Privacy Policy

Last updated: July 17, 2026

Overview

SourceML (“SourceML”, “we”, “us”) provides a talent-sourcing and outreach platform. This Privacy Policy explains what information we collect, how we use and share it, how long we keep it, and the choices you have. It also describes, in detail, how we handle data from email accounts you connect, including Google Gmail and Microsoft Outlook.

This policy applies to the SourceML website and applications. By using the Service you agree to this policy.

1. Information we collect

  • Account information: your name and email address, and the authentication data used to sign you in (we use passwordless magic-link and OAuth sign-in).
  • Billing information: managed by our payment processor, Stripe. We store limited subscription identifiers and status, not your full payment-card details.
  • Usage data: the searches you run, candidates you save, projects and sequences you create, and how you interact with the app, together with standard log and device information.
  • Candidate data: information about researchers and professionals compiled from public sources (such as OpenAlex academic data) and third-party enrichment providers, plus any email addresses you find or add.
  • Connected-mailbox data: if you connect Gmail or Outlook, we access — with your authorization — the data needed to send your outreach and track replies. See Section 3.

2. How we use information

  • Provide, operate, secure, and improve the Service.
  • Authenticate you and protect your account.
  • Enable candidate search, project management, outreach generation, and email sequencing.
  • Send the emails you compose or enroll through your connected mailbox, and show delivery and reply status.
  • Process payments and manage your subscription.
  • Provide customer support and send you service-related communications.
  • Comply with legal obligations and enforce our Terms.

3. Google and Microsoft user data (connected mailboxes)

If you choose to connect a Google (Gmail) or Microsoft (Outlook / Microsoft Graph) account, this section describes exactly how we access, use, store, and share that data. This access is optional and only occurs after you explicitly authorize it through Google or Microsoft.

  • Scopes we request: we request only the minimum permissions needed to (a) send the emails you compose or enroll in a sequence, and (b) read the messages and replies within the conversations you start, so we can thread replies, display delivery and reply status, and automatically stop a sequence when a recipient responds. We do not request permissions beyond what these features require.
  • How we use it: solely to provide and improve the user-facing features above. We do not use Google or Microsoft user data for advertising, and we do not sell it. We do not use it — or any of your data — to train generalized artificial-intelligence or machine-learning models.
  • What we store: the emails you send through the Service and the replies to those conversations, plus message and thread identifiers, so we can show your outreach history and inbox. We do not read or store unrelated messages in your mailbox. Access tokens are stored encrypted and used only to perform the actions above on your behalf.
  • How we share it: we do not transfer Google or Microsoft user data to others except to the subprocessors that host and operate the Service under confidentiality obligations, as needed to provide a feature you request, to comply with law, or in connection with a merger or acquisition with continued protection. We never sell it and never use it for advertising.
  • Revoking access and deletion: you can disconnect your mailbox at any time from the app, which revokes our ongoing access. You may also revoke access directly at your Google Account permissions page (myaccount.google.com/permissions) or your Microsoft account. When you disconnect, or delete your SourceML account, we delete the stored tokens and the mailbox content we hold, as described in Section 6.

4. Google API Services Limited Use disclosure

SourceML’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

5. Microsoft data

Our access to and use of data obtained through Microsoft Graph (Outlook) adheres to the Microsoft APIs Terms of Use and Microsoft’s data-handling requirements. We request only the scopes necessary for the sending and reply-tracking features described above, and we handle that data on the same limited-use basis as Google data.

6. Data retention and deletion

  • We retain personal data while your account is active and as needed to provide the Service and meet legal obligations.
  • When you disconnect a mailbox or delete your account, we delete the associated access tokens and stored mailbox content, typically within 30 days, except where retention is required by law.
  • You can request deletion of your account and associated personal data at any time through the Support page or by emailing us; we will delete or anonymize it as required by applicable law.

7. How we share information

We do not sell your personal information. We share it only:

  • with service providers and subprocessors that operate the Service under contract — for example Supabase (database and authentication hosting), Stripe (payments), and AI/email providers used to power specific features;
  • when required by law, legal process, or to protect the rights, property, or safety of SourceML, our users, or the public;
  • in connection with a merger, acquisition, or sale of assets, with continued protection of your data.

8. Data security

We use industry-standard safeguards, including encryption in transit, encrypted storage of OAuth tokens, access controls, and database row-level security, to protect your data. No method of transmission or storage is completely secure, but we work to protect your information and to promptly address any issues.

9. Your rights and choices

Depending on where you live (for example, under the GDPR in the EEA/UK, or the CCPA/CPRA in California), you may have rights to access, correct, delete, port, or restrict the processing of your personal data, and to object to processing or withdraw consent. To exercise these rights, contact us using the details below; we will respond as required by law, and we will not discriminate against you for exercising your rights.

10. International data transfers

We may process and store data in countries other than the one in which you live. Where required, we rely on appropriate safeguards for international transfers of personal data.

11. Cookies

We use only essential cookies needed for authentication and to keep you signed in. We do not use advertising or cross-site tracking cookies.

12. Children’s privacy

The Service is intended for business use and is not directed to children under 16. We do not knowingly collect personal data from children.

13. Changes to this policy

We may update this Privacy Policy from time to time. We will post the updated version with a new “Last updated” date and, for material changes, provide additional notice.

14. Contact us

For privacy questions, requests, or to delete your data, email support@sourceml.ai or use the Support page in the app.