This Privacy Policy explains how [LEGAL_ENTITY_NAME] ("SalesRuns", "we", "us") collects, uses, stores, and protects personal data when you use the SalesRuns desktop application and related services (the "Service") at salesruns.com.
Data controller: [LEGAL_ENTITY_NAME], registered at [REGISTERED_ADDRESS]. Privacy inquiries: [email protected].
SalesRuns is an AI sales assistant that helps business users manage outbound email campaigns and follow-up on replies. It connects to email accounts the user owns or is authorized to use, via standard protocols (IMAP/SMTP) or via the Gmail API and Microsoft Graph API under the user's explicit OAuth authorization.
| Permission (scope) | What we access | Purpose | What we do NOT do |
|---|---|---|---|
gmail.readonly (Gmail API) | Message headers and bodies of emails in the user's inbox that match known outbound recipients/threads the user sent through SalesRuns | To detect customer replies to the user's outreach, classify them with AI, and generate follow-up suggestions | We do not read, store, or process emails unrelated to the user's tracked outreach. We do not scan the full mailbox. We do not use content for model training, advertising, or any purpose beyond the above. |
gmail.send (Gmail API) | Send capability only | To send follow-up/reply emails that the user has reviewed and approved within the Service, on the user's behalf | We never send without the user's initiate/approval action in the app. |
Mail.Read (Microsoft Graph, delegated) | Same as gmail.readonly above, for Microsoft 365 mailboxes | Same reply-detection and AI follow-up purpose | Same restrictions as gmail.readonly. |
Mail.Send (Microsoft Graph, delegated) | Send capability only | Same as gmail.send | Same restrictions as gmail.send. |
offline_access | Refresh tokens | To keep the user's connection active without repeatedly asking them to re-authorize | Refresh tokens are stored encrypted on the user's own device; the user can revoke access at any time (Section 8). |
| IMAP/SMTP (other providers) | Mail the user's credentials allow | Same reply-monitoring and sending purposes | Credentials are stored only on the user's device in the OS keychain (encrypted at rest). |
Email bodies processed by SalesRuns are stored on the user's own computer in an encrypted local database. The default data path keeps message bodies on the user's device; SalesRuns servers receive only non-content operational metadata (e.g., send/reply event timestamps, delivery status) needed for the AI follow-up suggestion pipeline.
Where the user opts into cloud sync of their workspace, synced items are transmitted over TLS and stored encrypted; the user can disable cloud sync and delete synced data at any time (Section 8).
mail.google.com) and we do not use IMAP XOAUTH2 against Gmail.SalesRuns serves business customers internationally. Where personal data is transferred outside the EEA/UK, we rely on standard contractual clauses or equivalent mechanisms, and minimize transferred data as described in Section 4.
Depending on your jurisdiction (GDPR, CCPA, PIPL and others), you may request access, correction, export, or deletion of your personal data, or object to processing. Contact [email protected]; we respond within 30 days.
The Service is for business use and is not directed to persons under 16.
We will post any changes on this page with an updated "Last updated" date and, for material changes affecting email permissions, give at least 14 days' advance notice via the Service or email.
[LEGAL_ENTITY_NAME] · [email protected] · [REGISTERED_ADDRESS]