Privacy & Data

Privacy, Data & Security

What data contactID stores, how your message content stays private, your GDPR rights, cookie controls, and how we handle bot protection ethically.

contactID stores what it needs to run your outreach and nothing more. Here is exactly what is kept.

Account Basics

  • Email and name. Used for sign-in, notifications, and your profile.
  • Phone number and company details. Optional, only if you add them.
  • Sign-in method. Your email/password setup, or your Google account ID and profile photo URL if you sign in with Google.
  • Sessions. Kept active for 30 days on a sliding basis.
  • Plan and payment history. Processed through Stripe. contactID never sees or stores your actual card number.

Agents And Pitches

Everything you set up on the Agent tab is stored, including your message text: agent names, sender identities, pitch templates, and personalization settings.

Websites And Submissions

Every website you import is stored. For every submission, contactID keeps the outcome and the exact field values it typed or selected into the form. This detail is now visible in the Analytics detail view.

AI Personalization Usage

Your AI prompts are stored. For every AI request, contactID also records the model used, the tokens consumed, and the cost.

What contactID Does Not Store

contactID does not keep screenshots of target websites, the content of the sites you contact, or any replies you receive.

Yes. Here is exactly how your pitch content is protected and who can access it.

Encryption And Access Control

  • Encrypted at rest. Your pitches are encrypted in contactID’s database.
  • Access-controlled. Only your account can view them.
  • Encrypted in transit. Every connection, to contactID, to the AI providers, and to the database, uses TLS.

Internal Access

Support staff can view pitch content only when you share a specific record during a support ticket. Every internal access is logged.

AI Provider Access

When AI Personalization is on, your pitch template and the target site’s public content are sent to the AI provider you have chosen (OpenAI, Google, or Anthropic) purely to generate the personalized text. These providers do not retain your prompts, per their own published policies. If a pitch contains sensitive or confidential content, it is best kept out of AI Personalization and sent plain instead.

Once A Form Is Submitted

Once a form is actually submitted, the target site owns that content. contactID has no control over what happens to it afterward.

You are in control of your data, including how and when it is deleted.

Deleting Your Account

  • Go to the dashboard’s Security page and choose to delete your account.
  • Confirm with your password. If you never set one (for example, if you signed up with Google), set one first.
  • This signs you out everywhere immediately and schedules your data for removal.

Before deleting, use Advanced Export to export your websites and agents, and download any invoices you want to keep.

Requesting A Copy Or A Correction

Email contactID from your account address to request a copy of your data or a correction. These requests are answered within 30 days.

What Legally Has To Stay

Payment and invoice records are kept as long as accounting rules require. These records hold only your email address and payment amounts, never your website lists or message content.

Here is what contactID stores in your browser and how to control it.

Essential Cookies (Cannot Be Disabled)

Session and CSRF protection cookies keep the site secure and functional. Since contactID needs these to work, they cannot be turned off.

Analytics And Functional Cookies (Toggleable)

Analytics cookies track anonymized usage patterns, and functional cookies remember your language, timezone, and layout preferences. Both are toggleable in Account Settings.

No Ad Tracking

contactID sets no third-party ad-tracking cookies, does not sell data to advertisers, and does not run Google Analytics for ad targeting or a Facebook Pixel. The only third-party cookies come from Stripe (at checkout) and Google (for sign-in), under their own respective policies.

Do Not Track

contactID respects browser Do Not Track signals. When DNT is on, analytics cookies are automatically disabled.

Extension Storage

The Chrome extension uses Chrome’s sandboxed local storage rather than cookies. This is cleared automatically when you uninstall the extension.

Respecting a site’s Cloudflare or CAPTCHA protection is a deliberate policy at contactID, not a limitation. It honors the site owner’s expressed preference, and it protects your account: bypassing that protection risks getting your IP address banned. This philosophy shows up across the product in several ways.

Transparent Disclosure

On the free plan, every message includes the signature “Sent via contactID extension” in plain text, with no link.

Sending Rate Limits

contactID enforces a per-account sending rate limit of 60 submissions per minute.

Duplicate Contact Guard

The “Contacted Before” guard surfaces every repeat contact so you can decide whether to proceed. There is no forced cooldown; the choice is yours.

Centrally Maintained Blocklist

contactID maintains a blocklist covering government sites, major consumer platforms, and adult content. This list is not user-configurable.

Prohibited Uses

Prohibited uses of contactID include spam, malware or phishing, sexual content or harassment, impersonation, and any illegal activity. Depending on severity, violations can result in warnings, temporary suspension, or account termination.

Still stuck? We’re happy to help.

Install the extension, sign up, or reach out to support directly.

Back to Help Center