Outlio · Lead Engine · Legal
Lead Engine Privacy Policy
Last updated: Monday, 10 August 2026
This policy explains how Outlio (“we,” “us,” “our”) handles personal data in Outlio Lead Engine (the “Service”). It covers both the people who hold Lead Engine accounts and the people whose professional details appear inside the files those account holders upload.
It applies only to Lead Engine. Our website and our done-for-you outbound and video services are covered by the main Outlio Privacy Policy.
1. The Short Version
- We never connect to LinkedIn, and never ask for or hold your LinkedIn password, cookies, or session. The only thing we read is a file you upload.
- Your uploaded files and extracted records are deleted on a schedule set by your plan, or sooner if you clear them.
- One thing does outlive that: a short duplicate-detection key per record, so we can tell you who you have already seen. It is pseudonymous, not anonymous. Section 5 explains precisely what it contains.
- We do not sell personal data, and we do not train AI models on your data.
2. Our Role, and Yours
Two different kinds of personal data flow through the Service, with different roles:
- Account data — your name, email, and how you use the Service. For this, Outlio is the controller. We decide why and how it is processed.
- Data inside uploaded files — the professional details of the people in your search results. For this, you are the controller and Outlio acts as your processor. You choose which files to upload, why, and what happens to the output. We only process on your instructions.
Because you are the controller of that second category, you are responsible for having a lawful basis to process it, for meeting transparency obligations to those individuals, and for responding to their requests. Section 12 sets out the terms on which we process it for you.
3. Account Data We Collect
- Registration and verification details — name, work email, phone number, country, company, and your own LinkedIn profile URL.
- Authentication data — a hashed password held by our authentication provider, email verification state, and session records. We never see your password in readable form.
- Billing data — plan, credit balance, invoices, and transaction history. Card details are handled by our payment processor and never reach our servers.
- Support correspondence — messages you send us.
4. Uploaded Files and Extracted Records
When you upload a file, we store the file itself in a private bucket and, once processed, the structured records extracted from it. Extracted records may include a person's name, job title, employer, location, profile URL, public summary line, and time in role or at the company.
- Files are stored under a server-generated path. Your filename is never used to build a storage path.
- Uploaded files are never rendered in a browser. They are parsed server-side only, which means uploaded content cannot execute against you or us.
- We never infer, enrich, or invent values. A field absent from your file is stored as empty. We do not append emails, phone numbers, or any data from other sources.
- If a file contains authentication material such as cookies or tokens, it is stripped and never stored.
- Files and extracted records are deleted per the schedule in Section 7, or immediately when you clear them.
5. Duplicate-Detection Keys — Read This One
The Service tells you when a person appears in a new upload that you have already seen before. To do that after the underlying records are deleted, we keep one short key per record. These keys are retained for the life of your account.
Every key is a one-way SHA-256 hash. Whichever details the source file contained, they are hashed before storage and the original text is never written down:
| What identified the person | What we store | Readable personal data? |
|---|---|---|
| A LinkedIn member identifier | a one-way hash of it | No |
| A name, job title, and employer | a one-way hash of the three together | No |
| A name and employer | a one-way hash of the two together | No |
| Neither of the above | a one-way hash of the whole record | No |
We want to be exact about this, because it matters. A hash carries no readable name, employer or profile link, and cannot be turned back into one. But it is still pseudonymous, not anonymous: the same person produces the same hash every time, so it singles them out. Under the GDPR pseudonymous data is still personal data, and we treat it that way rather than calling it anonymous.
We keep them for one purpose only: telling you that you have seen someone before. They are never used to build a profile, are never shared, are never sold, and are scoped to your account alone. They are deleted when you delete your account, and we will erase them on request — see Sections 10 and 11.
6. Anti-Abuse and Technical Data
- Trial-eligibility signals. To enforce one free trial per person, we store a keyed one-way hash derived from the network address used at sign-up, a signed first-party browser token, and keyed hashes of normalised account identifiers. We do not store the raw network address or a raw device fingerprint in these records. They are removed when the associated account is deleted.
- Security and rate-limit logs. Timestamps, event types, and hashed identifiers used to detect abuse and to rate-limit sign-in, upload, export, and admin routes.
- Operational logs. Error and performance records from our hosting and database providers. We never log lead records, file contents, tokens, signed URLs, or cookies.
- Admin audit logs. Every administrative action on an account is recorded, append-only, for accountability.
7. Why We Process Data, and Our Legal Bases
| Purpose | Data | Legal basis (UK/EU GDPR) |
|---|---|---|
| Providing the Service | Account data, uploaded files, extracted records | Performance of a contract (Art. 6(1)(b)) |
| Duplicate detection | Duplicate-detection keys | Performance of a contract; legitimate interests (Art. 6(1)(b), (f)) |
| Billing and tax | Billing data | Contract; legal obligation (Art. 6(1)(b), (c)) |
| Preventing fraud and trial abuse | Anti-abuse signals | Legitimate interests (Art. 6(1)(f)) |
| Security, and keeping the Service running | Logs, audit records | Legitimate interests; legal obligation (Art. 6(1)(f), (c)) |
| Service and security notices | Account data | Contract; legitimate interests (Art. 6(1)(b), (f)) |
Where we rely on legitimate interests, we have balanced those interests against your rights and concluded the processing is proportionate. You may object at any time — see Section 10.
We do not sell personal data, and we do not share it for cross-context behavioural advertising, as those terms are defined under the CCPA/CPRA. We do not use your data to train AI or machine learning models.
8. How Long We Keep Things
| Data | Retention |
|---|---|
| Uploaded files and extracted records | Deleted on your plan's schedule — 3 days on the free trial, 30 days on Lead Engine, 90 days on Pro, 365 days on Custom — or immediately when you clear them. |
| Generated CSV exports | Removed on the same schedule as the extraction that produced them. |
| Duplicate-detection keys | For the life of the account. Deleted with the account, or earlier on request. |
| Account and profile data | Until you delete your account. |
| Anti-abuse signals | While the account exists; removed when the account is deleted. |
| Billing records | Up to 7 years, where tax and accounting law requires it. |
| Security and admin audit logs | Up to 12 months, or longer where needed for a live investigation. |
9. Who We Share Data With
We use a small number of infrastructure providers. Each is bound by a data processing agreement and may use data only to provide its service to us.
| Provider | What it does | Where |
|---|---|---|
| Supabase | Database, authentication, file storage | EU / US |
| Vercel | Application hosting and delivery | Global edge |
| Resend | Transactional email — verification, password reset, notices | EU / US |
| Stripe | Payment processing, where card payment is enabled | EU / US |
| Calendly | Scheduling, if you book a call with us | US |
We also disclose data where legally required, to enforce our terms, or in connection with a merger or acquisition — in which case we will give notice before your data becomes subject to a different policy. An up-to-date list of sub-processors is available at [email protected].
10. Your Rights as an Account Holder
Depending on where you live, you may have the right to access, correct, delete, port, restrict, or object to our processing of your personal data, and to withdraw consent where we rely on it. UK and EU residents may also lodge a complaint with their local supervisory authority. California residents have equivalent rights under the CCPA/CPRA, and will not be discriminated against for exercising them.
You can delete your account and its data yourself from your account settings. For anything else, email [email protected]. We respond within 30 days.
11. If Your Details Appeared in Someone Else's Upload
You may be reading this because your professional details were processed through Lead Engine by one of our customers. Here is the accurate picture:
- We did not collect your data from LinkedIn or from anywhere else. Our customer saved a page they were already viewing under their own account, and uploaded that file.
- That customer is the data controller for your data. They decided to process it and are the right party for questions about why. If you ask us who they are, we will tell you, unless doing so is unlawful.
- Your details are deleted from our systems on the schedule in Section 8. A duplicate-detection key as described in Section 5 may persist in that customer's account.
You can ask us directly to erase your data. Email [email protected] with the name and profile URL that identify you. We will delete any matching extracted records and duplicate-detection keys across all customer accounts, and confirm when it is done. We will not ask you to justify the request, and we will not charge for it.
12. Processing Terms (Data Processing Addendum)
This Section applies where Outlio acts as processor for personal data in your uploaded files, and forms part of our Lead Engine Terms of Service. We will:
- Process that data only on your documented instructions, which your use of the Service constitutes, and for no independent purpose of our own.
- Apply appropriate technical and organisational measures, as described in Section 13.
- Bind everyone with access to a duty of confidentiality.
- Engage sub-processors only as listed in Section 9, under equivalent obligations, and give notice before adding a new one.
- Assist you, so far as is reasonable, with data subject requests, impact assessments, and regulator engagement.
- Notify you without undue delay, and in any case within 72 hours, on becoming aware of a personal data breach affecting your data.
- Delete the data on termination, subject to the retention in Section 8, and make available the information needed to demonstrate compliance.
Subject matter: extraction of structured records from files you upload. Duration: your subscription, plus the retention periods in Section 8. Categories of data subject: the business professionals appearing in your files. Categories of data: name, job title, employer, location, public profile URL, public summary line, tenure.
International transfers are made under the EU Standard Contractual Clauses and the UK International Data Transfer Addendum where required. A separate signed DPA is available on request.
13. Security
- Data is encrypted in transit and at rest by our infrastructure providers.
- Every database table enforces row-level security, so one customer cannot read another's data.
- Uploaded files sit in a private bucket. They are reachable only through short-lived signed URLs, and never over a public path.
- Uploads are validated by inspecting file content, not by trusting the extension.
- Authorisation is enforced server-side on every request. Administrative access requires multi-factor authentication, and there is no self-service route to it.
- Sign-in, upload, export, and admin routes are rate-limited.
No system is perfectly secure. If you believe you have found a vulnerability, please report it to [email protected] rather than disclosing it publicly, and we will work with you.
14. Cookies
Lead Engine uses essential cookies only — to keep you signed in, to protect against cross-site request forgery, and to enforce trial eligibility. There are no third-party analytics, advertising, or tracking cookies in the product. Blocking essential cookies will prevent sign-in from working.
15. Children
The Service is for business use and is not directed at anyone under 18. We do not knowingly collect data from children, and you must not upload files containing data about them. If you believe a child's data has reached us, contact us and we will delete it.
16. Changes to This Policy
We may update this policy. The date at the top always reflects the current version. For material changes affecting your rights, we will give notice by email or in the product before they take effect.
17. Contact
Privacy questions, data requests, and erasure requests: [email protected]
Outlio is the data controller for account data. If you are in the UK or EU and are not satisfied with our response, you may complain to your local data protection authority.