Privacy Policy

Effective date: July 2, 2026

This Privacy Policy explains what information Salf AI ("Salf", "we", "us") collects when you use the Salf application at salf.ai, how we use it, who we share it with, and the choices you have. It reflects how the product actually works today during our private beta.

1. Who we are

Salf is an AI sales-development assistant for B2B SaaS founders. It researches accounts, builds an ideal customer profile, drafts and sends outbound email, triages replies, and books meetings on the user's behalf using the user's own Google account.

For the purposes of GDPR, Salf is the data controller of account data we collect about you (the Salf user), and a data processor for the contact data, email content, and calendar data we handle on your behalf.

2. Information we collect

2.1 Account data

  • Email address, hashed password (managed by our authentication provider), and sign-in timestamps.
  • Session metadata: device user-agent, truncated IP address, and last-active time, used to power the Active Sessions screen.
  • Optional profile information you enter: sender name, company name, and physical mailing address (required to send outbound email under CAN-SPAM).
  • Optional multi-factor authentication (MFA) state: if you enable time-based one-time password (TOTP) MFA, we store the enrollment record needed to verify future codes and a set of hashed recovery codes. We do not store recovery codes in plaintext.

2.2 Google OAuth data

If you connect Google, Salf stores:

  • Your Google account email and Google user ID.
  • OAuth access and refresh tokens, encrypted at rest with AES-GCM before being written to our database.
  • The set of OAuth scopes you granted.

2.3 Gmail data

  • Metadata and content of inbound replies to outreach Salf has sent or is tracking, including subject, body, headers needed for threading, message ID, and Gmail's internalDate timestamp.
  • Messages Salf sends on your behalf, plus the Gmail message ID and thread ID returned by Google.

Salf does not bulk-read or index your inbox. It accesses messages tied to threads it initiated or replies to addresses it is tracking for your active campaigns.

2.4 Calendar data

  • Events Salf creates on your primary calendar when booking a meeting (title, attendees, start/end time, time zone, Google Meet link).
  • Free/busy lookups used to propose meeting times. Salf reads availability windows; it does not store the titles or descriptions of unrelated events.

2.5 Prospect and company data

  • Companies and contacts you add or that Salf surfaces through enrichment providers (name, title, company, work email, optionally phone numbers you have explicitly revealed).
  • Outreach activity: drafts, sent messages, replies, classifications, and scheduling outcomes.
  • Account signals (e.g. open job postings) gathered from public sources to score accounts.

2.6 AI prompts and responses

When Salf classifies a reply, extracts a meeting time, drafts a message, or builds an ICP, we send the relevant inputs (prompt + necessary context such as the reply text or company description) to our AI provider and store the resulting output in your account.

2.7 Logs and operational data

  • Application logs, error reports, request rate-limit counters, and security audit events (e.g. failed authentication, OAuth connect/disconnect, quota hits).
  • Truncated IP addresses for abuse prevention and rate limiting.

Logs are automatically scrubbed for tokens, API keys, and obvious PII before being stored.

2.8 What we do not collect

  • We do not run third-party web analytics or advertising trackers on the application today.
  • We do not use advertising cookies.
  • We do not sell personal data.
  • Salf does not currently accept user-uploaded files.

3. How we collect it

  • Directly from you when you sign up, configure settings, or enter prospect data.
  • From Google via the OAuth scopes you authorize.
  • From enrichment and data providers (see Section 6).
  • Automatically from your device when you use the app (session, IP, user-agent).

4. How we use it

  • Operate the service: send outbound email, read replies you authorized, draft responses, and book meetings.
  • Authenticate you and protect your account (session management, rate limiting, security auditing).
  • Enforce daily quotas on AI calls and contact reveals.
  • Detect abuse, debug errors, and improve reliability.
  • Communicate with you about your account and service-related notices.

We do not use your data, your prospects' data, or your email content to train shared or public AI models.

5. Google OAuth, Gmail, and Calendar permissions

Salf's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

  • We request only the scopes needed to send mail, read replies on threads Salf manages, and create calendar events.
  • OAuth tokens are encrypted at rest with AES-GCM.
  • Gmail content is used solely to power the features you see in-product (reply triage, scheduling, follow-ups). It is not shared with third parties for advertising, and it is not used to train AI models.
  • You can revoke access at any time from your Google Account or by clicking "Disconnect Google" in Salf's Integrations page.

When you disconnect Google in Salf, we attempt to revoke your grant at Google's /revoke endpoint. Salf sends the stored refresh token first and, if a refresh token is not available, falls back to revoking the stored access token, so that the grant is withdrawn at Google regardless of which token type is on file. Salf then deletes the stored OAuth tokens and marks the integration as disconnected. You may also revoke access directly from your Google Account at any time.

Disconnecting Google does not by itself delete Gmail reply content, sent-message records, drafts, or calendar/meeting records that Salf previously imported or created on your behalf; those records remain in your account so historical activity stays intact. Imported Gmail content continues to be subject to the automated retention windows described in Section 7, and you can remove all records by deleting your account (Section 10) or by deleting individual records.

6. Third-party service providers

We share data with the following sub-processors strictly to operate the service. A current list is also published on our Subprocessors page.

  • Lovable — application platform, hosting, database, authentication, edge runtime, and email delivery for product and authentication notifications. Lovable's platform is built on Supabase and Cloudflare infrastructure.
  • Lovable AI Gateway — routes large-language-model requests to underlying model providers (currently Google's Gemini family). Prompts, context passed with them (such as the reply text or company description Salf is processing, after PII redaction), and model responses transit the gateway and the upstream model provider. Requests sent through the gateway under our agreement are not used to train the underlying models.
  • Salf AI SDR Backend (Render, Inc.) — Salf-operated inference microservice hosted on Render that orchestrates Anthropic Claude requests used by reply classification, reply drafting, meeting extraction, campaign generation, and contact enrichment. Inbound Gmail body text is HTML-stripped and PII-redacted (card numbers, SSNs, IBANs, and phone numbers) before send. Requests are transported over TLS with a shared bearer secret and are used only to serve the invoked feature. Render has confirmed that HTTP request bodies are not stored in Render's platform logs, that request-log metadata is retained per Render's plan-based retention (Hobby 7 days, Pro 14 days, Scale or Enterprise 30 days), and that Render does not train models on any nonpublic customer data, including private service logs or metrics. A GDPR DPA is available to all Render workspaces via the Render dashboard, and SOC 2 and ISO 27001 reports are available on Pro-or-higher plans under NDA. This transfer is covered by our Google API Services User Data Policy "Limited Use" commitment.
  • Google — Gmail API and Google Calendar API, only after you connect your account.
  • Apollo.io — contact and company enrichment, and on-demand phone number reveal.
  • Stripe, Inc. — payment processing for paid subscriptions. When you subscribe, Stripe collects and processes your billing name, billing address, email, tax identifiers (where applicable), and payment card details directly. Stripe returns to Salf a customer ID, subscription ID, plan/price identifier, subscription status, current billing period, and invoice metadata, which we store to operate billing and gate features to your plan. Salf does not receive, store, or process your full payment card number.

Billing information we store

  • Stripe customer ID and subscription ID.
  • Plan / price identifier, subscription status, current billing period, and cancel-at-period-end flag.
  • Invoice-level metadata (invoice ID, amount, currency, timestamps, payment status). We do not store card numbers, CVCs, or full bank-account details.

Your use of Stripe is subject to Stripe's Privacy Policy.

7. Data retention

Salf enforces the following retention windows on a scheduled, automated basis. Windows are measured from the record's creation or last-update timestamp.

  • Gmail reply bodies — the plain-text body of imported Gmail replies is redacted 30 days after the reply is received. Threading metadata (message ID, thread ID, subject, timestamps) is retained so historical activity remains visible.
  • Generated draft bodies — the body of AI-generated draft replies is redacted 30 days after the draft is created.
  • Gmail reply records — imported Gmail reply records are deleted 365 days after receipt.
  • Gmail sent-message records — records of messages Salf sent on your behalf are deleted 365 days after send.
  • OAuth tokens — deleted when you disconnect Google or delete your account.
  • Security and operational data — security audit logs, rate-limit counters, and similar operational records are retained for a limited period for abuse prevention and troubleshooting.
  • Campaign, account, and configuration data — retained while your account is active.
  • Calendar and meeting records — retained for the lifetime of your account and removed on account deletion.
  • Email suppression entries (unsubscribes) — retained indefinitely, including after account deletion, as required to comply with CAN-SPAM and similar laws.

Retention is enforced by a scheduled server-side job that redacts and deletes records according to the windows above.

8. Data security

  • All traffic is served over HTTPS/TLS, with HTTP Strict Transport Security (HSTS) enabled.
  • The application sends a Content Security Policy (CSP) and a standard set of security response headers (including X-Content-Type-Options, Referrer-Policy, and frame-ancestor restrictions) to reduce injection and clickjacking risk.
  • Optional TOTP-based multi-factor authentication is available on user accounts, with hashed recovery codes.
  • New and updated passwords are screened against the Have I Been Pwned (HIBP) breached-password corpus using a k-anonymity range query, so known-compromised passwords cannot be used.
  • OAuth tokens are encrypted at rest using AES-GCM with a server-held key.
  • Database access is restricted by row-level security so each user can only read their own rows.
  • Privileged server actions verify the caller's identity and role on the server side; admin tooling is gated by a server-checked role.
  • We log security-sensitive events (sign-in, OAuth connect/disconnect, quota and rate-limit hits, role changes) for review.
  • You can view active sessions and revoke any session, or sign out everywhere, from the Sessions page.

No system is perfectly secure. If we become aware of a breach that affects your personal data, we will notify you in line with applicable law.

9. Cookies and local storage

Salf uses cookies and browser local storage only as strictly necessary to keep you signed in and remember in-app preferences. We do not set advertising or third-party tracking cookies, and we do not currently run web analytics.

10. Account deletion and data export

From the Settings page you can:

  • Export your data as a JSON file containing all records associated with your account across our user-scoped tables.
  • Delete your account. Deletion revokes your Google OAuth grant, removes your rows from our application tables, and deletes your authentication record. Suppression-list entries are retained for CAN-SPAM compliance as noted in Section 7. Scrubbed operational logs and backups may persist for a short period before being overwritten in the normal course of backup rotation.

11. Email sending, unsubscribes, and prospect rights

Outbound emails Salf sends on your behalf include your physical mailing address, a functional unsubscribe link, and an RFC 8058 List-Unsubscribe header where the recipient's mail client supports it. Recipients who unsubscribe are added to your account's suppression list and Salf will refuse to send further outreach to that address.

As the Salf user, you are responsible for ensuring you have a lawful basis to contact the prospects you load into Salf and that your sender identity (name, company, mailing address) is accurate.

12. International transfers and business location

Salf is operated from Ontario, Canada. Our infrastructure is provided by third-party vendors that operate primarily in the United States (including Lovable, its platform infrastructure providers, Google, Apollo, and Stripe). If you access Salf from outside Canada or the United States, your information will be transferred to and processed in Canada, the United States, and other countries where these providers operate. Where required, we rely on the providers' Standard Contractual Clauses, adequacy decisions, or equivalent transfer mechanisms.

13. Your rights

Depending on where you live, you may have the right to access, correct, export, or delete your personal data, to object to or restrict certain processing, and to lodge a complaint with your local data-protection authority.

You can exercise the core rights directly in-product (export and delete from Settings, session management from the Sessions page, Google disconnect from Integrations). For any other request, email us at privacy@salf.ai.

Canadian residents (PIPEDA): as a business operating from Ontario, Canada, we handle personal information in accordance with the Personal Information Protection and Electronic Documents Act. You may access or correct your personal information using the in-product controls above, or contact our privacy office at privacy@salf.ai. You also have the right to complain to the Office of the Privacy Commissioner of Canada.

California residents (CCPA/CPRA): we do not sell or "share" personal information for cross-context behavioral advertising. You may request access to or deletion of your personal information using the controls above or by emailing us.

14. Children's privacy

Salf is a business tool and is not directed to children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.

15. Automated decision-making

Salf uses AI to classify replies, draft messages, score accounts, and propose meeting times. These outputs are tools to assist you; they do not produce legal or similarly significant effects about the recipients within the meaning of GDPR Article 22. You remain responsible for reviewing and approving automated behavior in your account settings (Autonomy page).

16. Updates to this policy

We may update this Privacy Policy as the product evolves. When we make material changes we will update the effective date above and, where appropriate, notify you in-product or by email. Continued use of Salf after an update constitutes acceptance of the revised policy.

17. Contact

Questions, requests, or complaints: privacy@salf.ai.