Privacy policy
Last updated: October 7, 2026. Contact: hello@genpilot.app.
Information we collect
GenPilot stores account details, search instructions, documents you choose to upload, lead results, drafts, and messages you approve for sending. We use product activity events to understand failures and improve the service. We do not include Gmail access tokens or email message bodies in analytics events. Payments are handled by Stripe.
Google account access and use
Connecting Gmail is optional. Our current send-only integration requests gmail.send to send messages you explicitly approve, immediately or on your chosen schedule, and userinfo.email to identify the connected mailbox. We store the mailbox address, an encrypted OAuth refresh token, and the messages sent through GenPilot with their send status and Google message identifiers. GenPilot does not request inbox-reading permission or import new Gmail replies in this version. Existing conversation records from the earlier reply-sync feature may remain in your account until deleted.
Scheduled sending
A message is sent only after your approval. You can pause scheduled outreach or disconnect Gmail in Settings. There are no automatic follow-ups by default. Because this version does not check your inbox, you must check Gmail for replies, bounces, and opt-out requests before sending additional messages. A successful send status means Google accepted the message, not that the recipient opened or received it.
Sharing and service providers
Approved messages are sent to Google and their intended recipients. Cloudflare hosts GenPilot and its stored data. Stripe processes billing, and PostHog processes product activity events. Our search and AI services use DeepSeek for search planning, lead assessment, and draft generation; Exa, Tavily, and SerpAPI for web research; and Monid as a gateway to TinyFish web search and page fetching. Cloudflare Workers AI converts documents you choose to upload into readable text. These services receive the search instructions, user-supplied context, and public source material needed for their tasks. Other disclosures occur only with your authorization or where necessary for security or applicable legal obligations.
AI processing and Google-data separation
Connecting Gmail does not authorize AI processing of your mailbox. The Gmail integration is separate from our search and AI pipeline: Google OAuth credentials, the mailbox identity returned by Google, Google message identifiers, stored sent-message history, and historical imported replies are not used as inputs to our AI or search providers. Additional emails are composed and approved by you, without sending conversation history to an AI model. GenPilot does not access Google Drive or Google Photos through Google APIs. Documents you upload directly to GenPilot, such as a CV or requirements brief, are processed by Cloudflare for text conversion and by our AI service to refine your search; they are not automatically imported from your Google account. Avoid uploading unnecessary sensitive information.
Protection of information
Connections to Google use HTTPS. OAuth refresh tokens are encrypted by the application before storage. Access to application data is controlled by authenticated, user-scoped requests. No service can guarantee absolute security. Human access to Google user data is limited to your explicit permission, necessary security investigations, applicable legal requirements, or aggregated and anonymized internal operations as permitted by Google's policies.
Retention, disconnecting, and deletion
We retain account and conversation records to provide your saved searches and history. Disconnecting Gmail removes its stored credentials, pauses pending outreach, and attempts to revoke Google's authorization. It does not delete your previous sent-message history or messages in Gmail. You may also revoke access at Google Account permissions. To request deletion of account data, uploaded documents, or historical Google-derived records, email hello@genpilot.app from your registered address. Billing or security records may be retained when legally necessary.
Google Limited Use
GenPilot's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy and the Google Workspace API User Data and Developer Policy, including their Limited Use requirements. We do not use, transfer, or sell Google API user data, including raw, aggregated, anonymized, or derived data, to develop, train, or improve foundational or generalized AI or machine-learning models. This restriction applies to GenPilot and to transfers to third-party model providers. We do not sell Google user data or use it for advertising. Any future inbox-reading or AI feature involving Google API data will require separate authorization, applicable Google approval, and a review of provider data-use controls before public availability.
Your choices
You can use lead search without connecting Gmail, edit your search information, disconnect Gmail, and request access, correction, or deletion of your personal information by contacting hello@genpilot.app. We will publish changes to this policy here and explain material changes to Google data access before requesting additional permissions.