Outbound data security at OutreachAuto

An outbound tool holds your inboxes, your contacts and every reply your prospects send. This page explains how OutreachAuto handles that data: what we store, how it is protected, who can reach it, how long it stays and how you remove it.

What data OutreachAuto processes

We process prospect data on your behalf and only to run your campaigns. Your contacts, emails and replies belong to your workspace, and we do not sell them, share them between customers or use them to build lists for anyone else.

  • Account data: your work email, name, team members, plan and billing details
  • Connected inboxes: the connection credentials or tokens needed to send campaign email and read replies to it
  • Prospect data: company and business contact details from public company data and the lists you upload or import from your CRM
  • Research: account briefs written from public websites and public signals such as job posts and news
  • Campaign data: sequences, sent emails, replies, reply labels, meetings and activity

Encryption in transit and at rest

All traffic between your browser, our application and connected inboxes is encrypted in transit with TLS. Data is encrypted at rest in our databases and backups. Inbox credentials and access tokens are stored encrypted, separately from campaign content, and are never shown again in the interface after you connect an inbox.

Connecting inboxes safely

Google Workspace and Microsoft 365 inboxes connect through OAuth, where the provider offers it: you sign in with the provider and grant access, and OutreachAuto never sees your password. You can revoke that access at any time from your Google or Microsoft account as well as from OutreachAuto. Other inboxes connect over SMTP and IMAP, where we recommend an app password rather than your main password. Campaigns always go out from your own inboxes, never from ours.

Access control inside your account

Every workspace is separate. Data in one workspace is not visible from another, which matters for agencies that run outbound for several clients. Sign-in uses your work email and password with a one-time code sent to your email for new devices and password resets.

Roles and permissions

On Growth and Scale, roles decide who can manage billing and members, who can edit the ideal customer profile and sequences, who can send, and who can only read and answer replies. You can give a client or a colleague a view-only seat. When someone leaves, removing their seat ends their access at once, and their sequences and activity stay in the workspace.

Single sign-on and audit log on Scale

Scale adds single sign-on through SAML, so access follows your identity provider and ends when you deactivate someone there. Scale also keeps an audit log of sign-ins, member and role changes, inbox connections, sequence edits, exports and deletions, with who did it and when.

Access by our team

Our staff do not open customer workspaces as a matter of routine. Access for support happens only when you ask for help with a specific issue, is limited to what that issue needs, and is logged.

Data retention and deletion

Your data stays in your account while your plan is active. You can delete a contact, a list, a sequence or a whole workspace at any time, and deletion removes it from the live system at once and from backups as they rotate. When you close your account, we delete your workspace data after a short grace period that lets you export it, unless the law requires us to keep billing records longer. Runs created on the homepage without an account are kept for 7 days. A deletion request from a person in your contact list is handled on cold email compliance.

Exporting your data

You can export contacts, sequences and activity at any time. Starter exports to CSV, and Growth and Scale also sync two-way with your CRM, so your records never live only inside OutreachAuto.

Subprocessors

We use a small number of service providers to run OutreachAuto, described here by category: a hosting provider in the EU, a database and backup storage provider, a payment operator, a provider of transactional email for account messages such as sign-in codes, and a provider of AI language models used to write briefs, first lines and reply labels. Each provider is bound by a data processing agreement and receives only the data its task needs. Prospect data sent to the AI model provider is used to produce your output and is not used to train their models.

International data transfers

Where data moves between the EU or UK and the United States, the transfer is covered by the standard contractual clauses approved by the European Commission and the UK addendum, with additional safeguards where the assessment calls for them. Our Data Processing Agreement sets out these terms, and on Scale it is countersigned in-app. Read it on the DPA page and in our Privacy Policy.

Responsible disclosure

If you believe you have found a security vulnerability in OutreachAuto, write to [email protected] with the subject line "Security" and enough detail for us to reproduce it. Please give us reasonable time to fix the issue before you share it, do not access data that is not yours, and do not run tests that degrade the service for others. We confirm receipt and keep you informed until the issue is resolved.

Try it on your own website