Privacy Policy
Last updated: 1 October 2026
1. Who we are
Cold Leads ("the Service") is a lead-management and e-mail campaign tool operated by Anton Tkachenko, ID (IČO) 17587557, Malešická 2855/2b, 130 00 Praha 3 – Žižkov, Czech Republic — the data controller for account data. Contact: support@coldleads.app.
2. Data we process
Account data: your name, e-mail address and authentication identifier received from the sign-in method you choose (e-mail link or Google via Firebase Authentication). Contact data you add: names, e-mail addresses, phone numbers, companies, social profile links, tags, notes and interaction history of your business contacts. Technical data: a session cookie required for sign-in and basic server logs (IP address, time) for security and rate limiting.
3. How we use data
Solely to provide the Service: authenticating you, storing your CRM data, sending the e-mail campaigns you explicitly launch, and generating drafts with AI. Payments are processed by Stripe (PCI DSS Level 1); we store only payment and subscription identifiers, never card numbers. Your consent to the recurring payment parameters is stored for at least 12 months as proof. We do not sell personal data and do not use it for advertising.
4. Subprocessors
We rely on: Vercel (hosting and the Prisma Postgres database), Google Firebase (authentication; Firebase Analytics for anonymous usage statistics and error reports after you accept the cookie notice), Microsoft Clarity (anonymised session replays and heatmaps to improve usability; typed text is masked, cookies only after you accept the cookie notice), Google Ads (conversion measurement — whether a subscription followed an ad click; cookies only after you accept the cookie notice), Stripe (Stripe Payments Europe, Ltd.; payments), Resend (e-mail delivery), OpenAI (the website AI assistant and ChatGPT integration; the data needed for these features is described in sections 7 and 8), unavatar.io (public avatars). Each receives only the data needed for its function.
5. Legal basis & your responsibilities
You must have a lawful basis for the contacts you upload and messages you send (consent or legitimate interest under GDPR / zákon č. 480/2004 Sb.). Every campaign e-mail includes an unsubscribe instruction; opt-outs are permanent. Addresses on the do-not-contact list (coldleads.app/remove-my-email) cannot be added or e-mailed in any account.
6. Retention & your rights
Data is kept while your account is active. You may request access, correction, export or deletion of your data at any time by e-mail to the address above or via Help → Send a report; we respond within 30 days. You may lodge a complaint with the Czech Office for Personal Data Protection (uoou.cz). The session cookie expires after 30 days.
7. AI assistant on the website
The website and the app include an AI assistant (Frosty) that answers questions about Cold Leads. Messages you type in the chat are sent to OpenAI to generate the reply, together with our public help content; under OpenAI's API terms they are not used to train models. We do not store chat transcripts in the app database. When a conversation ends (after a period of inactivity or when you leave the page) it is e-mailed to our support team so we can improve the answers; the copy in your browser lasts only for the current session. Do not enter passwords, card numbers or other sensitive data into the chat. For signed-in users the assistant also sees the account's plan, limits, usage and campaign statuses (never your contacts' data) so it can answer questions about the account. For a human, write to the address above.
8. ChatGPT integration
If you connect Cold Leads to ChatGPT, your requests and the results of tool calls you authorize (such as contact or campaign details) are sent to OpenAI to provide the integration and appear in your ChatGPT conversation. Cold Leads retains workspace data under the retention periods described above. Further retention of the conversation and processing of data in ChatGPT are governed by OpenAI's applicable policies, terms, and account or workspace settings.