Privacy Policy

SalesRuns.com  ·  Last updated: August 31, 2026

This Privacy Policy explains how [LEGAL_ENTITY_NAME] ("SalesRuns", "we", "us") collects, uses, stores, and protects personal data when you use the SalesRuns desktop application and related services (the "Service") at salesruns.com.

1. Data controller

Data controller: [LEGAL_ENTITY_NAME], registered at [REGISTERED_ADDRESS]. Privacy inquiries: [email protected].

2. What the Service does

SalesRuns is an AI sales assistant that helps business users manage outbound email campaigns and follow-up on replies. It connects to email accounts the user owns or is authorized to use, via standard protocols (IMAP/SMTP) or via the Gmail API and Microsoft Graph API under the user's explicit OAuth authorization.

3. Email permissions we request, and exactly how each is used

Permission (scope)What we accessPurposeWhat we do NOT do
gmail.readonly (Gmail API)Message headers and bodies of emails in the user's inbox that match known outbound recipients/threads the user sent through SalesRunsTo detect customer replies to the user's outreach, classify them with AI, and generate follow-up suggestionsWe do not read, store, or process emails unrelated to the user's tracked outreach. We do not scan the full mailbox. We do not use content for model training, advertising, or any purpose beyond the above.
gmail.send (Gmail API)Send capability onlyTo send follow-up/reply emails that the user has reviewed and approved within the Service, on the user's behalfWe never send without the user's initiate/approval action in the app.
Mail.Read (Microsoft Graph, delegated)Same as gmail.readonly above, for Microsoft 365 mailboxesSame reply-detection and AI follow-up purposeSame restrictions as gmail.readonly.
Mail.Send (Microsoft Graph, delegated)Send capability onlySame as gmail.sendSame restrictions as gmail.send.
offline_accessRefresh tokensTo keep the user's connection active without repeatedly asking them to re-authorizeRefresh tokens are stored encrypted on the user's own device; the user can revoke access at any time (Section 8).
IMAP/SMTP (other providers)Mail the user's credentials allowSame reply-monitoring and sending purposesCredentials are stored only on the user's device in the OS keychain (encrypted at rest).

4. Email content storage — local-first architecture

Email bodies processed by SalesRuns are stored on the user's own computer in an encrypted local database. The default data path keeps message bodies on the user's device; SalesRuns servers receive only non-content operational metadata (e.g., send/reply event timestamps, delivery status) needed for the AI follow-up suggestion pipeline.

Where the user opts into cloud sync of their workspace, synced items are transmitted over TLS and stored encrypted; the user can disable cloud sync and delete synced data at any time (Section 8).

5. What we collect from you directly

6. What we do NOT do

7. Security measures

8. Retention and deletion

9. International data transfers

SalesRuns serves business customers internationally. Where personal data is transferred outside the EEA/UK, we rely on standard contractual clauses or equivalent mechanisms, and minimize transferred data as described in Section 4.

10. Your rights

Depending on your jurisdiction (GDPR, CCPA, PIPL and others), you may request access, correction, export, or deletion of your personal data, or object to processing. Contact [email protected]; we respond within 30 days.

11. Children

The Service is for business use and is not directed to persons under 16.

12. Changes to this policy

We will post any changes on this page with an updated "Last updated" date and, for material changes affecting email permissions, give at least 14 days' advance notice via the Service or email.

13. Contact

[LEGAL_ENTITY_NAME] · [email protected] · [REGISTERED_ADDRESS]