LSLeadSprintBack to home
!This is a template pending legal review. All bracketed [PLACEHOLDERS] must be confirmed with qualified legal counsel before this policy is published to users.

Privacy Policy

Effective date: August 2, 2026

1. Who We Are

LeadSprint LLC, a North Carolina limited liability company (“LeadSprint,” “we,” “our,” or “us”) operates the LeadSprint CRM and AI lead-engagement service available at leadsprint.app (the “Service”). LeadSprint is a business-to-business product designed for companies operating in the United States.

Privacy questions or requests: [PRIVACY CONTACT EMAIL — suggest privacy@leadsprint.app]

2. Our Two Roles: Your Data vs. Your Leads’ Data

LeadSprint handles two distinct kinds of personal information, and our responsibilities differ for each:

  • Your account data — information about you and your team members as users of the Service. For this data, LeadSprint is the data controller and this policy describes how we handle it.
  • Your leads’ data — information about your leads, contacts, and customers that you upload, import, or receive through the Service. For this data, you are the controller and LeadSprint acts as your service provider (processor): we process it only on your instructions to operate the Service, and we look to you to have the legal right and any required consent to bring that data into LeadSprint and to contact those individuals.

3. Information We Collect

We collect the following categories of information when you use the Service:

  • (a) Account data — your name, email address, and workspace information provided through our authentication provider (Clerk) when you sign up or sign in.
  • (b) Lead data — names, email addresses, phone numbers, company details, notes, and messages belonging to your own leads and contacts, which you upload, import, or capture through intake forms and connected channels.
  • (c) Communications content — the text of emails and SMS messages sent and received through the platform on your behalf, including AI-generated draft replies and the conversation context used to produce them.
  • (d) Knowledge-base content — documents and business context you choose to upload so the AI can answer questions about your business accurately.
  • (e) Payment data — subscription payments are processed by Stripe. Your card number is transmitted directly to Stripe and never touches or is stored on LeadSprint servers; we retain only subscription status and billing metadata.
  • (f) Usage and operational logs — IP addresses, browser type, pages visited within the Service, timestamps, and error logs used for security, support, and service improvement.

We do not knowingly collect sensitive personal information such as government ID numbers or health data through the Service, and we ask that you not upload such data about your leads.

4. How We Use Your Information

We use the information we collect to:

  • Provide and operate the LeadSprint CRM and AI reply service;
  • Send email and SMS communications on your behalf to your leads (using the channels you configure);
  • Generate AI-assisted replies — as drafts for your review, or sent automatically where you have enabled and configured automated sending;
  • Retrieve relevant passages from your knowledge base to ground AI replies in your business facts;
  • Schedule meetings and manage bookings you or your leads confirm;
  • Authenticate users, prevent fraud and abuse, and enforce our Terms of Service;
  • Process subscription billing through Stripe;
  • Provide customer support and respond to your requests;
  • Monitor service health, debug errors, and improve the Service; and
  • Comply with legal obligations.

We do not use your account data, lead data, or communications content to train AI models, and we do not permit our AI subprocessors to use content submitted through their APIs for model training.

5. How AI Processing Works

To generate replies and insights, relevant conversation content, lead context, and knowledge-base passages are transmitted to our AI providers (listed in the subprocessor table below) for processing. This happens only to produce output for your workspace. AI provider API terms prohibit use of this content for model training. You control whether AI replies are sent automatically or held as drafts for human review, and automated sending is subject to per-workspace guardrails including verification checks, intent restrictions, and daily send caps.

6. Subprocessors (Third-Party Service Providers)

We share data with the following third-party subprocessors to deliver the Service. Each provider handles data only as necessary to perform its function and is bound by its own privacy and security commitments.

SubprocessorPurposePrivacy Policy
ClerkUser authentication and session managementclerk.com
NeonDatabase hosting (stores lead, account, and communications data)neon.tech
RenderApplication hosting (runs the LeadSprint API and web app)render.com
CloudflareCDN, DDoS protection, and network securitycloudflare.com
ResendTransactional and outbound email deliveryresend.com
TelnyxSMS delivery and phone number provisioningtelnyx.com
AnthropicAI reply generation (processes message content and business context to generate responses)anthropic.com
OpenAIKnowledge-base embeddings (converts your uploaded documents into search vectors)openai.com
StripeSubscription billing and payment processingstripe.com

Separately from the subprocessors above, you may choose to connect optional integrations to your workspace — for example a Google or Microsoft account for email or calendar sync, or a Calendly account for scheduling. Data flowing through a connected integration is governed by that provider’s own terms and privacy policy, and you can disconnect these integrations at any time from your workspace settings.

This list may be updated as we add or change providers. When we add a subprocessor that handles lead data, we will update this page.

7. Google and Microsoft Account Data (Limited Use)

When you connect a Google or Microsoft account to LeadSprint, you grant a narrow, specific set of permissions. This section explains exactly what we receive and how we handle it. You can use LeadSprint without connecting a Google or Microsoft account at all.

PermissionWhat it allowsWhy we need it
Send email as youSends messages from your connected address. It does not permit reading your mailbox.So replies to your leads arrive from your own address rather than a generic one.
Read your mailboxReads messages in the connected mailbox. Requested only if you enable two-way sync.So LeadSprint can see replies that land directly in your inbox and continue the conversation.
Identify the connected accountReturns the email address and basic profile of the account you connected.To show which address is connected and to prevent duplicate connections.
See when you are busyReturns busy and free intervals only — not event titles, attendees, or details.So the assistant only proposes meeting times that do not conflict with your calendar.
Manage a LeadSprint calendarCreates and manages events on a separate calendar that LeadSprint creates. Requested only if you enable calendar write-back.So confirmed bookings appear on your calendar. We do not read or modify your other calendars.

We request the narrowest permission that delivers the feature you turned on, and we request nothing until you connect an account.

Limited Use commitment

LeadSprint’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  • We use Google user data only to provide and improve the user-facing features described in this policy.
  • We do not transfer Google user data to third parties except (a) to the subprocessors listed in Section 6, as necessary to provide those features; (b) as required by applicable law; (c) as part of a merger or acquisition, with notice to you; or (d) with your explicit consent.
  • We do not use Google user data for advertising, and we do not sell it.
  • We do not use Google user data to determine credit-worthiness or for lending purposes.
  • We do not permit humans to read your Google user data, except (a) with your explicit consent for a specific message; (b) as necessary for security purposes, such as investigating abuse; (c) to comply with applicable law; or (d) where the data has been aggregated and anonymized for internal operations.

The same commitments apply to data we receive from Microsoft Graph.

Automated processing is not human review

Message content is processed by our automated systems and by the AI subprocessors listed in Section 6 in order to draft replies, as described in Section 5. It is not read by LeadSprint personnel except in the limited circumstances above. Your message content is not used to train any general-purpose AI model. [COUNSEL: confirm this statement is supported by our AI-subprocessor terms — the basis is Anthropic’s no-training and limited-retention commitments, and the equivalent terms for the knowledge-base embeddings provider.]

Storage, security, and retention

OAuth access and refresh tokens are encrypted at rest using AES-256-GCM and are never displayed back to you or to our staff. Message and calendar content is stored only to the extent needed to maintain the conversation and booking history in your workspace, and is deleted under the retention schedule in Section 8 — including the 90-day post-closure window.

How to revoke access

You can disconnect a connected account at any time in LeadSprint under Settings → Email or Settings → Scheduling. You can also revoke LeadSprint’s access directly at myaccount.google.com/permissions (Google) or myaccount.microsoft.com/privacy (Microsoft). Revocation stops all future access immediately. Data already stored in your workspace is removed under Section 8, or sooner on request to [PRIVACY CONTACT EMAIL].

8. Data Retention

We retain your account data and lead data for as long as your workspace is active. Following account closure, data is retained for 90 days and then deleted, or deleted sooner if you request it. This window exists so you can recover from an accidental closure, settle any final billing, and export your data — it is not a long-term archive. If you need continued access to historical lead data, keep your workspace active or export it before closing. Operational logs are retained for a shorter period as needed for security and debugging.

You may request deletion of your data at any time by contacting [PRIVACY CONTACT EMAIL]. We will process verified deletion requests within 30 days.

9. Your Privacy Rights

Depending on your location and applicable law, you may have the following rights regarding your personal information:

  • Access — request a copy of the personal information we hold about you;
  • Correction — request that inaccurate information be corrected;
  • Deletion — request that we delete your personal information, subject to legal retention obligations;
  • Data portability — request an export of your data in a machine-readable format.

We do not sell your personal information, and we do not share it for cross-context behavioral advertising.

To exercise any of these rights, contact us at [PRIVACY CONTACT EMAIL]. We will verify your identity before processing requests. If you are a lead or contact of a LeadSprint customer and wish to exercise rights over data that customer holds about you, we will refer your request to that customer and assist them in responding.

10. Data Location

The Service is hosted in the United States. If you access LeadSprint from outside the United States, your information will be transferred to and processed in the United States. By using the Service, you consent to this transfer.

11. Cookies and Essential Storage

LeadSprint uses only the cookies and browser storage necessary to operate the Service: authentication and session cookies (provided by Clerk), security cookies used for bot protection on public forms, and local preferences such as your theme choice. We do not use third-party advertising cookies or cross-site tracking technologies.

12. Children’s Privacy

The Service is a business tool and is not directed to individuals under the age of 18. We do not knowingly collect personal information from minors. If you believe we have inadvertently collected such information, please contact us at [PRIVACY CONTACT EMAIL] and we will delete it promptly.

13. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the “Effective date” at the top of this page and, where required by law, provide additional notice (such as an email notification). Continued use of the Service after the effective date constitutes acceptance of the updated policy.

14. Contact Us

For privacy-related questions, requests, or complaints, contact us at:

  • Email: [PRIVACY CONTACT EMAIL]
  • Legal entity: LeadSprint LLC, a North Carolina limited liability company
  • Address: 6152 Loch Laural Lane, Raleigh, NC 27613
© 2026 LeadSprint
HomePrivacy PolicyTerms of ServiceContact