1. Information We Collect
Account Information
When you create an account, we collect your name, email address, and password (stored securely using bcrypt hashing). If you sign up via Google or Microsoft OAuth, we receive your basic profile information from those providers.
Email Tracking Data
When you use Outsolvi to track emails, we collect metadata about email interactions, specifically open events (via tracking pixel) and click events (via link redirect).
Connected Mailbox
If you connect your Gmail or Microsoft mailbox to Outsolvi, we access that mailbox on your behalf so the product can do the two things you connected it for: send on your behalf, and notice when someone replies so your follow-ups stop automatically.
To detect replies reliably we synchronise messages from your mailbox to our servers, including received mail. We store the sender and recipients, subject, date, threading identifiers, and the message body. Both sent and received messages are covered, because a reply is by definition mail you received.
We use this only to run the features described above. We do not read your mail for any other purpose, we do not sell it, we do not use it for advertising, and we do not use it to train artificial intelligence or machine learning models. Access is limited to the systems that run these features, and to the small number of staff who need it to investigate a fault you have reported.
Disconnecting the mailbox in Settings stops the synchronisation immediately. Deleting your account removes the stored messages along with the rest of your data, as described in Data Retention below.
Usage Data
We collect standard usage analytics: pages visited, feature usage, device type, browser, and IP address. This helps us improve the product.
2. How We Use Your Data
- To provide and operate the Outsolvi email tracking service
- To display engagement analytics on your dashboard
- To send transactional emails (verification, password reset, billing)
- To detect and filter bot/scanner activity from genuine opens
- To improve our product and fix bugs
- To enforce our Terms of Service and prevent abuse
3. Data Storage & Security
Your data is stored on secure cloud infrastructure (PostgreSQL on Neon, hosted in AWS US-East). All data is encrypted in transit (TLS 1.3) and sensitive fields (OAuth tokens, API keys) are encrypted at rest using AES-256-GCM.
Passwords are hashed with bcrypt (12 rounds). We support two-factor authentication (TOTP) for admin accounts.
4. Cookies
We use essential cookies for authentication sessions and CSRF protection. We also use analytics cookies set by Mixpanel to understand how the product is used so we can find and fix problems. We do not use advertising cookies, and we do not run ad networks or ad retargeting.
5. Third-Party Services
We share limited data with these service providers:
- Dodo Payments, payment processing (billing info only)
- Resend, transactional email delivery
- Neon, database hosting
- Amazon Web Services, application hosting
- Cloudflare, DNS, CDN, and DDoS protection
- Mixpanel, product analytics. Receives your email address and account id so usage can be attributed to your account, plus which features you use. It does not receive the contents of your emails.
- Intercom, customer support messaging
- Sentry, error monitoring, so crashes reach us with enough context to fix them
- Grafana Cloud, server log storage used for debugging and security investigations
We never sell your data to third parties or use it for advertising.
6. Data Retention
We retain your account data for as long as your account is active. Email tracking events are retained for up to 12 months. When you delete your account, we remove all personal data within 30 days.
7. Your Rights
You have the right to:
- Access your personal data
- Correct inaccurate data
- Delete your account and associated data
- Export your data in a portable format
- Withdraw consent for optional data processing
If you are in the EU/EEA, you have additional rights under GDPR including the right to lodge a complaint with a supervisory authority.
8. Email Tracking Transparency
Outsolvi uses a 1x1 transparent tracking pixel to detect when recipients open tracked emails. We also wrap links to detect clicks. We employ bot filtering and confidence scoring to ensure accuracy, our system distinguishes between genuine human opens and automated security scans.
We do not access the body or subject of your emails. The tracking pixel only records: timestamp, approximate location (if available), device type, and a confidence score.
9. Browser Extension and Email Add-ins
Our Gmail browser extension and our Outlook add-ins are how tracking is added to the emails you send. This is what they do and do not do.
What they access:
- The compose window of an email you are writing: the recipients, the subject, and the message body, so the tracking pixel and tracked links can be inserted before you send.
- Your Outsolvi session, so the tracked email is saved to your account.
What they do not do:
- They do not read your inbox or your received mail. The extension and add-ins only see the message you are composing. Reply detection is handled separately by the connected mailbox described in section 1, and only if you have connected one.
- They do not track emails other people send to you, only the ones you send.
- They do not collect your Google or Microsoft password. Sign-in uses the provider's own authentication screen.
- They do not sell any data.
The extension sends product analytics to Mixpanel, including your email address and account id, so we can attribute feature usage and error rates to an account and fix reliability problems. It also reports its own version and health so we can tell you when an update is needed. Email contents are never sent to Mixpanel.
You can remove the extension at any time from your browser's extensions page. Removing it stops all new tracking immediately; engagement already recorded stays on your dashboard until you delete it.
10. Google User Data and Limited Use
Outsolvi's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, for data obtained through Google APIs:
- We use it only to provide and improve the features you connected your mailbox for.
- We do not transfer it to others except as needed to provide those features, to comply with the law, or as part of a merger or acquisition, and never for advertising.
- We do not use it for advertising, and we do not sell it.
- We do not use it to develop, improve, or train generalised artificial intelligence or machine learning models.
- We do not allow humans to read it, except with your explicit consent for a specific issue you have raised, where it is necessary for security purposes such as investigating abuse, to comply with the law, or where the data has been aggregated and anonymised.
You can review or withdraw Outsolvi's access to your Google account at any time at myaccount.google.com/permissions.
11. Changes to This Policy
We may update this policy from time to time. We will notify you of material changes via email or an in-app notice. The “Last updated” date at the top reflects the most recent revision.
12. Contact Us
If you have questions about this Privacy Policy or your data, contact us at support@outsolvi.com.