Legal

Privacy Policy

What LeadFinder AI collects, why we hold it, who else can see it, and how you get it back or have it deleted.

Last updated 8 August 2026

1. Scope

This policy covers the LeadFinder AI website and application, operated by Anantkamal Software Labs. It explains how we handle personal data in two quite different roles, and the distinction matters:

  • For your account data — the details you give us to open and pay for a subscription — we are the controller.
  • For the lead data you harvest — the business listings, contact details and outreach you generate — you are the controller and we process it on your instructions. You decide what to collect, who to contact, and on what lawful basis.

2. What we collect

Account and billing data:

  • Your name, email address, phone number and optional profile picture.
  • A hash of your password. We never store the password itself and cannot recover it.
  • Your plan, trial and billing period dates, and a record of payments — order and payment identifiers, amount, currency and status returned by Razorpay. Card, UPI and bank details never reach our servers.
  • Sign-in audit records: timestamp, outcome, IP address and user agent, kept so we can investigate account compromise.

Data generated by using the product:

  • Scan configuration — business category, locality, coordinates, radius and result limits.
  • Harvested business records: name, category, address, coordinates, public phone number, website, social profile URLs, publicly published email addresses, ratings and review counts, plus the audit results and score we compute from them.
  • Outreach content and status: the subject, body and message you send, and whether delivery succeeded.
  • Usage counters used to enforce your plan quotas.
  • Your mail server settings and a WhatsApp Web session for the number you link.
Harvested records are business listings, but a sole trader's mobile number or a proprietor's name in a business email address can still be personal data. That is why you, not we, decide what is collected and contacted — and why the Acceptable Use Policy forbids using the Service to build profiles of private individuals.

3. Why we use it

  • To provide the Service: run scans, score leads, draft copy and dispatch outreach through the channels you connect.
  • To operate your subscription: take payment, apply quotas, and tell you when a trial or period is ending.
  • To keep the Service secure: detect abuse, investigate suspicious sign-ins, and enforce rate limits.
  • To support you when you raise a ticket.
  • To meet legal, tax and accounting obligations.
  • To send service messages about outages, security or changes to these documents. These are not marketing and cannot be opted out of while you hold an account.

4. AI processing

Lead summaries and the first draft of your outreach copy are generated by Google Gemini. To do that we send the model the business details needed for the pitch — the business name, category, locality, and the gaps the audit found. We do not send your credentials, your account password, your payment data, or your other customers' records.

Every AI-drafted message is shown to you before anything is sent, and remains fully editable. Nothing is dispatched without you choosing to send it or starting a campaign that does.

5. Cookies

We use one cookie: an HttpOnly, Secure session cookie holding a signed JWT that keeps you logged in. It cannot be read by JavaScript and is removed when you sign out.

We do not use advertising cookies, cross-site trackers or third-party analytics pixels on this site.

6. Who else sees your data

We do not sell personal data and we do not share your leads with other customers. We rely on the following processors to run the Service:

  • MongoDB Atlas — the database your account and lead records are stored in.
  • Vercel and Render — hosting for the web application and the API and scraper.
  • Razorpay — payment processing. They are the controller for the payment instrument data you enter with them.
  • Google (Gemini) — generation of lead summaries and outreach drafts.
  • Your own mail server and WhatsApp account — outreach leaves through infrastructure you control, not a shared sender pool.

We may also disclose data where we are legally required to, or to establish or defend a legal claim.

7. How we protect it

  • Every record is scoped to your tenant at the database query level, so one account cannot read another's data.
  • Sessions use a signed JWT in an HttpOnly cookie, with strict CORS and rate limiting on the API.
  • Stored credentials — SMTP passwords, TOTP secrets — are encrypted at rest with AES-256-GCM.
  • Passwords are hashed; reset links are stored only as a SHA-256 hash and expire after an hour.
  • Operator accounts that can cross the tenant boundary require two-factor authentication and are audit-logged.
  • Traffic is encrypted in transit with TLS.

8. How long we keep it

  • Lead and outreach records are kept until you delete them or close your account. Wiping the lead database from the Leads screen removes them immediately and permanently.
  • Account data is kept while your account is open and for 30 days after closure, so an accidental cancellation can be undone.
  • Payment records are retained for as long as tax and accounting law requires, typically eight years in India.
  • Sign-in audit records are kept for 12 months.
  • A paid signup that never completes checkout is deleted automatically after 24 hours, so the email address is not held indefinitely.

9. Your rights

Depending on where you live you may have rights to access, correct, export, delete or restrict the processing of your personal data, and to withdraw consent. Most of these are available directly in the product:

  • Access and correction — the Profile screen.
  • Export — CSV export of your full lead database from the Leads screen.
  • Deletion — wipe your leads from the Leads screen, or ask us to close the account entirely.
  • Anything else — raise a request through the support portal and we will respond within 30 days.

If you are the recipient of outreach sent through the Service and want your details removed, contact the business that messaged you — they hold the data and decide what happens to it. If you cannot reach them, tell us via the support portal and we will pass the request on to the account concerned.

10. International transfers

Our providers operate globally, so your data may be processed outside your country, including in the United States and the European Union. Where that happens we rely on the transfer mechanisms those providers put in place, such as standard contractual clauses.

11. Children

The Service is a business tool and is not directed at anyone under 18. We do not knowingly collect data from children. If you believe a child has given us personal data, tell us and we will delete it.

12. Changes and how to reach us

We will update this policy as the Service changes, and the revision date is shown at the top of this page. Material changes are notified in the application or by email before they take effect.

For any privacy question, request or complaint — including a grievance under India's Digital Personal Data Protection Act — contact us through the support portal or at hello@leadfinder.ai. We acknowledge requests within 72 hours.

Questions about this document?

Raise a ticket on the support portal, write to us at hello@leadfinder.ai, or use the contact form.