1. Who We Are and Our Commitments
SalesSheet ("SalesSheet," "we," "us," or "our") is an AI-powered customer relationship management platform operated by SalesSheet Inc.
Three commitments frame everything in this policy:
- We do not sell your personal data, or the personal data of your contacts, to anyone.
- We do not disclose it to anyone except the service providers who help us operate the Service, and the situations described in Section 7.
- Under no circumstances do we use your CRM records, emails, call audio, or files to train generalized AI or language models — whether our own or a third party's.
If you have questions about this policy, contact us at andres@salessheets.ai.
2. Scope of This Policy
This Privacy Policy describes how SalesSheet collects, uses, stores, and shares information when you use our web application at salessheets.ai and any related services (collectively, the "Service"). It applies to all users regardless of location.
Google API Disclosure. SalesSheet's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We request access only to the data we need to provide the features described in this policy. Section 9 sets out the Limited Use commitments in full.
3. Information We Collect
3a. Account and Identity Information
When you create an account, we collect:
- Email address and name — provided during sign-up or imported from your Google profile
- Profile picture — imported from your Google account (optional)
- Google Account ID (sub) — used to link your Google identity to your SalesSheet account
- Password — if you register with email/password; stored as a one-way cryptographic hash (we never store plaintext passwords)
3b. Gmail Data
When you connect a Gmail account, SalesSheet uses the Gmail API to sync emails related to your CRM contacts. Specifically:
- What we read: Full email messages including subject, body (plain text and HTML), sender and recipient addresses (To, Cc, Bcc), date, Gmail labels, and read/importance status
- Attachments: We download and store inline images and image attachments. For all other attachment types we store only metadata (filename, MIME type, file size) — the file contents are not downloaded
- What we store: Synced emails and their metadata are stored in our database and remain until you delete them or delete your account
- Why we need it: To display email history alongside your CRM contacts, enable email search, power AI-assisted email features (summarization, reply suggestions), and help you track communication history without switching between apps
gmail.readonly scope is used to read and sync emails from your inbox.
gmail.compose scope is used to compose and send emails on your behalf directly from SalesSheet, and to create draft emails in your Gmail account.
We do not delete emails from your Gmail account, and we do not read emails unrelated to contacts stored in your CRM unless you explicitly trigger a full account import.
3c. Google Contacts
When you choose to import contacts from Google, SalesSheet uses the Google People API to read:
- Name, email addresses, phone numbers
- Organization name and job title
- Physical address
- Profile URLs (LinkedIn, website, etc.)
This is a one-time import at your direction — we do not continuously sync your Google Contacts. Imported contact data is stored in your SalesSheet account as CRM contacts.
contacts.readonly scope is used solely for this import feature.
3d. Google Calendar
When you connect your calendar, SalesSheet uses the Google Calendar API to:
- Read your calendar events to display them alongside your CRM activity timeline
- Create and update calendar events on your behalf when you schedule meetings from within SalesSheet
Calendar events are displayed in the SalesSheet interface but are not stored in our database. All calendar data remains in your Google Calendar.
calendar.events scope is used to read, create, and update calendar events.
3e. CRM Data You Enter
We store the data you and your team enter into SalesSheet:
- Contacts: name, email, phone, company, job title, address, custom fields, notes, and any files you attach
- Opportunities/Deals: name, value, stage, close date, associated contacts, custom fields, and notes
- Tasks and Activities: task name, description, due date, assignee, completion status, and linked records
- Email Compositions: emails you write and send via SalesSheet are stored as activity records alongside contacts
This data is scoped to your organization — other members of your SalesSheet organization can view it.
3f. AI Features and Voice DNA
SalesSheet offers AI-powered features including email summarization, reply suggestions, and a CRM chat assistant. To power these features:
- Email content and CRM context (contact names, notes, email snippets) are sent to third-party AI providers (see Section 4) on a per-request basis. We do not permanently store your data on AI providers' systems.
- Voice DNA: To help AI suggestions match your writing style, SalesSheet stores a rotating sample of up to 500 of your sent emails (capped at 15,000 characters each). This data is stored in our database and used only to provide writing-style context in your AI prompts. You can disable this feature in Settings.
- Audio transcription: If you use voice-to-text features, the audio clip is sent to our transcription provider. Audio files are not retained by SalesSheet after transcription.
3g. Usage Data and Analytics
- Error tracking: We automatically collect error reports, stack traces, and session replays (10% of sessions, 100% of error sessions) to diagnose and fix bugs. Reports include your user ID and organization ID but not email message content.
- Product analytics: Only with your explicit consent (via the cookie banner), we track anonymized product usage events such as page views and feature interactions. We do not include your name or email in these events. You can withdraw consent at any time in Settings → Cookie Preferences.
- Core Web Vitals: Performance metrics are collected to monitor application performance.
3h. Cookies and Local Storage
- Authentication cookie: A secure, HttpOnly session cookie set by our authentication provider to keep you logged in
- Browser local storage: Application preferences (column layout, filters, theme) and your cookie consent choice
- Session storage: Temporary OAuth state parameters used during Google sign-in; cleared immediately after sign-in completes
- No third-party advertising cookies: We do not use Google Analytics, Facebook Pixel, or any advertising or retargeting cookies
4. Service Providers
We rely on a small number of third-party providers to operate the Service. They cover hosting and database infrastructure, payment processing, email and calendar synchronization, telephony and call recording, AI model inference, transactional email, error monitoring, and product analytics.
- Each is bound by a written data-protection agreement requiring appropriate technical and organizational safeguards
- Each receives only the data its function requires
- None of them is permitted to use your data for its own purposes, or to train models on it
If you need the current list of providers for a vendor review or security questionnaire, contact us at andres@salessheets.ai and we will share it. We do not sell, rent, or trade your personal data to any third party, and we do not share your email content or CRM data with advertisers. Services you choose to connect yourself are governed by their own privacy terms, and we are not responsible for their independent practices.
5. How We Use Your Information
We process personal data only for these purposes:
- Providing the Service — syncing your mailbox, storing records, placing calls, and running the features you enable
- Billing — processing payments, issuing invoices, and meeting our tax and accounting obligations
- Security — preventing fraud, abuse, and unauthorized access
- Product quality — diagnosing defects and improving the product using diagnostic and aggregated data
- Communication — service messages about your account, and marketing messages you have opted in to
- Optional features — call recording, Voice DNA, and product analytics run only with your consent, which you may withdraw at any time
- Legal compliance — including responding to lawful requests from public authorities
6. Communications and Marketing
We send two kinds of message. Service messages — billing notices, security alerts, and changes to this policy — are part of your account and continue for as long as it is open. Marketing messages are optional: each carries an unsubscribe link, and unsubscribing never affects your access to the Service.
Separately, you may not use the Service to send unsolicited bulk email to people who have not opted in to hear from you. Cold emailing in breach of applicable anti-spam law violates our Terms of Service and may lead to suspension or termination of your account.
7. Contacts and Other Third Parties
Most of the personal data in your workspace describes other people — your contacts, prospects, and correspondents. That data is yours: we hold it on your behalf, act on your instructions, and never use it for our own purposes.
- You are responsible for having a lawful basis to upload and process that data, and for answering the requests those people make about it.
- If someone contacts us directly about data held in your workspace, we forward the request to your organization's account owner rather than act on it ourselves.
- Members of your organization can see the records, activity, and shared inbox content in the workspace, along with each other's name, photo, and email address.
- Content added to an organization stays with it: if a member leaves, the contacts and deals they contributed remain accessible to the rest of the team.
We may also disclose data to a service provider described in Section 4, where the law or valid legal process requires it, or to an acquirer in a merger, acquisition, or sale of assets — in which case this policy keeps applying until it is replaced.
8. Voice and Call Data
If you use SalesSheet to place or receive phone calls, additional data flows apply. Voice calling is provided through a third-party telephony provider; call audio transits that provider's infrastructure before and after reaching our systems.
- Call recordings: Outbound calls placed from the in-app dialer are recorded by default so we can produce a transcription and AI summary. Recordings are stored under your user ID and are accessible only to authenticated members of your organization. You may delete an individual recording from the call record view at any time.
- Transcripts and AI summaries: Generated from recordings and stored alongside the call record, under the same retention, access, and deletion rules as the underlying recording.
- Two-party consent: In many jurisdictions — including California, Florida, Illinois, Massachusetts, and Washington — recording a call requires the informed consent of every party. The dialer shows a recording notice before the call is placed. You are responsible for obtaining that consent, disclosing the recording verbally where the law requires it, or disabling recording before you dial.
- Your rights: You can access, correct, export, or delete any voice data we hold about you — recordings, transcripts, summaries, and Voice DNA samples — from within the app or by contacting andres@salessheets.ai.
9. Google API Limited Use Disclosure
SalesSheet's use of information received from Google APIs is limited to the practices disclosed in this Privacy Policy. We comply with the Google API Services User Data Policy, including its Limited Use requirements:
- We use Google user data only to provide or improve the features described in this policy
- We do not transfer Google user data to third parties except as necessary to provide the Service (for example, the AI features described above), with your consent, or as required by law
- We do not use Google user data for advertising purposes
- We do not use Google user data to develop, improve, or train generalized AI or language models
- We do not allow humans to read your Google user data unless you have given explicit permission, it is necessary for security or to resolve a support issue you raised, or we are required by law
You can revoke SalesSheet's access at any time from your Google Account Permissions page.
10. Data Retention and Deletion
We keep your data for as long as your account is open. You can delete individual records, emails, recordings, and your Voice DNA profile at any time from within the app.
| Data Type | Retention Period |
|---|---|
| Account and profile data | Until you delete your account |
| Synced emails | Until you delete individual emails or delete your account. Disconnecting a mailbox stops future syncing but previously synced emails remain in your CRM until you delete them. |
| CRM contacts, opportunities, tasks | Until you delete them or delete your account; soft-deleted contacts are permanently removed after 30 days |
| OAuth tokens | Deleted immediately when you disconnect the account |
| Call recordings, transcripts, and AI summaries | While your account is active; permanently deleted within 30 days of account deletion |
| Voice DNA samples | Capped at 500 samples; oldest pruned as new ones are added; deleted when you delete your profile or account |
| Error logs | 30 days |
| Analytics events | 90 days |
| Audio transcription files | Not retained after transcription completes |
| Cookies carrying an identifier or IP address | No longer than 13 months |
Deleting your account starts a full deletion: profile, CRM data, synced emails, call recordings, transcripts, and OAuth tokens are removed from production systems within seven days, purged from encrypted backups within 30 days, and cleared from operational logs within 90 days. If you are the last member of your organization, the organization and its data are deleted with it. Accounts with no sign-in for 24 consecutive months may be deleted after notice to the account email. We retain data beyond these windows only where the law requires it — invoices and tax records, for example, which we keep for the statutory period.
11. Data Security
Data is stored in a managed PostgreSQL database with row-level security policies that scope every record to its organization. Traffic is encrypted in transit with TLS and data is encrypted at rest. Access to production systems is limited to personnel who need it, protected by multi-factor authentication, and logged. Passwords are stored as one-way cryptographic hashes and OAuth tokens are stored encrypted. Further detail is on our Security page.
No system is perfectly secure. If a breach affects your personal data we will notify you, and any regulator entitled to notice, without undue delay.
12. Cookies and Analytics
We use cookies and local storage to keep you signed in, remember your preferences, and — with your consent — measure how the product is used. The specific cookies and storage keys are listed in Section 3h. Cookies that carry an identifier or an IP address are retained for no longer than thirteen months.
You can manage non-essential cookies from Settings → Cookie Preferences and block or delete cookies in your browser, though blocking essential cookies will prevent you from signing in. We do not use advertising or retargeting cookies.
13. Children's Privacy and Non-Discrimination
The Service is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16, and we will delete it promptly if we learn we hold it — a parent or guardian can reach us at the address in Section 16.
We also do not discriminate against anyone for exercising a privacy right: using the rights in Section 14 will never cause us to deny you the Service, charge you a different price, or provide a lower level of quality.
14. Your Rights and Choices
Depending on your location, you may have the following rights:
- Access: Request a copy of the personal data we hold about you
- Correction: Request that we correct inaccurate data
- Deletion: Request deletion of your account and all associated data. You can do this from Settings → Account → Delete Account. Deletion removes your profile, all CRM data, synced emails, call recordings, and OAuth tokens. If you are the last member of your organization, the organization and all its data are also permanently deleted.
- Portability: Request your CRM data in a structured, machine-readable format
- Objection: Object to or ask us to restrict certain processing
- Withdraw consent: Withdraw any consent you have given, including for marketing, analytics, call recording, and Voice DNA
- Withdraw Google authorization: Revoke SalesSheet's access to your Google account at any time via Google Account Permissions. This stops future syncs; previously synced data remains until you delete it or request deletion.
Exercise any of these by writing to andres@salessheets.ai. We acknowledge requests within 10 business days and answer them within 30 days, extending to a maximum of 90 days for complex requests — in which case we will tell you why.
California residents have specific rights under the CCPA/CPRA, including the right to know what personal information we collect and to request its deletion; we do not sell or share personal information as those terms are defined there. Where the data belongs to a contact in someone else's workspace, see Section 7.
15. Changes to This Policy
We may update this policy as the Service and the law change. The "Last Updated" date at the top of this page always reflects the current version. For material changes we will give notice by email or in-app notification before they take effect. Continued use of the Service after the effective date constitutes acceptance of the updated policy.
16. Contact Us
For any question about this policy, or to exercise a right:
- Email: andres@salessheets.ai
- Company: SalesSheet Inc.