Privacy Policy

Last updated: 21 August 2026

This is a genuine, substantive draft tailored to how MagFlow AI actually collects and processes data — not generic filler — but it is not a substitute for review by a qualified lawyer, especially given GDPR/UK GDPR enforcement risk around processing business contact data found through public sources. Have it reviewed before relying on it as your live policy, particularly section 4 below.

1. Two different groups of people this policy covers

Most privacy policies only need to cover the people who signed up. MagFlow AI is different: it also processes contact information about people who never created an account or interacted with us directly — the business contacts our customers are researching for cold outreach. This policy addresses both:

2. What we collect from account holders

DataWhy
Email, company nameAccount creation and login
Billing detailsHandled by Stripe directly — we store only your Stripe customer/subscription ID, never raw card details
Your own website URL and offer descriptionTo draft your ideal-customer profile and generate on-brand outreach copy
Sending-platform API keys (Instantly/Smartlead), if you provide themStored to push leads to your own connected account on your instruction — never used for any other purpose
Usage data (campaigns run, leads processed, feature use)Product operation, your monthly usage cap, support

3. What we collect about lead contacts

For each lead a Customer's campaign discovers, we may collect: name, job title, business email, company name and domain, and short excerpts of publicly available text (company website content, publicly indexed search results, publicly accessible job postings) used to verify and corroborate that contact's details. This data comes only from sources that are publicly accessible without logging in or bypassing any access control — we do not purchase lists from data brokers, and we do not access authenticated or login-walled platforms (for example, we do not log into LinkedIn on anyone's behalf).

4. Legal basis for processing lead contact data (GDPR / UK GDPR)

Because lead contacts haven't consented to this processing directly, this is the part of our practice that carries the most legal weight, and we want to be direct about it rather than vague.

Legal basis: legitimate interests

We (and our Customers) process lead contact data under the "legitimate interests" basis (GDPR Article 6(1)(f); Recital 47 specifically identifies direct marketing as a potential legitimate interest). We rely on this basis, and not consent, because:

Your rights, if you're a lead contact

If you've received an email or seen a landing page generated by MagFlow AI on a Customer's behalf, you have the right to:

We aim to action any lead-contact request within 30 days.

Operational gap worth flagging honestly: as of this policy being written, opt-outs are handled per-request rather than through an automated cross-campaign suppression list that prevents a person from being re-surfaced in a future, unrelated campaign. For genuine ongoing GDPR/CAN-SPAM compliance at scale, building a real suppression-list feature (a permanent do-not-contact record checked before every future enrichment) is a meaningful next step, not just documentation — flagging this so it doesn't get lost as "already handled."

5. How we use AI processing

We use third-party AI models (DeepSeek) to extract structured information from scraped public text and to draft outreach copy. Text sent to these providers for processing is limited to what's needed for that specific task (e.g. a company's public webpage text, not a full personal profile), and is not used by us to build unrelated profiles on individuals.

6. Data storage and security

Data is stored with Supabase (Postgres), with access controls restricting each Customer's data to their own account. We use industry-standard measures to protect data in transit and at rest, but no system is 100% secure, and we can't guarantee absolute security.

7. Data retention

Account data is retained for as long as your account is active. Lead contact data is retained for as long as reasonably needed to serve the Customer relationship it was collected for, or until an opt-out/erasure request is honored, whichever is earlier.

8. Third parties we share data with

We do not sell personal data to third parties, and we do not share lead contact data with anyone outside the Customer whose campaign generated it and the processors listed above.

9. International transfers

Our infrastructure providers (including Supabase and our AI/search processors) may process data outside your own country. Where personal data is transferred internationally, we rely on those providers' own standard contractual clauses (SCCs) or equivalent safeguards recognized under GDPR/UK GDPR as the transfer mechanism. (This is accurate as a general mechanism but not verified against the specific hosting region of this Supabase project — confirm your project's region in the Supabase dashboard and have a lawyer confirm this section names the correct safeguard for that region before launch.)

10. Changes to this policy

We may update this policy as the Service evolves. Material changes will be reflected here with an updated date.

11. Contact

Privacy questions or requests, from account holders or lead contacts alike: [email protected]