Legal
Privacy Policy
Last updated: September 15, 2026
This Privacy Policy explains how we collect, use, store, and protect your personal information when you use LeadPulse (the “Software”). By accessing or using our Software, you agree to the terms of this Privacy Policy.
Information We Collect
- Personal Information: We may collect personal information that you provide when you register an account, such as your name, email address, and organization details.
- Billing Information: We use Stripe for payment processing. Stripe collects identifying information about the devices that connect to its services and uses this information to operate and improve its services, including for fraud detection. You can learn more about Stripe and read its privacy policy at https://stripe.com/privacy.
- Usage Information: We may automatically collect certain information about how you use our Software, including browser type, usage patterns, and feature usage. This information does not include message content, recipient contact information, or uploaded files. This helps us analyze and improve the performance and functionality of the Software.
- Cookies and Similar Technologies: We may use cookies and similar technologies to collect information about your interactions with the Software. Cookies are small files stored on your device that help us provide a better user experience.
How We Use Your Information
- We use the collected information to provide, maintain, and improve our Software's functionality and user experience.
- We may use your personal information to send you updates, notifications, and other communications related to the Software or your account.
- We may use aggregated and anonymized data for analytical purposes, to understand user trends, and to enhance the Software's features and performance.
Email Communications
We may use the email address you provide during registration to send you communications related to new features, updates, promotions, and other information about the Software. By using our Software and providing your email address, you consent to receiving such communications. You can opt-out at any time by following the unsubscribe instructions in the emails or by contacting us at support@leadpul.se.
Google User Data
LeadPulse lets you connect a Google account so that you can read and send email from your own Gmail mailbox inside LeadPulse. This section describes exactly what Google user data LeadPulse accesses, how we use it, how we store and protect it, and how you can revoke our access and delete the data.
Google Account Access We Request
When you choose to connect a Google account, LeadPulse asks for your consent to the following OAuth scope:
https://mail.google.com/— full access to the connected Gmail mailbox. LeadPulse requires this scope because the product reads incoming mail to build conversation threads, sends outgoing mail from your address, and updates message state (read/unread, labels, archive, trash) so that actions taken in LeadPulse stay in sync with your mailbox. Narrower Gmail scopes do not permit this combination of read, send, and modify operations.
Connecting a Google account is entirely optional. LeadPulse is fully usable without one, and we never request Google account access unless you explicitly initiate the connection.
Google User Data We Access
- Email messages: message headers (from, to, cc, subject, date, thread and message identifiers), message bodies, and attachments in the connected mailbox.
- Mailbox metadata: Gmail labels, read/unread state, and history identifiers used to detect new messages.
- Account identity: the email address of the connected Google account, so that we can label the connected mailbox in the LeadPulse interface.
How We Use Google User Data
We use Google user data solely to provide and improve the user-facing features you connect your account for. Specifically, we use it to:
- Display your email conversations inside the LeadPulse inbox.
- Send email on your behalf from your connected address when you or a campaign you configured initiates a send.
- Match incoming messages to the corresponding lead record and thread them into the correct conversation.
- Detect replies, bounces, and unsubscribe requests so that campaigns pause or stop contacting a recipient appropriately.
- Generate optional AI assistance you explicitly request — such as a drafted reply, suggested subject line, or reply classification. Message content used for these features is sent to the Google Gemini API for processing and is not used to train any generative AI or machine learning model.
We do not use Google user data for advertising, for building marketing or data-broker profiles, for resale, for credit assessment or lending, or for training, developing, or improving generalized or generative AI/ML models. We do not allow humans to read your Google user data except where you have given explicit consent for a specific message, where it is necessary for security purposes or to comply with applicable law, or where the data has been aggregated and anonymized for internal operations.
How We Share Google User Data
We do not sell, rent, or transfer Google user data to third parties for their own purposes. Google user data is disclosed only to the following service providers, strictly to operate the features described above, and only to the extent required:
- Google Cloud Platform / Firebase — hosting, authentication, and database infrastructure where the data is stored and processed.
- Google Gemini API — processes message content only when you invoke an optional AI feature, and only for the duration of that request.
We may also disclose data where required by law or in response to a valid legal request. We do not transfer Google user data to any other third party for any purpose other than providing or improving the LeadPulse features you use.
How We Protect Google User Data
- OAuth access and refresh tokens are stored encrypted at rest and are never exposed to the browser or to any other organization on the platform.
- All data is transmitted over encrypted connections (TLS).
- Message data is isolated per organization and access is enforced at the database layer by Firestore security rules combined with role-based access control, so no other customer can read your mailbox data.
- Employee access to production systems is restricted to a limited number of authorized personnel and is used only for security, legal compliance, or support you have requested.
Retention and Deletion of Google User Data
- We retain email content synced from your connected mailbox only for as long as the account remains connected and your LeadPulse organization remains active, because that content is what populates your inbox and lead conversation history.
- Disconnecting the account: you can disconnect a connected Google account at any time from the Email Accounts screen in LeadPulse. Disconnecting immediately revokes and deletes the stored OAuth tokens and stops all further access to your mailbox.
- Revoking from Google:you can independently revoke LeadPulse's access at any time at https://myaccount.google.com/permissions.
- Deleting the data: you may request deletion of all synced Google user data at any time from the organization settings screen or by emailing support@leadpul.se. Deletion requests are executed within 30 days, after which the data is permanently removed from our production systems, and from routine encrypted backups within a further 30 days.
Limited Use Disclosure
LeadPulse's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Multi-Tenant Data Isolation
LeadPulse is a multi-tenant platform. Your organization's data — including leads, messages, and account configurations — is isolated from other organizations using role-based access control and Firestore security rules. Team users within your organization may have access to shared data based on their assigned roles and permissions.
Data Sharing and Disclosure
- We may share your personal information with trusted third parties who assist us in operating our Software and providing services to you (such as payment processing and analytics). These third parties are contractually bound to handle your information securely and only for the purposes specified by us.
- We may disclose your information if required by law, or in response to a valid legal request or government investigation.
- We do not sell your personal information to third parties.
Data Security
We take reasonable measures to protect your personal information from unauthorized access, use, or disclosure. LeadPulse uses industry-standard security practices including encrypted connections (TLS), Firebase Authentication, and Firestore security rules for data access control. However, no method of transmission over the Internet or electronic storage is completely secure, so we cannot guarantee absolute security.
Third-Party Links and Services
Our Software may contain links to third-party websites or services that are not controlled or operated by us. We are not responsible for the privacy practices or content of these third-party services. We encourage you to review the privacy policies of those services before providing any personal information.
Children's Privacy
Our Software is not intended for use by children under the age of 13. We do not knowingly collect personal information from children. If we become aware that we have collected personal information from a child under 13 without parental consent, we will take steps to remove that information from our servers.
Updates to this Privacy Policy
We reserve the right to update or modify this Privacy Policy at any time. We will notify you of any material changes by posting the revised Privacy Policy on our website. Your continued use of the Software after any such changes will signify your acceptance of the updated Privacy Policy.
Contact Us
If you have any questions or concerns about this Privacy Policy or our data practices, please reach out to us at support@leadpul.se.