apsurnapsurn
HomeAboutPricingContact
Get 50 credits

Legal

Privacy Policy

Effective 21 September 2026 · Last updated 21 September 2026

This policy describes how Apsurn (“Apsurn”, “we”, “us”) collects, uses, stores, and shares personal data when you use apsurn.com and the Apsurn application. It is written for Google OAuth verification, GDPR/UK GDPR, and CCPA/CPRA transparency, and for people whose professional contact details appear in customer prospecting lists.

On this page

  • Who we are
  • Who this covers
  • Data we collect
  • Google user data
  • How we use data
  • Legal bases
  • Sharing
  • Retention
  • Security
  • Your rights
  • Cookies and analytics
  • International transfers
  • Children
  • Changes
  • Contact

1. Who we are

Apsurn is a B2B outbound product: company research, ideal-customer profiling, prospect discovery, campaign drafting, and email sending through a mailbox the customer connects.

Controller for the Apsurn service: the operator of apsurn.com. Privacy contact: privacy@apsurn.com.

When a customer uses Apsurn to find or email other professionals, that customer is typically the controller of those prospect records. Apsurn processes that data on the customer’s instructions as a processor, except where we must process it to operate, secure, or improve the platform, or to handle a rights request sent directly to us.

2. Who this covers

  • Customers and trial users who create an Apsurn account, connect a website, connect Gmail, or use the dashboard.
  • Website visitors to apsurn.com, including analytics events if enabled.
  • Prospects and other professionals whose public B2B information is stored because a customer ran prospecting or outreach.

3. Data we collect

Account and billing identity

Email address, authentication identifiers (via our auth provider), company name and website URL you submit, and product settings. We do not ask for payment card numbers in the product today; if billing is added later, card data would be handled by the payment processor, not stored in Apsurn.

Company blueprint and workspace content

Content we generate or you edit from your site and inputs: positioning, ICP, personas, competitors, campaigns, email templates, sequences, enrollments, and send history.

Prospecting and contact data

Professional information from public pages and data providers, which may include name, job title, employer, domain, work email, phone (where present), LinkedIn URL, location, industry, fit scores, and short evidence excerpts. We index professional B2B information. We do not scrape authenticated social sessions. Phone numbers are not used for outreach until applicable do-not-call rules are implemented.

Market insights

Public social and web mentions, keywords, followed accounts, and notes a customer saves, when that feature is used.

Gmail connection

If you connect Gmail: the Gmail address, OAuth tokens (encrypted at rest), granted scopes, connection status, and records of messages Apsurn sends through that inbox (subject, body, timestamps, provider message/thread ids, delivery status). See Google user data.

Analytics on our marketing site

First-party pageviews on apsurn.com (path, referrer, approximate location/device, timestamp) via our own analytics script. We do not sell this data.

Support and privacy requests

Messages you send us, including email and the contents of a data-rights form submission.

Technical logs

IP address, user agent, timestamps, and error logs needed to operate and secure the service.

4. Google user data (Gmail OAuth)

Apsurn’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

When you click Connect Gmail we request:

  • gmail.send — to send outreach mail that you initiate or that you enrolled in a campaign, appearing as mail from your address.
  • userinfo.email — to display which Google account is connected.

We use that Google user data only to:

  • Authenticate the connection and show the connected address in Inboxes and Campaigns.
  • Send emails you compose or that a send pass sends for enrollments you created.
  • Refresh OAuth tokens so sending keeps working until you disconnect.
  • Record send identifiers so we can show status and avoid duplicate sends.

We do not use Gmail content to train generalized AI models. We do not sell Google user data. We do not share it with ads platforms. We do not allow humans to read Gmail tokens or message bodies except (a) with your permission for support, (b) for security/legal investigations, or (c) as required by law. Encrypted refresh and access tokens are stored in our database and are not exposed in the browser.

You can disconnect the inbox in Google Account → Security → Third-party access, and by asking us to delete the connection. After disconnect, Apsurn cannot send as you.

5. How we use data

  • Provide the product: blueprint, campaigns, prospecting, analytics dashboards, copilot.
  • Generate campaign and email drafts with AI providers acting as our processors.
  • Send mail through your connected inbox when you instruct the product to send.
  • Secure the service, prevent abuse, debug, and measure reliability.
  • Respond to support and privacy requests.
  • Comply with law and enforce acceptable use (no unlawful spam or scraping of private data).

6. Legal bases (EEA/UK)

  • Contract — to create your account and provide the features you ask for, including Gmail sending you connect.
  • Legitimate interests — to operate a B2B prospecting platform, secure it, and improve it, balanced against the rights of professionals whose public work details are processed.
  • Consent — where required (for example certain cookies, or connecting Gmail).
  • Legal obligation — tax, accounting, or lawful requests.

Customers are responsible for having a lawful basis to email prospects (for example legitimate interest assessments and CAN-SPAM / CASL / PECR compliance). Apsurn does not replace that obligation.

7. Sharing

We share personal data only with:

  • Infrastructure processors such as our database/auth host (Supabase) and application host.
  • AI processors (currently via OpenRouter / the configured model) to generate blueprints, campaigns, and drafts. Prompts may include the professional context you or the product supply.
  • Prospecting data providers (for example Icypeas and similar APIs) to resolve work emails for companies a customer asked us to find.
  • Google when you connect Gmail, solely to obtain tokens and send mail you authorized.
  • Email delivery for Apsurn’s own mail (for example Resend) for transactional notices such as privacy-request alerts to our team — not for cold outreach from your identity.
  • Professional advisors or authorities when required by law or to protect rights.

We do not sell personal information as defined by CCPA/CPRA.

8. Retention

  • Account and workspace data: until you delete the account or we close it for breach.
  • Prospect lists: until the customer deletes them or a verified suppression/deletion request is completed.
  • Gmail tokens: until you disconnect or the account is deleted.
  • Send logs: kept to operate sequences and abuse prevention, then deleted or aggregated.
  • After a verified suppress request we delete matching contact records and keep only a one-way hash so the same address is not collected again.

9. Security

Access to production data is restricted. Gmail OAuth tokens are encrypted at rest with an application key separate from the database. Transport uses HTTPS. No method is perfect; you should use a unique password and disconnect Gmail if you stop using Apsurn.

10. Your rights

Depending on where you live, you may have rights to access, correct, delete, restrict, port, or object to processing, and to withdraw consent. California residents may request know/delete and we will not discriminate for exercising those rights.

Use the form below or email privacy@apsurn.com. We verify identity (usually via the email address in the record) before changing data. We may refuse unfounded or excessive requests.

You may also complain to your data protection authority. EEA users can contact their local DPA; UK users the ICO.

Submit a data request

For access, correction, deletion, or permanent suppression of professional records tied to an email address.

11. Cookies and analytics

We use essential cookies for authentication and security. The marketing site may load our first-party analytics script to count visits. We do not use that script to serve cross-site advertising. You can block non-essential scripts in your browser; the product login will still require cookies needed for the session.

12. International transfers

We may process data in the United States and other countries where our processors operate. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses with those processors.

13. Children

Apsurn is for business users. We do not knowingly collect data from children under 16. If you believe we have, contact privacy@apsurn.com and we will delete it.

14. Changes

We will update this page when our practices change. The “last updated” date will change. If a change is material, we will provide a more prominent notice in the product or by email where we have an address.

15. Contact

Privacy: privacy@apsurn.com

Product site: apsurn.com

This page is a working privacy notice for the current Apsurn product. It is not legal advice. Have counsel review it before you rely on it for Google verification, enterprise contracts, or a specific jurisdiction. Related: Terms and Conditions.

apsurn

Stay connected

Product
HomePricingFeaturesFAQ
Company
AboutContact
More
Privacy PolicyTerms

All rights reserved.