Privacy Policy
Obtainr is a web application and companion service that chases people for documents and information on your behalf — drafting, sending, and following up on outreach emails, and checking replies against what you asked for. This policy explains what data Obtainr handles, why, and how it is protected. It applies to the Obtainr web application and its backend service (together, “Obtainr”, “we”, “us”).
1. Summary
- We collect only what is needed to run the chases you set up — your account details, the credentials you connect, the pages you choose to act on, and the messages exchanged in a chase.
- We do not sell your data, use it for advertising, or use it to assess creditworthiness or lending.
- Sensitive credentials and tokens are encrypted at rest.
- Your data is shared only with the providers you yourself choose (your AI provider and your email provider) in order to perform the actions you request.
2. Data we collect
Account and authentication
- Account details: the email address and password you register with. Passwords are stored only as a salted hash, never in plain text.
- Connected credentials: your AI provider API key, your email provider (Gmail / Outlook) OAuth access and refresh tokens, and — if you connect it — your WhatsApp Business credentials. These are encrypted at rest and used only to act on your behalf.
- Session: a login token stored locally in the browser so you stay signed in.
Content you act on
- Page content: when you start a chase from a page, the app reads that page’s visible text, links, and its title and URL, in order to pre-fill the request (for example, detecting the recipient’s name and email). This happens only when you initiate a chase, and only for the tab you are viewing — Obtainr does not track your browsing.
- Chase details: the recipient’s name and contact details, a description of what you are requesting, and the criteria a reply must satisfy.
Communications and documents
- Messages: the outreach emails Obtainr drafts and sends on your behalf, and the replies received to those messages.
- Uploaded and attached files: documents the recipient sends by email or uploads through the secure upload link, including any text extracted from them for verification. These may contain financial or other personal information depending on what you are chasing.
- Details typed into the upload link: where a chase asks for a specific value rather than a document (for example a reference number or a date), the recipient can type it directly into the upload page. That value is handled the same way as the rest of the reply: stored with the chase and checked against your requirements.
Recipients are third parties, not Obtainr users. When you set up a chase you are asking Obtainr to contact someone on your behalf and to receive what they send back, so you are responsible for having a proper basis to request that information from them, and for asking only for what you actually need.
We do not collect health data, precise location, or behavioural analytics (clicks, keystrokes, mouse movement, or browsing history).
3. How we use your data
- To run the chases you create: composing, sending, and following up on messages, and receiving replies.
- To verify whether a reply or document satisfies the requirements you specified.
- To authenticate you and keep you signed in.
- To operate, secure, and debug the service.
We use your data only for Obtainr’s single purpose — helping you obtain documents and information from other people. We do not use it for any unrelated purpose.
4. Who we share it with
We do not sell or rent your data. We share it only as needed to provide the service you requested:
- Your AI provider (e.g. Anthropic or OpenAI, per the key you configure): message and document content is sent to your chosen provider to draft messages and verify replies.
- Your email provider (Google / Microsoft): to send messages and read the replies to those messages, using the access you granted.
- Infrastructure providers that host the service (hosting and database) act as our processors under contract and only to run Obtainr.
We do not transfer your data to third parties except for these approved uses, and never to determine creditworthiness or for lending purposes.
Google user data
If you connect a Gmail account, Obtainr requests two scopes and uses them only as described here:
gmail.send— to send the chase messages you have set up, and only those.gmail.readonly— to read replies to those messages, so Obtainr can tell whether what you asked for has arrived. Obtainr reads the thread a chase is running on; it does not scan, index, or store the rest of your mailbox.
Obtainr’s use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.
In particular: data obtained through Google APIs is used only to provide and improve the user-facing features described above, is not sold, is not used for advertising, and is not read by humans except with your explicit consent, to resolve a specific support issue you have raised, for security purposes, or where required by law. Message content is sent to the AI provider you configure solely to draft a message or check a reply against your requirements — this is at your direction and for the feature you asked for, and that provider is not permitted to use it for its own purposes.
You can disconnect Gmail at any time from the app’s settings, which removes the stored tokens, and you can revoke Obtainr’s access directly at myaccount.google.com/permissions.
5. Storage and security
- Sensitive secrets (AI keys, OAuth tokens, WhatsApp credentials) are encrypted at rest using AES-256-GCM.
- The bodies of chase messages — both those Obtainr sends and the replies received, including any details typed into the upload page — are also encrypted at rest with the same scheme.
- Passwords are stored only as salted hashes.
- Access to your data requires your authenticated session.
- The recipient upload link is a single-purpose, upload-only credential scoped to one chase, and it stops working once the chase ends or the link expires. Uploaded files are screened, and dangerous file types are rejected before storage.
6. Data retention
We keep your chases and their associated data for as long as your account is active, so you can review past chases. You can archive and permanently delete individual chases from within the app. When you delete a chase, its messages, attachments, and requirements are deleted with it. If you ask us to delete your account, we remove your account data, including connected credentials.
7. Your choices and rights
- Disconnect any AI, email, or WhatsApp connection at any time in the app’s settings.
- Archive or permanently delete individual chases.
- Request access to, correction of, or deletion of your personal data by contacting us.
8. Children
Obtainr is not directed to children and is intended for use by adults in a professional or personal administrative capacity.
9. Changes to this policy
We may update this policy from time to time. Material changes will be reflected here with a new “last updated” date.
10. Contact
Questions or requests about your data: stuart151087@gmail.com.