Who we are
Introwire (introwire.com and app.introwire.com) is a product of OneObit, based in Noida, Uttar Pradesh, India. In this policy “we” means OneObit. Write to [email protected] about anything in it.
Whose data, and our role
- Visitors to introwire.com, including people who use the free tools.
- Customers: people who sign in to the app and the teams they add. For their account data we are the controller.
- Recipients: the people a customer emails through Introwire. The customer decides who to contact and why, and is the controller of that data; we process it on the customer’s behalf.
- People in our research directory: business-development contacts at web3 projects, gathered from public sources. For this data we are the controller.
What we collect
On introwire.com
- The domain you type into the domain check. The result is kept for ten minutes so a repeat check is fast.
- The email text you paste into the spam score. It is scored and not stored.
- Your email address, if you ask for a result to be sent to you, with the tool you used and what you checked.
- A first-party cookie,
iw_ref, kept for 30 days, that records which link or ad brought you. We use it to count sign-ups by source. - Your light or dark theme choice, stored in your browser only.
- Your IP address, used for a few minutes to limit how often one address can run the tools, and in our servers’ and Cloudflare’s logs.
In the app
- Your Google account: name, email address and Google account ID, from Google sign-in. We ask Google for nothing else at sign-in.
- Sign-in cookies:
iw_session(30 days) andiw_ws(which workspace you last opened). - Mailbox access: the address of each mailbox you connect and its app password, or, if you connect Gmail, a Google refresh token. Both are encrypted (AES-256-GCM) before they are stored and are never shown again.
- What you put in: your workspace settings, templates, the leads you import or add, notes, your team members’ email addresses and roles, and the never-email list.
- Mail: the emails Introwire sends for you, and the replies, bounces and automatic replies that arrive in your connected mailboxes. Introwire reads those mailboxes every ten minutes to find them and marks nothing as read.
- Telegram, if you connect a bot: its token (encrypted), and the messages in the groups it is added to.
- Usage needed to run the service: when emails were sent, which plan you are on, and until when it is paid.
- Payments: for each payment, the chain, coin, amount and transaction hash you give us. Transactions are public on their chain; we look them up there to confirm them.
About recipients and people in the directory
- Name, role, company, business email address and public profile links, from lists a customer imports, or, for the directory, from pages the person or their project published. Every contact detail in the directory is stored with the page it came from.
- Whether an email was sent, replied to, bounced or asked us to stop.
How we use it
- To run the service: send the emails a customer has set up, at the pace they chose, and find the replies.
- To keep sending safe: one email per company, a daily cap per mailbox, a pause when bounces pass 2%, and a never-email list that every send checks.
- To draft answers: the text of a reply, and of a question asked in a connected Telegram group, is sent to an AI model (Google Gemini or Groq) to classify it and draft a response for the customer to approve.
- To email you about your own account: setup steps, results, and answers to upgrade requests. Reply “stop” and we will not send these again.
- To send you the result you asked for from a free tool.
- To measure our marketing. On the page shown right after a new sign-up we may load X’s (Twitter’s) conversion tag, which tells X that a sign-up happened.
We do not sell personal data, and we do not use customers’ leads, emails or replies for anyone else or to train AI models.
Our legal bases under the GDPR and UK GDPR are the contract with you (running your account), our legitimate interests (security, product emails to customers, measuring sign-ups, and the research directory, which serves business-to-business introductions), and consent where you give it (the email you leave on a tool).
Google user data
Introwire’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google sign-in data is used only to identify you. If you connect a Gmail mailbox, its access is used only to send the emails you set up and to read replies and bounces to them. It is not used for advertising, not sold, not used to train AI models, and not read by people, except with your permission, for security, or where the law requires it.
Who processes it for us
- Google Cloud: the servers Introwire runs on.
- Cloudflare: DNS, content delivery, and storage for encrypted backups.
- Google: sign-in, and the Gemini model for reply drafts.
- Groq: an alternative AI model for reply drafts.
- Telegram: only for customers who connect a bot.
- Zoho: our own email, for the messages we send you.
- Your own email provider (Google Workspace, Zoho, Microsoft 365 or another), which carries the emails Introwire sends for you.
These providers may process data outside your country, including outside India and the EU. Where the law requires it, we rely on their standard contractual protections for those transfers.
How long we keep it
- Account and workspace data: while the account is open. When you ask us to close it, we delete it within 30 days; copies in backups go as those backups are replaced.
- A removed mailbox’s password or token is deleted at once; its send history stays with the workspace.
- Domain check results: ten minutes. Spam score text: not stored.
- An email left on a free tool: until you ask us to remove it.
- The never-email list is kept for as long as the workspace exists, so that a person who asked to stop is never emailed again.
Your rights
You can ask us for a copy of your data, to correct it, to delete it, to stop using it, or to move it elsewhere. These rights come from laws such as the GDPR, the UK GDPR, the CCPA and India’s Digital Personal Data Protection Act. Write to [email protected]; we reply within 30 days. If you are in our research directory, or a customer emailed you, and you want to be removed, write to us: we delete your record and add your address to the never-email list so you are not contacted through Introwire again. You can also complain to your data protection authority.
Security
Traffic is encrypted in transit. Mailbox passwords, Google tokens and bot tokens are encrypted at rest with a key kept outside the database. Access to the servers is limited to the people who run Introwire.
Children
Introwire is a business tool and is not for anyone under 18.
Changes
We will post any change here with a new date. If a change affects how we use data you already gave us, we will tell customers by email first.