privacy
updated 2026-10-07
Two kinds of data live here: yours, and publicly available information about companies. They are treated differently and this page says how.
Your data
We store your email, display name, timezone, your product URL and the model we build from it, your constraints, your drafts and your outcomes.
Mailbox OAuth tokens are encrypted at rest with a key we hold outside the database. We request the narrowest scope that can send mail and nothing that reads your inbox beyond the threads we sent.
Row-level security is on for every table holding your data. Another customer's session returns zero rows, and there is a test in the repository that proves it.
Analytics
PostHog, for product analytics and session replay. In the EU, the EEA, the UK, Switzerland and Brazil, and anywhere we cannot tell where you are, it does not load until you accept. Elsewhere it loads, and the footer has a one-click opt-out.
Every surface showing recipient data, contact details or draft message bodies is masked in both tools. We cannot read your drafts in a session replay and neither can they.
Referral links
If you arrive through somebody's referral link, a first-party cookie called igtm_ref holds that link's code and nothing else. It lets us credit the person who sent you if you sign up and pay.
Where we ask for consent first, it lasts until you close the browser, and 60 days once you accept. Elsewhere it lasts 60 days. It is never shared with an advertising network.
If you sign up, we record which link you came through, and the person who referred you sees that one signup arrived and, later, whether it became a paid account. They never see your name, email or anything in your workspace.
Company data
we keep raw observations for 24 Months. normalized events derived from them are kept alongside.
contact records are purged 90 Days after an account is disqualified or a workspace is deleted.
More detail, and a removal form, on the company data page.
Deleting things
Settings has a working delete control. It cascades. It is not a support ticket.
You can also download everything we hold about your workspace as JSON before you go.
Subprocessors
Supabase (database and auth), Vercel (hosting), Stripe (payments), Resend (product email), PostHog (analytics), and the model providers we route inference through: Anthropic, OpenAI and Google.
Contact enrichment and email verification providers are listed in the app under settings once connected.
Contact
Write to hello@instinctgtm.com about anything on this page: a copy of your data, a correction, deleting your account, or a question. A person reads every message.