Legal

Privacy Policy

This policy explains how ColdmailAI handles information when you use our website, workspace, Gmail extension, AI analysis, billing, and Gmail sending features.

Last updated: July 19, 2026

Who operates ColdmailAI

Fardeen Mansoori operates ColdmailAI and is responsible for the processing described in this policy. Its address for privacy and legal notices is Kota, Rajasthan, India. Privacy questions can also be sent to hi@fardeen.me.

Information we collect

  • Account and workspace information: account email, name, user and organization identifiers, membership, and authentication events provided through Clerk.
  • Content you provide: drafts, goals, analysis results, rewrites, templates, workspace brand context, contacts, campaign content, recipient details, suppression records, and support messages.
  • Google connection information: Google account email and identifier, granted scopes, encrypted refresh tokens, connection status, and Gmail send results or errors. ColdmailAI requests profile scopes and the Gmail send scope; it does not request permission to read your Gmail inbox.
  • Billing information: plan, subscription, checkout, customer, payment-status, and credit-ledger identifiers. Payment details are collected and processed by Dodo Payments rather than stored directly by ColdmailAI.
  • Technical and service information: request metadata, timestamps, feature usage, job and delivery status, error details, and essential authentication or security cookies.

How we use information

We use information to:

  • authenticate users and provide shared workspaces;
  • analyze and rewrite user-submitted outreach content;
  • save templates, contacts, campaign settings, and time-limited analysis history;
  • send messages through a Google account only when a user configures and starts that workflow;
  • manage subscriptions, credits, support, abuse prevention, reliability, and security; and
  • meet legal obligations and enforce our terms.

ColdmailAI does not sell personal information or use Google user data for targeted advertising.

Google API data and Limited Use

ColdmailAI uses Google profile information to identify the connected account and uses the Gmail send permission only to send messages that an authorized workspace user has prepared and scheduled. Google account identifiers and OAuth tokens obtained through Google APIs are not sent to AI model providers.

ColdmailAI's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

You can disconnect a Google account from the campaign settings. ColdmailAI then asks Google to revoke the refresh token and removes the stored local connection credential even if Google's revocation endpoint is temporarily unavailable. You can also revoke access from your Google Account. Campaign and delivery records may remain as described below.

Read the Google API Services User Data Policy.

Extension-local permissions and storage

The extension runs a content script on Gmail to place the assistant beside an open compose window. Gmail is not an extension host permission, and the extension does not request a tabs permission or permission to read your inbox. Its host access is limited to the configured ColdmailAI API, sign-in, and Clerk authentication origins. Its cookie permission is used only for Clerk session state on those configured authentication hosts, not Gmail cookies.

Clerk caches authentication state in local extension storage. Your versioned AI-processing consent is also stored locally and is tied to the signed-in user, so changing users requires the appropriate user's consent. Temporary sign-in tab state is kept in session storage. You can revoke AI-processing consent from the extension popup and can remove all extension-local data by uninstalling the extension or clearing its data.

Service providers and sharing

We share information only as needed to operate the service, follow your instructions, protect the service, complete a business transaction subject to appropriate safeguards, or comply with law. Current provider categories include:

  • Clerk for authentication and workspace identity;
  • Neon for application database services;
  • OpenRouter and the routed model provider for user-requested AI processing;
  • Google for OAuth, account identification, and Gmail sending; and
  • Dodo Payments for checkout and subscription processing.

Those providers process information under their own terms and privacy commitments. We may also disclose information when reasonably necessary to investigate abuse, protect rights or safety, or respond to valid legal process.

Retention and deletion

Saved analysis and rewrite history receives a 30-day expiry and is scheduled for deletion after expiry. Deleting a history entry removes it sooner. The 30-day period applies to that history feature; it does not mean every category of account or campaign data is deleted after 30 days.

To make retries idempotent and avoid duplicate AI charges, ColdmailAI keeps a transient AI operation record and, after completion, its response for up to 24 hours. Failed stale operations are recovered and refunded before their terminal records expire.

We retain account, workspace settings, templates, contacts, campaigns, delivery and suppression records, billing metadata, and security records while needed to provide the service, honor opt-outs, resolve disputes, prevent abuse, or meet legal obligations. Backup copies may persist for a limited period until overwritten. Aggregated or de-identified data may be retained when it can no longer reasonably identify a person.

To request account or workspace data deletion, follow the data-deletion instructions or contact hi@fardeen.me. We may need to verify your identity and authority over the workspace. Deleting your Clerk login does not by itself delete shared workspace or billing records. Some records may be retained where required or permitted by law, including suppression data needed to honor an unsubscribe request.

Security and your choices

We use administrative and technical safeguards designed to protect information, including encrypting stored Google refresh tokens. No online service can guarantee absolute security. Protect your account credentials and tell us promptly if you suspect unauthorized access.

You can avoid AI processing by not submitting a draft for analysis or rewrite, delete individual history entries in the product, disconnect Google accounts, and request broader access, correction, or deletion through support. Rights vary by location and may be subject to verification and legal exceptions.

International use, children, and changes

ColdmailAI and its providers may process information in countries other than your own. The service is intended for business users who are at least 18 or the age of legal majority where they live; it is not directed to children.

We may update this policy as the product or law changes. We will update the date above and, when a material change affects how previously collected information is used, provide an additional notice or request consent where required.

Contact

Privacy questions and requests can be sent to hi@fardeen.me. See the support page for request details.