Back

Privacy Policy

Last updated: October 6, 2026

1. Overview

This Privacy Policy describes how [Company Name] ("we", "us", or "our") collects, uses, and shares information when you use Rndl / People Search (the "Service"). By using the Service you agree to the practices described in this policy.

2. Information We Collect

2a. Information you provide

  • Account details: email address, name, current company, and job title at signup.
  • User profile data: professional background, skills, interests, past employers, and education — used to compute commonality scores with leads.
  • Resume content: if you upload a resume, we parse it to populate your profile fields. The file is processed and not stored long-term.

2b. Information from third-party services you connect

  • Outlook OAuth tokens (and Gmail tokens, for accounts connected before Gmail was paused): if you connect an email account to send outreach, we store your OAuth access and refresh tokens. Tokens are encrypted at rest using AES-256 before being saved to our database.
  • Permissions: Microsoft offers no permission narrower than "Read your mail", so connecting Outlook grants read access to your mailbox and the ability to send mail as you. We do not use the access to edit, move, or delete any of your mail.
  • What we actually read: we are notified when a new message arrives in your Inbox and look only at its conversation ID, to check whether it answers an outreach email the Service sent for you. Only when it does do we open that reply.
  • Replies to your outreach: we store the text of those replies with the outreach record and use an AI model to classify them (for example interested, not interested, out-of-office, or bounced), so your campaign can react to each person's answer.
  • Everything else in your mailbox is never opened, searched, indexed, or stored. Emails the Service sends for you appear in your Sent Items like any other message.

2c. Scraped public data (lead profiles)

  • We aggregate publicly available employee profiles from company websites: names, job titles, bios, LinkedIn URLs, email addresses listed publicly, and similar professional information.
  • This data is collected by our automated pipeline and enhanced using AI models to extract structured attributes (skills, interests, education, past roles).

2d. Usage data

  • Search queries you run, companies and profiles you click on, and emails you send through the Service.
  • Standard server logs (IP address, browser type, pages visited, timestamps).

3. How We Use Your Information

  • To provide and improve the Service, including computing commonality scores between you and leads.
  • To generate AI-drafted outreach emails using your profile context and lead profile data.
  • To authenticate your account and maintain your session.
  • To send emails on your behalf through a connected email account, when you send them or when a campaign you set up sends them.
  • To detect replies to those emails and classify them, so a campaign can respond to each person's answer.
  • To grant monthly credits and track your subscription tier and usage.
  • To detect and prevent abuse, fraud, or violations of our Terms of Service.

4. Third-Party Services

We share data with the following third parties in order to operate the Service:

  • Supabase — the open-source database and authentication software we use. We run it on our own servers, so your account data, profile, and lead data are not sent to Supabase the company.
  • OpenAI — we send lead profile text and your profile context to OpenAI's API to generate commonality scores, parse search queries, and draft outreach emails. OpenAI processes this data under its API data usage policy (data submitted via the API is not used to train OpenAI models by default).
  • Anthropic — we send the text of replies to your outreach emails to Anthropic's API to classify them, and may use it to draft outreach. Anthropic processes this data under its commercial terms (API data is not used to train its models by default).
  • Perplexity — optionally used to fetch recent news about a lead to add context to outreach drafts. Only the lead's name and company are sent.
  • Microsoft (Outlook / Graph API), and Google (Gmail API) for accounts connected before Gmail was paused — if you connect an email account, we interact with these APIs solely to send emails you initiate or that your campaigns send, and to read replies to those emails as described in section 2b. We do not read the rest of your mailbox.

We do not sell your personal information to any third party.

5. Data Retention

We retain your account and profile data for as long as your account is active. Lead profile data sourced from public websites is retained as part of our database. If you delete your account, your personal profile and email tokens are deleted. Aggregated or anonymized usage data may be retained longer for analytics.

6. Cookies and Session Data

We use HTTP-only cookies to maintain your authenticated session. These cookies are set server-side and are not accessible to JavaScript. We do not use third-party tracking cookies or advertising cookies. Session tokens are never embedded in URLs.

7. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access the personal data we hold about you.
  • Request correction of inaccurate data.
  • Request deletion of your account and associated personal data.
  • Object to or restrict certain processing of your data.
  • Withdraw consent for connected email accounts at any time by disconnecting them in the app.

To exercise any of these rights, contact us at edayan@ndexsystems.com.

8. Security

We take reasonable technical and organizational measures to protect your data. OAuth tokens are encrypted at rest using AES-256. Authentication sessions use secure, HTTP-only cookies. However, no system is perfectly secure and we cannot guarantee absolute security.

9. Children

The Service is not directed at individuals under the age of 16. We do not knowingly collect personal data from children.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will post the revised policy on this page with an updated effective date. Continued use of the Service after changes constitutes acceptance of the revised policy.

11. Contact

For privacy questions or requests, contact us at edayan@ndexsystems.com or by mail at [Company Name], [Company Address].