Privacy Policy
Effective Date: May 14, 2026
PitchHired ("we", "our", or "us") operates a platform that helps users identify relevant contacts at companies, generate personalized outreach emails, and send them through their connected Gmail account.
We are committed to protecting your privacy and complying with applicable data protection laws, including the General Data Protection Regulation (GDPR).
1. Information We Collect
We may collect the following types of data:
Account Information
- Name
- Email address
- Login details
User Content
- Profile data (skills, preferences, filters)
- Target company lists
- Generated and sent email content
Usage Data
- Platform activity and logs
- Campaign status and performance
Connected Account Data (Gmail)
- Permission to send emails via your Gmail account
- We do NOT store your Gmail password
- Access is limited to sending emails on your behalf
2. How We Use Your Data
We use your data to:
- Provide and operate the service
- Generate personalized outreach emails and related user-requested content
- Send emails through your Gmail account when you explicitly connect Gmail
- Track campaign performance
- Maintain platform security, reliability, and abuse prevention
3. Legal Basis (GDPR)
We process your data based on:
- Your consent
- Performance of a contract
- Legitimate interest (service improvement and security)
4. Data Sharing
We do NOT sell your data.
We may share data with:
- Infrastructure and hosting providers needed to operate the service
- Google, solely to enable Gmail sending features that you explicitly authorize
- Third-party AI providers, such as OpenAI, only as needed to provide user-requested content generation features
5. Data Retention
We retain data only as long as necessary to provide the service.
You may request deletion at any time.
6. Your Rights (GDPR)
You have the right to:
- Access your data
- Correct your data
- Request deletion
- Withdraw consent
To exercise your rights, contact: [email protected]
7. Security and Protection of Sensitive Data
We treat account credentials, OAuth tokens, email content, and other personal or authentication-related information as sensitive data. We apply technical and organizational measures designed to protect this data against unauthorized access, disclosure, alteration, or destruction.
Data protection mechanisms
- Encryption in transit: Data transmitted between your browser, our servers, and third-party APIs (including Google and OpenAI) is protected using HTTPS/TLS.
- Encryption at rest for OAuth tokens: Gmail refresh tokens are encrypted before storage in our database using application-level encryption (Fernet). We do not store your Gmail password.
- Access controls: User data is scoped to authenticated accounts. API access requires valid authentication, and inbox or send actions are limited to the account that authorized them.
- Least-privilege access: Production systems and credentials are restricted to personnel and services that need them to operate the platform.
- Secure secret management: API keys, encryption keys, and other secrets are stored as environment variables and are not exposed in client-side code.
- User revocation: You can disconnect Gmail at any time in the app, which stops further use of that connection for sending.
- Retention and deletion: We retain sensitive data only as long as needed to provide the service, and you may request deletion of your account data by contacting us.
No method of transmission or storage is 100% secure. If you believe your account or data has been compromised, contact us immediately at [email protected].
8. Third-Party Services
We integrate with third-party services such as Google Gmail API and OpenAI to provide user-requested platform features.
9. Google API Data
If you connect your Gmail account to PitchHired, we access and use Google user data only to provide the user-requested functionality of sending emails on your behalf through the Gmail API.
- We do not sell Google user data.
- We do not use Google user data for advertising or marketing profiling.
- We do not use Google user data for purposes unrelated to the Gmail sending feature you authorize.
- We do not use data obtained from Google APIs to develop, improve, or train generalized or non-personalized artificial intelligence or machine learning models.
PitchHired's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
10. Changes
We may update this policy. Continued use means acceptance of updates.
11. Contact
Operated by: PitchHired
Email: [email protected]
Address: Available upon request