This Privacy Policy explains how Zaram Web Mailer ("we", "our", "the service") collects, uses, stores, and protects information when you use our cold-email automation dashboard. By creating an account you agree to this policy.
1. Information we collect
1.1 Account information
When you register, we collect your email address and a password. The password is never stored in plain text — we store only a one-way bcrypt hash. We may also store the date your account was created and the timestamps of your activity inside the app.
1.2 Connected service credentials
To send email and read leads, you connect third-party accounts via OAuth:
- Microsoft Outlook — OAuth access and refresh tokens for sending email via Microsoft Graph (
Mail.Sendscope). - Google account — OAuth access and refresh tokens for reading and updating the specific Google Sheet whose URL you paste into the app (
spreadsheetsscope only — we do not request Drive access or list any of your other files).
All OAuth tokens are encrypted at rest with AES-256-GCM before being written to our database. We never see your Microsoft or Google passwords — OAuth keeps them with the provider.
1.3 AI provider credentials
You may save an API key for OpenAI or OpenRouter to enable email generation. API keys are encrypted at rest with AES-256-GCM. We display only a masked preview (e.g. sk-****1234) after saving and never return the full key to the browser again.
1.4 Lead and campaign data
When you connect a Google Sheet as a lead source, we read the rows you select and store a per-row copy in our database so the campaign runner can process them. This includes whatever columns are in your sheet (typically name, email, company, etc.). For each lead we also store the AI-generated subject and body, the send status, the send timestamp, and any error message returned by the email provider.
1.5 Cookies
We use a single httpOnly session cookie containing a signed JWT to keep you logged in. We do not use third-party advertising or analytics cookies. We use short-lived state cookies during OAuth flows to prevent CSRF attacks.
2. How we use information
- To authenticate you and keep you signed in
- To send emails on your behalf through your connected Outlook account
- To read and update the Google Sheets you specifically select
- To call the AI provider you configured to generate personalized email copy
- To show you progress, history, and analytics for your campaigns
- To investigate and resolve errors you encounter
We do not sell your data, share it with advertisers, or use it to train AI models.
3. Third-party services
When you use the service, your data flows to the third parties you have connected:
- Microsoft — receives the email recipient address, subject, and body via Microsoft Graph in order to send the email. Their use is governed by the Microsoft Privacy Statement.
- Google — receives requests to read and update the spreadsheets you select. Their use is governed by the Google Privacy Policy.
- OpenAI / OpenRouter — receives your prompt template combined with the per-lead data to generate email copy. Their use is governed by their respective privacy policies (OpenAI / OpenRouter).
Google data accessed through this service is used only to provide and improve the in-app functionality you have explicitly requested (read the sheet, write status back, move sent rows). We do not use Google user data for any other purpose, do not transfer it to other parties, and do not use it for ads. This is consistent with Google's Limited Use requirements.
4. Data storage and security
- Passwords are hashed with bcrypt (work factor 12).
- OAuth tokens and AI API keys are encrypted at rest with AES-256-GCM.
- All traffic to and from the app is over HTTPS.
- The database is hosted on a third-party managed Postgres provider with at-rest disk encryption.
No system is 100% secure. If we become aware of a breach affecting your data, we will notify you without undue delay.
5. Your rights and choices
- Disconnect a service — you can disconnect Outlook and Google at any time from the in-app settings. Disconnecting deletes the encrypted tokens from our database.
- Delete your AI key — one-click delete from the AI Settings page.
- Delete a campaign or its leads — done from the Campaigns page; this also deletes all associated lead and send-log rows.
- Delete your account and all data — contact us at the address below.
- Access or export your data — the Lead Logs page offers a CSV export of all leads matching your filters.
6. Data retention
We retain your data for as long as your account is active. You may delete individual connections, campaigns, leads, or the entire account at any time. Encrypted backups are retained for up to 30 days for disaster recovery.
7. International data transfers
Our infrastructure is hosted in the United States. By using the service, you consent to your data being transferred to and processed in the US, subject to the protections described in this policy.
8. Children's privacy
The service is not directed to anyone under 16. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.
9. Changes to this policy
We may update this policy. If we make material changes, we will notify you by email or by an in-app notice. Continued use after the effective date constitutes acceptance.
10. Contact
For privacy questions, requests, or to delete your data, contact us at ogbonnajohne@gmail.com.