub or a password.
- Your campaign brief: the sending name and address you send from, your postal address, and your website. The postal address is required because CAN-SPAM requires one in the messages you send.
- A record of your subscription — the PayPal subscription identifier, its status and renewal date. We never see or store your card details; PayPal handles those and we receive only the outcome.
- Counts of what you have used: emails sent and lead searches run, so plan limits can be applied.
We use it to run your account, to bill you, and to contact you about the service. We do not sell it, and we do not use it for advertising.
Information about the people you contact
When you run a lead search, the software collects business contact details from public sources — company websites and OpenStreetMap. That can include a business email address, a website, a phone number, a city and country, and sometimes a named owner and their role.
These are people who have not asked to hear from you, so it matters who is responsible for them. You are. You decide what to search for, who stays on the list and who is contacted; we store that list for you and apply the rules you configure. Under the GDPR you are the controller of that data and we act as your processor. We use it only to provide the service to you, we do not use it for our own purposes, and we do not share it with other customers — each account's list is isolated from every other.
Where the GDPR applies, Article 14 requires that a person told where their data came from when it was not collected from them directly. That notice is yours to give, and the software can add a source line to your messages to help. Leads in jurisdictions that require prior consent for cold email are excluded when the list is built.
If someone asks you to delete their data, you can remove them from the dashboard, and adding them to the do-not-contact list stops them being collected again.
Where it is kept
The application runs on Render in Singapore. Data is stored in Supabase, a hosted PostgreSQL service, in the same region. Files that belong to a campaign — its lead queue, its send history — sit on a disk attached to that server.
Who else processes it
- Supabase — database and sign-in.
- Render — hosting.
- PayPal — subscription payments. They are the controller of your payment data, under their own policy.
- Your own email provider — Resend or Amazon SES, under credentials you supply. Messages and their delivery events pass through your account with them, not ours.
How long we keep it
Campaign data stays until you erase it or close your account. The do-not-contact list is deliberately excluded from the erase tools: it exists to record that someone asked not to be emailed, and deleting it would lose that. Billing records are kept as long as tax law requires.
Your rights
Depending on where you live you may have the right to see the data we hold about you, correct it, delete it, or take it elsewhere. The dashboard already lets you export and erase campaign data yourself. For anything else, write to hello@galacticoutreach.com and we will respond within 30 days.
Security
Access is over HTTPS and each account's data is separated at the database level. Your email provider's API key is held in Supabase Vault rather than in the application database. No system is perfectly secure; if a breach affects you we will tell you.
Changes
If this policy changes materially we will tell you by email before the change takes effect.
Questions about this page: hello@galacticoutreach.com