Skip to main content
folup
Product Pricing Blog
Login Start free trial
Product Pricing Blog Login Start free trial

Privacy Policy

Effective date: 1 September 2026

On this page

  1. 1. Introduction & Scope
  2. 2. Who This Policy Covers
  3. 3. Information We Collect
  4. 4. Google User Data & Limited Use
  5. 5. Microsoft and Outlook Mailbox Data
  6. 6. How We Use Information
  7. 7. AI Drafting & Automated Processing
  8. 8. How We Share Information
  9. 9. Data Retention
  10. 10. Data Security
  11. 11. Your Rights
  12. 12. Candidates: Your Rights & Removal
  13. 13. Cookies & Analytics
  14. 14. International Data Transfers
  15. 15. Children’s Privacy
  16. 16. Changes to This Policy
  17. 17. Contact Us

1. Introduction & Scope

folup is a follow-up and outreach tool for recruiters. It helps you find a candidate’s business e-mail address, draft a message, send it from your own mailbox, and know when someone replies.

This Privacy Policy explains what we collect, why we collect it, who we share it with, how long we keep it, and what you can ask us to do about it. In this policy, “folup,” “we,” and “us” mean Folup LLC, a limited liability company formed in Florida, United States. It covers the folup website and the folup application (together, the “Service”).

2. Who This Policy Covers

Two different groups of people appear in folup, and our responsibilities differ for each.

  • Users — recruiters and sourcers with a folup account. We decide how account, billing, and usage data is handled, so for that data we are the controller.
  • Candidates — people a user contacts through folup. Where a user imports candidate records from their own systems, that user decides why and how the data is used, so they are the controller and folup acts as their processor. Where folup itself locates or verifies a business e-mail address, we are a controller for that record. Either way, see Section 12 for how to reach us.

3. Information We Collect

  • Account information — your name, work e-mail address, account credentials, and billing details.
  • Candidate and contact information — names, business e-mail addresses, employers, job titles, and public professional profile links. This reaches folup either because you imported it (a LinkedIn project export, manual entry, or a supported ATS integration) or because folup’s lookup feature located and verified a business e-mail address for a candidate you were already working with.
  • Connected mailbox data — when you connect Gmail or Outlook. This is deliberately narrow, and Sections 4 and 5 set out exactly what we can and cannot see.
  • Outreach you create — the drafts, sequences, and notes you write in folup.
  • Engagement data — whether a message you sent was opened, and whether a link in it was clicked, with the time it happened. This is collected using a tracking pixel and redirected links, and can include the recipient’s IP address and mail client. We suppress it entirely for recipients we have reason to believe are in the EEA or the UK, as Section 2 of our GDPR notice explains.
  • Usage data — which features you use, which pages you visit, and how your sequences progress.
  • Cookies and similar technologies — see Section 13.

4. Google User Data & Limited Use

If you connect a Gmail or Google Workspace account, folup requests exactly two permissions, and no others.

  • https://www.googleapis.com/auth/gmail.send — lets folup send your outreach from your own address, so the message lands in your Sent folder and replies come back to you. This permission grants no read access at all.
  • https://www.googleapis.com/auth/gmail.metadata — lets folup read message headers and labels so it can tell when a candidate has replied. This permission cannot return message bodies. Google does not make the content of your mail available under it, so folup is technically incapable of reading what your e-mails say.

What we access. Message headers (such as sender, recipient, subject, date, and message identifiers), thread identifiers, and labels — limited to threads that folup itself sent on your behalf.

What we do not access. Message bodies, attachments, drafts you wrote yourself, and any thread folup did not send. We do not search or index the rest of your mailbox.

What we store. Thread and message identifiers, the fact and timestamp of a reply, and delivery status — so the app can pause a sequence when someone answers. We do not store the content of your messages. This data is kept for as long as your account is active and is deleted with the rest of your data as described in Section 9.

Human access. We do not permit any person to read your Google user data, except in the four situations Google allows: with your affirmative agreement for specific messages; where necessary for security purposes, such as investigating abuse; to comply with applicable law; or in aggregated, anonymised form for internal operations.

What we never do. We do not sell Google user data. We do not transfer it to advertising platforms, data brokers, or information resellers. We do not use it to serve advertising, to determine credit-worthiness, or for lending purposes.

No AI training. We do not use Google user data to develop, improve, or train generalised artificial-intelligence or machine-learning models. Our AI provider (Section 7) is contractually prohibited from training any model on data we send it.

Withdrawing access. You can disconnect folup at any time from within the app, or revoke it directly at myaccount.google.com/permissions. Once revoked, folup can no longer send on your behalf or detect replies, and any running sequences stop.

folup’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

5. Microsoft and Outlook Mailbox Data

If you connect an Outlook or Microsoft 365 account, folup requests the following Microsoft Graph permissions, chosen on the same least-privilege basis as Section 4.

  • Mail.Send — lets folup send your outreach from your own address.
  • Mail.ReadBasic — lets folup read message metadata so it can detect replies. Microsoft defines this permission as reading mail excluding the body, attachments, and extensions, so as with Google, folup cannot read the contents of your mail.
  • offline_access — lets folup refresh its own access so it can detect a reply that arrives while you are not signed in. This is ongoing access, and you can revoke it at any time.
  • User.Read — reads your basic profile so we can sign you in and show which mailbox is connected.

Everything stated in Section 4 about what we access, what we store, who may read it, what we never do with it, and AI training applies equally to Microsoft mailbox data. Microsoft does not publish a Limited Use formula equivalent to Google’s, so we make these commitments in our own words instead.

Withdrawing access. Disconnect folup in the app, or revoke it at myaccount.microsoft.com under Apps and services. If your organisation granted folup access on your behalf, your IT administrator can revoke it for the whole tenant.

6. How We Use Information

We use the information described above only for the following purposes:

  • To operate the Service — running your account, importing candidates, and finding and verifying business e-mail addresses.
  • To draft outreach at your request, as described in Section 7.
  • To send messages from your connected mailbox and to detect replies, so sequences stop when a candidate answers.
  • To show you reply rates, open and click rates, and sequence progress — subject to the suppression described in Section 3.
  • To keep accounts secure and investigate abuse of the Service.
  • To take payment and handle billing.
  • To answer your support requests.

We do not use the candidate data you import for any purpose other than delivering the Service you have asked for. We do not build a shared marketing database out of it, and we do not use it to enrich other customers’ accounts.

7. AI Drafting & Automated Processing

When you ask folup to draft a message, we send the context needed to write it — typically the candidate’s name, role, and employer, the role you are hiring for, and any instructions or prior message you wrote — to Anthropic, which provides the underlying model. Anthropic acts as our service provider under contract and does not train its models on data submitted through its API.

We do not send connected-mailbox data to Anthropic or to any other AI provider. As Sections 4 and 5 explain, we do not hold the contents of your mail, so there is nothing of that kind to send.

Drafting is a suggestion, not a decision. folup does not score, rank, or evaluate candidates, and it makes no automated decision that produces legal or similarly significant effects for anyone. You decide what to send.

8. How We Share Information

We never transfer your data or your candidates’ data to advertising platforms, data brokers, or information resellers, and we do not share it for advertising or for cross-context behavioural advertising. The only parties who receive candidate data are you and the service providers below, acting on our instructions. We disclose information only in these circumstances:

  • Service providers. A small number of companies process data on our behalf, under contract, and only on our instructions:
    • Vercel — website and application hosting (United States).
    • Stripe — payment processing and billing. Your card details go to Stripe directly; we do not store them (United States).
    • Anthropic — AI drafting, as described in Section 7 (United States).
    • Sanity — content management for the folup blog. Only published blog content passes through it; no user or candidate data reaches it.
  • Services you connect yourself. Your e-mail provider, LinkedIn, or an ATS, to perform the functions you have authorised.
  • Legal and safety. Where required by law, or where necessary to protect folup, our users, or the public.
  • Business transfer. If folup is ever sold or merged, data may transfer as part of that transaction. Where connected-mailbox data is involved, we will obtain your explicit consent first.

9. Data Retention

We keep data for as long as your account is active. If you cancel, your data stays available for export for 30 days, after which it is permanently deleted from our production systems.

  • Account and billing data — life of the account, plus any period we are required to keep records for tax or accounting purposes.
  • Candidate records and outreach you created — life of the account, plus the 30-day export window.
  • Connected-mailbox metadata — life of the account, plus the 30-day export window. Disconnecting a mailbox ends folup’s access to it immediately; e-mail us if you want what we already hold deleted sooner.
  • Usage and analytics data — we do not currently run any third-party analytics. If we introduce it, analytics events will be kept no longer than 14 months and usage data no longer than 3 months.
  • Suppression records — if you ask us never to contact you again, we keep the minimum needed to honour that request indefinitely, because deleting it would undo the suppression.

10. Data Security

We encrypt data in transit using TLS and encrypt data at rest, and mailbox connection tokens are encrypted at rest. Access to production data is limited to what is needed to operate the Service.

No system is perfectly secure, and we do not claim otherwise. If a breach affects your personal data, we will notify you and any applicable regulator within the timeframes the law requires.

11. Your Rights

Depending on where you live, you may have the right to access your personal data, correct it, delete it, export it, restrict how we process it, object to processing, or withdraw consent you previously gave. To exercise any of these, e-mail hello@folup.ai. We will respond within 30 days and will not charge you or make you justify the request.

If you are in the EEA, the UK, or Switzerland, you also have the right to complain to your local supervisory authority.

If you are a California resident, you have the right to know what personal information we collect, to have it deleted or corrected, to opt out of its sale or sharing, and not to be treated differently for exercising any of those rights. We do not share personal information for cross-context behavioural advertising, and we do not transfer it to advertising platforms or data resellers.

To exercise any of these rights — including opting out of sale or sharing — e-mail hello@folup.ai and we will action it. You may use an authorised agent to make a request for you.

12. Candidates: Your Rights & Removal

If you received a message sent through folup, or believe your details are held in folup, this section is for you. You never gave us your information directly, so we want to be plain about where it came from.

Where we got it. Either a folup customer imported it from their own records — a LinkedIn project export, their applicant-tracking system, or manual entry — or folup’s lookup feature located and verified a business e-mail address for you through specialist business contact-data providers, which compile business e-mail addresses from public and commercial sources. We can tell you which provider supplied a particular record if you ask us about your own data.

What we hold. Business contact details: your name, a work e-mail address, your employer, your job title, and a link to a public professional profile. We do not seek out special-category data, home addresses, or personal e-mail accounts.

Whether we track you. If a folup user has e-mailed you, we may also record whether you opened the message or clicked a link in it. If you are in the EEA or the UK we do not do this at all — that tracking is switched off for those recipients, and nothing about your behaviour is collected.

Why we are allowed to. Where folup is the controller, we rely on legitimate interests under Article 6(1)(f) GDPR — operating a professional recruiting tool using business contact data. We have weighed that against your interests, which is why we limit ourselves to workplace details and honour objections without argument. You can object at any time.

How to be removed. E-mail hello@folup.ai. We will remove you from the contact data folup controls and add you to a suppression list so you are not looked up again. If a customer imported your details, they are the controller of that copy: we will pass your request to them, tell you who they are, and delete our own copy.

Stopping messages. Every message sent through folup carries an unsubscribe link. Using it removes you from that sender’s active sequences straight away.

13. Cookies & Analytics

Essential cookies only. We use cookies to keep you signed in, to remember your preferences, and to protect against fraud and abuse. The Service does not work without these.

What we do not run. We do not currently use any third-party product analytics, and we do not record or replay browsing sessions. We run no advertising cookies, no ad-network pixels, and no cross-site tracking. Aside from fonts and images served from our own domain, the pages you visit make no requests to third-party services.

If that changes. If we introduce product analytics, we will name the tool in this section and state what it collects before switching it on, and we will not enable session recording without saying so here first. Section 16 explains how we notify you of material changes.

Your choices. Because we run no analytics or tracking today, there is nothing to opt out of. If we add any, your browser’s tracking-protection settings or an ad blocker will block it and folup will keep working, and you can always e-mail hello@folup.ai to be excluded.

14. International Data Transfers

folup operates from the United States, and the service providers listed in Section 8 process data there. If you are in the EEA, the UK, or Switzerland, your information will be transferred to the United States. We rely on the European Commission’s Standard Contractual Clauses, and the UK Addendum where applicable, as the safeguard for those transfers. You can ask us for a copy of the relevant terms.

15. Children’s Privacy

folup is a business tool intended for professional use and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us data, e-mail hello@folup.ai and we will delete it.

16. Changes to This Policy

We may update this Privacy Policy from time to time. We will post the updated version here and change the effective date above. If a change materially affects how we handle your data, we will e-mail the address on your account at least 14 days before it takes effect. We will not begin using data received from Google or Microsoft APIs in a new way without first updating this policy and, where required, asking for your consent again.

17. Contact Us

Questions about this policy, or want to exercise a right described in Section 11 or 12? E-mail hello@folup.ai and a person will answer.

folup

Finds the e-mail LinkedIn won’t give you, then follows up from your own inbox.

Follow up. Get replies.

Coming soon

Product

  • Features
  • Pricing
  • How We Compare
  • FAQ
  • Chrome Extension Coming soon

Company

  • About
  • Contact
  • Blog

Legal

  • Privacy Policy
  • Terms of Service
  • GDPR
  • DPA

© 2026 Folup LLC. All rights reserved.

hello@folup.ai