Legal
Privacy policy
Last updated 2026-08-12
01What we collect
Your account (email, name), workspace and membership records (role, email signature), the connected-channel identity for each LinkedIn or email account you link (display name, connection status — not your password, which we never see), the prospect records you import or sync (name, title, company, location, LinkedIn profile data, email address), the notes, templates, and sequences you create, the message content sent and received through the product, and the operational logs (queued actions, send attempts, timeline events) needed to run and troubleshoot the product.
02How AI drafting uses your data
If you use AI-assisted drafting, the prospect and conversation context needed to write that message is sent to Cloudflare Workers AI (a Llama model hosted on Cloudflare's own platform) to generate the draft. It is not sent to a separate third-party AI vendor.
03Who can access it
Access is limited to authenticated members of your workspace. On a specialist-assisted plan, coach or operator seats can access only the workspaces they've been explicitly invited into — never other customers' workspaces — and that access is disclosed to you before it's granted. Red Leg Dev, as the operator of this deployment, can access data to provide support and keep the service running; administrative actions of that kind are recorded in an audit log.
04Where it is stored
The product runs on Cloudflare Workers, with your data in a Cloudflare D1 database dedicated to this deployment. Operational logs also flow to Red Leg Dev's own logging service, which runs on the same Cloudflare account. We don't specify a legal jurisdiction here — that's a question for the terms, not this page.
05How long we keep it
Message content and the billing usage ledger are kept indefinitely — we don't automatically delete them. Queued/sent action records are kept about 13 months, and timeline events and admin audit logs about 24 months, then purged automatically. Short-lived items like sign-in codes and expired invites are purged within days. You can request deletion of your data sooner — see the data request page.
06Self-service controls
Archiving a prospect removes it from your active views and stops any sequence it's enrolled in, but does not erase the underlying record. Removing a team member ends their access immediately, but notes and messages they created stay attached to your workspace's history. Entries you add to your suppression list can be deleted outright, any time, by your workspace.
07Analytics
Marketing analytics, when enabled, uses a privacy-respecting analytics host without advertising cookies. See the cookie notice.