Privacy Policy
Last updated 4 July 2026
This policy explains what personal data outr handles, why, and what your rights are. If you have a question about it, email support@tryoutr.io.
outr is an AI agent (called Mira) that builds and runs B2B cold email. It finds business leads that match your targeting, drafts the emails, sets up the sending, and, once you approve, sends and tracks replies.
Who this covers
- People who create and use an outr account (our customers and their team).
- The business prospects our customers choose to contact through outr (the leads), including anything those people write back.
- Visitors to our website.
It does not cover what our customers do with data on their own, or other services that run under their own terms.
The two roles we play (worth reading first)
We handle two kinds of personal data, and our legal role is different for each. We are straight with you about both.
Your account data. For the data of our customers and their team (account, billing, business profile, agent chats, usage), we are the controller: we decide how and why it is used.
Lead and reply data. For the data of the prospects our customers target, and the replies they send, the customer is the controller. The customer decides who to contact and why. When a customer tells outr to find leads, we are carrying out that instruction: we find people who match the customer's own criteria for the customer's own approved campaign, store them, draft the copy, and send only once the customer approves. For most of that, we act as the customer's processor, following their instructions. The details are in our Data Processing Addendum.
One honest point. Because we choose and run the tools that find the leads, run that search on the customer's instruction, provide the AI that writes the copy, and run the shared sending setup, a regulator could decide we are a controller, or joint controller, for parts of the lead lifecycle, especially finding the leads and any use of data to improve outr. Roles follow what you actually do, not what a document calls them, so we do not pretend our own obligations away. Where we do act as a controller, this policy explains the safeguards we apply.
What we collect
Your account data (we are the controller)
- Account: your email address, and the password you set (stored and hashed by our authentication provider, never by us).
- Billing: your customer and subscription identifiers at our payment processor, your subscription status, plan and price, billing dates, and cancellation, lapse, and add-on flags. We do not store your card number, expiry, or security code; our payment processor handles all of that.
- Business profile: your company, offer, value propositions, targeting (persona, industry, region, company size), tone, sender name, signature, and any constraints and facts you give us.
- Agent activity: your instructions, requests, chat with the agent, and the notes it saves.
- Usage: credits, leads added, emails committed, and lead counts.
Lead and reply data (the customer is the controller; we are the processor, subject to the honest point above)
- Leads: business email, first and last name, job title, company, LinkedIn URL, country, status, score, and how the lead was added (manual, sourced, or CSV upload).
- Replies: for prospects who write back, the subject and body, a preview, a category (interested, meeting, question, or not now), and read and answered times. We also store the full inbound message we receive from our email-sending provider.
- Campaigns: the campaign name, status, audience, the draft email sequence, metrics, and the inbox and campaign identifiers used to send.
Payment data
We only store the account and subscription identifiers at our payment processor, plus subscription details. All card data is collected and handled by that processor under its own terms.
Technical data and IP addresses
We use IP addresses briefly to rate-limit signup, lead-count checks, and agent requests. They live in memory and are not written to our database. Our hosting and error-monitoring providers handle request traffic and logs as part of running the service.
Cookies and browser storage
We use a strictly necessary sign-in cookie by default, and, where enabled and only with your consent, analytics and advertising cookies that do not load until you allow them. Our Cookie Policy lists everything, including the browser storage the app uses and how you give, change, or withdraw consent.
Why we use it, and our legal basis
Here is why we process account data, where we are the controller, and the GDPR basis for each.
| Purpose | Categories | Lawful basis |
|---|---|---|
| Create and operate your account; deliver the service you signed up for | Account, business profile, agent activity, usage | Performance of a contract (Art. 6(1)(b)) |
| Take payment, manage subscriptions, and prevent double-charging | Billing, payment identifiers | Performance of a contract (Art. 6(1)(b)); legal obligation for accounting and tax (Art. 6(1)(c)) |
| Secure the service, prevent abuse and fraud, enforce rate and spend limits | Technical data, IP (transient), usage | Legitimate interests (Art. 6(1)(f)): protecting the service, our infrastructure, and other customers |
| Provide support and send service and billing notices | Account, billing | Performance of a contract (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f)) |
| Improve and maintain the service | Aggregate and usage data | Legitimate interests (Art. 6(1)(f)) |
| Comply with legal obligations and respond to lawful requests | As required | Legal obligation (Art. 6(1)(c)) |
For lead and reply data, the customer is the controller and is responsible for having a lawful basis to contact each person (see below). Where we might be a controller or joint controller for finding leads, we rely on our legitimate interest in offering a B2B outreach tool, balanced against people's rights, and we support easy opt-out.
How leads get sourced, and what the customer is responsible for
Finding leads is something we do because a customer asked. The customer sets the targeting (role, industry, region, company size). On that instruction, the agent finds business leads that match, for the customer's own approved campaign. The customer reviews and approves the final list and the copy before anything sends. We never decide who to contact on our own.
The customer confirms it has a lawful basis and the right to contact the audience it targets, and it is responsible for any consent needed and for following every law that applies to it and its recipients wherever they are, including the GDPR, UK GDPR, ePrivacy rules, CAN-SPAM, CASL, and local law. outr is for B2B business contacts only. Consumer and purchased lists are blocked by our guardrails, every send has a one-click unsubscribe, and anyone who unsubscribes or bounces is suppressed for good.
How we use AI
Mira uses a large language model, through a third-party AI provider, to draft your email sequences, follow-ups, and reply suggestions, and to answer questions. To draft a reply, the prospect's reply text is sent to the model along with the relevant campaign and business context. Whatever the AI produces is a draft the customer reviews; nothing sends without approval. We will only state that the AI provider does not train on this data once that is confirmed; see our AI Usage Policy.
The providers we work with
We use trusted third-party providers to run outr: hosting and databases, authentication, payment processing, email-sending infrastructure, lead and data sourcing, lead-count estimation, AI text generation, inbox and domain setup, transactional email, and error monitoring. Each one only handles the data it needs for its job, under a data-processing agreement. Where enabled and only with your consent, we also use analytics and advertising providers, described by category in our Cookie Policy. We can share more detail about the categories of providers we use, and the kinds of data each handles, on request.
Sending data outside your region
Some of these providers are outside the European Economic Area, including in the United States. When personal data goes outside the EEA, we rely on a valid transfer mechanism, such as an adequacy decision, the EU-US Data Privacy Framework, or the European Commission's Standard Contractual Clauses, plus any extra safeguards needed. Ask us at support@tryoutr.io for detail on the transfers relevant to you.
How long we keep it
We keep personal data as long as we need it for the purposes here and to meet our legal obligations. Account data stays while your account is active. Sending history and campaign records are kept for a period while your account is active so outr can run, report on, and continue your outreach. When you delete your account, we permanently delete your account data (see below). Some operational records, like audit logs and aggregate stats, are kept after deletion for security, integrity, and legal reasons. The full periods are in our Data Retention Schedule.
Deleting your data
You can delete your account and its data from within outr. Deleting pauses your campaigns, detaches and releases your inboxes, cancels your subscriptions, and permanently removes your account records, business profile, agent memory, campaigns, leads, and replies. It is permanent, and we log that it happened.
When an account is cancelled, or an inbox is freed up for reuse, the inbox is scrubbed: detached from all campaigns and reset to a neutral sender name. The part of the address before the @ cannot be changed, because our sending provider does not allow it. Pooled inboxes can then be claimed again; dedicated inboxes are cancelled with the provider and never reused.
Two honest limits:
- Some records outlive deletion for security, integrity, and legal reasons (audit logs, error and job records, and aggregate stats with no identifier), plus scrub records we keep with the identifier removed so we can neutralize freed inboxes.
- Our email-sending provider keeps its own record of campaigns and lead lists. If you need those gone, you may have to ask that provider separately, and we will help you do it.
Security
We use technical and organizational measures suited to the risk, including keeping each customer's data isolated with row-level security, restricting sensitive writes, encrypting data in transit and at rest, keeping secrets out of our code, comparing automated-job and webhook secrets in constant time, verifying payment webhooks, protecting against open-redirects at sign-in, rate-limiting by IP, and hard spend limits on paid lead sourcing. Our providers add their own encryption and certifications. No system is ever completely secure, so we cannot promise absolute security. More is in our Security Statement.
Your rights
Depending on the law that applies and any exceptions in it, you can:
- see the personal data we hold about you;
- have wrong data corrected;
- have your data erased;
- restrict or object to processing, including processing based on legitimate interests and any direct marketing;
- get your data in a portable form;
- withdraw consent where we relied on it, without affecting what came before; and
- complain to your data protection authority (in the EEA, your local one).
To use a right, email support@tryoutr.io. We respond within one month, and may extend by up to two months for complex or bulk requests (we will tell you if we do). We may need to confirm who you are first.
If you are a lead or recipient (someone a customer contacted through outr): for most of that data the customer is the controller, so where it makes sense we will pass your request to that customer and help them answer. Where we are the controller or joint controller for finding that data, we will answer you directly. Reach us at support@tryoutr.io. We do not yet have a self-serve export or per-record delete for lead data, so we handle these by hand, which can take a little longer; we will keep you posted.
Children
outr is a B2B tool for adults at work. It is not for children, and we do not knowingly collect data from anyone under 16. If you think a child gave us data, email support@tryoutr.io and we will delete it.
Changes to this policy
We may update this policy. For material changes we will update the version and date above and, where it makes sense, tell you. Using outr after an update means you accept the new version.
Contact
For any privacy question, to use a right, or for legal matters, email support@tryoutr.io.
United States privacy notice
This section is for people in the United States and adds to the policy above. The California rights here are provided under the California Consumer Privacy Act as amended by the California Privacy Rights Act (together, "CCPA/CPRA"), and the California terms have the meanings that law gives them.
Email outreach and CAN-SPAM
Outreach sent through outr to US recipients is built to follow the CAN-SPAM Act: messages identify the sender, use a real reply address, avoid deceptive subject lines, and carry a working one-click unsubscribe, and unsubscribes and bounces are suppressed for good. The customer is responsible for the content it approves and for following CAN-SPAM and any state law for its own campaign and recipients.
What we collect
In the past 12 months we have collected these categories of personal information:
- Identifiers: name, email address, and account and billing identifiers.
- Commercial information: subscription, plan, and transaction records.
- Internet or network activity: usage records and, briefly, IP addresses for rate limiting. Where advertising cookies are enabled and you consent to them, this can also include online identifiers and browsing activity on our site collected by our advertising provider.
- Professional or employment information: job title, company, and business profile data (for account holders, and for the business leads our customers target).
- Other business-contact information for leads: business email, company, country, LinkedIn URL, and any reply content those prospects send.
We do not intentionally collect Social Security numbers, government IDs, financial account numbers, precise geolocation, biometric data, or the contents of private communications beyond the outreach replies above, and we do not knowingly collect sensitive personal information to infer characteristics.
Sources
We collect personal information from you when you create and use an account, from the providers that run the service for us (for example lead-sourcing and lead-count providers), and automatically from your use of the service.
Purposes
We use personal information to provide, secure, bill for, and improve the service, to communicate with you, and to comply with law, as described above.
Disclosures
We share personal information with the providers that run the service for us, for the business purposes in this policy. Where advertising cookies are enabled and you consent to them, some online identifiers and activity may also be shared with our advertising provider to measure and improve our advertising. Other than that, we do not hand personal information to third parties for their own separate purposes.
No sale, and sharing only with consent
We do not sell personal information, as that term is defined under CCPA/CPRA, and we have not done so in the past 12 months.
Where advertising cookies are enabled and you consent to them, that use may involve "sharing" for cross-context behavioral advertising as CCPA/CPRA defines it. You can opt out at any time by choosing "Reject all" in the cookie banner or through Cookie settings, and we treat that as your opt-out of sharing. Until you allow advertising cookies, no such sharing happens.
Do Not Sell or Share My Personal Information. We do not sell your personal information. To opt out of any sharing for cross-context behavioral advertising, choose "Reject all" in the cookie banner or use Cookie settings on the site; that is our opt-out mechanism. See our Cookie Policy for detail.
Your California rights
Subject to the law, you can:
- know the categories and specific pieces of personal information we collected, the sources, the purposes, and who we share with;
- delete personal information we collected from you;
- correct inaccurate personal information;
- opt out of the sale or sharing of personal information (we do not sell; where advertising cookies are enabled with your consent, opt out of sharing by choosing "Reject all" in the cookie banner or through Cookie settings); and
- limit the use of sensitive personal information (not applicable, because we do not use it to infer characteristics).
How to exercise your rights
Email support@tryoutr.io. We will verify your request, usually by confirming details tied to your account, before acting, and we respond within the timeframes the law requires. You can use an authorized agent, and we may ask the agent for proof of authorization and ask you to verify your identity with us directly.
Non-discrimination
We will not treat you differently for using a right. We will not deny you the service, charge a different price, or give you a lower quality of service because you exercised a right.
Other regions
United Kingdom. If you are in the UK, the UK GDPR and the Data Protection Act 2018 apply, and this policy applies to you the same way it does under the EU GDPR: the same roles, bases, rights, and safeguards, read as references to the UK regime. You can complain to the UK Information Commissioner's Office.
Canada. If you are in Canada, we aim to align with PIPEDA and, for commercial email, Canada's Anti-Spam Legislation (CASL). CASL generally requires consent before sending commercial email. The customer is responsible for having a valid basis under CASL (express or implied consent, as applicable) to contact its Canadian recipients, and every send identifies the sender and includes a working unsubscribe.
Everywhere else. Wherever a recipient is, the customer must follow every law that applies to it and to its recipients, including data protection, privacy, and anti-spam laws in each recipient's location. The customer picks its audience and approves every campaign, and it is responsible for the lawfulness of contacting the people it chooses to reach.
Questions about this page? Email support@tryoutr.io.