# Privacy Policy

> How HeyLead collects, uses, shares and deletes your data: Google sign-in, LinkedIn data through Unipile, optional Google Calendar, and visits to heylead.dev.

This is the Markdown twin of https://heylead.dev/privacy (the page, in text). Index for agents: https://heylead.dev/llms.txt

Last updated: September 23, 2026

HeyLead ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the HeyLead application and services (the "Service").

## 1. Information We Collect

We collect the following types of information:

- **Account Information:** When you sign in with Google, we receive your name, email address, and profile picture from your Google account.
- **Google Calendar Data:** Only if you separately choose to connect Google Calendar, we request the `https://www.googleapis.com/auth/calendar.events.owned` permission and store the resulting Google refresh token so we can create events on your behalf. Connecting Calendar is optional and is never part of signing in.
- **LinkedIn Data:** When you connect your LinkedIn account, we access your LinkedIn profile information, posts, connections, and messaging data through the Unipile API to provide our outreach services.
- **Usage Data:** We collect information about how you use the Service, including campaigns created, messages sent, and feature interactions.
- **Device Information:** We may collect information about the device and browser you use to access the Service.
- **Visits to heylead.dev:** A counter records each arrival at the website without anything that identifies you, and your first visit saves a note in your browser about how you found us. Section 9 describes both.

## 2. How We Use Your Information

We use the collected information to:

- Provide, operate, and maintain the Service
- Analyze your LinkedIn writing style to generate voice-matched outreach messages
- Create and manage LinkedIn outreach campaigns on your behalf
- Generate Ideal Customer Profiles (ICPs) and buyer personas
- Send connection requests, messages, and follow-ups through LinkedIn
- Create Google Calendar events on your primary calendar when a prospect agrees to a meeting time, if you have connected Calendar
- Provide analytics and reporting on campaign performance
- Improve and personalize the Service
- Communicate with you about the Service

## 3. Data Sharing and Disclosure

We do not sell your personal information. We may share your data with:

- **Service Providers:** Third-party services that help us operate the Service, including Unipile (LinkedIn API access), Google Cloud (hosting), and AI model providers (message generation).
- **Website Hosting:** Vercel serves the heylead.dev pages and Cloudflare sits in front of them. Like any web server, they receive your IP address and browser details when you load a page.
- **LinkedIn:** Actions performed on your behalf (messages, connection requests, comments) are sent to LinkedIn through your connected account.
- **Legal Requirements:** We may disclose your information if required by law or in response to valid legal process.

## 4. Data Storage and Security

Your data is stored securely on Google Cloud infrastructure. We use encryption in transit (TLS) and implement appropriate technical and organizational measures to protect your data. Campaign data, contact information, and message history are stored in secured databases with access controls.

## 5. Data Retention

We retain your data for as long as your account is active or as needed to provide the Service. You may request deletion of your data at any time by contacting us. Upon account deletion, we will remove your personal data within 30 days, except where retention is required by law.

## 6. Your Rights

Depending on your location, you may have the right to:

- Access and receive a copy of your personal data
- Rectify inaccurate personal data
- Request deletion of your personal data
- Object to or restrict processing of your data
- Data portability
- Withdraw consent at any time

To exercise these rights, contact us at [hello@heylead.dev](mailto:hello@heylead.dev).

## 7. Google API Services User Data Policy

HeyLead's use and transfer of information received from Google APIs adheres to the [Google API Services User Data Policy](https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.

We request two kinds of Google permission, and we request them separately:

- **Sign-in** ( `openid`, `email`, `profile`) — we use your name, email address and profile picture only to authenticate you and identify your account.
- **Google Calendar** ( `https://www.googleapis.com/auth/calendar.events.owned`) — requested only when you choose to connect Calendar, never during sign-in. We use it for one feature: when a prospect agrees to a meeting time in a LinkedIn conversation, HeyLead creates that meeting as an event on your primary Google Calendar, optionally with a Google Meet link and an invitation to the prospect's email address.

**What we do not do with Calendar access.** HeyLead only creates events. We do not read, list, download, modify or delete your existing calendar events, and we do not access any other Google service such as Gmail, Drive or Contacts. We deliberately request the narrower `calendar.events.owned` permission, which covers only calendars you own, rather than the broader `calendar.events`, which would reach every calendar you can see. A narrower permission still would not work: read-only Calendar access ( `calendar.events.readonly`) cannot create the meeting at all.

**What we store, and for how long.** When you connect Calendar we store the Google refresh token issued to us, in our database on Google Cloud SQL, which is encrypted at rest. The token is used solely to obtain short-lived access tokens for creating the events described above. We also store a record of the events HeyLead created (title, start and end time, attendee email address and the resulting event link) so the app can show you what it scheduled. We retain these for as long as your account is active; see “Data Retention” above.

**How to revoke it.** You can withdraw Calendar access at any time at [myaccount.google.com/permissions](https://myaccount.google.com/permissions), which immediately stops HeyLead creating any further events. Revoking Calendar access does not delete your HeyLead account or affect LinkedIn outreach. To have the stored token and event records deleted from our systems, contact us at [hello@heylead.dev](mailto:hello@heylead.dev).

Information received from Google APIs is never sold, never used for advertising, and never used to train generalised AI or machine learning models.

## 8. LinkedIn Data Usage

LinkedIn data accessed through your connected account is used solely to provide the outreach automation services you have requested. This includes reading your profile and posts to match your writing voice, searching for prospects matching your ICP, and sending messages on your behalf. We do not use your LinkedIn data for any purpose other than delivering the Service to you.

## 9. Cookies, Local Storage and Visit Counting

The Service uses essential cookies for authentication and session management. We do not use third-party advertising cookies or cross-site tracking.

**The visit counter.** Every page on heylead.dev runs a small script that counts arrivals. When you arrive from another site, or open the address directly, it sends us two things: the path of the page you opened, such as `/privacy`, without anything after a `?`; and the name of the site that sent you, such as `google.com`, not the full address of the page you came from. We store those two values and the time. The count holds no IP address, no browser details, no cookie and no identifier, so it is not linked to you or to your account. Moving between heylead.dev pages sends nothing. Our server uses your IP address in memory to stop any one address flooding the counter, and never stores it with the count. Because a count holds nothing about you, we keep counts without a time limit.

**How you found us.** heylead.dev keeps nothing in your browser to remember how you arrived: no cookie and no local storage. Instead, when you click Sign in or Start free, the link carries three things from the page you are on: the campaign tags in the address you followed (the `utm_` values), the name of the site that sent you, such as `news.ycombinator.com`, never the full address of that page, and the path of the first heylead.dev page you opened, without anything after a `?`. Each value is cut to 200 characters. Signing in sends those values to us, and we keep them only when that sign-in creates your HeyLead account: they are saved with your account's sign-up record, so we know how you found us. A sign-in to an account that already exists carries them too, and we discard them. Close the tab before you sign in and nothing was kept anywhere.

## 10. Children's Privacy

The Service is not intended for users under the age of 18. We do not knowingly collect personal information from children.

## 11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date.

## 12. Contact Us

If you have questions about this Privacy Policy, please contact us at:

- Email: [hello@heylead.dev](mailto:hello@heylead.dev)
- Website: [https://heylead.dev](https://heylead.dev)
