Privacy Policy
Effective date: 2026-10-07
This Privacy Policy explains what personal data CampaignFactory ("CampaignFactory," "we," "us") collects, how we use it, and what rights you have, including when you connect a Google or Microsoft account to CampaignFactory.
Who we are
CampaignFactory is operated by Goat Stone B.V., registered at Olympiaweg 26H, 1076 VX Amsterdam, the Netherlands, KvK number 95557024. We are the data controller for the personal data described in this policy. You can reach us at privacy@campaignfactory.io for any privacy question or request.
What we collect
We collect the following categories of information:
- Account and organization information: your name, work email, password (hashed, never stored in plain text), job title, and your organization's name and billing details.
- Customer data you enter or import: lead and contact records (names, companies, titles, email addresses, LinkedIn URLs), notes you write, and the campaigns and email sequences you create.
- Connected-account data, if you connect a Gmail, Outlook, or Google Calendar account — described in detail below.
- Usage and billing data: which features you use, and subscription and payment status (actual card details are handled entirely by our payment processor, Stripe — we never see or store your card number).
Google user data: exactly what we access and why
If you connect a Google account to send campaign emails, CampaignFactory requests the following Google API scopes. We request each scope narrowly, for the specific purpose below, and never more than that purpose requires.
- Gmail send (
gmail.send): lets CampaignFactory send campaign emails from your own Gmail address, on your explicit instruction (you approve every draft before it sends). We never send email on your behalf without that approval, and we never read your existing sent mail through this scope. - Gmail metadata (
gmail.metadata): lets CampaignFactory detect when a contact replies to a campaign email, so the campaign stops automatically instead of sending a follow-up to someone who already responded. This scope deliberately cannot read message bodies or subjects — Google's metadata scope only exposes headers. We read exactly three headers (From,Date, andMessage-ID) on messages in a thread we sent, to determine whether a new message arrived and who it's from. We never read, store, or process the text of any email you send or receive, your inbox, or any email outside a thread CampaignFactory itself started. - Email address and basic profile (
userinfo.email,userinfo.profile): lets us show which mailbox is connected, and lets CampaignFactory address you correctly when composing your own email signature. We do not access your Google contacts, Drive, Photos, or any other Google product through this.
If you separately connect Google Calendar (a distinct, optional connection from Gmail) so CampaignFactory can prepare meeting briefs ahead of external meetings, we request:
- Calendar, read-only (
calendar.readonly): lets CampaignFactory read your upcoming calendar events — title, time, location, and attendee list — to identify meetings with external contacts and prepare a briefing document before each one. This access is read-only: CampaignFactory never creates, edits, or deletes anything on your calendar.
We never send any Gmail or Google Calendar data to Anthropic or any other AI model. Reply detection only ever sees three message headers, never message content, so there is no email content to send to an AI model even if we wanted to. Calendar event details (title, attendees) are used to prepare meeting briefs through an AI model only for the specific meeting they describe, for the purpose of helping you prepare for that meeting.
CampaignFactory's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Microsoft / Outlook user data: exactly what we access and why
If you connect a Microsoft (Outlook, Office 365, or personal Microsoft) account instead of or alongside Gmail, CampaignFactory requests the following Microsoft Graph permissions:
- Send mail (
Mail.Send): the same purpose as Gmail's send scope above — sending campaign emails from your own mailbox, only on your explicit approval. - Read mail (
Mail.Read): used for the same reply-detection purpose described above. Microsoft Graph does not offer a headers-only equivalent to Gmail's metadata scope, so this permission is technically broader than what we use — but in practice, our code only ever requests and reads the sender address, the received timestamp, and the conversation/thread identifier of messages in a thread we sent. We never request, read, or store the subject or body text of any Outlook message, and we never browse your inbox outside a thread CampaignFactory itself started. - Basic profile (
User.Read): lets us show your display name, the same purpose as Google's basic-profile scope above. - Offline access (
offline_access): lets CampaignFactory keep your mailbox connected without asking you to sign in again every time a campaign needs to send.
As with Google data, we never send any Outlook mail data to Anthropic or any other AI model.
What we store, and for how long
- OAuth tokens (Google or Microsoft) are encrypted at rest in a dedicated secrets vault, never stored as plain text in our regular database, and are only ever decrypted server-side to make the specific API call described above.
- Reply records store only a conversation/thread identifier, a message identifier, and a timestamp — never the sender address, subject, or body text of the reply itself.
- Calendar-derived meeting records store the event title, time, location, organizer, and attendee list for meetings with external contacts — never the event's free-text description or notes field.
- Account, organization, and customer data (leads, contacts, campaigns) are retained for as long as your account is active.
- An unconfirmed signup (an account created but never verified by email) is automatically deleted after 30 days.
- If you close your account or request deletion (see below), we delete your personal data, including stored OAuth tokens, within 30 days — the timeframe GDPR requires us to respond to a deletion request in any event.
Disconnecting a mailbox or calendar, and requesting deletion
You can disconnect a connected Gmail, Outlook, or Google Calendar account at any time from Settings → Connected accounts. Disconnecting immediately stops CampaignFactory from accessing that account going forward.
To request deletion of your account and all associated personal data, including any connected-account credentials, email privacy@campaignfactory.io. We will confirm your identity and complete the deletion within 30 days.
How we use AI
CampaignFactory uses Anthropic's Claude models to draft outbound emails and research summaries, and to prepare meeting briefs from calendar data you've connected. Every AI-drafted email is a draft only — nothing sends without you reviewing and approving it. As stated above, Gmail and Outlook message content is never included in what we send to any AI model, because reply detection never reads message content in the first place.
Sub-processors
We use the following sub-processors to provide CampaignFactory. Each is bound by a data processing agreement consistent with GDPR Article 28.
- Supabase — database, authentication, and backend infrastructure (EU region).
- Vercel — application hosting for the CampaignFactory web app.
- Anthropic — AI model provider for email drafting, research summaries, and meeting briefs.
- Brave Search — company and news research used to personalize outbound emails.
- Stripe — payment processing and subscription billing.
Your rights (GDPR)
Goat Stone B.V. is based in the European Union, and processes personal data in accordance with the General Data Protection Regulation (GDPR). Regardless of where you are located, you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Request erasure of your data ("right to be forgotten").
- Restrict or object to our processing of your data.
- Receive your data in a portable, machine-readable format.
- Lodge a complaint with your local data protection supervisory authority, or with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens), if you believe we have not handled your data lawfully.
To exercise any of these rights, email privacy@campaignfactory.io.
Security
All data is encrypted in transit (TLS) and at rest. Access to production data is restricted to the personnel who need it to operate CampaignFactory. OAuth tokens are stored in a dedicated, encrypted secrets vault, separate from our regular database, and are never logged or exposed in plain text.
Cookies
We use only the strictly necessary cookies required to keep you signed in securely. We do not use third-party advertising or analytics cookies.
Children's privacy
CampaignFactory is a B2B product intended for business use and is not directed at children. We do not knowingly collect personal data from anyone under 16.
Changes to this policy
We may update this policy from time to time. If we make a material change, we will notify account owners by email before it takes effect.
Contact us
Questions about this policy or your data: privacy@campaignfactory.io. Goat Stone B.V., Olympiaweg 26H, 1076 VX Amsterdam, the Netherlands. KvK 95557024.