CRMlead

Privacy policy

CRMlead is a sales management software (CRM) published by Quantum Liquid LLC, a Wyoming limited liability company, 30 N Gould St, Sheridan, WY 82801, United States. This page explains what data CRMlead processes, why, where it goes and how long it is kept. Contact: support@scanlead.io.

1. Data processed

  • Account: name, email address, password (stored as a hash, never in clear text), language, preferences.
  • Sales data entered or imported by users: leads, contacts (name, job title, email, phone), notes, actions, amounts, attachments.
  • Connected mailboxes (Gmail, Microsoft 365, IMAP), only if the user connects them: see section 3.
  • Technical data: sign-in logs (date, IP address, browser) and an audit log of changes.

2. Purposes

Providing the service: showing and organising leads, scheduling actions, sending the emails the user asks for, producing the account's statistics.

Security: authentication, abuse prevention, traceability of changes.

CRMlead sells no data, shows no advertising and builds no marketing profiles.

3. Google (Gmail) and Microsoft data

"Continue with Google" only requests the openid, email and profile scopes: the Google account's address, name and identifier, to open a session. CRMlead requests no access to Gmail through Google APIs.

A Gmail inbox (like any other mailbox) is connected with an app password the user creates at Google, over the standard IMAP and SMTP protocols. This password is encrypted and can be revoked at Google at any time. The rules below apply to every connected mailbox:

  • Only emails exchanged with a contact of an open lead in the account are imported. Other emails are neither fully read nor stored.
  • "To sort" queue (can be turned off in the mailbox settings): for messages received from someone who is not yet a contact, only the sender, subject and date are stored, to suggest turning them into a lead. Never the content. Newsletters are left out, only the mailbox owner sees this list, and it is erased after 30 days.
  • Attachments are not copied: only their name, type and size are stored, and the file is read from the mailbox when the user opens it.
  • Emails are only sent when the user asks, from their own address.
  • Passwords and access tokens are encrypted. Disconnecting the mailbox in settings deletes them.
  • If the user asks for an AI-written reply draft, the content of that exchange is sent to the AI provider to write that draft only. CRMlead does not use this data to train AI models.
  • Dictating a note: the audio is recorded by the browser while dictating, sent in segments to the AI provider for transcription, then discarded. CRMlead only keeps the text. The note is then read by the AI to suggest the next action, which the user accepts or dismisses.

CRMlead's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements. No human reads this data, except with the user's explicit consent, for security purposes, or to comply with the law.

4. Recipients and processors

An account's data is only visible to that account's members, according to their permissions. A connected mailbox is only visible to the person who connected it.

  • Neon: hosting of the application and database.
  • Resend, Inc. (United States): service emails (password reset, notifications) and emails from accounts without a connected mailbox.
  • Z.ai (GLM models): email drafts, only if AI is enabled by the account administrator.
  • Cloudflare, Inc.: storage of files attached to leads, when enabled.
  • Google LLC and Microsoft Corporation: only for the mailboxes and sign-ins the user connected.

Some of these providers process data outside the European Union, notably in the United States.

5. Retention

For as long as the account exists, including on the free plan, which has no time limit. A lead moved to the trash stays there until an administrator empties it; it is then erased. When an administrator deletes the account, all its data is erased immediately. A disconnected mailbox loses its access tokens immediately; emails already attached to leads stay in the account.

6. Security

Encrypted connections (HTTPS), hashed passwords, encrypted mailbox tokens, database-level isolation between accounts, optional two-factor authentication, audit log.

7. Your rights

You may request access to, correction, erasure or export of your data, or object to processing, by writing to support@scanlead.io. You can also export an account's data from the application. These rights apply under the GDPR for people located in the European Union.

8. Changes

This policy may change; the last update date is shown here. Last updated: 17.09.2026.

Privacy · Terms of use