Privacy Policy

Last updated 2026-09-02

This policy explains what personal data sourcesignal collects, why, and what we do with it. It covers the sourcesignal.ai application and the services it connects to on your behalf.

Who we are

sourcesignal is operated by Bubblegum Search Limited (company number 10051436), registered at St James House, 9–15 St James Road, Surbiton, Surrey, England, KT6 4QH. For anything in this policy, contact contact@sourcesignal.ai.

We are the data controller for the account data of our own customers. Where you use sourcesignal to research and contact people on behalf of your clients, you are the controller of that data and we act as your processor.

What we collect

Account data

Your name, email address and organisation, plus authentication records held by our identity provider. Passwords are never stored by us in any form.

Data you connect

When you connect a mailbox, an analytics property or a third-party account, we store the connection reference and the settings you choose — never the credentials themselves, which stay with the provider.

Outreach data

To do what the product is for, we store the web pages you target, the business contacts discovered for them (name, work email address, job title and the public source each came from), the emails drafted and sent, and the replies received. Reply content is processed to classify sentiment and to detect out-of-office and delivery failures.

Usage data

Standard server logs, and a record of AI operations for billing and diagnostics.

Sub-processors

We use the following providers. Each receives only what its function requires.

ProviderPurposeData involved
SupabaseDatabase, authentication, storageAll stored data
VercelApplication hostingRequest data, logs
HetznerBackground job processingAll stored data
AnthropicDrafting and classificationPage content, contact context, email and reply text
UnipileMailbox connection and sendingMessage content, recipient addresses
HunterEmail discovery and verificationBusiness contact details
AhrefsAI-visibility dataBrand and page identifiers
GoogleAnalytics and Search Console readsAggregate traffic data for properties you connect — see “Google user data” below
StripePaymentsBilling details (card data never reaches us)
ResendTransactional emailYour account email address

Some of these process data outside the UK and EEA. Where they do, transfers rely on the provider’s Standard Contractual Clauses or an equivalent safeguard.

Google user data (Analytics and Search Console)

If you connect a Google account to sourcesignal, we request read-only access to Google Analytics (analytics.readonly) and Search Console (webmasters.readonly), plus your Google account email address. With that access we retrieve:

  • your Google account email address — shown in your settings so you can see which account is connected;
  • aggregate daily traffic metrics from the one Google Analytics property you choose to bind (sessions and channel totals, including sessions referred by AI assistants);
  • aggregate daily Search Console metrics from the one site you choose to bind (clicks and impressions, split into branded and non-branded queries).

How we use it:solely to display your own project’s Traffic & Search reporting to you and to the people you share that report with. We do not use Google user data for advertising, do not sell it, do not combine it across customers, do not use it to train AI models, and never send it to our AI providers.

Who we share it with: no one. We do not share, transfer or disclose Google user data to any third party. It is stored and processed only on the infrastructure that runs the service — Supabase (our database) and Vercel (our application host) — acting as processors under our instructions, and we would disclose it beyond that only if required by law.

How it is protected and kept: the connection token is stored server-side, encrypted at rest, is never exposed to the browser, and access to the retrieved metrics is scoped to your organisation and enforced in the database. Disconnecting Google in your settings deletes the stored token immediately, and you can also revoke sourcesignal’s access at any time from your Google account permissions page. Aggregate daily metrics already retrieved remain part of your project’s report history until the project is deleted or you ask us to remove them.

sourcesignal’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

AI processing

Drafting, classification and analysis run through Anthropic’s API. Content sent for these purposes is not used to train models. Every AI-drafted email is shown to a human for review, and nothing is sent without an explicit approval.

Business contact data

sourcesignal discovers publicly available professional contact details so our customers can make relevant, individual approaches. We rely on legitimate interests for this. We do not buy contact lists, we do not send bulk untargeted mail, and every email identifies its sender and offers a way to opt out.

If you have received an email sent through sourcesignal and want your details removed, write to contact@sourcesignal.ai and we will suppress the address across the platform and pass the request to the customer who sent it.

How long we keep it

  • Account data — for the life of the account, then 30 days.
  • Outreach and reply data — for the life of the project, then 90 days.
  • Billing records — as long as tax law requires.
  • Logs — 30 days.

Your rights

You can request access, correction, deletion, restriction or portability of your personal data, and object to processing based on legitimate interests. Write to contact@sourcesignal.ai; we respond within one month. You may also complain to your data protection authority.

Security

Data is encrypted in transit and at rest. Access is scoped per organisation and enforced in the database itself, not only in the application. Provider credentials are held by the providers, not by us.

Changes

We will update this page when our processing changes, and will tell account holders directly if a change is material.