Last updated: 21 August 2026
Most privacy policies only need to cover the people who signed up. MagFlow AI is different: it also processes contact information about people who never created an account or interacted with us directly — the business contacts our customers are researching for cold outreach. This policy addresses both:
| Data | Why |
|---|---|
| Email, company name | Account creation and login |
| Billing details | Handled by Stripe directly — we store only your Stripe customer/subscription ID, never raw card details |
| Your own website URL and offer description | To draft your ideal-customer profile and generate on-brand outreach copy |
| Sending-platform API keys (Instantly/Smartlead), if you provide them | Stored to push leads to your own connected account on your instruction — never used for any other purpose |
| Usage data (campaigns run, leads processed, feature use) | Product operation, your monthly usage cap, support |
For each lead a Customer's campaign discovers, we may collect: name, job title, business email, company name and domain, and short excerpts of publicly available text (company website content, publicly indexed search results, publicly accessible job postings) used to verify and corroborate that contact's details. This data comes only from sources that are publicly accessible without logging in or bypassing any access control — we do not purchase lists from data brokers, and we do not access authenticated or login-walled platforms (for example, we do not log into LinkedIn on anyone's behalf).
Because lead contacts haven't consented to this processing directly, this is the part of our practice that carries the most legal weight, and we want to be direct about it rather than vague.
We (and our Customers) process lead contact data under the "legitimate interests" basis (GDPR Article 6(1)(f); Recital 47 specifically identifies direct marketing as a potential legitimate interest). We rely on this basis, and not consent, because:
If you've received an email or seen a landing page generated by MagFlow AI on a Customer's behalf, you have the right to:
We aim to action any lead-contact request within 30 days.
We use third-party AI models (DeepSeek) to extract structured information from scraped public text and to draft outreach copy. Text sent to these providers for processing is limited to what's needed for that specific task (e.g. a company's public webpage text, not a full personal profile), and is not used by us to build unrelated profiles on individuals.
Data is stored with Supabase (Postgres), with access controls restricting each Customer's data to their own account. We use industry-standard measures to protect data in transit and at rest, but no system is 100% secure, and we can't guarantee absolute security.
Account data is retained for as long as your account is active. Lead contact data is retained for as long as reasonably needed to serve the Customer relationship it was collected for, or until an opt-out/erasure request is honored, whichever is earlier.
We do not sell personal data to third parties, and we do not share lead contact data with anyone outside the Customer whose campaign generated it and the processors listed above.
Our infrastructure providers (including Supabase and our AI/search processors) may process data outside your own country. Where personal data is transferred internationally, we rely on those providers' own standard contractual clauses (SCCs) or equivalent safeguards recognized under GDPR/UK GDPR as the transfer mechanism. (This is accurate as a general mechanism but not verified against the specific hosting region of this Supabase project — confirm your project's region in the Supabase dashboard and have a lawyer confirm this section names the correct safeguard for that region before launch.)
We may update this policy as the Service evolves. Material changes will be reflected here with an updated date.
Privacy questions or requests, from account holders or lead contacts alike: [email protected]