Privacy Policy

Last updated: August 5, 2026

Effective: August 5, 2026


PLACEHOLDERS TO FILL BEFORE PUBLISHING — search for [ and replace:

[LEGAL ENTITY], [REGISTERED ADDRESS], [JURISDICTION], [HOSTING REGION].




1. Who we are


GTMatic (“GTMatic”, “we”, “us”) is a go-to-market agent for founders. You connect

the tools your company already runs on, GTMatic reads them to build a model of

your business, and it proposes one high-impact move at a time for you to approve.


This Privacy Policy explains what we collect, why, who we share it with, and the

control you have over it. It covers the GTMatic web application at

gtmatic.com and app.gtmatic.com, our API, and the GTMatic browser extension.


The data controller is [LEGAL ENTITY], [REGISTERED ADDRESS].


Contact: dain@gtmatic.com




2. The short version


• We read data from the services you explicitly connect — nothing else.

• We use it to build your company’s knowledge graph and to draft and send the

actions you approve. That is the whole purpose.

We do not sell your data. We do not use it for advertising. We do not use

it to train generalized AI models — ours or anyone else’s.

• Content from your connected accounts is sent to Google’s Gemini API for

processing under a no-training agreement. Details in §7.

• You can disconnect any service at any time, and delete your entire account and

all associated data from inside the app.




3. Information we collect


3.1 Account information


When you sign up we collect your email address, and — if you sign in with Google

— the name and profile picture Google returns from the openid and email

scopes. Authentication is handled by Supabase Auth; we never see or store your

password in readable form.


3.2 Business context you provide


Your company website URL, the business description and priorities you enter, your

buyer definitions, and any text you type into Ask, Decisions, or message drafts.


3.3 Data from services you connect


GTMatic only reads a connected service after you complete that service’s OAuth

consent screen, and only within the scopes shown there. You can revoke any

connection at any time from Settings.


| Service | Scopes we request | What we read | Why |

|---|---|---|---|

| Google — Gmail | gmail.readonly; gmail.send (added later, only when you first send) | Message headers, bodies and threads in your mailbox | To detect buying signals, surface threads that need a reply, and send replies you approve |

| Google — Calendar | calendar.readonly; calendar.events (added later, only when you first book) | Event titles, times, attendees | To detect meetings with buyers and create events you approve |

| Microsoft Outlook | User.Read, Mail.Read, Mail.Send, Calendars.ReadWrite, offline_access | Same as Gmail/Calendar above, for Outlook mailboxes | Same as above |

| IMAP / SMTP | Credentials you supply | Mailbox contents | Same as above, for mail providers without OAuth |

| Slack | team:read, channels:read, channels:history, users:read, chat:write, channels:join | Messages in the public channels the GTMatic bot is added to, plus workspace and user directory | To learn facts about your business from team conversation, and to post decisions to a channel |

| Stripe | Read-only account access | Charges, subscriptions, customers, revenue totals | To ground revenue and retention facts in real numbers |

| PostHog | openid, email, query:read, person:read, event_definition:read, project:read | Product analytics events and person properties | To detect activation, churn and usage signals |

| GitHub | read:user, repo | Repository metadata and activity | To detect shipping velocity and product changes |

| Fathom | public_api | Meeting recordings metadata, transcripts and summaries | To turn sales calls into signals and follow-ups |

| X (Twitter) | tweet.read, tweet.write, users.read, dm.write, offline.access | Your account identity | To post and DM on your behalf when you approve an action |


We only read the scopes listed. Where a provider returns broader access than

we need, we discard the extra grants at the callback.


3.4 Data GTMatic generates about your business


From the above we derive and store: knowledge graph objects and edges (facts about

your customers, product, revenue and pipeline), company memories, decision

proposals and your responses to them, opportunity events, workflow run records,

and Ask conversation history including the citations and reasoning traces behind

each answer.


3.5 Prospect and buyer data


When you run buyer discovery, we send search queries to Exa and receive public

profile information (name, title, company, public profile URL). If — and only if —

you explicitly opt in on a specific lead, we send that person’s name and company to

Apollo.io to retrieve a work email address so a cold email can be drafted.


This means GTMatic may process personal data about people who are not our users.

Where you act as the controller for that data, you are responsible for having a

lawful basis to contact them; see §9 and the Terms of Service.


3.6 Outreach and communications


Message drafts, the outbound queue, send timestamps, per-channel rate limits and

warm-up state, delivery outcomes, and inbound replies routed back into the app.


3.7 Payment information


Billing is handled by Stripe. We store your Stripe customer ID, subscription

status, plan and renewal dates. **We never receive or store your full card

number.**


3.8 Technical and usage data


Server logs (IP address, user agent, request paths, timestamps), error reports,

LLM usage records (token counts and cost per request, for billing integrity and

abuse prevention), and product analytics on how the GTMatic app itself is used.


3.9 Browser extension


The GTMatic browser extension sends LinkedIn messages you have already approved in

the app, from your own logged-in browser session. It:


• reads the GTMatic app page only to receive a pairing token,

• opens LinkedIn conversation pages and types the approved message,

• reports back only whether the send succeeded or failed.


It does not read your LinkedIn inbox, connections, feed or profile data, does

not store your LinkedIn credentials, and runs on no sites other than linkedin.com

and GTMatic’s own domains.




4. How we use your information


| Purpose | Examples |

|---|---|

| Provide the service | Build your knowledge graph, generate decision proposals, draft and send approved messages |

| Keep it working | Refresh OAuth tokens, sync mailboxes, retry failed sends |

| Billing | Charge your plan, enforce Free-tier limits, detect abuse of LLM spend |

| Support | Respond to your requests at dain@gtmatic.com |

| Security and integrity | Detect fraud, abuse, rate-limit violations and unauthorized access |

| Product improvement | Aggregated, de-identified usage statistics only |

| Legal | Comply with law, enforce our Terms, defend legal claims |


We do not: sell personal information, share it with data brokers, use it for

targeted advertising, or use your connected-account content to train AI models.




5. Legal bases (EEA / UK users)


| Basis | Applies to |

|---|---|

| Contract (Art. 6(1)(b)) | Everything needed to deliver the service you signed up for |

| Consent (Art. 6(1)(a)) | Each OAuth connection; each write action you approve; optional marketing email |

| Legitimate interests (Art. 6(1)(f)) | Security, fraud prevention, aggregated product analytics, and — for prospect data you direct us to process — supporting your outreach |

| Legal obligation (Art. 6(1)(c)) | Tax records, responding to lawful requests |


You may withdraw consent at any time by disconnecting the service or deleting your

account. Withdrawal does not affect processing already carried out.




6. Automated decision-making


GTMatic proposes; you decide. Every action that touches the outside world — an

email, a LinkedIn or X message, a calendar invite, a Slack post — requires your

explicit approval before it is executed. GTMatic does not make decisions that

produce legal or similarly significant effects about you without human

involvement.




7. AI processing


GTMatic uses Google’s Gemini API (gemini-3.5-flash) to interpret your data

and generate proposals and drafts. Content from your connected accounts — email

bodies, Slack messages, meeting transcripts, analytics results — is sent to the

Gemini API as part of that processing.


• We use the paid Gemini API tier, under which Google does not use submitted

data to train or improve its models.

• We do not use your data to train any model of our own.

• We do not send your data to any other AI provider.




8. Google API Services — Limited Use disclosure


GTMatic’s use and transfer of information received from Google APIs to any other

app will adhere to the

[Google API Services User Data Policy](https://developers.google.com/terms/api-services-user-data-policy),

including the Limited Use requirements.


Specifically, for Gmail and Google Calendar data:


1. We use it only to provide and improve the user-facing features described in

this policy.

2. We do not transfer it to third parties except (a) as necessary to provide

or improve those features, (b) for security purposes, or (c) to comply with

applicable law.

3. We do not use it for advertising, and we do not sell it.

4. We do not allow humans to read it, except (a) with your explicit consent

for a specific message, (b) where necessary for security purposes such as

investigating abuse, (c) to comply with applicable law, or (d) where the data

has been aggregated and de-identified.

5. We do not use it to develop, improve or train generalized AI or machine

learning models. Data is sent to Google’s Gemini API solely to produce your

user-facing output, under a no-training agreement.




9. Sharing and sub-processors


We share data only with the following categories of recipients.


Infrastructure and processing sub-processors:


| Sub-processor | Role | Data involved |

|---|---|---|

| Vercel | Application hosting | Requests, logs |

| Supabase | Database, authentication, storage | All stored account and business data |

| Google (Gemini API) | AI inference | Content sent for processing (see §7) |

| Stripe | Payments and subscription billing | Billing identity, payment status |

| Exa | Buyer discovery search | Search queries; public profile results |

| Apollo.io | Email enrichment (opt-in per lead) | Prospect name and company |

| PostHog | Product analytics for GTMatic itself | Usage events, pseudonymous identifiers |


We update this list as our stack changes; the current list always lives in this

document.


**Others:**


Service providers you connect — we send data back to them only to carry out

actions you approve (e.g. sending a Gmail message).

Legal and safety — where required by law, or to protect our rights, users

or the public.

Business transfer — in a merger, acquisition or asset sale, subject to this

policy continuing to apply. We will notify you before your data becomes subject

to a different privacy policy.


**We do not sell personal information, and we do not share it for cross-context

behavioral advertising**, as those terms are defined under the CCPA/CPRA.




10. International transfers


Our infrastructure is operated primarily in [HOSTING REGION]. If you are in the

EEA, UK or Switzerland, your data may be transferred to and processed in countries

that have not received an adequacy decision. Where that happens, we rely on the

European Commission’s Standard Contractual Clauses (and the UK Addendum where

applicable), which our sub-processors have entered into.




11. Data retention


| Data | Retention |

|---|---|

| Account and business data | While your account is active |

| Connected-account content and derived knowledge graph | While the connection is active; deleted when you disconnect that service or delete the account |

| OAuth refresh tokens | Until you disconnect or delete your account, at which point we also revoke the token with the provider where the provider supports revocation |

| Ask conversations and decision history | While your account is active |

| Server and security logs | Up to 12 months |

| Billing records | As long as required by tax and accounting law (typically 7 years), after which they are deleted |


Account deletion is available in-app. Deleting your account removes your

projects, knowledge graph, memories, decisions, inbox threads, conversations,

outreach queue and all encrypted connector tokens, and cancels any active

subscription. Deletion is permanent and cannot be undone. Backups are purged on a

rolling basis within 30 days.




12. Security


• OAuth refresh tokens and connector credentials are encrypted at rest with

AES-256-GCM using keys held outside the database.

• OAuth state is carried through the redirect signed with HMAC-SHA256 to

prevent tampering and CSRF.

• All traffic is served over TLS.

• Database access is scoped per user via row-level security; the elevated

service-role key is used only server-side and is never exposed to the browser.

• Access to production systems is limited to personnel who need it.


No system is perfectly secure. If we become aware of a breach affecting your

personal data, we will notify you and any required regulator without undue delay,

and within 72 hours where GDPR applies.




13. Your rights


Everyone. You can access, correct, export or delete your data. Most of this is

self-serve: disconnect any service in Settings, or delete your account entirely

from the account page. For anything else, email dain@gtmatic.com.


EEA / UK (GDPR). You have the right to access, rectification, erasure,

restriction of processing, data portability, objection to processing based on

legitimate interests, and withdrawal of consent. You also have the right to lodge

a complaint with your local supervisory authority.


California (CCPA/CPRA). You have the right to know what personal information

we collect and how we use it, to request deletion, to request correction, and to

opt out of sale or sharing — though we do not sell or share personal

information as those terms are defined. We will not discriminate against you for

exercising these rights.


Other US states (Colorado, Connecticut, Virginia, Utah, and others with

comparable laws) — you have substantially similar rights, which you can exercise

through the same channels.


We respond to rights requests within 30 days (or the shorter period your law

requires). We may need to verify your identity, which we do by confirming control

of the email address on the account.




14. Cookies and similar technologies


We use strictly necessary cookies to keep you signed in and to protect against

CSRF. We use first-party product analytics to understand how the app is used. We

do not use advertising cookies or third-party trackers.




15. Children


GTMatic is a business tool and is not directed at children. We do not knowingly

collect personal information from anyone under 16. If you believe a child has

provided us data, email dain@gtmatic.com and we will delete it.




16. Changes to this policy


We may update this policy as the product changes. If a change is material, we will

notify you by email or in-app at least 14 days before it takes effect. The “Last

updated” date at the top always reflects the current version.




17. Contact


Questions, requests, or complaints:


Email: dain@gtmatic.com

Entity: GTMatic


If you are in the EEA or UK and are not satisfied with our response, you may

contact your local data protection authority.

BG

Stop wondering what to do next.
Your GTM Employee already knows.

Paste your URL and see real buyers in about 30 seconds.

It's free to look.

BG

Stop wondering what to do next.
Your GTM Employee already knows.

Paste your URL and see real buyers in about 30 seconds.

It's free to look.

BG

Stop wondering what to do next.
Your GTM Employee already knows.

Paste your URL and see real buyers in about 30 seconds. It's free to look.