Privacy Policy
Last updated: August 5, 2026
Effective: August 5, 2026
PLACEHOLDERS TO FILL BEFORE PUBLISHING — search for [ and replace:
[LEGAL ENTITY], [REGISTERED ADDRESS], [JURISDICTION], [HOSTING REGION].
1. Who we are
GTMatic (“GTMatic”, “we”, “us”) is a go-to-market agent for founders. You connect
the tools your company already runs on, GTMatic reads them to build a model of
your business, and it proposes one high-impact move at a time for you to approve.
This Privacy Policy explains what we collect, why, who we share it with, and the
control you have over it. It covers the GTMatic web application at
gtmatic.com and app.gtmatic.com, our API, and the GTMatic browser extension.
The data controller is [LEGAL ENTITY], [REGISTERED ADDRESS].
Contact: dain@gtmatic.com
2. The short version
• We read data from the services you explicitly connect — nothing else.
• We use it to build your company’s knowledge graph and to draft and send the
actions you approve. That is the whole purpose.
• We do not sell your data. We do not use it for advertising. We do not use
it to train generalized AI models — ours or anyone else’s.
• Content from your connected accounts is sent to Google’s Gemini API for
processing under a no-training agreement. Details in §7.
• You can disconnect any service at any time, and delete your entire account and
all associated data from inside the app.
3. Information we collect
3.1 Account information
When you sign up we collect your email address, and — if you sign in with Google
— the name and profile picture Google returns from the openid and email
scopes. Authentication is handled by Supabase Auth; we never see or store your
password in readable form.
3.2 Business context you provide
Your company website URL, the business description and priorities you enter, your
buyer definitions, and any text you type into Ask, Decisions, or message drafts.
3.3 Data from services you connect
GTMatic only reads a connected service after you complete that service’s OAuth
consent screen, and only within the scopes shown there. You can revoke any
connection at any time from Settings.
| Service | Scopes we request | What we read | Why |
|---|---|---|---|
| Google — Gmail | gmail.readonly; gmail.send (added later, only when you first send) | Message headers, bodies and threads in your mailbox | To detect buying signals, surface threads that need a reply, and send replies you approve |
| Google — Calendar | calendar.readonly; calendar.events (added later, only when you first book) | Event titles, times, attendees | To detect meetings with buyers and create events you approve |
| Microsoft Outlook | User.Read, Mail.Read, Mail.Send, Calendars.ReadWrite, offline_access | Same as Gmail/Calendar above, for Outlook mailboxes | Same as above |
| IMAP / SMTP | Credentials you supply | Mailbox contents | Same as above, for mail providers without OAuth |
| Slack | team:read, channels:read, channels:history, users:read, chat:write, channels:join | Messages in the public channels the GTMatic bot is added to, plus workspace and user directory | To learn facts about your business from team conversation, and to post decisions to a channel |
| Stripe | Read-only account access | Charges, subscriptions, customers, revenue totals | To ground revenue and retention facts in real numbers |
| PostHog | openid, email, query:read, person:read, event_definition:read, project:read | Product analytics events and person properties | To detect activation, churn and usage signals |
| GitHub | read:user, repo | Repository metadata and activity | To detect shipping velocity and product changes |
| Fathom | public_api | Meeting recordings metadata, transcripts and summaries | To turn sales calls into signals and follow-ups |
| X (Twitter) | tweet.read, tweet.write, users.read, dm.write, offline.access | Your account identity | To post and DM on your behalf when you approve an action |
We only read the scopes listed. Where a provider returns broader access than
we need, we discard the extra grants at the callback.
3.4 Data GTMatic generates about your business
From the above we derive and store: knowledge graph objects and edges (facts about
your customers, product, revenue and pipeline), company memories, decision
proposals and your responses to them, opportunity events, workflow run records,
and Ask conversation history including the citations and reasoning traces behind
each answer.
3.5 Prospect and buyer data
When you run buyer discovery, we send search queries to Exa and receive public
profile information (name, title, company, public profile URL). If — and only if —
you explicitly opt in on a specific lead, we send that person’s name and company to
Apollo.io to retrieve a work email address so a cold email can be drafted.
This means GTMatic may process personal data about people who are not our users.
Where you act as the controller for that data, you are responsible for having a
lawful basis to contact them; see §9 and the Terms of Service.
3.6 Outreach and communications
Message drafts, the outbound queue, send timestamps, per-channel rate limits and
warm-up state, delivery outcomes, and inbound replies routed back into the app.
3.7 Payment information
Billing is handled by Stripe. We store your Stripe customer ID, subscription
status, plan and renewal dates. **We never receive or store your full card
number.**
3.8 Technical and usage data
Server logs (IP address, user agent, request paths, timestamps), error reports,
LLM usage records (token counts and cost per request, for billing integrity and
abuse prevention), and product analytics on how the GTMatic app itself is used.
3.9 Browser extension
The GTMatic browser extension sends LinkedIn messages you have already approved in
the app, from your own logged-in browser session. It:
• reads the GTMatic app page only to receive a pairing token,
• opens LinkedIn conversation pages and types the approved message,
• reports back only whether the send succeeded or failed.
It does not read your LinkedIn inbox, connections, feed or profile data, does
not store your LinkedIn credentials, and runs on no sites other than linkedin.com
and GTMatic’s own domains.
4. How we use your information
| Purpose | Examples |
|---|---|
| Provide the service | Build your knowledge graph, generate decision proposals, draft and send approved messages |
| Keep it working | Refresh OAuth tokens, sync mailboxes, retry failed sends |
| Billing | Charge your plan, enforce Free-tier limits, detect abuse of LLM spend |
| Support | Respond to your requests at dain@gtmatic.com |
| Security and integrity | Detect fraud, abuse, rate-limit violations and unauthorized access |
| Product improvement | Aggregated, de-identified usage statistics only |
| Legal | Comply with law, enforce our Terms, defend legal claims |
We do not: sell personal information, share it with data brokers, use it for
targeted advertising, or use your connected-account content to train AI models.
5. Legal bases (EEA / UK users)
| Basis | Applies to |
|---|---|
| Contract (Art. 6(1)(b)) | Everything needed to deliver the service you signed up for |
| Consent (Art. 6(1)(a)) | Each OAuth connection; each write action you approve; optional marketing email |
| Legitimate interests (Art. 6(1)(f)) | Security, fraud prevention, aggregated product analytics, and — for prospect data you direct us to process — supporting your outreach |
| Legal obligation (Art. 6(1)(c)) | Tax records, responding to lawful requests |
You may withdraw consent at any time by disconnecting the service or deleting your
account. Withdrawal does not affect processing already carried out.
6. Automated decision-making
GTMatic proposes; you decide. Every action that touches the outside world — an
email, a LinkedIn or X message, a calendar invite, a Slack post — requires your
explicit approval before it is executed. GTMatic does not make decisions that
produce legal or similarly significant effects about you without human
involvement.
7. AI processing
GTMatic uses Google’s Gemini API (gemini-3.5-flash) to interpret your data
and generate proposals and drafts. Content from your connected accounts — email
bodies, Slack messages, meeting transcripts, analytics results — is sent to the
Gemini API as part of that processing.
• We use the paid Gemini API tier, under which Google does not use submitted
data to train or improve its models.
• We do not use your data to train any model of our own.
• We do not send your data to any other AI provider.
8. Google API Services — Limited Use disclosure
GTMatic’s use and transfer of information received from Google APIs to any other
app will adhere to the
[Google API Services User Data Policy](https://developers.google.com/terms/api-services-user-data-policy),
including the Limited Use requirements.
Specifically, for Gmail and Google Calendar data:
1. We use it only to provide and improve the user-facing features described in
this policy.
2. We do not transfer it to third parties except (a) as necessary to provide
or improve those features, (b) for security purposes, or (c) to comply with
applicable law.
3. We do not use it for advertising, and we do not sell it.
4. We do not allow humans to read it, except (a) with your explicit consent
for a specific message, (b) where necessary for security purposes such as
investigating abuse, (c) to comply with applicable law, or (d) where the data
has been aggregated and de-identified.
5. We do not use it to develop, improve or train generalized AI or machine
learning models. Data is sent to Google’s Gemini API solely to produce your
user-facing output, under a no-training agreement.
9. Sharing and sub-processors
We share data only with the following categories of recipients.
Infrastructure and processing sub-processors:
| Sub-processor | Role | Data involved |
|---|---|---|
| Vercel | Application hosting | Requests, logs |
| Supabase | Database, authentication, storage | All stored account and business data |
| Google (Gemini API) | AI inference | Content sent for processing (see §7) |
| Stripe | Payments and subscription billing | Billing identity, payment status |
| Exa | Buyer discovery search | Search queries; public profile results |
| Apollo.io | Email enrichment (opt-in per lead) | Prospect name and company |
| PostHog | Product analytics for GTMatic itself | Usage events, pseudonymous identifiers |
We update this list as our stack changes; the current list always lives in this
document.
**Others:**
• Service providers you connect — we send data back to them only to carry out
actions you approve (e.g. sending a Gmail message).
• Legal and safety — where required by law, or to protect our rights, users
or the public.
• Business transfer — in a merger, acquisition or asset sale, subject to this
policy continuing to apply. We will notify you before your data becomes subject
to a different privacy policy.
**We do not sell personal information, and we do not share it for cross-context
behavioral advertising**, as those terms are defined under the CCPA/CPRA.
10. International transfers
Our infrastructure is operated primarily in [HOSTING REGION]. If you are in the
EEA, UK or Switzerland, your data may be transferred to and processed in countries
that have not received an adequacy decision. Where that happens, we rely on the
European Commission’s Standard Contractual Clauses (and the UK Addendum where
applicable), which our sub-processors have entered into.
11. Data retention
| Data | Retention |
|---|---|
| Account and business data | While your account is active |
| Connected-account content and derived knowledge graph | While the connection is active; deleted when you disconnect that service or delete the account |
| OAuth refresh tokens | Until you disconnect or delete your account, at which point we also revoke the token with the provider where the provider supports revocation |
| Ask conversations and decision history | While your account is active |
| Server and security logs | Up to 12 months |
| Billing records | As long as required by tax and accounting law (typically 7 years), after which they are deleted |
Account deletion is available in-app. Deleting your account removes your
projects, knowledge graph, memories, decisions, inbox threads, conversations,
outreach queue and all encrypted connector tokens, and cancels any active
subscription. Deletion is permanent and cannot be undone. Backups are purged on a
rolling basis within 30 days.
12. Security
• OAuth refresh tokens and connector credentials are encrypted at rest with
AES-256-GCM using keys held outside the database.
• OAuth state is carried through the redirect signed with HMAC-SHA256 to
prevent tampering and CSRF.
• All traffic is served over TLS.
• Database access is scoped per user via row-level security; the elevated
service-role key is used only server-side and is never exposed to the browser.
• Access to production systems is limited to personnel who need it.
No system is perfectly secure. If we become aware of a breach affecting your
personal data, we will notify you and any required regulator without undue delay,
and within 72 hours where GDPR applies.
13. Your rights
Everyone. You can access, correct, export or delete your data. Most of this is
self-serve: disconnect any service in Settings, or delete your account entirely
from the account page. For anything else, email dain@gtmatic.com.
EEA / UK (GDPR). You have the right to access, rectification, erasure,
restriction of processing, data portability, objection to processing based on
legitimate interests, and withdrawal of consent. You also have the right to lodge
a complaint with your local supervisory authority.
California (CCPA/CPRA). You have the right to know what personal information
we collect and how we use it, to request deletion, to request correction, and to
opt out of sale or sharing — though we do not sell or share personal
information as those terms are defined. We will not discriminate against you for
exercising these rights.
Other US states (Colorado, Connecticut, Virginia, Utah, and others with
comparable laws) — you have substantially similar rights, which you can exercise
through the same channels.
We respond to rights requests within 30 days (or the shorter period your law
requires). We may need to verify your identity, which we do by confirming control
of the email address on the account.
14. Cookies and similar technologies
We use strictly necessary cookies to keep you signed in and to protect against
CSRF. We use first-party product analytics to understand how the app is used. We
do not use advertising cookies or third-party trackers.
15. Children
GTMatic is a business tool and is not directed at children. We do not knowingly
collect personal information from anyone under 16. If you believe a child has
provided us data, email dain@gtmatic.com and we will delete it.
16. Changes to this policy
We may update this policy as the product changes. If a change is material, we will
notify you by email or in-app at least 14 days before it takes effect. The “Last
updated” date at the top always reflects the current version.
17. Contact
Questions, requests, or complaints:
Email: dain@gtmatic.com
Entity: GTMatic
If you are in the EEA or UK and are not satisfied with our response, you may
contact your local data protection authority.
