Privacy Policy
We process personal data in accordance with the Swiss Federal Act on Data Protection (FADP) and, where applicable, the EU General Data Protection Regulation (GDPR). This policy explains what data we process, why, on what legal basis, and how we keep it secure. We collect only what a feature actually needs.
1. What ThePilot does
ThePilot is a B2B software platform for AI-assisted lead generation, e-mail outreach and a lightweight CRM. You connect your own mailbox and calendar; ThePilot helps you research business contacts, draft messages with AI, send them through your own account, and track replies. We are a tool provider — you remain in control of whom you contact and what you send.
2. Data we process
- Account data: name, e-mail address, hashed password, language preference, role.
- Workspace content: leads, company profiles, campaigns, notes, tasks, message drafts.
- Connected mailboxes (IMAP/SMTP or Google/Microsoft login): when you connect a mailbox, we synchronise messages of that mailbox into the platform (sender, subject, body, attachments metadata) so you can read and reply in-app. Access credentials and OAuth tokens are stored encrypted (AES-256-GCM).
- Calendar: for a connected Google/Outlook calendar, event data (title, time) for the in-app calendar.
- WhatsApp notifications: the mobile number you provide and control messages, if you opt in.
- Billing data: plan, credit usage and, for paid plans, data needed by our payment provider.
- Technical data: log data for error analysis, security and abuse prevention.
3. Purposes & legal bases
- Providing the service (outreach, inbox, CRM, calendar, notifications) — where the GDPR applies, Art. 6(1)(b) covers processing necessary for a contract with the data subject. It does not by itself cover personal data of leads, employees or other correspondents.
- AI text generation, sorting and suggestions — the applicable basis depends on the data, purpose and our role. Activating an AI feature does not itself establish a lawful basis for processing other people's data.
- Security, abuse prevention, deliverability protection — legitimate interest (Art. 6(1)(f) GDPR).
- Billing and support — contract and legal obligations.
- Optional connections (Google/Microsoft/WhatsApp) — you authorise technical access and can disconnect in settings. This authorisation is not consent from other correspondents to data processing or advertising.
Processing on behalf of a customer requires documented instructions and, where required by law, a data processing agreement before processing starts; the controller must establish the applicable lawful basis. For processing for which we are the controller, our own data protection obligations remain. We assess our processing under the FADP; an overriding interest under Art. 31 FADP is not a blanket permission for advertising. Where the GDPR applies, reliance on legitimate interests under Art. 6(1)(f) GDPR requires necessity and a balancing of interests.
4. AI processing
For AI features (drafts, classification, suggestions, the assistant in chat and WhatsApp) we transmit the necessary content to Anthropic (Claude). Voice messages and dictations are transmitted to OpenAI for conversion into text; if Anthropic is unavailable, an OpenAI model may serve as fallback. Under their API terms, neither provider uses content transmitted through the interface to train its models. We send only what the respective feature requires.
5. Google user data (Limited Use)
Our use of information received from Google APIs (Gmail, Google Calendar) adheres to the Google API Services User Data Policy, including its Limited Use requirements. Specifically, Google user data is used only to provide the user-facing features you activate (inbox, sending, calendar). It is not sold, not used for advertising, not transferred to third parties except to provide or improve those features (or as required by law), and not used to train generalised AI models. Humans do not read your Google data except with your explicit permission, for security/abuse handling, or where required by law.
6. Recipients & sub-processors
| Processor | Purpose | Location |
|---|---|---|
| Railway (USA) | Hosting, database, cache and file storage | Data centre EU West (Netherlands) |
| Anthropic | AI processing: drafts, classification, suggestions, assistant | USA |
| OpenAI | Transcription of voice messages and dictations; fallback AI model | USA |
| Meta Platforms (WhatsApp) | WhatsApp assistant and notifications (messages, voice messages, phone number) | EU/USA |
| Sign-in with Google; mailbox and calendar if you connect them; company search (Google Places) | EU/USA | |
| Microsoft | Calendar, if you connect it | EU/USA |
| Stripe | Payments, invoices and customer portal for paid plans | EU/USA |
| Hostpoint | Delivery of our own system e-mails | Switzerland |
| Umami (self-hosted on Railway) | Visitor statistics of our public pages | Data centre EU West (Netherlands) |
7. International transfers
Several of the providers listed in section 6 are based in the USA (Railway, Anthropic, OpenAI, Meta, Google, Microsoft, Stripe), even where the data centre is in the EU. Where a provider is certified under the Swiss-U.S. Data Privacy Framework, we rely on that certification; otherwise on the EU Standard Contractual Clauses in the provider's data processing agreement together with its supplementary measures. Customer mailboxes remain with the mail provider you choose.
8. Security
We use technical and organisational measures appropriate to the risk: encryption in transit (TLS), encryption of mailbox credentials and OAuth tokens at rest (AES-256-GCM), access controls and logging. No system is perfectly secure, but we work to protect your data accordingly.
9. Retention
Account and workspace data are kept until 90 days after the end of the contract; statutory retention obligations remain reserved. You can disconnect a mailbox at any time in settings; synchronised copies can be deleted there.
10. Your rights
Subject to the applicable statutory conditions, you have rights of access, rectification, erasure, data portability and objection and, under the GDPR, restriction of processing. Where processing is based on consent, you may withdraw it at any time with effect for the future. You may object to processing for direct marketing at any time. We answer access requests under Art. 25 FADP within 30 days, as a rule free of charge. To exercise your rights, contact datenschutz@thepilot.ch. You may contact the FDPIC (EDÖB) in Switzerland or lodge a complaint with the competent data protection authority where the GDPR applies.
11. Recipients of outreach e-mails
ThePilot supports researching business contacts and preparing outreach. A publicly listed business address does not itself authorise advertising messages. Customers must establish and document permission for the recipient, channel and target market before sending. For recipients of outreach e-mails:
- Every outreach e-mail sent through ThePilot receives sender identification and a one-click unsubscribe link; the customer may not remove either (see Terms).
- Opt-outs are enforced platform-wide for further advertising e-mails through ThePilot, as far as the address is recognisable; for this we store the data needed to honour the opt-out (address or domain, time, reason), for as long as necessary.
- A lawful basis for processing contact data, including legitimate interests where applicable, does not replace any required permission to send advertising. In Switzerland, electronic mass advertising without the prior consent of the recipients is unfair (Art. 3(1)(o) Swiss UCA/UWG). Without consent it is permitted only towards customers whose contact details the sender obtained when selling goods, works or services, provided they were informed of the possibility to refuse at that time, and only for the sender's own similar offers. Every message needs correct sender details and a simple, free way to refuse. Recipients abroad are additionally protected by the rules of their country, which are often stricter (in the EU, consent is generally required even for business recipients).
- Business relevance, personalisation, a campaign approval or an unsubscribe link do not, on their own, establish permission. An existing customer relationship is not enough unless all conditions of the applicable exception are met. Our own statutory obligations remain unaffected by the customer's responsibilities.
- If you received an e-mail through ThePilot and wish to be removed, use the unsubscribe link in that e-mail or write to datenschutz@thepilot.ch.
12. Cookies
We use only the cookies technically necessary to run the application (e.g. login session, language). We do not use advertising or cross-site tracking cookies. Fonts are served from our own servers. For our public pages (start page and sign-up page) we measure visits with a self-hosted instance of Umami: page path, campaign parameters (utm_source, utm_medium, utm_campaign, utm_content), the referring website's origin and the browser language. No cookies and no identifier are stored in your browser; on the server, IP address and browser type are processed transiently into a session hash for the day and are not stored. Logged-in users are not measured. If your browser sends «Do Not Track», we do not measure. Data stays on our Umami instance in the EU West data centre.
13. Changes
We may update this policy as the product evolves. The current version is always available here; material changes will be communicated appropriately.
14. Applicable law
We process personal data under Swiss data protection law (FADP) and, where applicable, the GDPR. Our registered seat is Zug, Switzerland. Mandatory data protection rights and statutory complaint and judicial remedies remain unaffected.