Boostie

Privacy Policy

Effective date: July 25, 2026

Boostie ("Boostie", "we", "us") is an AI-powered outreach platform available at boostie.io and app.boostie.io (the "Service"). This policy explains what personal data we collect, why, who processes it on our behalf, how long we keep it, and the rights you have over it.

Two kinds of people are covered here: customers (you, the person with a Boostie account) and business contacts (professionals whose business contact details are processed through the Service for outreach). Section 5 is written for business contacts; if you received an email sent through Boostie and want to know your options, start there.

1. Data we collect about customers

  • Account data — name, email address, and a salted password hash. Email verification is required before sign-in.
  • Workspace content — everything you or the AI agent create in your workspace: campaign configuration, your business description and website URL, email copy, conversations with the AI agent (including any attachments you upload), and reply threads from your campaigns.
  • Billing data — your prepaid wallet balance, an itemized ledger of every charge and top-up, your auto-recharge settings (trigger, amount, monthly ceiling), and subscription tier. Card details are collected and stored by our payment processor, never by us; we hold only a payment-method token and receipts.
  • Usage and log data — IP addresses, request logs, and per-feature metering (for example AI tokens consumed) needed to operate, bill, and secure the Service.

2. How we use customer data

  • To provide the Service: run your campaigns, operate the AI agent, deliver replies to your inbox.
  • To bill you: meter usage against your prepaid wallet, process top-ups and auto-recharge, detect and prevent fraud.
  • To send transactional email: account verification, password resets, billing receipts, low-balance and campaign notifications. These are service messages, not marketing; you cannot opt out of essential ones while you hold an account.
  • To secure and improve the Service: debugging, abuse prevention, aggregate (never per-customer-identifiable) product analytics.

3. AI processing

Core features of the Service — researching your business, scoring leads, and writing emails, and the conversational agent — are powered by third-party AI infrastructure providers acting as our processors. Content you provide (your business description, campaign configuration, agent conversations) and business-contact records are sent to those providers to produce the feature's output, under agreements that restrict use of the data to providing the service to us.

We do not sell your data, and we do not permit AI providers to use it for advertising.

4. Business contact (lead) data

The Service processes professional contact records — typically name, job title, company, business email address, and public professional profile information — sourced from licensed third-party data providers and from information our customers import. We process B2B contact data only; the Service is not intended for consumer marketing lists.

Before an email is written to a business contact, the Service may gather publicly available information about the contact's company (for example, from the company's own website) so the email is relevant, and verify that the email address is deliverable.

5. Deletion of business contact data — and your rights as a recipient

To avoid re-buying and re-verifying the same public business record many times over, Boostie maintains a de-duplicated internal directory of business-contact records. Each customer workspace holds its own copy-on-reference of the records it has acquired; customers never see one another's lists, notes, or campaign activity.

  • When a customer deletes a contact (or an entire workspace), we delete that workspace's copy — its acquisition record, scores, notes, generated emails, and campaign history for that contact. Copies independently acquired by other customers are their records and are not affected by another customer's deletion.
  • When a business contact asks us to erase their data, we remove the underlying record from our systems entirely — every workspace copy and the shared directory entry — and add the address to a suppression list so it is not re-acquired or contacted again.
  • When a recipient unsubscribes or objects, the address is suppressed from future sending permanently.

If you received an outreach email sent through Boostie and want your data erased or suppressed, email hello@boostie.io or use the opt-out link in the email itself.

6. Cold-outreach compliance posture

Boostie is built for lawful B2B outreach and ships with compliance guardrails: honest sender identities, working unsubscribe handling, permanent suppression lists, email verification before sending, per-inbox volume limits, and complaint-rate monitoring. Customers remain responsible for the lawfulness of their own campaigns in the jurisdictions they target (see the Terms of Service), including CAN-SPAM (US), GDPR/ePrivacy rules in the EU/UK, and CASL (Canada).

7. Billing, wallet, and auto-recharge

Boostie billing is a prepaid wallet: you add funds (or a subscription tier converts its monthly fee into wallet credit), and usage is metered against the balance with an itemized record of every line. If you enable auto-recharge, your saved payment method is charged automatically when your balance falls below your chosen trigger, up to a monthly ceiling you set. Payment processing — including card storage, 3-D Secure, and fraud screening — is handled by our payment processor as an independent controller of your card data; a processing fee is itemized at checkout rather than hidden in our prices.

8. Cookies and authentication

The app uses first-party cookies strictly necessary to run the Service: session authentication cookies (to keep you signed in) and security cookies (for example, CSRF protection). We do not run third-party advertising cookies or cross-site trackers. If we later add product analytics that require consent, we will update this policy and ask first.

9. Subprocessor categories

We use a small set of vetted service providers, bound by data processing agreements, in these categories:

  • Cloud hosting and databases (EU-based infrastructure)
  • Email delivery and inbox infrastructure (campaign sending, done-for-you inboxes, reply collection)
  • AI infrastructure providers (research, scoring, writing, and the conversational agent)
  • Business-contact data providers (licensed B2B contact records)
  • Email verification (deliverability checks)
  • Payment processing (wallet top-ups, subscriptions)
  • Transactional email (account and billing notifications)
  • Domain registration (done-for-you sending domains)

A current list of subprocessors within each category is available to customers on request.

10. Retention

  • Account and workspace data: kept while your account is active; deleted or anonymized within 90 days of account deletion, except records we must keep longer (billing ledgers, for tax and accounting law).
  • Business-contact records: kept while at least one customer workspace holds a copy, then eligible for removal; erasure and suppression requests are honored as described in Section 5.
  • Server logs: rotated on a short schedule (weeks, not years).

11. International transfers

Our primary infrastructure is hosted in the EU. Some subprocessors (notably AI infrastructure and payment providers) process data in the United States; where they do, transfers are covered by recognized safeguards such as Standard Contractual Clauses or an adequacy framework.

12. Your rights

Depending on where you live (GDPR/UK GDPR, CCPA/CPRA, and similar laws), you may have the right to access, correct, export, restrict, object to the processing of, or delete your personal data, and the right to complain to a supervisory authority. Customers can exercise most of these directly in the app (account settings, contact deletion); anyone can email hello@boostie.io. We respond within 30 days. We do not sell personal data and do not use it for cross-context behavioral advertising.

13. Security

All traffic is encrypted in transit (TLS). Access to production systems is restricted and audited; workspaces are isolated at the database layer so one customer can never read another's data; payments are handled by a PCI-DSS-compliant processor. No system is perfectly secure — if we learn of a breach affecting your data, we will notify you and the relevant authorities as the law requires.

14. Changes and contact

We will post any changes to this policy here and update the effective date; material changes are announced to customers by email. Questions, requests, and complaints: hello@boostie.io.