Privacy Policy
What Blackbook Engine collects, why, and what we do with it.
Last updated: August 2026
1. What we collect
When you sign up for Blackbook Engine we collect the information you give us directly: your organization name, your subdomain, the email address on your account, and the number of seats you subscribe to. We may also collect the names and email addresses of users you add to your account.
To bill you we collect the payment details needed to process charges. Card numbers are handled by our payment processor, Stripe; we never see or store your full card number. Your subdomain, tier, and seat count are tied to your subscription.
When you use the Service we process the data you bring to it: contact records, outreach drafts and messages, meeting notes, and the accounts you connect (email, LinkedIn, CRM). This data is processed to run the Service for you.
2. How we use your data
We use the data you provide to operate your instance, generate drafts and research, send messages you approve, keep your records in sync, bill you, and provide support. We use aggregated, non-identifying usage information to improve the Service.
3. Who we share data with
We share data only with the service providers needed to run Blackbook Engine, and only for that purpose:
- Stripe: payment processing and subscription billing;
- Microsoft Azure: hosting of the Service, including storage and AI inference;
- Hetzner: the per-customer database servers that hold your CRM data;
- SendGrid: delivery of the emails your outreach sends;
- Anthropic: the language models that generate drafts and research;
- DeepSeek: the language models that draft internal monitoring digests;
- HuggingFace: image generation for ad creative;
- Meta (Facebook): ad campaigns and custom audiences;
- GitHub: source control and CI/CD.
We do not sell your data. We do not share it for advertising. We may disclose data where required by law, or in connection with a merger or acquisition of the business.
4. Security
We protect the service with SOC 2 controls: encryption in transit and at rest, secrets in Azure Key Vault, per-customer data isolation, and least-privilege access reviewed quarterly. No system is perfectly secure, and we cannot guarantee absolute security of data transmitted over the internet. See how we secure the platform.
5. Retention
We keep your data for as long as your account is active and for a reasonable period after cancellation to allow you to export it. After that, we delete or de-identify it. Backup copies are retained according to our backup schedule and then rotated out.
6. Your rights
You can access and export your data through the Service, correct inaccuracies, and delete your data or account. If you have a request we can't fulfill through the product, email us and we'll help. If you are in the EU or UK, you have the additional rights granted by the GDPR; we process your data as a data processor on your instructions.
7. Cookies
The Service uses a small number of cookies and local storage for authentication and preferences. The marketing site may use privacy-respecting analytics. We do not use third-party advertising cookies.
8. Changes and contact
We may update this policy from time to time and will notify you of material changes by email or through the Service. Questions about this policy can be sent to the contact address on our contact page.