This Privacy Policy is provided by Appenda, Inc., a Delaware corporation ("Appenda," "we," "us," or "our").
It describes the types of personal information we collect from website visitors and people who use our Services, how we use and share that information, and the choices you have. Please read it carefully.
Capitalized terms not defined in this Policy have the meaning given in our Terms of Service.
1. Who we are
Appenda builds go-to-market software: primarily cloud-hosted workspaces and collaboration for paid plans, a desktop or client app (including on-device storage on free or limited plans), agent tooling, and the public website at appenda.ai (the "Site").
Email (privacy): [email protected]
Email (legal): [email protected]
We take privacy seriously and align our practices with leading U.S. and international frameworks, including the GDPR (where applicable) and California CCPA/CPRA.
2. Definitions
"Services" means the Site, the Appenda application (desktop and web clients), cloud-hosted workspace and team features, APIs, agent adapters, documentation, and related product surfaces we operate.
"Personal Information" means information about an identified or identifiable natural person; an identifiable person is one who can be identified, directly or indirectly, by reference to an identifier such as a name, an identification number, location data, an online identifier, or one or more factors specific to that person’s identity.
"Customer Content" means tables, rows, fields, files, commits, prompts, agent transcripts and outputs, configuration, and other workspace data you or your organization create, import, or submit through the Services. As between you and Appenda, you or your organization retain ownership of Customer Content.
"Service Providers" (sub-processors) are products or services not owned by Appenda that help us run the Services (for example hosting, authentication, analytics, or billing). Their own privacy notices also apply to their handling of information.
3. Scope of this Policy
This Policy explains how we collect, use, share, and protect personal information when you:
- browse appenda.ai or related product domains;
- create an account, sign in, or manage a workspace;
- download or use the desktop or other client application;
- use cloud-hosted workspaces, team, or hosted API features;
- interact with our emails, support channels, or product analytics and telemetry; or
- use agents, enrichments, or integrations that transmit data with your approval.
Where Customer Content is stored.On paid and premium plans, Customer Content is generally stored and processed in Appenda's cloud infrastructure by default under your plan, so you can collaborate and use hosted features. On free or limited plans, more Customer Content may remain on your device in local storage instead of Appenda cloud, as described in-product, unless you upgrade or otherwise move that data to a cloud workspace. Across tiers (including on-device free use), Appenda may collect product usage analytics and telemetry (for example via PostHog or similar tools) about how you use the app and Site. Those signals are distinct from Customer Content: they help us operate, secure, and improve the product and are not used to build a shared prospecting database for other customers.
This Policy applies where Appenda acts as a data controller (we decide why and how personal information is processed), including for our Site, accounts, billing, security, and product analytics. It does not replace situations where Appenda acts only as a data processor under a customer agreement or Data Processing Agreement (DPA), processing Customer Content solely on your instructions. A DPA binds the parties only when executed or expressly accepted; until then, our Terms of Service and this Privacy Policy apply. See Sections 8a through 8c.
Appenda is not a data broker and does not sell business contact databases to third parties. When you connect third-party enrichment providers, those providers supply their own data under their own policies; see Section 8c.
This Policy does not cover third-party websites, agent providers, or enrichment APIs that you connect. Their own privacy statements apply.
Controller details: Appenda, Inc. is the controller for personal information described in this Policy unless otherwise stated. Contact us at the emails above.
4. Acceptance of this Policy
Browsing the Site may be subject to this Privacy Policy by notice posted on the Site. Creating an account, starting a trial, or purchasing paid Services requires your affirmative agreement to our Terms of Serviceand this Privacy Policy (for example, by checking a box or clicking a button labeled "I agree" or similar). If you do not agree, do not create an account, start a trial, or purchase the Services. Questions: [email protected].
5. Updates to this Policy
We may update this Policy from time to time. When we do, we will post the revised version on this page and update the effective date at the top. For material changes, where we have an account email for you, we will provide notice by email and by in-product or Site notice, and we will post the updated Policy on the Site. Continued use of the Services after the effective date means you accept the revised Policy where permitted by law. If you do not accept a material change, you may cancel before the effective date. Cancellation and any fee or refund consequences are governed by the commercial terms in our Terms of Service, not by this Privacy Policy.
5a. Legal basis for processing
Under GDPR and similar privacy laws, we must have a legal basis to process personal information. Depending on the activity, we rely on:
| Processing activity | Legal basis | Explanation |
|---|---|---|
| Account creation, authentication, workspace membership | Contract performance (GDPR Art. 6(1)(b)) | Necessary to provide the Services you request |
| Cloud workspaces, hosted APIs, billing, and paid plan delivery | Contract performance | Necessary to operate cloud-hosted and commercial features |
| Transactional product emails (security, receipts, service notices) | Contract performance / legitimate interests | Service delivery and account security |
| Product analytics, cloud operational identifiers, reliability metrics | Legitimate interests (GDPR Art. 6(1)(f)) | Understand product usage, improve performance, and operate cloud infrastructure safely |
| Security logging, abuse prevention, fraud controls | Legitimate interests | Protect users, systems, and the Services |
| Optional marketing emails | Consent (GDPR Art. 6(1)(a)) where required | You can opt out anytime |
| Non-essential Site cookies / advertising pixels (if used) | Consent where required | Managed via cookie controls and applicable law |
| Tax, accounting, legal compliance | Legal obligation (GDPR Art. 6(1)(c)) | Required by law |
6. Information we collect
We collect information from: (a) you directly; (b) your device, browser, or app automatically; (c) Service Providers that help us operate accounts and cloud features; and (d) optional integrations you connect.
| Category | Examples | How we collect it |
|---|---|---|
| Account identifiers | Name, email, authentication subject IDs, workspace/org membership, role | Sign-up, sign-in, invites, admin settings |
| Fraud prevention and verification | Sign-in and device signals, IP address, approximate location, account age and activity patterns, payment risk signals, bounce or abuse indicators, and similar signals used to verify accounts and block fraud or automated abuse | Authentication, billing, security, and anti-abuse systems when you create an account, sign in, pay, or use cloud features |
| Billing references | Plan tier, customer/subscription IDs, limited payment metadata (never full card numbers when processed by our payment provider) | Checkout and billing providers |
| Cloud product & device identifiers | Workspace/instance IDs, client/app version, platform, region preference, session or device identifiers used for operation and support | Desktop and cloud clients under your plan (cloud workspaces on paid/premium; on-device more often on free/limited) |
| Usage & product analytics | Feature usage events, page views on the Site, performance timings, error diagnostics, approximate geo derived from IP | Analytics and observability tools on the Site and in the app across plans, including free and on-device tiers |
| Customer Content (cloud) | Tables, commits, views, configuration, and related metadata in a paid or premium cloud workspace (the default for those plans) | Stored and processed in Appenda cloud under your plan; free or limited plans keep more on-device unless you upgrade or otherwise move data to cloud |
| Agent transcripts and session data | Prompts, agent replies, tool-call summaries, approval decisions, and related session metadata when you use agents | Agent sessions you run; retained in your paid/default cloud workspace, or more on-device on free/limited plans unless you upgrade or otherwise move that data to cloud |
| Support records | Messages, attachments, diagnostic details you send us | Email or support channels |
| Marketing & engagement data | Email opens/clicks, campaign membership, unsubscribe status | Email and Site analytics providers |
We do not intentionally collect sensitive personal information such as government identifiers, precise health records, or special-category data to operate Appenda. Please do not submit such information unless we expressly ask for it for a support or compliance purpose.
6.1 Third-party login and SSO
You may create or access an account using a third-party login or single sign-on tool (for example Google, Microsoft, Okta, or another identity provider wired through our authentication service). When you do, that provider shares certain profile information with us, which often includes your name, email address, and authentication identifiers, and may include other details you make available through that account.
We use that information only to create and secure your Appenda account and as otherwise described in this Policy. We do not control how the identity provider uses your information. Review their privacy notice and your provider account settings for those practices. You are responsible for protecting your credentials and the email inbox used for account recovery.
6.2 On-device Customer Content (free or limited plans)
Where your plan stores Customer Content on your device rather than in Appenda cloud, that content generally remains under your control on the machine. Appenda does not receive the contents of those local tables unless you upgrade or otherwise move that data to a cloud workspace, export or share, run an approved provider or agent action that transmits data, or send data to us for support. Separately, the app may still send product usage analytics and telemetry (see Section 3 and Section 8) even when Customer Content stays on-device.
7. How we use your information
We process personal information to:
- Provide the Services: accounts, authentication, cloud workspaces, collaboration, client updates, and plan-dependent on-device storage.
- Operate and secure: prevent abuse, verify accounts, detect and block fraud, debug failures, monitor availability, and protect accounts.
- Understand product usage: analyze Site and product analytics and telemetry across plans (including free tiers), such as identifiers and feature events via PostHog or similar tools, to improve reliability, UX, and capacity planning. This is separate from Customer Content stored in a workspace.
- Aggregated insights: generate anonymized or aggregate statistics to operate and improve the Services (not to rebuild Customer Content for other customers).
- Bill and administer plans: process subscriptions and related accounting.
- Communicate: send transactional notices; send marketing only where permitted (with opt-out).
- Comply with law and defend our legal rights.
We do not sell personal information for money. We do not share personal information for cross-context behavioral advertising except where disclosed in our Cookie Policy and permitted (or opted into) under applicable law.
8. Cookies & similar technologies
We use first- and third-party cookies, local storage, and similar technologies on the Site to keep sessions secure, remember preferences, and measure usage. See our Cookie Policy for details. You can control cookies through your browser settings; blocking all cookies may degrade signed-in Site features.
Examples of technologies we may use:
- Essential: authentication, security, load balancing
- Analytics: product and Site analytics (for example PostHog or similar) to understand aggregate usage
- Infrastructure diagnostics: error and performance monitoring for cloud surfaces
8a. Customer Content: how we use it (and how we do not)
When we process Customer Content on your instructions (for example cloud workspaces, team features, or hosted APIs), we act as a data processor(or "service provider" under applicable U.S. privacy laws). You or your organization remain the controller of that Customer Content, subject to your agreement with us and any Data Processing Agreement (DPA).
In that capacity:
- We use Customer Content only to provide the Services to your account or workspace (including security, support you request, and features you enable).
- We do not sell Customer Content.
- We do not use Customer Content to build, enrich, or validate a shared Appenda prospecting or people database for other customers.
- We do not make Customer Content available to other Appenda customers.
- We do not use Customer Content to train foundation models for Appenda or for third-party AI providers, except under a separate written agreement (for example an order form or DPA addendum) that expressly authorizes such training. Ordinary product use, feature toggles, or click-throughs do not authorize training.
- We may use aggregated or de-identified product metrics (for example feature usage or error rates) to operate and improve the Services. Those metrics are not used to reconstruct your tables or contact lists.
A Data Processing Agreement (DPA) and a current list of sub-processors are available on request by emailing [email protected] or [email protected](subject line "DPA Request"). A DPA binds the parties only when executed or expressly accepted. We may publish a dedicated DPA page later; until then, request it by email. Where a signed or expressly accepted DPA applies, it controls over this Policy for Customer Content processed as a processor.
8b. Agents, AI providers, and automated processing
Appenda includes optional agent features that can read workspace context you select, propose changes, call tools, or help with GTM workflows. Agents run only when you (or an authorized workspace user) start them, and durable writes or provider calls generally require your approval where the product is designed to gate those actions.
Depending on the agent or model you choose, prompts, tool results, and related context may be processed by third-party AI providers such as:
- Anthropic (including Claude / Claude Code agent adapters where configured)
- OpenAI (including Codex agent adapters where configured)
- Cursor (Cursor agent / ACP adapters where configured)
When you enable a model or agent provider, that vendor processes data under its own terms and privacy notices. Appenda facilitates the connection and transmission; it is not the principal for those model vendors. You control which agent provider you connect, what you send, and (where available) bring-your-own-key configurations. Appenda acts as a Service Provider or subprocessor only where we contract a provider for our own infrastructure to deliver the Services, not merely because you connect a vendor account.
Automated decision-making and profiling (GDPR Art. 22)
Agents and related automation may classify rows, suggest enrichments, draft messages, or match records using automated means. These tools support your workflows. We do not use automated decision-making that produces legal effects or similarly significant effects on individuals within the meaning of GDPR Article 22 without meaningful human involvement. Product defaults emphasize human approval before durable writes or external side effects.
If you believe an automated suggestion or classification is inaccurate or unfair, contact [email protected] to request an explanation or human review where applicable law provides that right.
8c. Third-party enrichment and marketplace providers
Appenda may let you connect enrichment, verification, sequencing, or other marketplace providers (for example email finders or data APIs). When you run those providers:
- You (or your organization) remain the controller of the personal information you choose to send.
- Appenda transmits the fields you map or approve so the provider can return results to your workspace. Appenda facilitates those connections and transmissions; unless a signed order form says otherwise, Appenda is not the seller, broker, or agent of enrichment providers. In that flow we act as a processor / service provider for your instructions.
- The enrichment provider is an independent party. Their privacy notice and terms govern their use of data they receive. Appenda does not control those provider databases and is not able to delete data from a provider's systems on your behalf.
- Results returned into your workspace become Customer Content subject to Section 8a. We do not harvest those results into a shared Appenda contact database for other customers.
Preview and approval flows are designed so you can see what will leave your workspace before a provider call runs, where the product supports that gate.
Appenda is not a consumer reporting agency. The Services and their outputs are not consumer reports and must not be used for FCRA-regulated eligibility decisions. See the Terms of Service.
9. Who we share information with
We disclose information to Service Providers as needed to run Appenda. We require providers to keep information confidential and use it only for the purposes we disclose. Categories include:
| Type | Examples of recipients | Purpose |
|---|---|---|
| Cloud database | Neon and similar Postgres hosts | Store account, routing, and synced workspace metadata |
| Edge / compute / object storage | Cloudflare (Workers, Queues, R2, and related services) | API edge, sync pipelines, large artifacts |
| Web hosting | Vercel or equivalent | Host appenda.ai and related web surfaces |
| Authentication | Hosted identity providers (for example WorkOS) | Sign-in, SSO, session security |
| Payments | Stripe or similar | Subscriptions and invoicing |
| Analytics | PostHog or similar | Product and Site usage analytics |
| Error / ops monitoring | Sentry, Better Stack, or similar | Errors, uptime, and operational signals |
| Transactional email providers | Receipts, security, and product notices | |
| Code & CI | GitHub or similar | Software delivery (not your workspace tables) |
| AI / agent model providers | Anthropic, OpenAI, Cursor, and similar providers you select or that power an agent adapter you run | Process prompts and context to deliver agent features you initiate (see Section 8b) |
| Enrichment / marketplace providers | Third-party data, verification, or sequencing APIs you enable | Fulfill enrichment or integration jobs you approve (see Section 8c) |
A current list of sub-processors used when we act as a processor, and our Data Processing Agreement (DPA), are available on request at [email protected].
We may also share information:
- to comply with law or valid legal process;
- to enforce our Terms of Service or investigate abuse;
- in connection with a merger, acquisition, or asset sale, subject to appropriate confidentiality; or
- with your direction or consent (for example an agent provider or enrichment integration you enable).
Categories disclosed for a business purpose (last 12 months)
| Category | Recipient types | Purpose |
|---|---|---|
| Identifiers | Auth, hosting, email, analytics, payments | Operate accounts and Services |
| Commercial / billing data | Payment processors | Subscriptions and fraud prevention |
| Internet / device activity | Analytics, security, hosting | Usage insights, security, performance |
| Customer Content (if synced) | Cloud database / edge / storage providers | Provide cloud workspaces and team features |
| Support records | Support and email tools | Customer support |
10. International transfers
Appenda is based in the United States. If you access the Services from the EEA, United Kingdom, Switzerland, or other regions, personal information may be processed in the United States and other countries where our Service Providers operate.
Where required, we use appropriate safeguards such as Standard Contractual Clauses (SCCs), the UK IDTA, transfer impact assessments, vendor review, data minimization, and contractual confidentiality commitments. Safeguards may vary by vendor and transfer type.
Request documentation of safeguards by emailing [email protected].
11. Retention
We keep personal information only as long as needed for the purposes in Section 7, to resolve disputes, or as required by law. When no longer needed, we delete or de-identify it. If immediate deletion is not possible (for example backups), we isolate the data from further processing until purge is complete.
Typical retention periods by category:
| Category | Retention period |
|---|---|
| Account data (name, email, membership, roles) | Life of the account, then up to three (3) years after account closure, unless you request earlier deletion and we can honor it |
| Payment and billing records | Seven (7) years after the relevant transaction (tax and accounting) |
| Marketing preferences and consent records | Three (3) years after last marketing interaction, or until you withdraw consent, whichever is earlier |
| Product analytics and usage events | Twenty-four (24) months, then deleted or kept only in aggregated form |
| Security, fraud, and abuse logs | Twenty-four (24) months |
| Agent transcripts and session metadata (cloud) | Twelve (12) months after the session, or until the workspace is deleted if sooner (subject to legal holds) |
| Synced Customer Content (cloud tables, commits, views) | While the workspace is active. After account or workspace deletion or a valid erasure request, you may have up to thirty (30) days to export cloud Customer Content if it remains technically available (see Terms of Service §14.4). After that export window, we may delete it from active systems (backups remain isolated until purged) |
| Support correspondence | Three (3) years after the ticket is resolved |
| On-device Customer Content (free/limited plans) | Under your control on device until you delete it; Appenda does not retain a copy unless you synced to cloud or otherwise sent it to us. Product telemetry may still be collected separately (see Section 3) |
We may retain limited records longer when required for fraud prevention, dispute resolution, or legal compliance. Customer agreements or a signed DPA may set different periods for Customer Content we process as a processor.
12. Your choices & rights
- Marketing email: unsubscribe in any message or email [email protected].
- Cookies: use browser controls; see the Cookie Policy.
- Access / correction / deletion: request a copy or deletion of personal information by emailing [email protected].
- California and other U.S. state residents: see the state privacy rights notices below.
- EEA/UK/Swiss individuals: GDPR rights of access, rectification, erasure, restriction, objection, and portability, exercisable via the same email.
We will respond within 30 days (or the period required by applicable law, which may allow up to 45 days for certain U.S. state requests with notice of an extension). We may ask for identity verification. We do not charge a fee unless a request is manifestly unfounded, repetitive, or excessive. Privacy rights under this Policy do not create a right to fee refunds; refunds are governed by the Terms of Service.
Account changes and deletion
You may review or update certain account details in product settings when that capability is available. To terminate your account or request deletion of personal information associated with it, email [email protected]with subject line "Account Deletion," or use in-product account deletion controls when offered.
After a verified deletion request, we deactivate or delete the account and remove personal information from active systems according to Section 11. We may retain limited information as needed to prevent fraud, troubleshoot abuse, enforce our Terms of Service, or comply with law.
Do Not Track.Most browsers include a Do Not Track ("DNT") setting. At this stage no uniform technology standard for recognizing and implementing DNT signals has been finalized. As such, we do not currently respond to DNT browser signals or any other mechanism that automatically communicates a choice not to be tracked online. If a standard is adopted that we must follow, we will update this Policy. For cookies and Site measurement, see our Cookie Policy.
California privacy rights (CCPA/CPRA)
California residents may request to know the categories and specific pieces of personal information we collected, the categories of sources, the business or commercial purposes for collection, and the categories of third parties with whom we disclose personal information. You may request deletion or correction, subject to legal exceptions. You may also opt out of “sale” or “sharing” as those terms are defined under California law, to the extent we engage in such activities.
We do not sell personal information for money. If we disclose identifiers or device data to advertising or analytics partners in a way California treats as “sharing,” you may opt out by emailing [email protected]with the subject line "California Opt-Out" and adjusting cookie preferences where available.
We will not discriminate against you for exercising CCPA/CPRA rights. You may designate an authorized agent to submit a request; we may require proof that the agent is authorized to act for you.
Other U.S. state privacy rights
Residents of certain other U.S. states (including, where applicable, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, and similar comprehensive state privacy laws) may have rights to access, correct, delete, or obtain a portable copy of personal information, and to opt out of targeted advertising, sale of personal information, or certain profiling, as defined by those laws.
To exercise those rights, email [email protected]with subject line "State Privacy Request" and tell us which state you live in. We will verify your request and respond as required by applicable law. If we deny a request, you may appeal by replying to our decision email; we will explain the outcome of the appeal.
EEA/UK/Swiss supplemental notice
You may lodge a complaint with your local data protection authority. Where we rely on consent, you may withdraw it at any time without affecting prior processing. Where we rely on legitimate interests, you may object; we will honor objections as required by law.
13. Security
We implement technical and organizational measures appropriate to the risk, including encryption in transit for cloud surfaces, encrypted local storage for desktop Customer Content, access controls, monitoring, and vendor diligence. See our Security page for a product-oriented overview.
No method of transmission or storage is 100% secure. You acknowledge this inherent risk when using internet-connected Services.
Integration credentials you save (vault or similar features) may be encrypted in transit and at rest in local and/or cloud vault storage, solely to operate integrations you enable. Residual risk remains. See Terms of Service §12.4.
Data breach notification
If we become aware of a personal data breach affecting your information, we will notify regulators and affected individuals where required by applicable law, and provide information about the nature of the incident and mitigation steps as required.
14. Responsible disclosure
If you discover or suspect a security vulnerability in the Services, notify us at [email protected]. If you encounter sensitive data during testing, stop and do not share that data. We will investigate in a reasonable timeframe.
15. Children’s privacy
The Services are intended for users eighteen (18) years of age or older and for business use. They are not directed to children. We do not knowingly collect personal information from anyone under sixteen (16). If we learn that we have collected personal information from a child under 16, we will delete it. If you believe we have collected such information, contact [email protected].
16. Governing law; severability
Except where privacy or consumer-protection laws of your jurisdiction require otherwise, this Policy is governed by the laws of the State of Delaware, USA, without regard to conflict-of-law rules. Disputes related to this Policy are subject to the dispute-resolution and venue provisions in our Terms of Service.
If any provision of this Policy is held invalid or unenforceable, the remaining provisions will continue in full force and effect, and the invalid provision will be modified to the minimum extent necessary to make it valid and enforceable.
17. Contact
For privacy rights requests or data-protection inquiries, email [email protected]with subject line "Privacy Request" or "Data Protection Inquiry."
General legal questions: [email protected].