ocuro Privacy Policy
Effective date: September 9, 2026
ocuro ("we", "us") is an email outreach assistant offered as a Chrome extension with a managed backend service. This policy explains what information ocuro handles when you use it, and how.
What ocuro accesses, and why
When you sign in with Google and connect a spreadsheet, you authorize ocuro to:
- Read your basic Google profile (name, email address): to identify your account inside ocuro.
- Read and update the lead spreadsheet you connect: your spreadsheet is the source of truth for your leads; ocuro reads lead details from it and writes outreach status and sent-email records back to it. ocuro only touches the spreadsheet you explicitly connect.
- Create drafts in your Gmail and read your outreach threads: ocuro writes personalized email drafts into your Gmail Drafts folder and checks the conversations it created to detect when you sent an email, when a prospect replied, or when a message bounced. ocuro never sends email on your behalf. You review and send every message yourself from Gmail.
What we store
- Your account identifiers (name, email) and Google OAuth tokens (never your password; Google issues scoped tokens that you can revoke at any time at myaccount.google.com/permissions).
- Lead information from your connected spreadsheet and the outreach emails generated for those leads, so sequences and follow-ups work.
- Your voice profile: a short description of your writing style (for example, preferred sentence length and formality), learned from the edits you make to drafts before sending. It never contains your emails themselves, and you can delete it at any time with “Reset voice profile” in the side panel's account menu.
- Documents you choose to upload about your own business (for example a one-pager or a case study): ocuro extracts a short fact sheet from each file once and stores only that fact sheet and the filename, never the file itself. Fact sheets are used solely to ground the emails written for you, and you can remove any of them at any time from the side panel's Documents card.
- Operational records (campaign settings, send/reply status, service logs). Internal event logs are automatically deleted after 90 days.
How your information is used
Solely to operate ocuro for you: generating personalized outreach emails, placing drafts in your Gmail, tracking your campaigns, and showing your dashboard. Lead details are shared with our AI provider (Anthropic) only as needed to write each email, under contractual terms that prohibit training on or retaining your data beyond service delivery.
We do not sell your data. We do not use it for advertising. We do not transfer it to third parties except the service providers that run ocuro (Google APIs, Anthropic for text generation, Supabase for secure hosting, Resend for service alert and referral invitation emails), each processing it only on our instructions.
Voice learning
ocuro adapts to how you write. When you edit a draft in Gmail before sending it, ocuro compares the draft it wrote with the email you actually sent and updates your voice profile: a short, plain-language description of your writing tendencies (things like sentence length, formality, and how direct your asks are). Future drafts are written with that profile so they sound more like you.
- The comparison uses only emails ocuro itself drafted in your outreach campaigns; ocuro does not read any other mail in your account.
- The profile describes how you write. It never stores the text of your emails, and analysis happens only for a limited number of edited emails (the first 20, then up to 10 per month).
- The two email versions are shared with our AI provider (Anthropic) only to perform this comparison, under the same no-training, no-retention terms as email generation.
- “Reset voice profile” in the side panel's account menu deletes your current profile immediately.
Refer a friend
If you use the "Refer a friend" feature, you give us the email address of someone you know so we can send them a single invitation on your behalf. We use that address only to deliver that invitation and to grant the promised usage credits ($5 to each of you) if they join and their first email is generated within 5 days of joining. It is never added to a marketing list, never sold, and never used for anything else. If the person does not join, the invitation simply expires.
OMNI-PRESENCE (optional add-on)
If you turn on OMNI-PRESENCE, ocuro also looks for publicly available posts and articles published by the prospects in your campaign, and by any public profiles you choose to add to your watch list, so it can email you a short list of things worth engaging with.
- What is collected: links to public posts, their titles, publication dates, short summaries, and the public handle or profile the post appeared on. Only publicly visible content is used. ocuro does not log in to any social network, does not access private profiles or private messages, and never posts, comments, likes, or messages anyone on your behalf. Every suggestion is something you carry out yourself.
- Watch list: the profile links or handles you add are stored so we can check them for new public posts on your alert days. You can remove any of them at any time in the side panel, which deletes the entry.
- Who it is shared with: the same providers listed above (Anthropic to find and summarize the posts, Supabase to store the queue, Resend to deliver your alert email). It is never sold or used for advertising.
- Retention: suggestions expire within a week and are deleted after 30 days. Turning the add-on off stops all collection.
Google API Services: Limited Use disclosure
ocuro's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used only to provide the user-facing features described above, is never sold, is never used for advertising, and is never read by humans except with your explicit consent, for security purposes, or as required by law.
Security
Data is encrypted in transit (TLS) and at rest. Access to production systems is restricted to the operator. Backend secrets are stored in managed vaults, never in the extension you install.
Retention and deletion
Your data is retained while your account is active. Disconnecting a campaign stops all processing for it. To delete your account data entirely, email us and we will remove your stored leads, generated emails, and tokens. Leads removed from your spreadsheet stop being processed immediately and are automatically purged from our systems after 12 months (kept that long so a lead you re-add resumes its sequence instead of being emailed from scratch).
Contact
Questions or deletion requests: support@useocuro.com
We may update this policy as ocuro evolves; material changes will be reflected on this page with a new effective date.