Sesame

Privacy Policy

Last updated: 11 June 2026

Sesame ("Sesame", "we", "us") is an AI-assisted outreach platform that helps you research companies, find contacts, and write and send better emails. This policy explains what data we collect, how we use it, and the choices you have. It applies to the Sesame web application and any related services.

Information we collect

  • Account data — your name, email address, and authentication identifiers when you sign up or sign in (including via Google or Microsoft).
  • Mailbox connection data — when you connect an email account, we store OAuth tokens and the minimum metadata needed to send emails on your behalf and detect replies to emails you sent through Sesame.
  • Contact and company data — information about companies and people you research, import, or discover through the platform (for example names, job titles, work email addresses, and company details), including data sourced from third-party providers.
  • Content you create — email drafts, edits you make to AI-generated drafts, templates, notes, and campaign settings.
  • Usage and engagement data — how you use the platform, send events, delivery outcomes, and engagement signals such as opens, clicks, replies (as events), and unsubscribes.

How we use your information

  • To provide, operate, and secure the service.
  • To generate email drafts and research using AI models, acting on your instructions.
  • To send emails you choose to send, from your connected mailbox.
  • To bill you for paid plans, if applicable.
  • To improve the service, including training and evaluating our own models — subject to the limits described below.
  • To comply with legal obligations.

AI and model training

We use platform-generated data — such as AI drafts produced in the app, the edits you make to them, send settings, campaign metadata, and aggregate engagement outcomes — to improve our product and to train and evaluate models that make outreach more effective. Where practical we aggregate or de-identify this data before using it for training.

We do not use data obtained from Google or Microsoft mailbox APIs (such as the contents of emails or replies in your inbox) to train generalized AI or machine learning models.

You can opt out of your data being used for model training at any time by contacting us at the address below. Opting out does not affect your use of the service.

Google API Limited Use disclosure

Sesame's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular, Google user data is used only to provide user-facing features of Sesame (sending emails you compose and detecting replies to them), is not transferred to third parties except as necessary to provide those features, is not used for advertising, and is not used to train generalized AI or machine learning models.

How we share information

We do not sell your personal information. We share data only with service providers (sub-processors) that help us run the platform, under contracts that restrict their use of it:

  • Vercel — application hosting.
  • Supabase — database hosting.
  • Google — sign-in, mailbox connectivity (Gmail), and AI model services.
  • Microsoft — sign-in and mailbox connectivity (Outlook).
  • Apollo — company and contact data enrichment.

We may also disclose information if required by law, or as part of a merger, acquisition, or sale of assets (in which case this policy will continue to apply to your data).

Information about email recipients

Sesame stores information about the people you contact (such as names, job titles, and work email addresses) on your behalf. We honour unsubscribe and suppression requests from recipients, and recipients may contact us at the address below to access or request deletion of personal information we hold about them.

Data retention

We retain your data for as long as your account is active. If you delete your account, we delete or de-identify your personal data within 30 days, except where we are required to retain it by law (for example billing records) or where it exists in encrypted backups that expire on a rolling schedule.

Security

We use industry-standard safeguards including encryption in transit and at rest, scoped OAuth permissions, and tenant-level data isolation. No system is perfectly secure; if we become aware of a breach affecting your data we will notify you as required by law.

International transfers

We are based in Australia and our service providers may process data in other countries, including the United States. Where data is transferred internationally, we rely on our providers' safeguards and standard contractual protections.

Your rights

Depending on where you live (including under the Australian Privacy Principles and the EU/UK GDPR), you may have the right to access, correct, export, or delete your personal information, to object to or restrict certain processing, and to withdraw consent. To exercise any of these rights, contact us at the address below. You may also lodge a complaint with your local privacy regulator (in Australia, the OAIC).

Children

Sesame is not directed at children under 16 and we do not knowingly collect their personal information.

Changes to this policy

We may update this policy from time to time. We will post the updated version on this page and, for material changes, notify you by email or in the app.

Contact

Questions or requests: ziggyb544@gmail.com.