Obtainr

Privacy Policy

Last updated: 7 August 2026 · Home · Terms of Service · Support

Obtainr is a web application and companion service that chases people for documents and information on your behalf — drafting, sending, and following up on outreach emails, and checking replies against what you asked for. This policy explains what data Obtainr handles, why, and how it is protected. It applies to the Obtainr web application and its backend service (together, “Obtainr”, “we”, “us”).

1. Summary

2. Data we collect

Account and authentication

Content you act on

Communications and documents

Recipients are third parties, not Obtainr users. When you set up a chase you are asking Obtainr to contact someone on your behalf and to receive what they send back, so you are responsible for having a proper basis to request that information from them, and for asking only for what you actually need.

Usage data

We do not collect health data or precise location, and we do not record your keystrokes, your mouse movement, video replays of your session, or the contents of your chases, your documents, or your recipients’ details into any analytics system. Session recording and automatic click capture are switched off, not merely unused. We do not track you across other companies’ websites and we do not use your data for advertising.

3. How we use your data

We use your data only for Obtainr’s single purpose — helping you obtain documents and information from other people. We do not use it for any unrelated purpose.

4. Who we share it with

We do not sell or rent your data. We share it only as needed to provide the service you requested:

We do not transfer your data to third parties except for these approved uses, and never to determine creditworthiness or for lending purposes.

Google user data

If you connect a Gmail account, Obtainr requests one scope and uses it only as described here:

Obtainr does not request read access to your mailbox and cannot open your email. It previously used gmail.readonly to find replies; that scope has been dropped. Each chase now carries its own reply-to address, so a reply reaches Obtainr directly instead of being read out of your inbox — which means your mail is never scanned, indexed or stored by us.

Obtainr’s use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.

In particular: data obtained through Google APIs is used only to provide and improve the user-facing features described above, is not sold, is not used for advertising, and is not read by humans except with your explicit consent, to resolve a specific support issue you have raised, for security purposes, or where required by law. Message content is sent to the AI provider you configure solely to draft a message or check a reply against your requirements — this is at your direction and for the feature you asked for, and that provider is not permitted to use it for its own purposes.

You can disconnect Gmail at any time from the app’s settings, which removes the stored tokens, and you can revoke Obtainr’s access directly at myaccount.google.com/permissions.

5. Cookies and analytics

Obtainr sets no advertising cookies and does not track you across other companies’ websites. It uses two cookies at most, and only one of them is ever optional.

We use this to answer questions we cannot answer any other way — which pages bring people to sign up, where people get stuck in setting up their first chase, and which features are actually used. Our lawful basis is your consent, and you can withdraw it at any time using cookie settings (or by clearing cookies for this site); doing so deletes the analytics cookie.

Mixpanel acts as our processor and is not permitted to use the data for its own purposes. Our Mixpanel project is configured for EU data residency, so analytics data is held on servers in the European Union rather than the United States. Mixpanel is a US-headquartered company, and any access from outside the EEA is governed by its data processing terms. We identify you to it by your Obtainr account id and email address — never by the contents of a chase, a document, a recipient’s details, or your connected credentials, none of which are ever sent to it. When you delete your account we delete your analytics profile with it — the record carrying your email address. Historical events remain, keyed to an identifier that no longer corresponds to a person.

6. Storage and security

7. Data retention

Documents are deleted automatically. Obtainr is a conduit, not your filing system — the copy that matters belongs in your own records, and a second copy sitting here indefinitely is a liability rather than a convenience. So anything collected through a chase, whether a file someone attached or an answer they typed into an upload link, is destroyed on a schedule you set.

The countdown starts when a chase finishes, and runs for 30 days by default. You can change that to 7 or 90 days in Settings → Agent behaviour, and 7 days is the right choice if you file documents into your own system promptly.

Nothing is kept beyond 90 days from the day it arrived, whatever that setting says and whether or not the chase ever finished. This second limit is not adjustable, and it exists because a chase nobody closes would otherwise hold someone's passport scan forever.

When a document is destroyed we delete the file itself, the text we extracted from it in order to check it, and any value typed into an upload link. What remains is the file's name, a checksum of its contents, and the date it was deleted — enough for the chase's history to still make sense, and enough to prove that the copy in your own records is the one that came through Obtainr, but not enough to reconstruct anything.

The rest of a chase — who you asked, what you asked for, and the messages exchanged — is kept for as long as your account is active, so you have a record of what happened. You can archive and permanently delete individual chases at any time; deleting a chase removes its messages, documents and requirements immediately rather than waiting for the schedule above.

You can delete your whole account yourself, from Settings → Privacy. Deletion is immediate and irreversible: there is no grace period and no recovery. When you delete your account we erase every chase, message, and uploaded document; cancel any subscription straight away, with no refund of the remainder of the paid period; and hand back our access to your connected mailbox. Upload links you have already sent to other people stop working at the same moment, so anyone still holding one will no longer be able to send you anything.

Two things are outside our control and we will tell you at the time if they apply. Microsoft provides no way for an application to revoke its own access, so where you connected an Outlook mailbox you should also remove Obtainr from your Microsoft account. And routine encrypted backups may retain deleted records for a short period before they age out; those backups are not used to restore deleted accounts.

8. Your choices and rights

9. Emails we send you

These are emails from Obtainr to you, about your own account. They are separate from the chases themselves, which are sent from your own connected mailbox to the people you are chasing.

You can turn these off at any time in Settings → Notifications:

Some emails cannot be turned off, because they are how you find out that money or data has moved: problems with a payment, changes to your subscription, security notices, and confirmation that an account has been deleted. These are sent because they are necessary to provide the service you have asked for, not for marketing, and we do not send you marketing email on the basis of holding an account.

10. Children

Obtainr is not directed to children and is intended for use by adults in a professional or personal administrative capacity.

11. Changes to this policy

We may update this policy from time to time. Material changes will be reflected here with a new “last updated” date.

12. Contact

Questions or requests about your data: stuart151087@gmail.com.