Privacy Policy
Last updated: April 5, 2026
Overview
Necto ("the app", "we", "us") helps finance students find contacts at target firms and send personalized coffee chat emails from their own Gmail account. This policy explains what data we collect, how we use it, and your rights.
Information we collect
- Account information — your name and email address, collected via Clerk when you sign up.
- Search results — names, titles, and company information returned from the Apollo.io API when you search for contacts. This data is stored in your account so you can manage leads.
- Email drafts — the subject lines and body text of AI-generated emails. These are stored in your account so you can review and edit them before sending.
- Gmail send confirmation — after you send an email, we store the Gmail thread ID (a string like "17abc…") so we can link you to the sent thread and keep any follow-up you send in the same conversation. We do not store the email content after it is sent.
- Gmail account email address — stored when you connect Gmail, so the app can display which account is connected.
How we use Google user data
Necto uses one Google OAuth scope: https://www.googleapis.com/auth/gmail.send
gmail.send — what it allows: sending emails on your behalf via the Gmail API. Used only when you explicitly click "Send" or "Send All." The app sends only the emails you have reviewed and chosen to send. We never send emails automatically without your action.
What we do not do: we do not read your inbox content, access draft emails, modify labels, or use any Gmail data beyond sending the message you triggered.
Data retention: the Gmail access token is managed by Clerk (our authentication provider) and is never stored in our own database. The thread ID returned after a send is stored so we can link to the thread and keep follow-ups in the same conversation, and can be deleted by deleting your account.
Limited Use disclosure
Necto's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Third-party services
- Clerk — handles user authentication and manages OAuth tokens on our behalf. Clerk's privacy policy is at clerk.com/privacy.
- Apollo.io — used to search for professional contacts. We send search queries (company names, role filters) and receive publicly available professional profile data. Apollo's privacy policy is at apollo.io/privacy-policy.
- Anthropic Claude — used to generate personalized email drafts. We send contact name, title, company, and a research-derived interest hook. No personal data from your Gmail account is shared with Anthropic.
Data sharing
We do not sell, rent, or share your personal data with third parties for advertising purposes. Data is shared with the service providers listed above only as necessary to operate the app.
Data security
Your data is stored in a PostgreSQL database hosted on Neon. Access tokens for Google OAuth are managed by Clerk and are not stored in our database. We use HTTPS for all data transmission.
Your rights and choices
- Revoke Gmail access: visit myaccount.google.com/permissions and remove Necto from the list of connected apps.
- Delete your account: contact us at the email below and we will delete all data associated with your account within 30 days.
- Data access: you can request a copy of your stored data by contacting us.
Children's privacy
This app is not directed at children under 13. We do not knowingly collect data from children under 13.
Changes to this policy
We may update this policy from time to time. We will update the "Last updated" date at the top of this page. Continued use of the app after changes constitutes acceptance of the revised policy.
Contact
If you have questions about this privacy policy or your data, contact us at privacy@usenecto.com.