Privacy Policy
Effective July 27, 2026
Herald Engine (“Herald Engine”, “we”, “us”) operates a cold email outreach platform that lets users build lead lists, connect their own email sending accounts, and run automated email campaigns. This policy explains what we collect, why we collect it, and the choices you have.
Google user data
When you connect a Gmail or Google Workspace account, Herald Engine requests access through Google OAuth 2.0. We never ask for or store your Google password.
We request these scopes and use them only as described:
- Send email on your behalf: to deliver the campaign and follow-up messages you compose and schedule in Herald Engine, from your own address.
- Read email metadata and messages: to detect when a recipient replies, so we can automatically stop the remaining follow-ups in that sequence and show the conversation in your unified inbox.
- Basic profile and email address: to identify which account is connected and display it in your settings.
We store OAuth access and refresh tokens encrypted at rest using AES-256-GCM. We store message content only where needed to show replies in your inbox and to stop sequences. You can disconnect an account at any time in Settings, which revokes the token and deletes the stored messages for that account. You can also revoke access directly at myaccount.google.com/permissions.
Limited Use disclosure
Herald Engine's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data to serve advertising, we do not sell it, we do not transfer it except as needed to provide or improve the features you requested, and we do not allow humans to read it except with your explicit consent, for security purposes, to comply with applicable law, or where the data is aggregated and anonymized.
Other information we collect
- Account data: name, email address, and organization, used to create and secure your account.
- Lead data you upload: contact records you import or create. This is your data; we process it only to run your campaigns.
- Campaign engagement data: opens, clicks, replies, and bounces for messages you send, used to produce your analytics.
- Billing data: handled by Stripe. We store a customer reference, not your card number.
- Operational logs: used to diagnose errors and detect abuse.
How we share information
We do not sell personal information. We share it only with service providers that operate the platform on our behalf (hosting, email delivery, error monitoring, and payment processing), and only to the extent they need it. We may also disclose information when required by law.
Retention and deletion
We keep your data while your account is active. Disconnecting an email account removes its tokens and stored messages. When you close your account, we delete or anonymize your data within 30 days, except where we must retain records to meet legal or accounting obligations. To request deletion, email privacy@heraldengine.com.
Security
Data is encrypted in transit with TLS. OAuth tokens and email credentials are encrypted at rest with AES-256-GCM. Access to production systems is restricted, and every customer's data is isolated at the database level using row-level security.
Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal information, and to object to or restrict certain processing. To exercise any of these, contact us at privacy@heraldengine.com.
Changes to this policy
If we make a material change, we will update the effective date above and notify account holders by email before it takes effect.
Contact
Questions about this policy or your data: privacy@heraldengine.com.
Herald Engine · Terms of Service