Privacy Policy
Obtainr is a web application and companion service that chases people for documents and information on your behalf — drafting, sending, and following up on outreach emails, and checking replies against what you asked for. This policy explains what data Obtainr handles, why, and how it is protected. It applies to the Obtainr web application and its backend service (together, “Obtainr”, “we”, “us”).
1. Summary
- We collect only what is needed to run the chases you set up — your account details, the credentials you connect, the pages you choose to act on, and the messages exchanged in a chase.
- We do not sell your data, use it for advertising, or use it to assess creditworthiness or lending.
- Sensitive credentials and tokens are encrypted at rest.
- Documents are deleted on a schedule, not kept indefinitely — 30 days after a chase finishes by default, and never more than 90 days from the day they arrived. See Data retention.
- Your data is shared only with the providers you yourself choose (your AI provider and your email provider) in order to perform the actions you request.
- We measure how the product is used, but only if you agree to it first. Nothing is stored on your device and no analytics data leaves your browser until you say yes, and you can change your mind at any time. See Cookies and analytics.
2. Data we collect
Account and authentication
- Account details: the email address and password you register with. Passwords are stored only as a salted hash, never in plain text.
- Connected credentials: your AI provider API key, your email provider (Gmail / Outlook) OAuth access and refresh tokens, and — if you connect it — your WhatsApp Business credentials. These are encrypted at rest and used only to act on your behalf.
- Session: a login token stored locally in the browser so you stay signed in.
Content you act on
- Page content: when you start a chase from a page, the app reads that page’s visible text, links, and its title and URL, in order to pre-fill the request (for example, detecting the recipient’s name and email). This happens only when you initiate a chase, and only for the tab you are viewing — Obtainr does not follow you around the web or read pages you have not chosen to act on.
- Chase details: the recipient’s name and contact details, a description of what you are requesting, and the criteria a reply must satisfy.
Communications and documents
- Messages: the outreach emails Obtainr drafts and sends on your behalf, and the replies received to those messages.
- Uploaded and attached files: documents the recipient sends by email or uploads through the secure upload link, including any text extracted from them for verification. These may contain financial or other personal information depending on what you are chasing.
- Details typed into the upload link: where a chase asks for a specific value rather than a document (for example a reference number or a date), the recipient can type it directly into the upload page. That value is handled the same way as the rest of the reply: stored with the chase and checked against your requirements.
Recipients are third parties, not Obtainr users. When you set up a chase you are asking Obtainr to contact someone on your behalf and to receive what they send back, so you are responsible for having a proper basis to request that information from them, and for asking only for what you actually need.
Usage data
- Product analytics: if — and only if — you agree to it, we record which pages of our site and app you open and which actions you take in them (for example: created a chase, connected a mailbox, submitted the demo form, started a subscription), along with your account identifier and the approximate location and device type your browser reports. This is described in full under Cookies and analytics below.
- Measurements attached to those actions: alongside each one we record simple
numbers that describe it — how many recipients a chase had, how many follow-ups it took, how long
you had been on a page and how far down it you had scrolled when you clicked a link, and the domain
part of your email address (for example
example.co.uk) so we can tell which kinds of firm are using Obtainr. We record the size and shape of what you do, not its content: never the text of a request, a message, a document, or a form you filled in.
We do not collect health data or precise location, and we do not record your keystrokes, your mouse movement, video replays of your session, or the contents of your chases, your documents, or your recipients’ details into any analytics system. Session recording and automatic click capture are switched off, not merely unused. We do not track you across other companies’ websites and we do not use your data for advertising.
3. How we use your data
- To run the chases you create: composing, sending, and following up on messages, and receiving replies.
- To verify whether a reply or document satisfies the requirements you specified.
- To authenticate you and keep you signed in.
- To operate, secure, and debug the service.
- To email you about your own account — see “Emails we send you” below.
We use your data only for Obtainr’s single purpose — helping you obtain documents and information from other people. We do not use it for any unrelated purpose.
4. Who we share it with
We do not sell or rent your data. We share it only as needed to provide the service you requested:
- Your AI provider (e.g. Anthropic or OpenAI, per the key you configure): message and document content is sent to your chosen provider to draft messages and verify replies.
- Your email provider (Google / Microsoft): to send messages and read the replies to those messages, using the access you granted.
- Infrastructure providers that host the service (hosting and database) act as our processors under contract and only to run Obtainr.
- Stripe handles subscription payments. Your card details are entered on Stripe’s own pages and are never seen or stored by us.
- Mixpanel, our analytics processor — but only if you have agreed to analytics, and only the usage data described in section 5. No chase content, document, recipient detail or credential is ever sent to it.
We do not transfer your data to third parties except for these approved uses, and never to determine creditworthiness or for lending purposes.
Google user data
If you connect a Gmail account, Obtainr requests one scope and uses it only as described here:
gmail.send— to send the chase messages you have set up, and only those.
Obtainr does not request read access to your mailbox and cannot open your email.
It previously used gmail.readonly to find replies; that scope has been dropped. Each
chase now carries its own reply-to address, so a reply reaches Obtainr directly instead of being
read out of your inbox — which means your mail is never scanned, indexed or stored by us.
Obtainr’s use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.
In particular: data obtained through Google APIs is used only to provide and improve the user-facing features described above, is not sold, is not used for advertising, and is not read by humans except with your explicit consent, to resolve a specific support issue you have raised, for security purposes, or where required by law. Message content is sent to the AI provider you configure solely to draft a message or check a reply against your requirements — this is at your direction and for the feature you asked for, and that provider is not permitted to use it for its own purposes.
You can disconnect Gmail at any time from the app’s settings, which removes the stored tokens, and you can revoke Obtainr’s access directly at myaccount.google.com/permissions.
5. Cookies and analytics
Obtainr sets no advertising cookies and does not track you across other companies’ websites. It uses two cookies at most, and only one of them is ever optional.
- Your consent choice — a cookie recording whether you said yes or no to the
analytics below, so we don’t ask again on every page. It is set on
obtainr.co.ukso that one answer covers both this site and the app, lasts six months, and is exempt from consent because it exists solely to honour your decision. - Analytics — if you agree, one cookie set by Mixpanel, which we use to measure how the product is used. Nothing is downloaded, set, or sent before you agree: decline and the analytics code is never loaded at all.
We use this to answer questions we cannot answer any other way — which pages bring people to sign up, where people get stuck in setting up their first chase, and which features are actually used. Our lawful basis is your consent, and you can withdraw it at any time using cookie settings (or by clearing cookies for this site); doing so deletes the analytics cookie.
Mixpanel acts as our processor and is not permitted to use the data for its own purposes. Our Mixpanel project is configured for EU data residency, so analytics data is held on servers in the European Union rather than the United States. Mixpanel is a US-headquartered company, and any access from outside the EEA is governed by its data processing terms. We identify you to it by your Obtainr account id and email address — never by the contents of a chase, a document, a recipient’s details, or your connected credentials, none of which are ever sent to it. When you delete your account we delete your analytics profile with it — the record carrying your email address. Historical events remain, keyed to an identifier that no longer corresponds to a person.
6. Storage and security
- Sensitive secrets (AI keys, OAuth tokens, WhatsApp credentials) are encrypted at rest using AES-256-GCM.
- The bodies of chase messages, both those Obtainr sends and the replies received, are also encrypted at rest with the same scheme. So is every value typed into an upload page — a National Insurance number, a date of birth — which is held separately from the message it arrived with.
- Files themselves are stored unencrypted at rest within our managed database, which is itself encrypted at the disk level by our hosting provider. We are working on encrypting them individually. The retention limits above are the stronger protection in the meantime: a file that no longer exists cannot be exposed.
- Passwords are stored only as salted hashes.
- Access to your data requires your authenticated session.
- The recipient upload link is a single-purpose, upload-only credential scoped to one chase, and it stops working once the chase ends or the link expires. Uploaded files are screened, and dangerous file types are rejected before storage.
7. Data retention
Documents are deleted automatically. Obtainr is a conduit, not your filing system — the copy that matters belongs in your own records, and a second copy sitting here indefinitely is a liability rather than a convenience. So anything collected through a chase, whether a file someone attached or an answer they typed into an upload link, is destroyed on a schedule you set.
The countdown starts when a chase finishes, and runs for 30 days by default. You can change that to 7 or 90 days in Settings → Agent behaviour, and 7 days is the right choice if you file documents into your own system promptly.
Nothing is kept beyond 90 days from the day it arrived, whatever that setting says and whether or not the chase ever finished. This second limit is not adjustable, and it exists because a chase nobody closes would otherwise hold someone's passport scan forever.
When a document is destroyed we delete the file itself, the text we extracted from it in order to check it, and any value typed into an upload link. What remains is the file's name, a checksum of its contents, and the date it was deleted — enough for the chase's history to still make sense, and enough to prove that the copy in your own records is the one that came through Obtainr, but not enough to reconstruct anything.
The rest of a chase — who you asked, what you asked for, and the messages exchanged — is kept for as long as your account is active, so you have a record of what happened. You can archive and permanently delete individual chases at any time; deleting a chase removes its messages, documents and requirements immediately rather than waiting for the schedule above.
You can delete your whole account yourself, from Settings → Privacy. Deletion is immediate and irreversible: there is no grace period and no recovery. When you delete your account we erase every chase, message, and uploaded document; cancel any subscription straight away, with no refund of the remainder of the paid period; and hand back our access to your connected mailbox. Upload links you have already sent to other people stop working at the same moment, so anyone still holding one will no longer be able to send you anything.
Two things are outside our control and we will tell you at the time if they apply. Microsoft provides no way for an application to revoke its own access, so where you connected an Outlook mailbox you should also remove Obtainr from your Microsoft account. And routine encrypted backups may retain deleted records for a short period before they age out; those backups are not used to restore deleted accounts.
8. Your choices and rights
- Disconnect any AI, email, or WhatsApp connection at any time in the app’s settings.
- Archive or permanently delete individual chases.
- Choose which emails Obtainr sends you, in Settings → Notifications.
- Delete your entire account and everything in it yourself, in Settings → Privacy.
- Request access to, or correction of, your personal data by contacting us.
9. Emails we send you
These are emails from Obtainr to you, about your own account. They are separate from the chases themselves, which are sent from your own connected mailbox to the people you are chasing.
You can turn these off at any time in Settings → Notifications:
- When something needs you — a chase has stopped, a reply needs your decision, or your mailbox has disconnected.
- Daily summary — one email on working-day mornings covering what arrived and what is outstanding. Nothing is sent on days when nothing happened.
- When a project finishes — everyone you were chasing has sent what you asked for.
Some emails cannot be turned off, because they are how you find out that money or data has moved: problems with a payment, changes to your subscription, security notices, and confirmation that an account has been deleted. These are sent because they are necessary to provide the service you have asked for, not for marketing, and we do not send you marketing email on the basis of holding an account.
10. Children
Obtainr is not directed to children and is intended for use by adults in a professional or personal administrative capacity.
11. Changes to this policy
We may update this policy from time to time. Material changes will be reflected here with a new “last updated” date.
12. Contact
Questions or requests about your data: stuart151087@gmail.com.