Skip to content

Legal

Privacy Policy

Last updated: July 29, 2026

This policy explains what we collect when you use Outrigger, what we do with it, who we share it with, and the rights you have over your data. We try to keep it readable. If something isn't clear, email privacy@outriggerai.com.

1. Who we are

Outrigger is a software platform operated by Direct Rank LLC ("we", "us", "our"), a limited liability company registered in Wyoming, United States. In this policy, "Outrigger" means the platform and websites we operate at outriggerai.com. Outrigger is operated from the United States and offered primarily to business customers in the United States.

For privacy enquiries, email privacy@outriggerai.com. We target an initial response within 30 days and apply the identity-verification, deadline, extension, and exception rules required by the law governing the particular request.

2. What we collect

We collect the following categories of data:

  • Account data — the name, email address, agency name, and password hash you provide at signup. Required to create your account.
  • Brand workspace data — the client brand briefs, website URLs, keywords, competitor names, and team-member emails you add inside the product. This is the working content of your subscription.
  • Operational telemetry — usage events, IP address, browser type, error logs, and pages visited. Used to keep the service running and to diagnose problems. Marketing-attribution events (ad clicks, signups, conversions) are sent to Google Ads / Analytics via our cookie banner.
  • Connected Gmail data — if you explicitly connect a Gmail mailbox for Press, we process mailbox identity, OAuth credentials, outbound message identifiers, and replies that can be matched to an Outrigger campaign. Matched reply content may be sent to Anthropic for classification. The connection can send only after an authorised user approves outreach.
  • Journalist and outreach-recipient data — names, professional email addresses and phone numbers, publication and role, profile and author-page links, region, beats, articles, professional interests, source and verification information, prior outreach and engagement, replies, and opt-out or suppression status. Customers may upload this information or ask us to find it from publication sites, author pages, professional profiles, search providers, or other sources they are authorised to use. A public source does not by itself remove privacy or direct-marketing duties.
  • Press pitch and delivery data — approved pitch subject/body and personalisation, campaign and sender metadata, delivery identifiers, opens/clicks where enabled, bounces, replies, complaints, and unsubscribe events. For the customer-isolated Instantly delivery option, Outrigger uploads recipient contact and personalisation data and campaign content to the customer's authorised Instantly workspace and receives campaign, delivery, engagement, reply, and suppression events. Instantly is not receive-only for this workflow.
  • Research participation data — if you enrol in an Outrigger research study (such as our AI-visibility field studies), we collect the enrolment, consent, and study-measurement data described in the consent flow presented at enrolment, and use it only for the study purposes you consented to there.

We do not ask customers to provide special-category data (health, ethnicity, religion, biometric identifiers, etc.). A connected mailbox or customer-supplied workspace could nevertheless contain such information, so customers should connect only a dedicated outreach mailbox and avoid submitting unnecessary sensitive data. Public Reddit, Quora, and similar content discovered by the platform is treated as public-web research data.

3. Connected Gmail and Google user data

Connecting Gmail is optional and starts only when an authorised user selects the clearly labelled connection button in Press settings and then grants permission on Google's consent screen. Outrigger requests your connected email address plus Gmail read-only and send permissions. Those Gmail permissions are broad at the provider level; our application limits how it uses them as follows:

  • Access and collection — during the first sync, we examine bounded metadata for non-sent messages from the preceding 30 days, then use Gmail history for newly added messages. We use message and thread identifiers, sender, subject, date, and references to match replies to an Outrigger Press campaign. We open bounded message content only after a message matches a campaign thread or appears to be an automated delivery-status notice that must be authenticated and matched. We do not request attachment bodies separately, and attachment parts included by Gmail in a matched-message response are ignored rather than decoded or stored. Ordinary unrelated message bodies are not opened or retained.
  • Actions taken — send permission is used only to send a Press pitch or in-thread reply that an authorised user has reviewed and explicitly confirmed in Outrigger. After an ambiguous or retried send, we may search the connected Sent folder only for Outrigger's deterministic Press Message-ID to confirm delivery and prevent a duplicate. That reconciliation reads only the matching Gmail message and thread identifiers; it does not open or store the Sent message body. Send permission is not used for hidden or autonomous mailbox actions.
  • Storage and human access — we store the connected address, encrypted OAuth credentials, delivery identifiers, and campaign-matched replies and classifications. If processing a Gmail message fails, its Gmail identifier and a safe diagnostic can remain in a bounded retry/dead-letter record for up to seven days, after which that record is deleted. Matched replies are visible to authorised members of your Outrigger workspace in the Press inbox. Our personnel do not routinely read Gmail data; access by us is limited to specific data you affirmatively ask us to inspect for support, or when necessary for security or legal obligations.
  • Anthropic transfer for reply assistance — when a matched journalist reply needs classification, we send its subject and bounded body, together with the related original pitch and campaign, client, journalist, publication, and spokesperson context, to Anthropic's commercial Claude API. We transfer it solely to classify the reply and prepare a reviewable draft in the Press inbox. Anthropic processes it under its commercial terms, including the limited safety and legal exceptions described below. We do not send unrelated mailbox content or attachments to Anthropic.
  • Prohibited uses — we do not sell Google user data or use it for advertising, retargeting, surveillance, credit decisions, or to create, train, or improve any general-purpose AI or machine-learning model. We do not opt Gmail-derived API inputs or outputs into Anthropic model training or submit them through provider feedback tools.

Anthropic states that inputs and outputs from its commercial API are not used to train its models by default. Under Anthropic's standard API retention, inputs and outputs are deleted from its backend within 30 days, except where longer retention is required to enforce its usage policy or comply with law. See Anthropic's commercial model-training explanation and API retention explanation.

Outrigger's use and transfer of information received from Google Workspace APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements, and the additional Google Workspace User Data and Developer Policy.

Disconnecting a mailbox immediately disables its use in Outrigger and requests revocation from Google. If Google is temporarily unavailable, the encrypted credential is kept only long enough to retry revocation and is erased when revocation succeeds. You can also revoke access directly from your Google Account connections. Disconnecting stops future access but does not by itself erase campaign records already stored in Outrigger. Those records follow the workspace retention period below, and a signed-in user can request access or deletion from Settings → Privacy.

4. Why we collect it (purposes and legal bases)

We collect and use data for the purposes below. Where the EU or UK GDPR applies to particular processing, the corresponding Art. 6 lawful basis is noted:

  • Contract — we need account and workspace data to deliver the service you've subscribed to.
  • Connected Gmail feature you request — when you affirmatively connect Gmail, we process the Google user data described above to perform the Press sending, reply matching, and drafting feature you requested under our contract and your explicit Google authorisation. Disconnecting withdraws that authorisation for future Gmail access; stored campaign records remain subject to the retention and deletion controls described above.
  • Legitimate interests — operational telemetry, fraud prevention, and product analytics. We've weighed these against your rights and consider them proportionate.
  • Consent — advertising and marketing cookies fire only after you accept them via the cookie banner. You can withdraw consent at any time from the cookie settings in the footer.
  • Legal obligation — certain billing and tax records are retained for compliance with US tax and EU VAT rules.
  • Customer instructions and legitimate interests for Press outreach — we process recipient data to build and deliver customer-directed media outreach, measure delivery, handle replies, prevent repeat contact, and protect the service. The customer must identify and document the lawful basis and communications rules that apply to each list, recipient, message, and destination. Where Outrigger acts as a controller for its own security, compliance, or suppression records, it uses only the minimum information necessary for those purposes.

5. Customer and recipient data roles

For contact lists, press pitches, and campaigns that a customer supplies or directs, the customer generally determines the purpose and means of outreach and acts as controller (or the equivalent business under applicable law); Outrigger generally acts as its processor or service provider. Customers are responsible for lawful list sourcing, transparency notices, lawful basis or consent where required, geographic and industry restrictions, accurate sender identification, message content, and responding to recipient rights. A customer must not instruct Outrigger to contact a person who has objected or is suppressed.

Outrigger may separately act as controller for account administration, billing, platform security, fraud prevention, legally required records, and the minimum suppression evidence needed to prevent repeat outreach. The exact allocation must be confirmed in an approved Data Processing Addendum before launch; this draft does not itself create that agreement.

Outrigger's Press outreach features are designed for media outreach to recipients in the United States, where the CAN-SPAM Act and related US rules apply; those rules have no general business-to-business exception. A customer that directs outreach to recipients outside the United States must first document that the campaign complies with the destination country's communications and privacy rules (for example the EU/UK GDPR and ePrivacy rules, Canada's CASL, or Australia's Spam Act 2003). We may restrict outreach destinations at our discretion.

6. Who we share it with (subprocessors)

We use the third-party services below to deliver Outrigger. Each handles a specific slice of your data and is contractually bound to protect it. By using Outrigger you authorise these subprocessors.

SubprocessorPurposeRegion
SupabaseDatabase, authentication, file storageUS, EU
VercelApplication hosting, edge functionsGlobal (regional)
CloudflareDNS, CDN, bot mitigation (Turnstile)Global
StripePayment processing, subscription billingUS, EU, AU
Anthropic (Claude)AI processing — brand briefs, classification, response generation, and campaign-matched Gmail reply assistanceUS
OpenAIAI probing — ChatGPT citation discoveryUS
PerplexityAI probing — citation discovery, keyword researchUS
Google (Gmail, Gemini, GA4, Ads, GTM)Connected Gmail sending and reply synchronisation, AI probing, analytics, and advertising attributionGlobal
ApifyWeb scraping for SERP, Reddit, Quora contentEU
SerpApiSearch results, AI Overviews monitoringUS
MozBacklink and domain authority dataUS
SpyFuCompetitor traffic signalsUS
ResendTransactional email deliveryUS, EU
InngestBackground job orchestrationUS
SentryError monitoringUS, EU
PostHogProduct analyticsUS, EU
InstantlyCustomer-authorised Press outreach delivery — recipient contact data, personalised pitch/campaign content, sender metadata, suppression and delivery/reply eventsUS and other locations described in Instantly's privacy and data-processing terms

Provider locations and transfer mechanisms vary. Where a restricted international transfer occurs, the parties must use a valid mechanism appropriate to that transfer, which may include Standard Contractual Clauses, the UK Addendum, an adequacy decision, or another legally available safeguard. Our DPA, provider DPAs (including Instantly's), subprocessor list, and transfer assessments require qualified legal approval before launch. We do not sell personal data to any third party.

7. Cookies and tracking

We use three categories of cookies, distinguished in our consent banner:

  • Strictly necessary — session, CSRF, and authentication cookies. Required for the site to work. Set without consent.
  • Analytics — PostHog, Google Analytics 4. Set only after you accept analytics cookies.
  • Marketing — Google Ads remarketing, conversion pixels via Google Tag Manager. Set only after you accept marketing cookies.

Until you accept, Google Tag Manager runs in Consent Mode v2 with ad_storage=denied and analytics_storage=denied, so no identifiers are written. You can change or withdraw consent at any time using the Cookie settings control in the site footer.

8. How long we keep it

  • Account data — kept while your subscription is active. After verified closure, it enters a 90-day deletion-review target. Legal holds, security evidence, disputes, and legally required billing or tax records are separated and retained only for the applicable purpose and period. A closure or deletion request is not evidence that every exception has ended.
  • Workspace data — after verified closure, it enters the same 90-day deletion-review target. Primary systems, storage, relevant subprocessors, and restored backups are inventoried; completed deletion tombstones must be replayed if an older backup is restored.
  • Connected Gmail data — disconnecting immediately disables the mailbox in Outrigger and requests revocation from Google. Encrypted credentials are erased after Google confirms revocation; during a provider outage they are retained only long enough to retry revocation. Campaign-matched message and reply records follow workspace retention. Temporary failed-message identifiers and safe diagnostics are deleted after no more than seven days. Ordinary unrelated message bodies are neither opened nor retained; potential automated delivery-status notices may be opened only to authenticate and match the delivery event, and their bodies are not retained when unrelated. Sent-mail reconciliation reads only the identifiers for an exact Outrigger Press Message-ID match and does not retain the Sent message body.
  • Journalist and Press data — kept while the customer has a documented outreach or relationship-management purpose, then deleted or de-identified under the customer's instructions and applicable law. Instantly-hosted data follows the customer's authorised workspace settings and the approved Instantly contract/DPA; the customer and Outrigger must coordinate deletion in both systems.
  • Suppression records — a minimal email or irreversible matching value and opt-out evidence may be retained while necessary to honour an objection and prevent repeat outreach. It is isolated from prospecting and may be disclosed to an outreach processor only to suppress contact.
  • Billing records — reviewed for retention for up to seven years, or a different period required by applicable tax, accounting, dispute, or legal obligations. Qualified counsel must approve the actual jurisdictions and schedule.
  • Telemetry & logs — retained for 30 days, then aggregated. Sentry error events follow Sentry's 30-day default.

9. Your rights

You have the right to:

  • Access the data we hold about you.
  • Correct data that's inaccurate or incomplete.
  • Delete eligible data, subject to applicable exceptions such as legal obligations, legal claims, and the minimum suppression record needed to honour an objection.
  • Export your data in a portable format (where the GDPR applies, Art. 20).
  • Restrict or object to processing.
  • Withdraw consent for marketing or analytics cookies.
  • Lodge a complaint with a supervisory authority. For California: the California Privacy Protection Agency (CPPA). For the EU/UK: your local Data Protection Authority.

United States. Where a US state privacy law (such as those of California, Colorado, Connecticut, Texas, or Virginia) applies to you, it may also give you rights to opt out of targeted advertising and to appeal a refused request. We extend the access, correction, deletion, and export rights above to all users regardless of location. To opt out of targeted advertising, decline or withdraw marketing cookies using the Cookie settings control in the site footer.

Signed-in users can submit and track a request in Settings → Privacy. You may also email privacy@outriggerai.com. Journalists and other outreach recipients do not need an Outrigger account to request access, correction, deletion, restriction, or to object to outreach. We verify identity and respond within the period required by the applicable law; the deadline and available exceptions vary by jurisdiction. An opt-out is applied to suppression independently of whether a broader privacy request can be completed immediately.

10. Security

Workspace data is stored in Supabase with row-level security policies that isolate each agency. All connections are TLS 1.2+. Passwords are hashed with bcrypt. Service-role credentials are scoped to server-side processes only.

We do not currently hold SOC 2 certification ourselves. Our primary infrastructure providers (Supabase, Vercel, Cloudflare, Stripe, Anthropic) are independently SOC 2 Type II audited.

11. Children

Outrigger is a B2B product. We do not knowingly collect data from anyone under 18. If you believe a child has registered, email us and we will delete the account.

12. Changes to this policy

We will update this page when we materially change how we handle data, and the "Last updated" date above will change with it. For account holders, material changes will also trigger an email.

13. Contact

Privacy enquiries: privacy@outriggerai.com
Postal: Direct Rank LLC, Wyoming, United States (full postal address available on request).

See also: Terms of Service.