Trust Center

Security & Privacy, Shown β€”
Not Just Promised

Everything a customer, a DPO, or a procurement team needs to evaluate SalesRuns: what data exists where, which mechanisms protect it, who helps us operate, and how to get paperwork like a DPA.

Last updated: September 1, 2026

The Architecture in One Paragraph

SalesRuns is local-first. Customer email originals are stored in an encrypted SQLite database inside the desktop app on your machine and are never uploaded to our servers in readable form. Cloud services handle account management, plan enforcement, and β€” only when an AI task needs a cloud model β€” process redacted summaries (names, addresses and signature blocks stripped client-side). Mailbox credentials are sealed with the OS keychain (macOS Keychain / Windows Credential Manager) and, when synced across your devices, end-to-end encrypted with AES-256-GCM under a key derived from your master password.

🏠Stays on your machine

Email originals Β· contact records & conversation memory Β· AI-generated drafts before you send Β· mailbox credentials (keychain-sealed) Β· your price sheets and knowledge base.

☁️Touches our cloud

Account & plan data Β· redacted AI summaries (ephemeral processing) Β· anonymized usage counters for quota enforcement Β· end-to-end encrypted sync blobs we cannot decrypt.

Protective Mechanisms

πŸ”Encryption at rest & in transit

Local database encrypted on-device; all network traffic over TLS 1.2+; cross-device credential sync end-to-end encrypted (AES-256-GCM) with a master password and recovery code only you hold.

πŸ”Data minimization for AI

Redaction runs client-side before any AI request leaves the device. Cloud models receive the minimum context needed to draft a reply β€” never your contact list, never raw mailboxes.

πŸŽ›οΈRisk grading & recall

Every outbound message is graded L0–L3. Money- and commitment-related content (L2/L3) is blocked pending human approval; automated sends are recallable within 24 hours with a full reasoning trace.

🧾No training on your data

Customer correspondence and summaries are never used to train shared or third-party models. Your workflows are your data.

πŸšͺExit anytime

Export your contacts and history (paid plans) directly from the app; deleting your account removes cloud-side account data. Because originals were never uploaded, deletion on our side cannot cost you your records β€” and vice versa.

Sub-processors

We use the minimum set of providers needed to run the service. Redacted summaries are processed on a tiered basis; the fallback list below reflects current operations.

ProviderPurposeData processedRegion
CloudflareHosting, CDN, Workers, D1/KV (accounts, plans, vouchers, app metadata)Account email, plan & usage counters, encrypted sync blobsGlobal edge / US & EU regions
LLM providers (tiered)AI drafting & summarization for paid/trial plans and free-lane off-peakRedacted message summaries only β€” no names, addresses or signature blocksPer provider; list on request
Email providers (via your account)IMAP/SMTP transport for your own mailbox β€” direct between your device and your providerYour mail flows device↔provider; not through SalesRuns serversYour provider's region

Full sub-processor list with data-category mapping available on request at [email protected]. We notify customers of material sub-processor changes by email and on this page.

Regulations This Design Supports

SalesRuns' architecture reduces or repositions common obligations β€” but compliance is a shared responsibility.

πŸ‡ͺπŸ‡ΊGDPR

Because customer email originals stay on your device, you act as both controller and holder for the bulk of the data; our processing surface is limited to account data and redacted summaries. We provide a DPA and standard contractual clauses for the cloud components.

πŸ‡ΊπŸ‡ΈCCPA / CPRA

We do not sell personal information, and data-minimization plus local storage limit "sharing" to redacted AI summaries processed under contract. Deletion and access requests for cloud-side data are handled via the workflows below.

🌐Cross-border transfers

By design, bulk customer data does not cross borders at all β€” it never leaves your machine. Only account metadata and redacted summaries traverse our cloud, under SCCs where applicable.

⚠️The honest caveat

No product is "GDPR certified." Compliance ultimately depends on how your organization configures, uses, and documents its processing β€” including your lawful basis for contacting buyers (e.g., B2B legitimate interest vs. consent rules that vary by country). We provide the mechanisms and paperwork; your counsel owns the conclusion.

DPA & Requests β€” FAQ

Can I get a Data Processing Agreement?

Yes. Paid-plan customers can request our DPA (with SCC annexes) at [email protected]; we countersign standard terms within 5 business days.

How do I handle a data subject request that involves my SalesRuns workspace?

You fulfill it from the app β€” customer records and mail live on your machine, so access, rectification and erasure are immediate, local operations. Requests touching our cloud (your account data) go to [email protected]; we respond within 30 days.

Do you have a security incident process?

Yes β€” incidents affecting customer data are assessed within 24 hours and, where required by regulation, notified to affected controllers without undue delay. A public status page is available at status.salesruns.com.

Can you read my customers' emails if compelled?

There is nothing readable to compel for stored data: originals never reach our servers, and sync is end-to-end encrypted with keys only you hold. Account metadata and transient redacted summaries are the limits of what exists cloud-side.

Questions before your security review?

Send us the questionnaire β€” we answer as a matter of course, not as a favor.

Email [email protected] Privacy Policy