Privacy Policy
Last updated: August 10, 2026
1. Who we are
Emerging Technology Group LLC ("we", "us") operates the LeadFuel suite at leadfuel.cloud and related subdomains. For questions about this policy contact privacy@leadfuel.cloud.
2. Data we collect
LeadFuel is more than one product: the B2B outbound tools (Scope, Reach, Signal, Orbit) and the personal suite (Life, Echo, Lucid) share the same account and the same underlying data store. What follows covers both. We only collect a category below if you've connected, uploaded, or turned on the feature that produces it.
- Account data: email, name, organization, sign-in timestamps.
- Product usage: features used, sessions, AI prompts and responses, admin actions (retention: 90 days, aged out by an automated daily process; see §7).
- Customer-supplied content: ICPs, campaign drafts, prospect lists, and any document, note, or file you upload to the Knowledge System or Briefcase, including a data export from another product (for example, a ChatGPT conversation export) if you choose to import one.
- Mail and calendar content: if you connect Gmail, Microsoft 365, or Google Calendar, we read message and event content (not just metadata) to run the features you use: relationship intelligence, drafting, scheduling, and the personal-model features described below. See §5 for the Google-specific disclosure. Certain confirmation/receipt emails from a short list of recognized senders (for example ClassPass, Planet Fitness, Mindbody) can be parsed into fitness-session records; this is off by default and requires the account owner to explicitly turn it on.
- Connected wearables and meeting recorders (Fieldy, Fireflies): if you connect a Fieldy device or a Fireflies account (by pasting your own API key or pointing their webhook at your private ingest URL, entirely your choice), we store the conversation transcripts, summaries, and action items they send us. A Fieldy transcript can include the words of other people who were present and did not create a LeadFuel account. We have no way to ask them for consent, so you are responsible for getting any consent that recording-of-others law requires in your jurisdiction before you connect and use a Fieldy device around other people. Before any Fieldy data reaches us at all, we require you to explicitly confirm that responsibility at /fieldy/consent, an attestation that stays current only for a year at a time rather than a box you tick once at signup and forget; revoking it there stops new Fieldy data immediately. Once a conversation is in, segments the system could not attribute to you (someone else's voice, or a voice it simply couldn't tell) have their text automatically redacted 30 days after the conversation happened, kept only as a record that a conversation occurred, not what the other person said. Your own words are not affected by that limit and are kept until you delete them.
- Financial data (QuickBooks): if you connect QuickBooks, we pull your financial records on a recurring basis to power money-related features and summaries.
- Location: the product can derive a coarse "current city" from your calendar's meeting locations, or accept GPS pings from a connected companion app, to power location-aware features. This capability exists in the code but is behind a feature flag that is not turned on for most accounts today. We're listing it because we'd rather over-disclose a dormant capability than under-disclose a live one.
- Connected accounts: encrypted OAuth tokens for Google (Gmail + Calendar), Microsoft 365, LinkedIn, Slack, and Resend (we never see your provider passwords).
- Billing: Stripe stores your card and processes payments; we store only the Stripe customer/subscription identifiers.
3. How we use it
- Run the product features you signed up for.
- Build and keep current a personal model of you ("the Self") from the content you've connected (episodic memory, documents, and, if enabled, mail-derived signals), so features like your report, planning, and relationship intelligence can reason over your own history. This runs both when you explicitly request it (for example "Re-analyze") and automatically in the background as new data lands, bounded by a per-account cost cap. See §4 for what that sends to Anthropic.
- Send transactional emails (sign-in links, billing receipts, account notices).
- Send marketing emails only if you've opted in. You can opt out via any marketing email's Unsubscribe link.
- Improve the product (aggregated, de-identified usage analytics).
- Detect abuse, prevent fraud, and comply with legal obligations.
4. Sub-processors and what we actually send them
We use a small set of vendors to operate the product. This list is deliberately specific rather than reassuring. See /data-policy for the full per-service breakdown.
- Railway: application hosting and managed Postgres.
- Resend: transactional and marketing email delivery.
- Stripe: payment processing.
- Anthropic: runs the AI features across the suite, including ICP synthesis and, for the personal suite, the deep-inference "Self" engine. That engine's prompts are built from a sampled selection of your own connected content, which, when you've connected mail, can include mail-derived text and the names/addresses that appear in it, along with your uploaded documents and (if you've imported one) your ChatGPT conversation history. This is a correction to an earlier version of this page, which said no contact PII or mail content ever reached Anthropic; that was inaccurate. We do not send Fieldy conversation transcripts or raw location pings to Anthropic through this pipeline: those categories are excluded from the sample by design. Per Anthropic's commercial API terms, prompts sent through the API are not used to train their models.
- OpenAI: used for optional voice-based ICP intake (Realtime API) where offered, and, only if the founder has turned it on for an account, transcription of an uploaded voice recording during a data import. Not used for training under OpenAI's API terms.
- Unipile: powers optional LinkedIn messaging. Dormant unless the account has explicitly connected LinkedIn messaging.
- Fireflies.ai: only if you connect it yourself (see §2); we pull the meeting data associated with your Fireflies account.
- Microsoft / Google: process your connected mailbox and calendar as described in §2 and §5.
- OpenWeb Ninja and BestTime: place- and foot-traffic-intelligence providers. Both now have API keys configured, and OpenWeb Ninja is switched on: when a plan looks for somewhere to go, we send a place query (a category and a coordinate) and get back candidate venues. BestTime is keyed but returns nothing at present, its quota being spent. Neither receives your mail, your documents or your contacts. This corrects an earlier version of this page, which said neither had a key configured; that stopped being true when world-context was enabled.
- B2B Rocket and Microsoft Clarity:
portal.leadfuel.cloudis a partner portal operated by B2B Rocket, and the page it serves loads Microsoft Clarity, which records session activity (clicks, scrolling, page views) on that hostname. It is a separate surface from the app: nothing you store in LeadFuel is exposed to it, and Clarity does not run on any otherleadfuel.cloudhost. - Sentry: error tracking (no request bodies, no cookies).
5. Google user data (Limited Use disclosure)
LeadFuel's use and transfer of information received from Google APIs to any other
app will adhere to the
Google API Services User Data Policy,
including the Limited Use requirements. Concretely: when you connect a Google
account, we request read access to Gmail (and, if you opt into mailbox management,
the ability to modify/archive/label/send) plus read and event-management access to
Google Calendar. We deliberately never request the unrestricted
mail.google.com scope, which would allow permanent deletion. Gmail and
Calendar data are used only to power the product features described in §2 and §3 of
this policy (drafting, relationship intelligence, scheduling, and, if you've
connected mail, the Self engine described in §4). It is never used for advertising,
and never sold. Only automated systems and the account owner access this data in the
normal course of operation; a human at LeadFuel accesses it only for support you
request, security investigation, or a legal obligation.
6. Your rights (GDPR / CCPA)
While logged in you can:
- Export every record we keep about you:
GET /api/me/export. The export enumerates the same underlying tables our deletion tooling erases, and it refuses to hand back a silently-incomplete bundle: a partial export fails loudly instead of pretending to be complete. Uploaded document files are included as actual downloadable content, not a size marker: the bytes are bundled directly into the export, or, for a document too large to inline, a real per-document download link is provided instead. - Delete just what one connected source taught us, immediately, without touching
your account:
POST /api/data/delete-source(for example, remove everything learned from Fireflies or Fieldy without deleting your account), orPOST /api/data/delete-allto clear all learned/inferred data while keeping your account and mailboxes connected. - Request deletion of your account and data:
POST /api/me/delete. Your access is revoked immediately, and your data is permanently purged after 30 days by an automated daily process. If you've linked more than one login email to the same person, deletion and export both cover every linked identity, not just the one you're logged in as.
If you can't access the product, email privacy@leadfuel.cloud with proof of identity and we'll honor your request within 30 days.
7. Retention
- Account data: kept for the life of your account, then purged automatically 30 days after a deletion request.
- Audit logs: 90 days, aged out automatically by a daily background process.
- Mailbox-derived episodic memory and other learned/inferred content (the personal-model "corpus" behind Life/Echo/Lucid and the relationship intelligence features): kept until you delete it (via §6's tools) or delete your account. There is no fixed age-out on this category today. We are stating that honestly rather than implying a schedule that doesn't exist.
- Fieldy conversation segments: kept until you delete them or delete your account. There is no age-out. An automatic 30-day redaction of segments we could not attribute to you ran between 17 and 23 August 2026 and has been stopped; the text it had removed was restored on 24 August 2026. We are stating that plainly rather than describing a schedule that no longer runs. See §2's Fieldy entry.
- Billing records: 7 years (US/EU tax law).
8. Security
HTTPS-only, encrypted at rest (Postgres + Fernet for OAuth tokens), session cookies signed and SameSite-strict, magic-link tokens hashed (SHA-256), CSRF protection on every form, rate limits on auth + send endpoints. We are not a HIPAA-eligible vendor, so please do not upload protected health information.
9. Changes
Material changes will be emailed to the account address on file at least 30 days before they take effect.