LeadGen AI
LeadGen AI

Privacy Policy

Last updated: September 14, 2026

1. Data We Collect

  • Account data: name, email, password (hashed, never stored in plain text), agency/business name.
  • Lead data you add: business names, addresses, phone numbers, websites, and notes you manually enter, import via CSV, or discover through the platform.
  • Payment data: we never see or store your card/UPI details — these are handled entirely by Cashfree, our PCI-DSS compliant payment processor. We store only the subscription plan, amount, and transaction status.
  • Usage data: login timestamps, IP address (for security/rate-limiting), and feature usage counts (leads added, messages generated, emails sent) to enforce plan limits.

2. How We Use Your Data

  • To provide and operate the Service (storing your leads, running AI scoring, sending emails you compose).
  • To process payments and manage your subscription, via Cashfree.
  • To send transactional emails (e.g. follow-up reminders you've configured, receipts).
  • To detect and prevent fraud, abuse, and unauthorized access.

3. Third-Party Services We Use

  • Cashfree — payment processing. See Cashfree's Privacy Policy.
  • OpenStreetMap (Nominatim/Overpass) — public business data used for lead discovery, queried by the city/keyword you search.
  • Groq (optional, if configured) — processes lead details you choose to generate an AI message for, solely to return the generated message text.
  • Your configured email provider (e.g. Mailgun, SMTP) — used only to send emails you compose to leads you've added.

4. Data Retention

We retain your account and lead data for as long as your account is active. If you delete your account, your data is permanently removed within [30] days, except where we're required to retain records for legal or accounting purposes (e.g. payment records).

5. Your Rights

You can access, correct, export, or delete your data at any time from within the app, or by emailing [support@yourdomain.com]. Depending on your location, you may have additional rights under applicable law (e.g. India's Digital Personal Data Protection Act, 2023, or the GDPR if you're in the EU/UK).

6. Security

Passwords are hashed with bcrypt. Sessions use secure, HTTP-only cookies. Sensitive stored credentials (e.g. SMTP passwords) are encrypted at rest. Payment credentials are never handled by our servers directly — Cashfree's hosted checkout handles that.

7. Children's Privacy

The Service isn't directed at anyone under 18. We don't knowingly collect data from minors.

8. Changes to This Policy

We'll update the "Last updated" date above when this policy changes, and notify you of material changes via email or an in-app notice.