Privacy Policy
Last updated: August 15, 2026
1. Overview
This Privacy Policy explains how Tantra hosted on usetantra.com ("Tantra", "we", "us") collects, uses, and protects information when you use our websites, applications, and related services (the "Services").
Tantra is an outreach platform. You connect your own sending accounts, you upload your own contact data, and you decide who receives a message. For the data you upload and the people you contact, you are the controller of that personal data and we process it on your behalf and on your instructions. For your own account and billing data, we are the controller.
2. Information We Collect
Account information: name, work email, company, role, and the identifiers used to sign you in.
Billing information: plan, add-ons, subscription status, and invoice records. Card details are handled by our payment processor and are not stored by us.
Service usage: product interactions, device information, IP address, time stamps, diagnostics, and crash data.
Content you create: campaigns and sequences, message and invitation copy, templates, event details, schedules, and settings.
Contact data you provide: the records you import or create for the people you want to reach, such as name, email address, phone number, company, role, website, social identifiers, tags, and any custom fields you add.
Communication records: requests you send to support, feedback, and survey responses.
Cookies and similar technologies: to maintain sessions, remember preferences, and measure product performance.
3. Data From the Accounts and Platforms You Connect
The Services only reach a connected platform with access you grant, and you can withdraw that access at any time.
Email and calendar: When you connect Google Workspace, you do so with your organization's own service account and the domain-wide delegation you authorize in your admin console. We never receive your Google password. That authorization lets us send email from the mailboxes you nominate, create and update calendar events and invitations, and read the mailbox activity needed to run your campaigns. We process the messages needed to match activity to your campaigns, and we do not retain unrelated mail.
Message content: We process the messages sent from your connected mailboxes and the responses they receive, including reply text, delivery and bounce notices, and message metadata such as sender, recipient, subject, and thread identifiers. This is what lets the product detect replies and bounces, stop a sequence when someone answers, honor unsubscribe requests, and show your conversations in the shared inbox.
Calendar and RSVP data: The events you create through the Services, their attendee lists, and the RSVP responses returned by the calendar provider.
Messaging and social accounts: If you connect a LinkedIn, WhatsApp, or Telegram account, we process the identifiers and profile details of that connected account, the messages, connection requests, and profile actions sent through it, the replies received, and the social identity of the recipient used to deliver a message, such as a profile identifier, username, or phone number.
Webinar platforms: If you connect a webinar platform such as Zoom or WebinarGeek, we process the webinar and session details, registrant records, and attendance information needed for reporting and for attributing attendance to a campaign. Registering a contact with a provider on their behalf happens only where you turn that option on, and the provider may then email that person directly.
Credentials for connected platforms: Service account keys, provider client secrets, and similar credentials you upload are encrypted before they are stored and are used only to operate the connection you created.
4. Webhooks, API, and Assistant Access
Outbound webhooks: If you configure a webhook, we send the events you select, and the associated recipient and campaign data, to the destination URL you provide. You choose that destination and you are responsible for how the receiving system handles the data.
API keys and assistant tools: Account-level API keys, and the tools that use them, including our MCP server for AI assistants, allow you or a tool you authorize to read and write the same data you can access in the product. Anyone holding a valid key can act as your account, so treat keys as credentials, share them carefully, and revoke a key you no longer use.
Tracking links and opt-outs: Where you enable link tracking or an unsubscribe link, we record that a recipient clicked or opted out so that reporting and suppression work. We do not use tracking pixels to record message opens.
5. AI Features and Personalization
Some optional features use AI models to draft or personalize message content and to classify the intent of a reply. You can supply your own provider API key, in which case the request is sent to the provider you selected under your own account. If you have not configured a provider, we send the request to our default provider on your behalf. The content sent can include the message or reply text and the campaign context needed to produce the result.
Where you turn on website personalization, the public web page of a recipient or their company domain is fetched through a third-party page-to-markdown conversion service, and the text it returns is used as context for the generated message. That means public page content leaves our systems to reach that service. Website personalization is off unless you enable it on a step or campaign.
We record the model used, token counts, and the request and response content of AI calls so that you can audit usage and cost. API keys you store for a provider are encrypted. AI providers process the content we send under their own terms, so review those terms before enabling these features. We do not use your Customer Content to train models.
6. How We Use Information
- Provide and operate the Services, including creating campaigns, sending messages and invitations, tracking replies, bounces, RSVPs, and opt-outs, and displaying results.
- Maintain the connections you authorize and keep sending within the limits of each connected platform.
- Produce the reporting, analytics, and attribution shown in your account.
- Improve reliability, performance, and user experience through analytics and diagnostics.
- Communicate with you about account notices, product updates, billing, and support.
- Detect, investigate, and prevent security incidents, abuse, and misuse of the Services.
- Meet legal obligations and enforce our terms.
7. What We Do Not Do
- We do not sell personal information.
- We do not use your content to build public datasets or to train AI models.
- We do not share your contact data with other customers or add it to a shared lead database.
- We access the content of a connected mailbox or messaging account only to operate the features you enable, such as sending, reply and bounce detection, and your inbox. Staff access is limited to what is needed for support you request, security, or a legal obligation.
8. Sharing of Information
We share information only with:
- The platforms you connect: your email, calendar, messaging, social, and webinar providers receive what is needed to carry out the actions you request.
- Service providers: cloud hosting and infrastructure, authentication, payment processing, transactional email, connectivity to messaging platforms, AI processing, page conversion for personalization, analytics, logging, and customer support tools. These providers act as our subprocessors, may only process data on our instructions, and are bound by confidentiality and data protection obligations.
- Destinations you choose: webhook endpoints and API or assistant clients you configure.
- Business transfers: if we merge, acquire, or sell assets, information may transfer under continued protections.
- Legal: when required by law or to protect rights, safety, or security.
We review subprocessors before they are engaged. If you need the current list for a vendor assessment, ask us using the contact details below.
9. Data Retention and Deletion
We retain information for as long as your account is active and for as long as needed for the purposes described in this Policy, including reporting, security, resolving disputes, and meeting legal and accounting obligations.
You can delete contacts, campaigns, messages, and templates in the product, and you can disconnect any connected account at any time. Disconnecting revokes our ability to act on that account going forward. You can also revoke access directly with the provider, for example in your Google Workspace admin console.
When your account is closed, we delete or anonymize the personal data we hold for you within a reasonable period, except where we must keep records to comply with law, resolve a dispute, or enforce our agreements. Suppression and unsubscribe records are kept so that an opt-out continues to be honored.
You may request export or deletion as described in Section 12.
10. Security
We employ administrative, technical, and physical safeguards designed to protect your information, including encryption in transit, encryption of stored credentials such as uploaded service account keys and provider API keys, access controls, and event logging. No method of transmission or storage is fully secure; we continuously improve our protections. Keeping your own credentials, API keys, and connected accounts secure is your responsibility.
11. Your Choices
- Access and update: You may view and update account information in Settings.
- Connected accounts: You may disconnect any connected mailbox, calendar, messaging, or webinar account at any time.
- AI features: Personalization and website enrichment are optional and can be turned off per campaign or step.
- Communications: You may manage communication preferences from emails or in Settings.
- Cookies: You can control cookies via your browser; some features may rely on them.
12. Your Rights and Requests
Depending on your location, you may have rights to request access, correction, deletion, restriction, or portability of certain information, and to object to some processing. To submit a request, contact us at [email protected]. We may need to verify your identity before fulfilling a request. If you were contacted through the Services and want your data removed, the customer who uploaded it is the controller of that data, so we will refer your request to that organization and help them act on it.
13. If You Received a Message
If you received an email, invitation, or message sent through Tantra, the sender is our customer and chose to contact you. You can use the unsubscribe or opt-out option in the message, or reply to the sender directly. You may also write to us at [email protected] and we will pass the request to the sender and record the opt-out so that sender's future messages respect it.
14. Children
The Services are not directed to individuals under 16, and we do not knowingly collect information from them.
15. International Transfers
We and our service providers may process information in countries other than your own. Where information is transferred across borders, we apply appropriate safeguards and contractual protections.
16. Third-Party Links
Our Services may contain links to external sites. Their practices are governed by their own policies.
17. Changes to This Policy
We may update this Policy from time to time. Material changes will be notified via email or in-product notices, and we will revise the "Last updated" date. Your continued use of the Services after changes take effect constitutes acceptance.
18. Contact Us
Email: [email protected]