Privacy Policy
Last updated 8 September 2026
The Outbound Animal (“the Service”) is recruiting outreach software operated by 680 Partners (“we”, “us”). This policy explains what the Service does with your data, and with the data of the people you contact through it.
Two different groups of people appear in this policy, and they are treated differently throughout: users, meaning recruiters with an account, and contacts, meaning the candidates and other people whose details a user stores in the Service. Contacts do not have accounts and usually have no direct relationship with us.
Who is responsible for what
For data about users — your account, your login, your billing — we decide how that data is handled, and this policy governs it.
For data about contacts, the recruiting firm using the Service decides what to collect and why. We process it on that firm’s behalf and under its instructions. If you are a candidate who wants their data corrected or deleted, the firm that contacted you controls that decision; we will help them act on it, and you can also contact us at the address below and we will route your request.
What we collect
From users
- Your name, email address, and the identity provider you signed in with (Microsoft or Google).
- OAuth access and refresh tokens for the mailbox and calendar permissions you grant.
- Usage records — what you sent, when, and which features you used — including counts of AI requests made on your behalf.
From your mailbox and calendar
With your explicit consent at sign-in, the Service connects to your Microsoft 365 or Google account. It uses that access to:
- Send the outreach messages you compose, from your own mailbox, so that replies come back to you and your sending reputation is your own.
- Read incoming mail in order to detect replies to campaigns you sent, so a reply stops the follow-up sequence and appears in your queue. We match against messages the Service sent; we do not index your mailbox generally.
- Read calendar events in order to detect that a meeting with a candidate was booked, so the candidate’s status updates without you doing it by hand.
About contacts
- Name, email addresses, phone numbers, job title, employer, location and LinkedIn profile URL.
- Resumes and CVs that you upload, forward, or import.
- Notes, assessments and interview records that you write.
- The messages exchanged with them through the Service, including their replies.
- Where it came from — which import, campaign or search a record originated in — so that the provenance of a record is auditable.
What we do not do
- We do not sell personal data, and we do not share it with data brokers.
- We do not use your data, or your contacts’ data, for advertising.
- We do not use Google or Microsoft mailbox data to build a shared or cross-customer dataset.
- We do not read your mail for any purpose other than the ones described above.
Google API Services — Limited Use
The Service’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- Google user data is used only to provide and improve the user-facing features described in this policy — sending your outreach, detecting replies to it, and detecting booked meetings.
- Google user data is not transferred to others except as necessary to provide those features, or as required by law.
- Google user data is not used for advertising.
- Google user data is not sold.
- Google user data is not used to develop, improve, or train generalised artificial intelligence models.
- No human reads your Google user data, except where you explicitly ask us to (for example, when you report a problem), where it is necessary for security purposes such as investigating abuse, or where required by law.
The equivalent commitments apply to data obtained through Microsoft Graph.
Automated processing
The Service uses Anthropic’s Claude API to provide specific features you invoke. We are naming these precisely, because some of them process the content of email:
- Reply classification. The body of a reply received in your mailbox is sent to the API to determine whether it is interest, a decline, a referral, an out-of-office, and so on.
- Suggested reply drafts. When you ask for one, the inbound message is sent so a response can be drafted for you to edit.
- Message personalisation from a contact’s title, employer and background.
- Resume parsing. An uploaded resume is sent so contact details and work history can be extracted.
This is a transfer to a service provider for the sole purpose of delivering these features. Under Anthropic’s commercial terms, data submitted through the API is not used to train its models. It is not used for advertising and it is not sold. If you would prefer these features not run against your mail, tell us and we will disable them for your account.
Automated classification affects how a message is filed and what follow-up is suggested. It does not make decisions about a candidate on its own — every submission, rejection and outreach decision in the Service is taken by a person.
Who else processes data
We use a small number of providers to run the Service:
- Vercel — application hosting.
- Neon — the PostgreSQL database where your data is stored.
- Anthropic — the AI features described above.
- Microsoft and Google — mail and calendar, under the permissions you grant.
How long we keep things
Contact records, messages and notes are kept until you delete them or close your account. When an account is closed we delete or return its data within 90 days, except where we must keep something to comply with a legal obligation.
Two things are kept deliberately. Suppression records — people who asked not to be contacted — are retained after a contact is deleted, because the only way to reliably honour “never email me again” is to remember the request. OAuth tokens are deleted as soon as you disconnect an account or revoke access.
Security
Data is encrypted in transit and at rest. Access to your organisation’s data is restricted to members of your organisation, and within it by role. Access codes for shared client reports are stored hashed, expire, and are invalidated after repeated failed attempts. We do not store passwords: authentication is handled by Microsoft or Google.
The Service is in beta. It has not undergone SOC 2 audit or Google CASA assessment. We are telling you that plainly rather than implying certifications we do not hold.
Your rights
Depending on where you live, you may have the right to access, correct, delete, or export your personal data, to object to processing, or to complain to a supervisory authority. To exercise any of these, write to the address below. We aim to respond within 30 days.
You can revoke the Service’s access to your mailbox and calendar at any time, without involving us, from your Google account permissions or your Microsoft account settings. Revoking access stops all sending and syncing immediately.
International transfers
The Service is operated from the United States and data is processed there. If you are in the UK, EEA or Switzerland, your data will be transferred outside your jurisdiction to be processed.
Children
The Service is for professional recruiting use and is not directed at anyone under 18.
Changes
If we change this policy materially, we will update the date at the top and notify account holders by email before the change takes effect.
Contact
Privacy questions and data requests: privacy@outboundanimal.com
680 Partners, operator of The Outbound Animal, United States.
The Outbound Animal