Privacy Policy
Effective
1. Information we collect
When you create an Overwise account, we collect: your name and email address (from your OAuth provider), your mailbox content via OAuth-scoped read access (sent folder for brand-voice extraction; inbox for reply triage), the lead data and campaign settings you create, and usage logs (timestamps, IPs, user agents).
We do not collect: payment-card details (Stripe handles those — we only see the last 4 and brand), passwords (we use OAuth only), browsing history, social-graph data, or any data not directly required to provide the service.
2. How we use your information
To provide the service: discovering leads, drafting outreach, sending email, classifying replies, billing. To support you: troubleshooting and account-recovery. To improve the product: aggregated, anonymized analytics on feature usage and error rates.
We do not use your data to train AI models. Anthropic and OpenAI prompts are sent with explicit no-training flags. Your sent-folder samples used for brand-voice extraction live only in your project — never shared, never aggregated.
3. Sub-processors
We use the following sub-processors. Full list and details on the Security page.
- Anthropic (LLM drafting + classification — US/EU)
- OpenAI (embeddings for voice extraction — US)
- MongoDB Atlas (data storage — EU-Central, Frankfurt)
- Stripe (billing — US/EU)
- Postmark (transactional email — US)
- Apify (lead-discovery scraping — EU)
4. Data retention
Active account: data retained as long as your subscription is active. After cancellation: data is read-only for 30 days (so you can re-activate without loss), then hard-deleted from primary storage. Backups are retained for an additional 60 days, then purged.
To request immediate deletion, email tobias@overwise.com from the email associated with your account.
5. Your rights
Under GDPR and applicable laws, you have the right to access, correct, port, or delete your personal data. Most rights can be exercised directly from the Settings page in-app: download lead data as CSV, edit account info, delete the account. For requests not self-serve, email tobias@overwise.com; we respond within 30 days.
7. Contact
Privacy questions or data-subject requests: tobias@overwise.com. We aim to respond within 30 days. For EU residents: you may also lodge a complaint with your local supervisory authority.