Privacy Policy
Last updated 2026-09-02
This policy explains what personal data sourcesignal collects, why, and what we do with it. It covers the sourcesignal.ai application and the services it connects to on your behalf.
Who we are
sourcesignal is operated by Bubblegum Search Limited (company number 10051436), registered at St James House, 9–15 St James Road, Surbiton, Surrey, England, KT6 4QH. For anything in this policy, contact contact@sourcesignal.ai.
We are the data controller for the account data of our own customers. Where you use sourcesignal to research and contact people on behalf of your clients, you are the controller of that data and we act as your processor.
What we collect
Account data
Your name, email address and organisation, plus authentication records held by our identity provider. Passwords are never stored by us in any form.
Data you connect
When you connect a mailbox, an analytics property or a third-party account, we store the connection reference and the settings you choose — never the credentials themselves, which stay with the provider.
Outreach data
To do what the product is for, we store the web pages you target, the business contacts discovered for them (name, work email address, job title and the public source each came from), the emails drafted and sent, and the replies received. Reply content is processed to classify sentiment and to detect out-of-office and delivery failures.
Usage data
Standard server logs, and a record of AI operations for billing and diagnostics.
Sub-processors
We use the following providers. Each receives only what its function requires.
| Provider | Purpose | Data involved |
|---|---|---|
| Supabase | Database, authentication, storage | All stored data |
| Vercel | Application hosting | Request data, logs |
| Hetzner | Background job processing | All stored data |
| Anthropic | Drafting and classification | Page content, contact context, email and reply text |
| Unipile | Mailbox connection and sending | Message content, recipient addresses |
| Hunter | Email discovery and verification | Business contact details |
| Ahrefs | AI-visibility data | Brand and page identifiers |
| Analytics and Search Console reads | Aggregate traffic data for properties you connect — see “Google user data” below | |
| Stripe | Payments | Billing details (card data never reaches us) |
| Resend | Transactional email | Your account email address |
Some of these process data outside the UK and EEA. Where they do, transfers rely on the provider’s Standard Contractual Clauses or an equivalent safeguard.
Google user data (Analytics and Search Console)
If you connect a Google account to sourcesignal, we request read-only access to Google Analytics (analytics.readonly) and Search Console (webmasters.readonly), plus your Google account email address. With that access we retrieve:
- your Google account email address — shown in your settings so you can see which account is connected;
- aggregate daily traffic metrics from the one Google Analytics property you choose to bind (sessions and channel totals, including sessions referred by AI assistants);
- aggregate daily Search Console metrics from the one site you choose to bind (clicks and impressions, split into branded and non-branded queries).
How we use it:solely to display your own project’s Traffic & Search reporting to you and to the people you share that report with. We do not use Google user data for advertising, do not sell it, do not combine it across customers, do not use it to train AI models, and never send it to our AI providers.
Who we share it with: no one. We do not share, transfer or disclose Google user data to any third party. It is stored and processed only on the infrastructure that runs the service — Supabase (our database) and Vercel (our application host) — acting as processors under our instructions, and we would disclose it beyond that only if required by law.
How it is protected and kept: the connection token is stored server-side, encrypted at rest, is never exposed to the browser, and access to the retrieved metrics is scoped to your organisation and enforced in the database. Disconnecting Google in your settings deletes the stored token immediately, and you can also revoke sourcesignal’s access at any time from your Google account permissions page. Aggregate daily metrics already retrieved remain part of your project’s report history until the project is deleted or you ask us to remove them.
sourcesignal’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
AI processing
Drafting, classification and analysis run through Anthropic’s API. Content sent for these purposes is not used to train models. Every AI-drafted email is shown to a human for review, and nothing is sent without an explicit approval.
Business contact data
sourcesignal discovers publicly available professional contact details so our customers can make relevant, individual approaches. We rely on legitimate interests for this. We do not buy contact lists, we do not send bulk untargeted mail, and every email identifies its sender and offers a way to opt out.
If you have received an email sent through sourcesignal and want your details removed, write to contact@sourcesignal.ai and we will suppress the address across the platform and pass the request to the customer who sent it.
How long we keep it
- Account data — for the life of the account, then 30 days.
- Outreach and reply data — for the life of the project, then 90 days.
- Billing records — as long as tax law requires.
- Logs — 30 days.
Your rights
You can request access, correction, deletion, restriction or portability of your personal data, and object to processing based on legitimate interests. Write to contact@sourcesignal.ai; we respond within one month. You may also complain to your data protection authority.
Security
Data is encrypted in transit and at rest. Access is scoped per organisation and enforced in the database itself, not only in the application. Provider credentials are held by the providers, not by us.
Changes
We will update this page when our processing changes, and will tell account holders directly if a change is material.