Privacy
How Recoupex handles your data
A plain-language summary of what Recoupex collects, how the AI uses it, who processes it on our behalf, and the rights you keep in front of it.
Effective date: 2026-08-16
1 — Information we collect
What Recoupex stores on your behalf
Recoupex is a revenue-recovery workspace. The data we hold is the data you load or generate inside the product — we do not collect end-user data from your customers’ own customers beyond what you put in.
- Leads — name, contact details (email, phone), source, status, and any notes or tags you attach.
- Contacts — the people surfaced from your CRM imports, with their contact history and prior conversation state.
- Segments — the filters and rules you define to group leads for outreach (e.g. “dormant 60+ days, US”).
- Message drafts — outbound copy generated or edited by the AI, plus the human edits you apply on top.
- Account & billing — sign-in email, profile, subscription tier, and receipt metadata from our payment processor.
Everything else — your CRM, billing system, calendar — stays in your stack. Recoupexconnects to them through read-only or operator-approved integrations; we copy the minimum needed to run the workflow.
2 — How the AI uses it
Drafting outreach, training nothing
The model drafts outreach from inputs you supply — the lead row, the segment spec, and any earlier draft history you ask it to learn from. Prompts are routed through the Polsia AI proxy; Recoupex does not call model providers directly and never holds a provider key.
Drafts are scoped per tenant. One customer’s inputs are not visible to another’s drafts or model calls, and we do not use your drafts or leads to train any shared model.
Drafts are drafts: nothing is sent until you approve or schedule it. You can edit any line before it goes out, and the original draft is preserved for audit.
3 — Third-party processors
Who handles your data when we don’t
Payments — Stripe Checkout
One-time and subscription payments are processed by Stripe via hosted Checkout. Card details are entered on Stripe’s surface and never reach Recoupex — we only see the outcome (paid / failed) and the receipt metadata Stripe issues. Stripe handles that data under its own terms and privacy policy.
Email — Polsia email proxy
Transactional and outreach email is sent through the Polsia email proxy. Reply threads are threaded by replyToEmailId, so each reply lands back on the right lead record. Bounces and undeliverables are recorded on the lead so the workspace stays accurate.
AI / LLM — Polsia AI proxy
Model calls are routed through Polsia’s AI proxy. Recoupex holds no direct provider API key — only the proxy knows about model endpoints. Prompts include only the context the operator assembled: the lead row, the segment definition, and the prior drafts you want the model to draw on.
Hosting — managed Postgres
Application data is stored in a managed PostgreSQL database. Connections are transport-encrypted (TLS) and credentials are injected by the platform; we do not store vendor secrets inside this repo.
Subprocessors
The full processor list, with regions and DPA basis
The named list of third parties we share data with — what they process, which data category, where the processing happens, and the legal basis — lives at /legal/subprocessors. We update that page before any new subprocessor starts receiving data, and we announce material changes in-product.
4 — Cookies & sessions
What cookies do (and don’t)
Auth. Sign-in issues a session through our auth provider. The session cookie scopes every /api read and write to the signed-in user, and is HttpOnly. No third-party tracking cookies are set.
Locale. If the locale module ships, a cookie stores your language preference. It is purely functional — used only to render the UI — and is not used for analytics.
No advertising or analytics cookies. Recoupex does not run third-party ad pixels, retargeting tags, or analytics scripts on the marketing or app surface.
5 — Your data, your rights
Access, export, deletion
Access. Every record in the product — segments, leads, message drafts, message history — is visible to you from the workspace and is yours to inspect.
Export. Leads, segments, and quotes can be exported as CSV or XLSX from the corresponding page. If you need the rest of the data (auth logs, billing history) on demand, write to the address below.
Deletion. Account deletion cascades — segments, leads, message drafts, and message history scoped to that user are removed within the time stated in the deletion confirmation flow. For a hard-delete outside the in-product flow, email the address at the bottom of this page and we will action it manually and confirm in writing.
6 — Security
How we protect it
- Transport. All traffic is served over HTTPS; the database is reached over TLS.
- Per-tenant scoping. Every query is filtered with
where: { userId: user.id }; one tenant cannot read another tenant’s rows. - Secret hygiene. API keys and database URLs are injected by the platform. They are not committed to the repo and they are not sourced from the front end.
- Session hygiene. The session cookie is HttpOnly and scoped to the product domain; there is no shared admin password and no custom admin cookie.
7 — Changes to this policy
How updates ship
We update the effective date at the top of this page whenever the policy changes. Material changes are also announced in-product and on the Recoupex blog, and you will get a reasonable heads-up before they take effect.
Non-material changes (typos, clarifications, formatting) update silently with the effective date bumped at the top.
8 — Contact
Questions, requests, complaints
For anything privacy-related — a data request, a deletion ask, a question about a processor, or a complaint — write to recoupex-ni4aa2@polsia.app. We reply from the same address and aim to acknowledge within two business days.
This policy is offered in English. If translations are added later, the English version here stays the source of truth.