Everything a customer, a DPO, or a procurement team needs to evaluate SalesRuns: what data exists where, which mechanisms protect it, who helps us operate, and how to get paperwork like a DPA.
SalesRuns is local-first. Customer email originals are stored in an encrypted SQLite database inside the desktop app on your machine and are never uploaded to our servers in readable form. Cloud services handle account management, plan enforcement, and β only when an AI task needs a cloud model β process redacted summaries (names, addresses and signature blocks stripped client-side). Mailbox credentials are sealed with the OS keychain (macOS Keychain / Windows Credential Manager) and, when synced across your devices, end-to-end encrypted with AES-256-GCM under a key derived from your master password.
Email originals Β· contact records & conversation memory Β· AI-generated drafts before you send Β· mailbox credentials (keychain-sealed) Β· your price sheets and knowledge base.
Account & plan data Β· redacted AI summaries (ephemeral processing) Β· anonymized usage counters for quota enforcement Β· end-to-end encrypted sync blobs we cannot decrypt.
Local database encrypted on-device; all network traffic over TLS 1.2+; cross-device credential sync end-to-end encrypted (AES-256-GCM) with a master password and recovery code only you hold.
Redaction runs client-side before any AI request leaves the device. Cloud models receive the minimum context needed to draft a reply β never your contact list, never raw mailboxes.
Every outbound message is graded L0βL3. Money- and commitment-related content (L2/L3) is blocked pending human approval; automated sends are recallable within 24 hours with a full reasoning trace.
Customer correspondence and summaries are never used to train shared or third-party models. Your workflows are your data.
Export your contacts and history (paid plans) directly from the app; deleting your account removes cloud-side account data. Because originals were never uploaded, deletion on our side cannot cost you your records β and vice versa.
We use the minimum set of providers needed to run the service. Redacted summaries are processed on a tiered basis; the fallback list below reflects current operations.
| Provider | Purpose | Data processed | Region |
|---|---|---|---|
| Cloudflare | Hosting, CDN, Workers, D1/KV (accounts, plans, vouchers, app metadata) | Account email, plan & usage counters, encrypted sync blobs | Global edge / US & EU regions |
| LLM providers (tiered) | AI drafting & summarization for paid/trial plans and free-lane off-peak | Redacted message summaries only β no names, addresses or signature blocks | Per provider; list on request |
| Email providers (via your account) | IMAP/SMTP transport for your own mailbox β direct between your device and your provider | Your mail flows deviceβprovider; not through SalesRuns servers | Your provider's region |
Full sub-processor list with data-category mapping available on request at [email protected]. We notify customers of material sub-processor changes by email and on this page.
SalesRuns' architecture reduces or repositions common obligations β but compliance is a shared responsibility.
Because customer email originals stay on your device, you act as both controller and holder for the bulk of the data; our processing surface is limited to account data and redacted summaries. We provide a DPA and standard contractual clauses for the cloud components.
We do not sell personal information, and data-minimization plus local storage limit "sharing" to redacted AI summaries processed under contract. Deletion and access requests for cloud-side data are handled via the workflows below.
By design, bulk customer data does not cross borders at all β it never leaves your machine. Only account metadata and redacted summaries traverse our cloud, under SCCs where applicable.
No product is "GDPR certified." Compliance ultimately depends on how your organization configures, uses, and documents its processing β including your lawful basis for contacting buyers (e.g., B2B legitimate interest vs. consent rules that vary by country). We provide the mechanisms and paperwork; your counsel owns the conclusion.
Yes. Paid-plan customers can request our DPA (with SCC annexes) at [email protected]; we countersign standard terms within 5 business days.
You fulfill it from the app β customer records and mail live on your machine, so access, rectification and erasure are immediate, local operations. Requests touching our cloud (your account data) go to [email protected]; we respond within 30 days.
Yes β incidents affecting customer data are assessed within 24 hours and, where required by regulation, notified to affected controllers without undue delay. A public status page is available at status.salesruns.com.
There is nothing readable to compel for stored data: originals never reach our servers, and sync is end-to-end encrypted with keys only you hold. Account metadata and transient redacted summaries are the limits of what exists cloud-side.
Send us the questionnaire β we answer as a matter of course, not as a favor.
Email [email protected] Privacy Policy