← OutboundOS

Privacy Policy

Effective July 28, 2026 · OutboundOS is operated by SETR AI (“we”, “us”). Contact: admin@getsetr.ai

What OutboundOS is

OutboundOS helps businesses find prospects, write outreach emails, and send them from the business’s own email inbox. By default, every email is reviewed and approved by a human before it sends. You can optionally turn on autonomous replies for an agent — then only replies that pass automated safety checks send without per-email review. That setting is off by default and you can turn it off at any time.

What we collect

  • Account information — your name, email address, and login credentials.
  • Business information you provide — company details, what you sell, who your customers are, documents you upload, and email drafts you edit.
  • Prospect data — contact and company information you import, or that the product finds from public sources at your direction.
  • Email activity — emails sent through the product, delivery status, opens on emails that use tracking, and replies to your outreach.
  • Usage data — how you use the product (features used, actions taken), for operating and improving it.

Google user data

If you connect a Gmail or Google Workspace inbox with “Sign in with Google,” we request only two things: permission to send email on your behalf (the gmail.send scope) and your basic profile (email address) to identify the connected account.

  • How we use it: solely to send email from your own inbox at your direction — emails you approved individually, or, only if you have turned on autonomous replies for an agent, replies that pass automated safety checks under that standing instruction. Sending never happens outside those two paths.
  • What we do not do: we do not read, browse, or store your mailbox through Google’s APIs. We do not use Google user data for advertising, and we never sell it.
  • How it is stored: the connection token Google gives us is stored encrypted, on servers with restricted access, and is used only for the sending described above. Disconnecting your inbox in Settings asks Google to invalidate the token and permanently deletes our copy; you can also revoke access anytime at myaccount.google.com/permissions.
  • Who it is shared with: no one, beyond the infrastructure that runs the product (listed below). No human at OutboundOS reads your Google data except with your permission to resolve a support issue you raise.

OutboundOS’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Reading replies

If you connect your inbox with an app password instead of Google sign-in, the product checks that inbox for replies to your outreach — so follow-ups stop automatically when someone answers, and a suggested response can be drafted for your review. It looks for replies to emails the product sent; it is not a general mailbox reader.

Who we share data with

We use a small set of service providers to run the product: hosting (Vercel), database (Supabase), AI text generation (Anthropic), and email delivery infrastructure. They process data only to provide their service to us. We do not sell your data or share it for advertising. We may disclose data if the law requires it.

Retention and deletion

We keep your data while your account is active. Ask us at admin@getsetr.ai and we will delete your account data, including connected-inbox tokens and prospect data, within 30 days.

Security

Data is encrypted in transit and at rest. Inbox credentials and tokens are stored encrypted, access to production systems is restricted, and sending requires human approval by default (per-email review unless you explicitly enable autonomous replies for an agent).

Changes and contact

If this policy changes materially, we will note it here with a new effective date. Questions or requests: admin@getsetr.ai.