Sailsy.ai Legal
Privacy Policy
1. Introduction
Sailsy.ai is an AI-powered sales management platform for B2B businesses, operated by Sailsy, which is responsible for your account data; for CRM data your organisation is the controller (see section 2). The platform is developed with our technology partner Son of a Coder (Stockholm, Sweden), which works on our behalf as a supplier. This Privacy Policy explains what information we collect, how we use it, and the choices available to you. The full, current policy is at sailsy.ai/privacy.
2. Information We Collect
We collect account details such as your name and email address, CRM records you create, import or approve for import, usage information, and data from connected services (Google, Microsoft, Twilio, HubSpot) that you explicitly authorize. For your organisation's CRM data, including data found in connected mailboxes, your organisation is the controller and we process it on its behalf.
3. How We Use Information
We use information to provide the service, maintain security, improve product performance, support CRM workflows, and deliver the AI-powered features you request.
4. Mailbox Data (Gmail and Outlook)
Connected mailboxes are used only for reply detection and activity logging, sending emails you write, schedule in a sequence, or that your booking page sends (confirmations and reminders), calendar scheduling, and — when you turn on "Read my inbox" — contact discovery. Contact discovery reads senders, recipients and dates from the last 12 months, does not keep newsletters or automated senders, and has up to three recent messages from your strongest business contacts analysed by our AI provider to find titles, phone numbers, companies and open quotes. Messages that appear to concern health, beliefs, union membership, sexual orientation, criminal or private family matters are filtered out before AI analysis, and messages from personal email addresses are never sent to the AI. Organization admins can turn contact discovery off, and people who object can be blocked from being suggested again. The bodies and subject lines it reads are not stored. Suggestions are visible only to you, nobody is added to your CRM until you import them, and suggestions you don't import are deleted after 60 days, or immediately when you disconnect the mailbox.
Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements, and we apply the same rules to Microsoft data. Mailbox data is never sold, never used for advertising, and never used to develop, improve, or train generalized AI or machine-learning models.
5. Sharing and Subprocessors
We do not sell personal information. We share data with providers that help us operate the features you use, mainly: Supabase (database, EU — Ireland), DigitalOcean (hosting), Upstash (scheduled delivery), Google reCAPTCHA (abuse protection), Anthropic and OpenAI (AI processing, or a model provider your organisation connects with its own key), ElevenLabs and Deepgram (voice), Resend (email delivery), Twilio (calls and SMS), Daily (video meetings), Stripe (payments), Apollo, Hunter, Firecrawl, Apify, LinkdAPI, ScrapingDog, Perigon, NewsAPI and Pexels (company research, when used), and Google Analytics and Microsoft Clarity (analytics, with consent). Transfers outside the EU/EEA rely on appropriate safeguards such as the EU Standard Contractual Clauses or the EU–US Data Privacy Framework. We may also disclose information when legally required or in connection with a business transfer.
6. Data Security and Retention
We use technical and organizational safeguards to protect your data. Account and CRM data are kept while your account is active and deleted when you delete them. Import suggestions are deleted after 60 days if not imported, and 30 days after being imported or dismissed. Mailbox tokens are deleted when you disconnect.
7. Your Rights
Under the GDPR you may have rights to access, correct, delete, restrict, or export your personal data, and to object to processing based on legitimate interests. You can also lodge a complaint with a data protection authority — in Sweden, Integritetsskyddsmyndigheten (IMY).
8. Contact
For privacy questions, contact Sailsy at privacy@sailsy.ai.