Legal

Privacy Policy

Last updated 18 September 2026.

This policy explains what personal data Peitho handles, why, who it goes to, and what you can ask us to do about it. It covers both the public website and the application. The short version is in section 2; the detail follows it.

1. Who we are and what this covers

The Service is operated as Peitho (“Peitho”, “we”, “us” or “our”). We are the controller of the personal data described here — that is, we decide why it is collected and how it is used. Our contact address for anything to do with privacy is support@peitholeads.com.

This policy applies to the public website, the Peitho application, and the emails we send about accounts, invitations and the messages you choose to send through the Service. It does not apply to a platform you connect (such as Reddit, X, LinkedIn, Meta, TikTok, Google or Discord), or to any other company's service that we link to or that you connect; those are governed by their own policies.

Where you use the Service through an organisation, that organisation decides much of what is stored in its workspace and who can see it. In that case it is also responsible for the data in its account, and you should raise questions about it with its administrators as well as with us.

2. In short

  • We collect what is needed to run the Service and nothing more.
  • We do not sell your personal data, and we do not run advertising or tracking pixels on this site.
  • We use cookies only where the Service cannot work without them — to keep you signed in and to protect sign-in.
  • We do not use your content to train any AI model. Text is sent to the content generation service configured for your deployment only to produce the draft or classification you asked for.
  • We share data with the providers that make the Service work, listed in section 7, and with nobody else except where the law requires it.
  • You can ask for a copy of your data, ask us to correct it, or ask us to delete it — see section 12.

3. What we collect

Account and organisation details. Your email address, a securely hashed password (we never store the password itself), your name where you provide one, your role in an organisation, the organisation's name, the email address of anyone you invite, and whether an address has been confirmed.

Content you put in the Service. Campaign names, descriptions, links, keywords and the places you target; briefs and instructions; generated drafts and your edits to them; approvals and rejections; scheduling and drip settings; notes, tags and pipeline stages you record against leads; media URLs you supply; outreach messages you write or edit; and anything you submit through the feedback or bug-report forms, together with the page you were on and the browser you used.

Data from accounts and platforms you connect. When you connect an account we store access and refresh tokens for it, in encrypted form, and the identifiers the platform gives us for it (such as an account id or handle). While the connection is active we read and store the posts you publish through the Service, the engagement figures for them — views, likes, replies and the like — the replies and comments people leave on them, and the information those replies contain, which normally includes the author's public handle and what they wrote.

Public data about potential leads. The Service searches public sources and business registries for conversations, companies and creators that may be relevant to your campaigns. What it stores is the public record of that material: the text of a public post or comment, its author's public handle, the community or platform it appeared in, its date, its public engagement counts, and, for companies, the details a register or public listing publishes — name, registration number, address, and any email address, phone number or contact name that the company itself publishes. This is business contact information about people acting in a professional capacity, gathered from sources that are open to everyone.

Billing data. The plan you are on, its status, the period it covers, and the identifiers our payment provider gives us for you and your subscription. Payments are handled by the payment provider: your card or bank details are given to it directly, and we never see or store them.

Technical data. Your IP address and the time of a request, which we use to enforce rate limits and to protect accounts from abuse; server and application logs, which record events such as a sign-in, an approval, a publish or an error; and the identifiers stored in the cookies described in section 6.

We do not ask for special categories of data (such as health, political opinions, or trade union membership), and you should not put them into the Service.

4. Why we use it, and on what basis

  • To provide the Service you asked for — creating and securing your account, finding leads, drafting and scheduling posts, publishing them to the accounts you connected, collecting their results, and showing you your reports. Legal basis: performance of our contract with you.
  • To take payment and keep proper records — charging your subscription, handling renewals and failed payments, and keeping the accounting records the law requires. Legal basis: performance of the contract, and compliance with a legal obligation.
  • To keep the Service working, safe and secure — authenticating you, rate limiting, monitoring for abuse, fraud and attacks, investigating errors, and maintaining backups. Legal basis: our legitimate interests in operating a secure and reliable service, and compliance with legal obligations.
  • To support you — answering your questions, diagnosing a problem you report, and notifying you about the Service, including changes to it or to our terms. Legal basis: performance of the contract and our legitimate interests.
  • To send the emails you ask us to send — confirmation, password reset, password changed and organisation invitations. Legal basis: performance of the contract.
  • To send outreach messages about you — where you use the outreach feature, messages are sent from your organisation's own verified address in your name, and the legal basis for that sending is yours to establish, including getting any consent your law requires. We provide the tool, keep the record, honour opt-outs, and do not send anything by ourselves.
  • To comply with the law — responding to lawful requests, enforcing our terms, and establishing or defending legal claims. Legal basis: compliance with a legal obligation and our legitimate interests.
  • With your consent — where we ask for it for something specific, in which case you may withdraw it at any time.

Where we rely on our legitimate interests, we have balanced those interests against your rights, and you may object to processing on that basis — see section 12.

5. What we do not do

  • We do not sell or rent your personal data to anyone.
  • We do not run advertising networks, third-party tracking pixels, session recording, or cross-site behavioural profiling on the site or in the application.
  • We do not use your content, your connected accounts' data, or your customers' data to train AI models — ours or anyone else's.
  • We do not send outreach messages ourselves, and we do not build mailing lists for our own marketing out of the leads in your account.
  • We do not use the public data we find for our own marketing, or share it with your competitors.

6. Cookies and similar storage

We use cookies only where the Service needs them. There is no advertising, profiling or analytics cookie, and no third-party tag that sets one.

  • Strictly necessary — sign-in. A short-lived access cookie and a longer-lived refresh cookie keep you signed in as you move between pages, and let the application renew your session without asking you to sign in again. They are allowed only by the site that set them, are not readable by scripts, and are removed when you sign out.
  • Strictly necessary — sign-in protection. A short-lived, single-purpose cookie is set while you authorise a connected account. It carries the value that protects the authorisation round trip against tampering, and expires within minutes.
  • Strictly necessary — notice acknowledgement. A small value is kept in your browser's local storage so the notice about cookies is not shown to you again once you have accepted it. It contains no identifier and is not sent to us.

Because all of these are needed for the Service to work and none of them track you, they do not require a separate opt-in. We show a notice so that you know they are there. You can remove cookies and clear local storage at any time through your browser settings; signing out does it for the sign-in cookies, and clearing the site's storage brings the notice back.

7. Who we share it with

We share personal data only with providers that help us run the Service, and only as much as each one needs. They act on our instructions and are bound to protect what they receive.

  • Hosting and networking. Our application servers, database and content delivery are hosted by third-party infrastructure and network providers, which necessarily process the data as it passes through and is stored on their systems.
  • Payments. Our payment provider processes your subscription, holds your payment details, and sends us the plan and status information described in section 3.
  • Account email. Our email provider delivers the account, invitation and outreach messages described above, and therefore processes the recipient addresses and message content.
  • Content generation and analysis. The text needed to carry out a task — the brief and the lead it relates to, or the reply being classified — is sent to the model configured for your deployment so that it can produce that draft or classification. What is sent is limited to what the task requires.
  • Platforms you connect. Posts, replies, messages and the requests needed to read engagement and replies are sent to the platforms you have connected, under your authorisation.
  • Public sources and registries. Discovery queries are sent to the public search engines, registries, directories and map services the Service draws on. A query contains your campaign's keywords and, where relevant, a place — not your account details.
  • Services you choose to connect. Where you connect a CRM or a webhook, the data you have asked us to send is forwarded to the destination you configured.
  • Members of your organisation. People in your organisation can see the data in its workspace, according to the roles their administrators have given them.
  • Legal and safety. We may disclose data where we are required to by law or by a competent authority, to enforce our terms, or to protect the rights, property or safety of anyone; and to a buyer or successor if the business or its assets are transferred. Where we can, we will tell you before doing so.

Where a provider processes data outside the country you are in, we put in place the safeguards the law requires for that transfer — a decision that the destination provides adequate protection, or a contract using the standard data protection clauses, together with any supplementary measures needed.

8. Automated processing and AI

Parts of the Service are automated. Drafts, relevance scores, sentiment labels and optimisation suggestions are produced by software and, for some of them, by a language model. To produce them, the relevant text is sent to the model endpoint configured for your deployment, together with the instructions that shape the task.

The output is advisory. It is never published or sent on its own: a person has to review and approve it first, and the Service is built so that this gate cannot be removed. We do not use any of it to make a decision with legal or similarly significant effect about you or about anyone else, and we do not build profiles of individuals for marketing purposes.

If you would like to know more about how a particular automated feature works before you rely on it, write to us at the address in section 1.

9. Keeping it and deleting it

We keep personal data for as long as it is needed for the purposes set out in section 4: while your account is open, so that the Service can work, and after that for as long as we need it to meet our legal, tax and accounting obligations, to resolve disputes, to keep records of opt-outs and suppressions, and to enforce our agreements. Different kinds of data are kept for different lengths of time, because different laws and purposes apply to them.

When data is no longer needed for any of those purposes we delete it or make it anonymous so that it can no longer be linked to a person. Data held in backups is removed as those backups expire in the ordinary course. If you want to know how a particular kind of data is treated, ask us at the address in section 1.

You can ask us to delete your account and the data in it at any time; see section 12. Where you are a member of an organisation rather than its owner, the organisation controls its workspace data, and such a request should also be made to its administrators.

10. How we protect it

  • All traffic between your browser and the Service, and between the Service and the providers in section 7, is encrypted in transit.
  • Passwords are stored only as a one-way hash. Tokens for connected accounts are encrypted before they are stored.
  • Access within the Service is scoped to your organisation, and what each person can see and do is governed by the role they hold. A customer cannot reach another customer's data.
  • Sessions are short-lived by design: sign-in tokens expire quickly and are renewed, and a password change or reset ends other sessions.
  • We keep records of significant actions, monitor for abuse, and keep backups so that data can be recovered.

No system is perfectly secure. If a breach occurs that is likely to result in a risk to your rights, we will tell you and the relevant authority as the law requires.

11. Where your data is stored

The Service runs on servers and services operated by our providers, which may be in a different country from you, and which may involve support and operations staff in more than one country. Wherever data is transferred internationally we rely on the safeguards described at the end of section 7.

12. Your rights

Depending on where you are, you may have some or all of the following rights. We will not charge you for exercising them, and we will not treat you differently for doing so.

  • Access. A copy of the personal data we hold about you, and information about how we use it.
  • Correction. Putting right data that is inaccurate or incomplete. Most of it you can edit yourself in the application.
  • Deletion. Asking us to delete your data, where we do not have a legal or other overriding reason to keep it.
  • Portability. Receiving the data you provided in a structured, commonly used, machine-readable format, or having us send it to another provider where that is technically possible. The application already exports much of it — leads, companies, creators and reports can be downloaded as CSV.
  • Objection. Objecting to processing based on our legitimate interests, and to direct marketing at any time. Where we rely on consent, you can withdraw it at any time without affecting what was done before.
  • Restriction. Asking us to pause the processing of your data while a question about it is resolved.
  • Complaint. Complaining to the data protection authority in your country, region or state. We would rather you came to us first, but it is your right to go to them directly.

To exercise any of these, write to support@peitholeads.com. We may need to confirm who you are before we act, so that we donot give your data to somebody else, and we will answer within the period the applicable law sets. If your request concerns data in an organisation's workspace and you are not its owner, we may need to involve its administrators.

Where you have received an outreach message and want no further contact from the organisation that sent it, use the opt-out link in that message. We keep a record that the address has opted out so that it is not contacted again.

13. Children

The Service is a business tool and is not intended for anyone under 18. We do not knowingly collect personal data from children. If you believe a child has given us their data, contact us and we will delete it.

14. Changes to this policy

We may update this policy as the Service or the law changes. The date at the top of the page shows when the current version took effect. Where a change is significant, we will give you notice by email or in the application before it takes effect, so that you can review it.

15. Contact

For anything in this policy — a question, a request, or a complaint — write to support@peitholeads.com. If you are in the European Economic Area, the United Kingdom,Switzerland or another jurisdiction with a comparable regime and you are not satisfied with our answer, you may also complain to the supervisory authority where you live or work, or where the issue happened.

Questions about this document go to support@peitholeads.com. See also our Terms of Service.