LeadSweeper

Privacy Policy

Last updated 14 September 2026

Who we are

LeadSweeper is operated by Martin Frelih s.p., Godovič 54A, 5275 Godovič, Slovenia. For the purposes of the EU General Data Protection Regulation we are the controller of the personal data described below. You can reach us at martin@frelih.net.

What LeadSweeper does

LeadSweeper helps marketing agencies find local businesses that are currently running advertising, collect publicly available contact details for them, draft outreach emails, and send those emails from the agency’s own inboxes.

Google account data

This section describes exactly what we receive from Google and what we do with it. It is deliberately specific, because the honest answer is narrower than most applications require.

The permissions we ask for

ScopeWhy
openid, emailTo learn which Gmail address you just connected, so the app can show it to you and send from the right mailbox.
gmail.sendTo send the outreach emails you have written and approved, from your mailbox, at the rate you set.
gmail.metadataTo notice replies. For each conversation LeadSweeper started, it reads the headers of the messages in it (sender, subject, date and the headers that mark an automatic reply), so a business that answered is not sent a follow-up.

What we cannot do

We do not request any permission to read the content of your mail, or to search, download, label, modify or delete it. The gmail.metadata permission does not give access to the text or attachments of any email, only to headers, and LeadSweeper asks only for the conversations it started. It keeps a record only of messages that answer an email it sent: sender, subject and time. An account connected before this permission was requested can only send, and replies to it are marked by hand.

What we store

  • The email address of each connected Google account, and a display name if Google provides one.
  • OAuth access and refresh tokens, so sending can continue on the schedule you chose without you being present. These are encrypted with AES-256-GCM inside the application before they are written to the database, so they are not readable from a database backup or by the database provider.
  • A record of each message sent through your account: recipient, subject, body, and the time it went out.

Limited Use

LeadSweeper’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, we do not transfer Google user data to third parties except as necessary to provide or improve the service, we do not use it for advertising, we do not sell it, and we do not allow humans to read it except with your explicit consent, to resolve a support issue you have raised, for security purposes, or where required by law.

The content of your outreach emails is drafted by an AI model before it is sent (see Subprocessors). That drafting happens from the business information LeadSweeper collected, not from anything in your mailbox.

Disconnecting

You can disconnect a Google account at any time in Settings, which deletes the stored tokens and stops all sending from it. You can also revoke access directly at myaccount.google.com/permissions.

Inboxes connected with an app password

You can instead connect an inbox with its address and an app password, a separate password your email provider issues for one application. This does not use Google sign-in or any Google API permission. The app uses it for two things only:

  • Sending the outreach emails you have written and approved, over SMTP, at the rate you set.
  • Noticing replies, over IMAP. Every few minutes the app reads the headers of messages that arrived in the inbox since it last looked (sender, subject, date, and the headers that say which message they answer), and the text of delivery-failure notices, to find which address failed. It opens the inbox read-only: nothing is marked read, moved, labelled or deleted. It keeps a record only of messages that answer an email LeadSweeper sent: sender, subject and time. Nothing else from the inbox is stored.

An app password technically allows more than this, which is why it is encrypted with AES-256-GCM inside the application before it reaches the database, and why removing the inbox in LeadSweeper deletes it. You can also revoke it at any time from your email provider’s account settings.

Your account data

  • Your email address and password, which is hashed and never stored in readable form.
  • Your business details: name, description, postal address, who you sell to, and your preferred tone. The postal address is used in the footer of the emails you send, because anti-spam law in most jurisdictions requires a physical address in commercial mail.
  • Your campaigns, offers, copy settings and sending schedules.
  • Billing records. Card details are handled by Stripe and never reach our servers.

Data about the businesses you search for

This is the part of LeadSweeper that handles other people’s data, so it deserves plain description.

When you run a search, LeadSweeper collects information about local businesses from publicly available sources: business listings, the businesses’ own websites, and public advertising archives such as the Meta Ad Library and the Google Ads Transparency Centre. This includes business names, addresses, phone numbers, websites, social profiles, published email addresses, and the names and job titles of people published on those websites.

Where those details identify an individual, for example a named owner of a practice, that is personal data and we process it on the basis of legitimate interests: business-to-business outreach to a publicly listed professional contact. We do not collect special category data, and we do not build profiles beyond what is needed to write one relevant email.

If you are a business owner who has received an email sent through LeadSweeper and you want your details removed, write to martin@frelih.net and we will delete them and add you to a suppression list so they are not collected again. You do not need an account to make that request.

Who we share data with

We do not sell personal data. We use a small number of processors to run the service, each listed with what it receives on the Subprocessors page.

How long we keep it

  • Account and campaign data: for as long as your account exists, and deleted within 30 days of you closing it.
  • Google tokens: until you disconnect the account or close your account, whichever comes first.
  • Sent message records: kept while the account exists, because they are what stops the same business being emailed twice.
  • Suppression list entries: kept indefinitely, since their entire purpose is to remember not to contact somebody.

Where data is held

Data is stored with Supabase and served through Vercel. Some processors operate outside the European Economic Area, in which case transfers rely on the European Commission’s Standard Contractual Clauses or an adequacy decision.

Your rights

If you are in the EU or UK you have the right to access, correct, delete, restrict or object to our processing of your personal data, and to receive it in a portable form. Write to martin@frelih.net and we will respond within one month. You may also complain to your national data protection authority; in Slovenia this is the Information Commissioner.

Security

Access to your data is enforced at the database level, so one account’s rows are not reachable from another. Google refresh tokens are encrypted with AES-256-GCM before storage. Traffic is served over HTTPS. No system is perfectly secure, and we will notify affected users and the relevant authority without undue delay if a breach occurs that is likely to result in a risk to them.

Children

LeadSweeper is a business tool and is not directed at anyone under 18.

Changes

If we change this policy we will update the date at the top, and for material changes we will tell account holders by email before the change takes effect.