Privacy Policy
Last updated: 1 September 2026. This policy explains what we collect, why, and how long we keep it.
What we collect about you
- Account data: email, name (optional), hashed password, organization.
- Usage data: prompts, job metadata, credit ledger, API key usage. Prompts are sent to a language-model provider to be parsed; scraped fields are truncated and never used to train models.
- Attribution: UTM parameters and the referring page on your first visit, stored in your browser session and attached to your signup.
- Analytics: cookieless product analytics (PostHog, memory-only persistence) and error reports (Sentry) with personal data stripped. No advertising trackers.
People who appear in lists
This section is for you if you are not a LeadMind customer but your details may appear in a list a customer generated.
- What we collect: business name, job title, work email, work phone, website, business address and public social profile links.
- Where it comes from: publicly available business listings (Google Maps), business directories, company websites and public LinkedIn pages. Every list is scraped live when a customer asks for it; we do not maintain a standing database of people.
- Why we process it: our legitimate interest, and our customers' legitimate interest, in business-to-business prospecting (GDPR Art. 6(1)(f); UAE PDPL Art. 4). We limit collection to business contact data, exclude private individuals outside a business context, and honour every objection.
- Why you were not told individually: we obtain the data indirectly from public sources; contacting every person at collection time would involve disproportionate effort (GDPR Art. 14(5)(b)). This policy is the public notice instead.
- How long we keep it: raw scrape material for 14 days; normalized rows until the customer deletes them or their account is closed. Contact fields are encrypted at rest.
- Who receives it: the customer who ran the job. Once they export a list they are an independent controller of it, as our Terms require.
- Your choices: use the data request page to object, opt out of sale or sharing, ask for deletion, or ask what we hold. Identifiers you give us go on a suppression list (stored as hashes) so no future list includes them. California residents: this is our "Do Not Sell or Share My Personal Information" mechanism; we do not use sensitive personal information and do not discriminate for exercising rights.
Lead data in customer accounts
Contact fields are encrypted at rest. Raw scrape material is deleted after 14 days; normalized leads remain in the customer's account until they delete them. Dedupe keys are hashes and contain no personal data.
Your rights as a customer
You can export or delete all of your data from Settings → Delete my data. Deletion removes your account, jobs, leads and API keys within 24 hours; financial records are retained as required by law. You may also contact privacy@leadmind.com.
Processors
We use Stripe (payments), Apify and Scrapingdog (data collection), Google/Groq/Anthropic (prompt parsing and scoring), Resend (email), PostHog (analytics), Sentry (errors), and cloud hosting in the EU/US. Each processor is bound by a data-processing agreement.
Security
Access tokens are short-lived and kept in memory; refresh tokens are rotating, httpOnly cookies. API keys are stored hashed. Report vulnerabilities to security@leadmind.com.
Contact
privacy@leadmind.com