Privacy Policy

Last updated: October 5, 2026

This policy explains what information Napalm (“Napalm”, “we”) collects when you use the Napalm application, how we use and protect it, and the choices you have. Questions: thepeteryuanlu@gmail.com.

Information we collect

  • Account information: your name, email address and workspace membership.
  • Workspace data you add: leads, companies, campaigns, email templates, notes and settings.
  • Connected mailbox data: when you connect a Google account, we receive an OAuth access and refresh token for that account and its email address.
  • Usage and diagnostic data such as logs needed to operate and secure the service.

Google user data

Napalm requests the Gmail scope (https://mail.google.com/) for mailboxes you choose to connect. We use it only to:

  • send emails you create or schedule in Napalm (campaign steps, replies, forwards, test emails) from that mailbox over SMTP;
  • read new messages in that mailbox's inbox over IMAP to detect replies, out-of-office notices and delivery failures related to your campaigns, and to show those conversations in your Napalm inbox.

For each new inbox message we first read only its headers. We download and store a message only if it replies to a conversation Napalm sent, comes from a contact in your workspace, or is a delivery-failure notice. Other personal email is not downloaded or stored.

Limited Use disclosure. Napalm's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular: we use Google user data only to provide and improve the user-facing features described above; we do not sell it; we do not use it for advertising; we do not use it to train or improve generalized AI or machine-learning models; and humans do not read it except with your explicit consent, for security purposes, to comply with law, or when aggregated and anonymized for internal operations.

AI features (such as labelling a reply as “interested” or drafting a response) send the relevant message text to our AI model provider solely to produce that result for you. The provider does not use this data to train its models.

How we store and protect data

  • OAuth tokens and mailbox passwords are encrypted at rest (AES-256-GCM) and are never shown in the application or sent to your browser.
  • Data is stored in managed databases in the United States and transmitted over TLS.
  • Access to production systems is limited to personnel who need it to operate the service.

Sharing

We do not sell personal information. We share data only with service providers that host or operate Napalm on our behalf (cloud hosting, database, email delivery and AI processing), under contractual confidentiality obligations, or when required by law.

Retention and deletion

  • You can disconnect a Google mailbox at any time (Email Accounts → mailbox → Disconnect). This revokes Napalm's access at Google and deletes the stored tokens. You can also revoke access at myaccount.google.com/permissions.
  • Workspace data is kept while your workspace is active. You can delete records in the app or ask us to delete your workspace and its data.
  • To request access to, correction of, or deletion of your data, email thepeteryuanlu@gmail.com; we respond within 30 days.

Changes

We will post any changes to this policy on this page and update the date above.