Privacy Policy
Last updated: September 3, 2026
LeadCori provides business prospect discovery, lead organization, professional contact discovery, lead scoring, campaign preparation, and connected account functionality. This Privacy Policy explains what information LeadCori collects, how it is used, how it may be shared, how it is protected, and the choices available to users.
About LeadCori
LeadCori operates the LeadCori web application and the public LeadCori website at https://leadcori.com. LeadCori is a business-to-business product used by sales and business development teams to discover potential business customers, organize them into lead lists, review professional contact information, score match quality, and prepare outreach campaigns. This policy applies to the LeadCori application, the public website, and connected account integrations that a user chooses to authorize.
1. Information you provide
When you create an account and use LeadCori, you may provide:
- Your name and email address.
- Account and login credentials handled by our authentication infrastructure.
- An optional profile image.
- Organization and workspace information, including your business profile details.
- Businesses (companies) you explicitly choose to save.
- Professional contacts (people) you explicitly choose to save.
- Lead lists you create and the records you add to them.
- Saved searches, including the search criteria you store.
- Campaign drafts, including subject lines and message drafts.
- Campaign recipient selections, inclusions and exclusions.
- Account settings, notification and workspace preferences.
- Integration choices, such as connecting or disconnecting a Google account.
- Support requests and privacy or deletion requests you submit, including the email address and description you provide.
2. Information collected automatically
To operate and secure the service, LeadCori may collect operational information such as IP address, browser and device information, timestamps, authentication events, feature usage and usage counts, security events, application diagnostics, and error and log data.
LeadCori does not use advertising trackers and does not operate advertising or interest-based tracking technologies.
3. Business and professional data
LeadCori processes business and professional information that you enter and that is returned by third-party data providers when you run a discovery search. This information may include:
- Business name, website and domain.
- Business phone number.
- Business address, city, region, country and location coordinates.
- Industry or category classification.
- Company size, where available.
- Professional name, job title, department and seniority.
- Professional email address and email verification status supplied by the provider.
- Professional phone number, where available.
- Professional profile URL, where available.
This information is business-context information. Some of it originates from third-party providers, and its availability, completeness and accuracy depend in part on those providers. Current provider integrations may include Apollo, Foursquare, Hunter and Google. These providers do not necessarily endorse LeadCori, and their inclusion here does not imply any endorsement, sponsorship or affiliation.
You are responsible for using business and professional information lawfully, including compliance with applicable data protection and anti-spam requirements in your jurisdiction and in the jurisdiction of the people you contact.
4. Google user data
When you choose to connect a Google account to LeadCori through Google OAuth, LeadCori may receive and store the following Google user data:
- Your Google account identifier.
- The Google account email address.
- The Google profile name.
- The profile image, if provided by Google.
- OAuth authorization metadata, such as connection and verification timestamps.
- The OAuth scopes you granted.
- OAuth access credentials and refresh credentials required to keep the authorized connection working.
LeadCori requests exactly these Google scopes for a connected sender account:
openidhttps://www.googleapis.com/auth/userinfo.emailhttps://www.googleapis.com/auth/userinfo.profilehttps://www.googleapis.com/auth/gmail.send
These permissions are used to:
- Authenticate and identify the connected Google account.
- Display the connected sender identity inside LeadCori.
- Maintain your authorized connection so it does not need to be re-established.
- Enable sending from that connected account when you explicitly use a LeadCori sending feature that supports it.
Current implementation disclosure. LeadCori does not currently use its Google connection to read Gmail inbox messages, read sent messages, read drafts, read Gmail labels, download Gmail attachments, import Google Contacts, or access Google Calendar. LeadCori does not request Gmail read or modify mailbox scopes for the sender connection.
5. How LeadCori uses Google user data
Google user data is used only to provide and operate user-facing LeadCori functionality that you requested. Specifically, to:
- Identify the connected Google sender account.
- Maintain the authorized OAuth connection.
- Display the sender identity in Settings and during campaign preparation.
- Enable email-sending functionality when you explicitly activate a supported sending feature.
- Maintain security of the connection and troubleshoot connection problems.
LeadCori does not use Google user data for:
- Targeted or personalized advertising.
- Retargeting or interest-based advertising.
- Building advertising profiles.
- Selling data to data brokers or information resellers.
- Creditworthiness or lending decisions.
LeadCori does not use Google Workspace API data to develop, improve or train generalized or non-personalized artificial intelligence or machine-learning models.
6. Sharing and disclosure of Google user data
LeadCori does not sell Google user data. Google user data may be processed or disclosed only as reasonably necessary to:
- Operate LeadCori's infrastructure, such as cloud hosting and database services.
- Provide the Google integration you requested.
- Maintain security and prevent abuse.
- Comply with applicable legal obligations.
- Respond to lawful legal process.
Google user data is not shared with Apollo, Foursquare, Hunter, advertisers, data brokers or unrelated third parties. LeadCori does not transfer Google user data to third parties for advertising, resale, creditworthiness or lending decisions, or for generalized AI or machine-learning training.
7. Google API Services User Data Policy
LeadCori's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
8. OAuth credential security
LeadCori uses technical and organizational safeguards designed to protect Google OAuth credentials and other sensitive account data. OAuth credentials are handled server-side and are not displayed to users or stored in ordinary browser-accessible storage. Credential records are protected in storage and access to them is restricted to the server-side processes that operate the integration.
No method of transmission or storage is completely secure, and we do not claim otherwise.
9. How LeadCori uses other information
Information other than Google user data may be used to:
- Create and manage user accounts.
- Operate organization workspaces and enforce access boundaries.
- Perform business discovery searches that you request.
- Display discovered businesses and their available details.
- Save businesses that you explicitly select.
- Discover professional contacts when you request them.
- Save professional contacts that you explicitly select.
- Calculate LeadCori Match scores and match explanations.
- Create and manage Lead Lists.
- Save and re-run search criteria.
- Prepare campaign audiences and recipient selections.
- Create and manage campaign drafts.
- Operate connected integrations that you authorize.
- Secure the service, troubleshoot problems and prevent abuse.
- Improve product reliability and user-facing functionality.
- Comply with applicable law.
10. Third-party service providers
LeadCori relies on third-party services necessary to operate the platform. These may include cloud hosting and database providers, authentication and application infrastructure providers, business-data providers, professional-contact providers, and Google APIs.
Third-party services process information according to their own terms and privacy policies in addition to our instructions. Their appearance in this policy does not indicate ownership, sponsorship, endorsement or any affiliation beyond the service relationship described.
10a. Replies sent to LeadCori reply addresses
Messages you send through LeadCori carry a LeadCori reply address on a dedicated receive-only subdomain, in addition to your own visible sending address. When a recipient replies, the reply is delivered to LeadCori through an inbound email processing provider acting as a sub-processor on our instructions.
For those replies LeadCori receives and stores the sender address and name, the subject, the plain-text message body, the message identifiers needed to match the reply to the message it answers, and the provider's spam assessment. Attachment contents are not stored; LeadCori records only that an attachment was present.
This information is used to show the reply in your Inbox, to match it to the right conversation, to stop that recipient's follow-up messages, and to suppress addresses that permanently fail. It is not used for advertising, resale, credit or lending decisions, or generalized artificial-intelligence or machine-learning model training.
This reply routing does not give LeadCori access to your mailbox. LeadCori holds send-only Google permission and requests no Gmail read, modify or metadata access, no Google Contacts access and no Google Calendar access. Replies that cannot be matched to a message you sent are kept separate from your contact records and can be deleted, and reply content is deleted with your workspace data on request.
11. Data retention
LeadCori retains information for as long as reasonably necessary to provide the service, maintain user accounts and workspaces, preserve deliberate user records such as saved leads, lead lists, saved searches and campaign drafts, maintain security and audit records, comply with legal obligations, and resolve disputes or enforce agreements.
Retention differs by data type. Records you create deliberately remain until you delete them or your account is deleted. Operational, audit and security records may be retained for longer where necessary for security or legal purposes.
For the Google integration, OAuth credentials are cleared and invalidated within LeadCori when a supported disconnect action is completed. Non-credential records, such as audit entries showing that a connection was created or removed, may be retained for legitimate security and legal purposes.
12. Data deletion
You can delete records you created directly in the product, and you can request deletion of your account and workspace data. Full instructions and a request form are available on the LeadCori Data Deletion page (/data-deletion).
- Disconnecting a Google account is not the same as deleting your LeadCori account. Disconnecting removes the sender authorization; your LeadCori account and workspace data remain.
- Deleting your LeadCori account or disconnecting an integration does not automatically delete data that is independently controlled by third-party providers, including business data providers or Google.
- We may need to verify your identity before fulfilling a deletion request, so that we do not act on requests made by someone else.
To remove a connected Google sender authorization, go to Settings → Integrations → Google/Gmail → Disconnect.
13. Google account disconnection
You may disconnect a connected Google account at any time from within LeadCori at Settings → Integrations → Google/Gmail → Disconnect. When you disconnect, LeadCori stops offering that sender account for supported LeadCori functionality and clears and revokes the stored OAuth credentials according to the implemented disconnect process.
You can also revoke LeadCori's access directly from your Google Account security settings, under the third-party access or connected apps controls at myaccount.google.com/connections.
14. Security
We use reasonable administrative, technical, and organizational safeguards designed to protect information. These include access controls and authentication, workspace isolation enforced at the database level, server-side authorization for privileged operations, protected and encrypted storage for integration credentials, audit and security logging, and restricted access to sensitive integration credentials.
No service can guarantee absolute security. Please protect your own account credentials and notify us if you believe your account has been compromised.
15. Data sharing
Beyond the Google-specific rules above, LeadCori may share information with:
- Vendors and service providers that help operate the service.
- External API providers when this is necessary to perform an action you requested, such as running a discovery search.
- Professional advisers, such as legal or accounting advisers, where appropriate.
- Government or law-enforcement authorities where legally required.
- Parties involved in a legitimate business transaction such as a merger, financing or acquisition, subject to applicable law.
None of this means LeadCori sells Google user data. LeadCori does not sell Google user data.
16. User choices and rights
You can:
- Update your account and workspace settings in the product.
- Disconnect supported integrations, including a connected Google account.
- Request deletion of your data.
- Request privacy assistance through our contact channels.
- Stop using the service at any time.
Depending on where you live, you may have additional rights, such as rights to access, correct, export or delete personal data, or to object to certain processing. Whether a given right applies depends on your jurisdiction and the applicable law.
18. Children
LeadCori is intended for business and professional use. It is not directed to children under 13, and we do not knowingly collect personal information from children.
19. International processing
Information may be processed in countries where LeadCori and its service providers operate, which may differ from your own country. Where required, we rely on appropriate safeguards for those transfers and process information subject to applicable law.
20. Changes to this policy
We may update this policy as the product develops or as legal requirements change. When we do, we will update the "Last updated" date at the top of this page. For material changes, we may provide additional notice in the product or by email where appropriate.
21. Contact
For privacy questions, data requests or assistance with a connected Google account:
- Email: a dedicated privacy mailbox is being finalized. Until it is published here, please use the contact form below — requests submitted there reach the LeadCori privacy team.
- Contact form: leadcori.com/contact
- Data deletion requests: leadcori.com/data-deletion