Privacy policy
Last updated: 27 August 2026
ColdMerge ("ColdMerge", "we", "us") is a tool for sending cold-email outreach through your own Gmail or Google Workspace account and detecting the replies to it. This policy explains, plainly and specifically, what data we handle, why, what we deliberately do not keep, and the choices you have. It is written to describe how this product actually works, not from a generic template.
Two kinds of people are covered here: the person who signs in and connects a Google account (our customer, "you"), and the people that customer chooses to email (their "contacts"). Sections below say which is which where it matters.
Contents
- Google account data and scopes
- Limited Use commitments
- What we store and do not store
- Data about the people you email
- How we use data
- Who we share data with
- Retention, deletion, and erasure
- Your choices and rights
- How we protect data
- Where data is processed
- Children
- Changes to this policy
- Contact us
1. Google account data and scopes
When you connect a Google account, we ask Google for a specific, minimal set of permissions (OAuth scopes). We request only what the product needs to work, and never more. You see and approve these on Google's own consent screen.
| Scope | What we use it for |
|---|---|
gmail.send |
To send your outreach and follow-ups from your own Gmail account, as you. |
gmail.readonly |
To read incoming mail solely to detect replies and bounces to the messages this product sent, so a sequence stops when someone replies and a permanent bounce suppresses that address. See the "match-or-drop" rule below. |
openid, userinfo.email |
To identify which Google mailbox you connected (its email address). |
userinfo.profile |
To use your name as the sender's display name, so your messages go out as "Your Name <you@example.com>" rather than a bare address. This one is optional; decline it and your mail simply sends from the address alone. |
Workspace customers who choose to run domain-deliverability diagnostics may additionally be asked for a read-only Google Postmaster Tools scope, only at that point and never at connect. It is never requested from free Gmail users, who cannot use it.
The match-or-drop rule. The mailbox watch sees your whole inbox, including your entirely personal mail. An incoming message is recorded and acted on only if it belongs to a conversation this product started (matched by the Gmail thread identifier of a message we sent). Everything else is dropped, unread, and never stored. This is the hard line that keeps reply detection from being mailbox reading.
2. Limited Use commitments
ColdMerge's use and transfer to any other app of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements. In concrete terms:
- We use Google user data only to provide and improve the user-facing features described here (sending your mail, detecting your replies and bounces).
- We do not transfer Google user data to others except as needed to provide those features, for security or legal reasons, or as part of a merger you are notified of.
- We do not use Google user data for advertising of any kind, and we never sell it or provide it to data brokers.
- No human at ColdMerge reads the content of your Gmail messages. Reply and bounce classification is fully automated. The narrow exceptions Google allows (your explicit agreement, security, or a legal requirement) are the only times a person would look at specific data.
3. What we store and do not store
The most important fact about ColdMerge is how little of your mail it keeps. Gmail stays the system of record for your message content; we keep the minimum needed to run and account for your campaigns.
Outgoing messages
For each message sent we store correlation keys (the Gmail message and thread identifiers), which account and contact it involved, the rendered subject line, the outcome, and timestamps. We do not store the message body. The full message already sits in your own Gmail Sent folder, under your own retention policy; if it needs to be shown, we fetch it from Gmail on demand.
Incoming messages (replies and bounces)
For an incoming message that matches a conversation we started, we store correlation keys, the sender, a short snippet, and a timestamp, and no body. Non-matching mail is never stored (the match-or-drop rule above).
Your Google credentials
Your OAuth tokens are encrypted at rest using envelope encryption, with the wrapping key held in Google Cloud Key Management Service in production. They live in a separate, access-controlled store, not alongside ordinary account data. Disconnecting an account revokes Google's grant and destroys the stored token.
Account and billing
We store your login identity and organization details, and the minimum billing facts (which plan, its status, a Stripe customer reference, the period end). We never store card numbers or payment details; our payment processor holds those.
4. Data about the people you email
When you import contacts, that data (names, email addresses, and any fields you upload) belongs to you and is stored in isolation for your organization only. We process it on your behalf to send your campaigns and personalize your messages. We do not use your contact lists for our own purposes, do not share them between customers, and do not sell them.
Optionally, you may check whether an uploaded address is likely deliverable. That check sends the address to an email-verification provider and stores the resulting verdict so the same address is not re-checked needlessly.
Every send honors an organization-wide suppression list: anyone who unsubscribes, hard-bounces, or is manually suppressed is never emailed again. Unsubscribes are permanent records.
5. How we use data
- To send the outreach and follow-ups you create, from your account.
- To detect replies and bounces and stop or suppress accordingly.
- To personalize your messages using the fields you provide.
- To show you your campaigns, results, and reply notifications.
- To operate, secure, support, and bill for the service.
We do not use your data, or your recipients' data, for advertising, profiling, resale, or training unrelated systems.
6. Who we share data with
We use a small set of sub-processors to run the service. Each receives only what it needs for its job:
| Provider | Purpose |
|---|---|
| Gmail sending and reply detection, sign-in, key management (Cloud KMS), and reply push notifications (Cloud Pub/Sub). | |
| Stripe | Payment processing and billing. Card and payment data go directly to Stripe and never touch our servers. |
| MillionVerifier | Optional email-address verification of addresses you upload. |
| Resend | Sending our own transactional email to you (for example, reply notifications and account mail). |
| Cloudflare | DNS, TLS, and proxying for our domains, and hosting for this site. |
| Hetzner | Server hosting for the application and database, in the EU. |
We may also disclose data if required by law, or to protect the rights, safety, and security of ColdMerge, our customers, or the public. If ColdMerge is ever involved in a merger or acquisition, we will notify affected customers as required.
7. Retention, deletion, and erasure
We keep data for as long as your account is active and you need it to run your campaigns, then no longer than necessary. Some specifics:
- Disconnecting a Google account revokes the grant and destroys the stored token immediately.
- Uploaded import files are held only briefly: the staged copy of an uploaded file is deleted about 30 days after upload, by a daily sweep, once the import's outcome has been recorded.
- When you delete a contact, their messages and history are removed with them. Because we never stored message bodies, there is no hidden archive to scrub.
Erasure (right to be forgotten). On a valid erasure request we hard-delete the person's personal data and history. To honor a prior opt-out without keeping their address, we retain only a one-way hash of the email address on the suppression list. The hash cannot be reversed to recover the address; it exists solely so the person is never emailed again. This is a deliberate, minimal exception to full deletion, and it is the standard way to reconcile "delete my data" with "never contact me again".
8. Your choices and rights
Depending on where you live (for example under the GDPR or UK GDPR), you may have rights to access, correct, export, or delete your personal data, and to object to or restrict certain processing. You can:
- Disconnect a Google account at any time from within the app.
- Ask us to access, correct, or delete your personal data by emailing privacy@coldmerge.com.
- Manage or revoke ColdMerge's access to your Google account directly at your Google account permissions page.
If you are a recipient of email sent through ColdMerge and want to stop hearing from a sender, use the unsubscribe option in their message; that adds you to that sender's permanent suppression list. You may also contact us at the address below.
9. How we protect data
Google credentials are encrypted at rest with per-record data keys wrapped by a managed key service, and every use of that key is logged and revocable. Each customer's data is isolated to their own organization. Access to production systems is limited and need-based. No system is perfectly secure, but we design to keep the most sensitive data (your tokens and your recipients' details) tightly held and minimally retained.
10. Where data is processed
Our application and database are hosted in the European Union (Hetzner). Google, Stripe, and our other providers operate globally and may process data in other countries under their own safeguards. By using ColdMerge you understand your data may be processed in the locations these providers operate.
11. Children
ColdMerge is a business tool and is not directed to children. We do not knowingly collect personal data from anyone under 16.
12. Changes to this policy
We may update this policy as the product changes. When we do, we revise the "last updated" date above, and for material changes we will take reasonable steps to let account holders know.
13. Contact us
Questions about this policy or your data, or to make a privacy request, email privacy@coldmerge.com. For anything else, reach us at hello@coldmerge.com.