Privacy Policy

Last updated: April 6, 2026

Overview

Flint ("we," "our," or "us") is an AI-powered outreach platform that helps businesses find leads, generate personalized email content, and manage multichannel outreach sequences. This Privacy Policy describes how we access, collect, use, store, and share your information when you use our service at flinthq.net.

Information We Collect

Account Information

When you create a Flint account, we collect your name, email address, company name, and password. This information is used to identify you and manage your account.

Lead Data

Flint integrates with Apollo.io to search for and import business contact information. The lead data you import (names, titles, company names, email addresses, LinkedIn URLs, and employment history) is stored in your Flint workspace and is only accessible to members of your organization.

Content You Create

We store the outreach content generated by our AI on your behalf, including email drafts, playbooks, messaging rules, and sequence configurations. This content is created for your use and is not shared with other users.

Google User Data

Flint accesses Google user data through the Gmail API. This section specifically describes how we handle data obtained through Google APIs, in compliance with the Google API Services User Data Policy.

Scopes We Request

  • gmail.send — Used to send outreach emails on your behalf from your connected Gmail account. Flint only sends emails that you have reviewed and approved (or that you have explicitly enabled for auto-sending in your settings).
  • userinfo.email — Used to identify which Google account you are connecting and to display your email address in the Flint settings page.

How We Use Google User Data

Google user data accessed through the Gmail API is used exclusively to:

  • Send outreach emails from your Gmail account on your behalf
  • Display your connected email address and sending status in the Flint dashboard

How We Store Google User Data

We store OAuth access tokens and refresh tokens securely in our database to maintain your Gmail connection. These tokens are encrypted and are only used to authenticate API requests on your behalf. We store the message ID of emails sent through Flint to enable reply tracking. We do not store the full content of your Gmail inbox or any emails not sent by Flint.

Google User Data We Do NOT Access

Flint does not:

  • Read your entire Gmail inbox
  • Access emails not related to Flint outreach
  • Access Gmail drafts, labels, or settings
  • Access Google Drive, Calendar, Contacts, or any other Google services
  • Modify or delete any existing emails in your Gmail account

Data Sharing

We do not sell, trade, rent, or transfer Google user data to any third party. Google user data is never used for advertising, retargeting, credit assessment, or any purpose other than providing the Flint outreach service as described in this policy.

Data Retention and Deletion

OAuth tokens are retained as long as your Gmail account is connected to Flint. You can disconnect your Gmail account at any time from the Flint Settings page, which will revoke our access and delete the stored tokens. When you delete your Flint account, all associated Google user data (tokens, message IDs, sending history) is permanently deleted from our systems.

Third-Party Services

Flint integrates with the following third-party services to provide its functionality:

  • Apollo.io — Lead search and enrichment. When you search for leads, your search criteria are sent to Apollo's API. Apollo's use of data is governed by their own privacy policy.
  • Anthropic (Claude AI) — AI content generation. Lead data (names, titles, company information) is sent to Anthropic's API to generate personalized email content. Anthropic does not use this data for training. See Anthropic's Privacy Policy.
  • Supabase — Database and authentication. Your account data and lead data are stored in a Supabase-hosted PostgreSQL database with row-level security.
  • Vercel — Application hosting. The Flint dashboard is hosted on Vercel's infrastructure.

We do not share your data with any third parties beyond what is necessary to provide the services described above. We do not sell or transfer user data to data brokers, advertisers, or information resellers.

Data Security

We implement appropriate technical and organizational measures to protect your data, including:

  • All data is transmitted over HTTPS (encrypted in transit)
  • Database access is controlled by row-level security policies scoped to your organization
  • OAuth tokens are stored securely and are only accessible by server-side processes
  • API keys are stored per-organization and are not exposed to the client
  • Authentication is required for all application pages and API endpoints

Your Rights

You have the right to:

  • Access your data — all data is visible in your Flint dashboard
  • Export your data — you can export your lead lists and outreach history
  • Delete your data — you can delete individual leads, lists, or your entire account
  • Revoke Google access — disconnect Gmail from the Settings page at any time
  • Opt out of automated sending — control auto-send settings in your dashboard

Email Tracking

Flint uses a tracking pixel (a small transparent image) in outreach emails to detect when a recipient opens an email. This tracking records the time of open and is used to update your outreach analytics. No personal information about the recipient is collected beyond the fact that the email was opened. Recipients' email clients may block tracking pixels, in which case the open will not be recorded.

Children's Privacy

Flint is a business-to-business service and is not intended for use by individuals under 18 years of age. We do not knowingly collect personal information from children.

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the updated policy on this page and updating the "Last updated" date. Your continued use of Flint after any changes constitutes your acceptance of the updated policy.

Contact Us

If you have questions about this Privacy Policy or how we handle your data, contact us at:

Email: privacy@flinthq.net

Website: flinthq.net