Privacy Policy

Last updated: July 16, 2026

Overview

Polinary (“we,” “our,” or “the Service”) is a lead generation tool consisting of a web application and a Chrome browser extension. This policy explains what data we collect, why we collect it, and how it is used and protected. By using Polinary you agree to the practices described here.

What we collect

Account data. When you create an account we collect your name, email address, and a hashed password. This is stored in our database hosted on Supabase (PostgreSQL) and is used solely to authenticate you and identify your workspace.

Ad capture data. The browser extension reads publicly visible ad cards from Meta Ads Library, Google Ads Transparency Center, and LinkedIn Ad Library. No private or user-specific data is accessed. Captured fields include: advertiser name, ad copy, creative URL, call-to-action text, landing page URL, and run duration. This data is synced to your Polinary account.

Contact research data. When you run a contact lookup, we first look at publicly published sources — principally the business's own website — to find contact addresses it has chosen to publish. If you have connected your own AI or enrichment provider key, the lead's domain is also sent to that provider using your credential and under your agreement with them; Polinary does not resell or pool provider data. Discovered addresses are checked by an email verification service before being marked as usable. Results are stored in your account. We do not sell or share these results.

Connected inbox tokens. If you connect a Gmail or Outlook account, we store your OAuth access token and refresh token in encrypted form (AES-256-GCM). We use these only to send outreach emails and check for replies on your behalf. We never read, store, or process your email inbox contents beyond detecting reply counts in threads you initiated through Polinary.

Outreach data. Emails sent through Polinary (subject, body, recipient) are stored in your account to power the activity feed and reply tracking.

AI script generation inputs. If you provide an offer description and writing voice sample during onboarding, these are stored at the organization level and sent to Anthropic's API to generate email script templates. They are not used to train AI models.

Billing data. Payments are processed by Stripe. We do not store card numbers or payment details. We store your Stripe customer ID and subscription status.

How we use your data

  • To authenticate you and maintain your session
  • To sync captured ads to your lead pipeline
  • To research and display contact information for leads
  • To send outreach emails and detect replies on your behalf
  • To generate AI-assisted email script templates
  • To process your subscription payments via Stripe
  • To enforce usage limits (outreach emails, seats, workspaces) per your plan, and to count contact lookups for capacity planning

We do not sell your data, use it for advertising, or share it with third parties beyond the service providers listed below.

Third-party services

Polinary relies on the following third-party providers to deliver the Service. Each operates under its own privacy policy.

SupabaseDatabase, authentication, and realtime infrastructure.
StripePayment processing and subscription management.
AnthropicAI-generated email script templates via the Claude API.
Google (Gmail API)Sending outreach and detecting replies from connected Gmail accounts.
Microsoft (Graph API)Sending outreach and detecting replies from connected Outlook accounts.
VerifaliaEmail deliverability verification for discovered contact addresses.
Your own provider keysIf you connect an AI or enrichment provider key, that provider processes lookups under your own agreement with them, not ours.

Google User Data & Limited Use Disclosure

Polinary' use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically, when you connect a Gmail account to Polinary:

  • We access your Gmail data only to (1) send outreach emails that you compose, on your behalf, and (2) detect replies in those specific outreach threads.
  • We do not use Gmail data for serving advertisements, and we do not use it for any purpose other than the features described above.
  • We do not sell, rent, or transfer Gmail data to third parties, except as strictly necessary to provide the features above (e.g., our database provider, Supabase, which stores encrypted data on our behalf and does not independently access it) or where required by law.
  • We do not use Gmail data to train or improve generalized (non-personalized) AI or machine learning models.
  • No human at Polinary reads your Gmail data, except: (a) with your affirmative consent for a specific support request, (b) where necessary for security purposes such as investigating abuse, or (c) to comply with applicable law.
  • You can revoke Polinary' access to your Gmail account at any time from Settings → Inbox, or via your Google Account's Security → Third-party apps & services settings.

The free ad checker

The ad checker at /ad-checker works without an account. When you use it:

  • We check the site you name for publicly visible advertising pixels. We do not store the site's page content.
  • If you reveal a contact, we look only at pages that business publishes on its own website. We do not use a third-party contact database for this.
  • The business email we find is stored for up to 31 days, keyed to that company's domain, so repeat lookups of the same company do not repeat the work. It is then deleted automatically.
  • We store a one-way hash of your IP address, never the address itself, for up to 8 days. It enforces the daily lookup limit and nothing else.
  • We do not ask for your email, and there is no sign-up, tracking pixel, or advertising cookie on the page.

If you are the owner of a business email address surfaced by this tool and want it removed, email us and we will delete it.

Data retention

Your account data is retained for as long as your account is active. If you close your account, your data is deleted within 30 days, except where retention is required by law or for legitimate business purposes (e.g., billing records). You may request deletion at any time by emailing us. Data from the free ad checker is deleted on the schedule described in that section above, whether or not anyone asks.

Security

We apply industry-standard security practices including encryption at rest for OAuth tokens, HTTPS for all data in transit, row-level security on our database so users can only access their own org's data, and API key hashing for extension authentication. No system is perfectly secure, and we cannot guarantee absolute security.

Cookies

Polinary uses session cookies to maintain your authenticated state. We do not use tracking cookies or third-party advertising cookies. The browser extension uses Chrome's local and session storage (not browser cookies) to store your API key and workspace preference.

Your rights

Depending on your location you may have rights including:

  • Access — request a copy of the personal data we hold about you
  • Correction — ask us to correct inaccurate data
  • Deletion — request that we delete your account and associated data
  • Portability — receive your data in a portable format
  • Objection — object to certain processing activities

To exercise any of these rights, email us at the address below. We will respond within 30 days.

Children

Polinary is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.

Changes to this policy

We may update this policy from time to time. Material changes will be communicated by email to account holders at least 7 days before they take effect. Continued use of the Service after the effective date constitutes acceptance of the updated policy.

Contact

Questions or requests regarding this policy can be directed to:
hey@polinary.com