LingxuAILingxuAI

Privacy Policy

How LingxuAI collects, uses, stores and shares personal data — including exactly what we do, and do not do, with your Google account.

Effective Aug 4, 2026

1. About this policy

LingxuAI is a business-to-business lead generation platform operated by [COMPANY LEGAL NAME] ("we", "us"). It helps businesses find companies that match their ideal customer profile, enrich those records with publicly available business contact details, and send outreach email from their own email account.

This policy explains what personal data we handle, why we handle it, how long we keep it, who we share it with, and the rights you have. It covers the LingxuAI web application at app.lingxu168.com, our API, and the background services that support them.

It is written for two different audiences: people who hold a LingxuAI account, and people whose business contact details appear in a customer's workspace without ever having signed up. Both are covered. If you are in the second group, section 12 is written for you.

2. Our role: controller and processor

Our responsibilities differ depending on which data is involved.

Account data — we are the controller
The information you give us to create and run your account, and the technical records we keep to secure it. We decide how that data is used, within this policy.
Workspace data — we are the processor
The leads, companies, contacts, campaigns and messages inside your workspace. You decide what to search for, which records to keep, and who to contact. We process that data on your instructions, to provide the service. You are the controller and are responsible for having a lawful basis for the outreach you send.
Our crawler — our own responsibility
How our crawler behaves on the public web — how it identifies itself, how fast it fetches, what it refuses to do — is our decision, not a customer instruction, and we answer for it independently. Its published behaviour is documented at /crawler.

3. Information we collect about you

When you register and use the service we collect:

Identity and sign-in
Your full name, email address, and a password. Passwords are stored only as an Argon2id hash with a server-side pepper — we never store, log or transmit your password in a form we can read, and we cannot recover it for you.
Preferences
Interface language and time zone.
Organisation and role
Your company name (for reseller accounts), your role, which organisation you belong to, and the workspace you own.
Sender profile
The sender name, job title, company details and signature you configure for outreach. This is inserted into the emails you send.
Payment approval records
Because billing is handled offline, we record the amount, currency and the transaction reference you submit for approval, together with the approval decision. We do not collect or process card numbers, and no card data passes through LingxuAI.
Security and audit records
IP address, browser user agent, timestamps, and a description of significant actions taken in your account (for example: a login, an export, an administrator viewing a workspace). Failed login attempts are counted so that accounts can be locked after repeated failures.
Support content
Anything you write to us in a support ticket or by email.

We do not buy personal data about you from data brokers, and we do not build advertising profiles.

4. Data inside your workspace, including third-party contact data

The core function of LingxuAI is finding business contact information. When you run a discovery request, we collect information about businesses and the people who represent them from publicly available sources, and store it in your workspace.

That typically includes: company name, website, industry, size, location and technology signals; and, where publicly published, business email addresses, business phone numbers, job titles, and links to public company or professional social profiles.

Some of this is personal data, because a named individual at a company is an identifiable person. We treat it as personal data, and this policy applies to it.

Where it comes from
Publicly accessible web pages, public business directories, search engine results, and — only if you connect them yourself — your own third-party accounts or paid data providers you choose to enable.
How we collect it
Our crawler identifies itself honestly by name, obeys robots.txt, fetches slowly with per-site rate limits, does not attempt to bypass access controls or bot challenges, and does not log in to anything. See /crawler for the full statement and how to block it.
Legal basis (GDPR)
Legitimate interests under Article 6(1)(f) — providing business-to-business contact information for business communication. We collect business, not private, contact details, we limit collection to what serves that purpose, and we honour objections. Where you as our customer then send outreach, you must have your own lawful basis for doing so.
What we do not collect
We do not seek out special categories of data (health, race, religion, political opinion, sexual orientation, biometric data), government identifiers, or financial account details, and we do not target private individuals.
Messages you send
When you send outreach, we store the recipient, subject, body, timestamps and delivery status in your workspace. This is our record of what you sent through the product. It is not a copy of your mailbox — see section 5.

5. Google account data and Gmail access

Connecting a Google account is optional. Everything else in LingxuAI works without it. You connect it only if you want outreach to be sent from your own Gmail address, so that replies come back to you directly.

When you connect, we request exactly three OAuth scopes and no others:

openid
Confirms which Google account authorised the connection.
email
Gives us your Google account email address, so we can show you which account is connected and set the correct "From" address on the mail you send.
https://www.googleapis.com/auth/gmail.send
Permission to submit an outgoing message for delivery. This is the narrowest Gmail scope that exists for sending. It grants no ability to read, search, list, download or modify any message in your mailbox, and no access to drafts, labels, settings, contacts, Calendar or Drive.

We use this access for one purpose only: to send the specific email you have composed and approved inside LingxuAI, at the moment you send it or at the time you scheduled it. Each send is one API call, initiated by you. There is no background or automatic sending that you did not set up.

To state it plainly, and because the technical scope makes it verifiable:

  • We do not read your Gmail messages. The scope we hold does not permit it.
  • We do not scan, index, analyse or profile the content of your mailbox.
  • We do not use Gmail data for advertising of any kind.
  • We do not use Gmail data to train, retrain or fine-tune machine learning or AI models.
  • We do not sell Gmail data, and we do not transfer it to third parties except the infrastructure providers strictly needed to operate the sending feature, or where the law requires it.
  • No human at our company reads your Google user data, except with your explicit consent (for example, to resolve a support issue you have raised), where necessary for security investigation, or where required by law.

The emails you send through LingxuAI are stored in your workspace as your own outreach record, along with the message identifier and delivery status Google returns. That record exists because you created the message in our product — it is not obtained by reading your Gmail account.

You can disconnect Google at any time from Settings. Disconnecting revokes the connection immediately: sending stops, and the stored token is marked revoked and is no longer used to reach your account. The record itself is erased when your account is deleted.

Disconnecting inside LingxuAI does not withdraw the authorisation you granted at Google. To remove it on Google's side as well, revoke our access from your Google Account security page at myaccount.google.com/permissions.

6. Google API Services Limited Use commitment

LingxuAI's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

The policy is published at https://developers.google.com/terms/api-services-user-data-policy.

7. Authentication and how we store credentials

We never see your Google password
Authorisation happens on Google's own consent screen. Google returns a short-lived authorisation code to our server, which we exchange for tokens. Your Google credentials never reach us.
Access tokens
Short-lived and refreshed automatically shortly before they expire.
Refresh tokens
Encrypted at rest in our database using symmetric encryption with a key held outside the database and a recorded key version. They are never written to application logs, exports, or audit records. Disconnecting marks the connection revoked so the token is no longer used; the record is erased when your account is deleted.
Other connected credentials
The same encryption applies to any social account you connect for research, to third-party integration credentials, and to webhook signing secrets. Inbound webhook tokens are stored only as a hash and compared in constant time.
Isolation between customers
Every operational record — including tokens — carries a workspace identifier, and the database enforces row-level security so a query executed for one workspace cannot return another workspace's rows.
Your LingxuAI password
Hashed with Argon2id and a server-side pepper. It cannot be reversed, and we cannot tell you what it is; we can only let you set a new one.

8. Cookies

We set only the cookies the service needs in order to work. We do not use advertising cookies, cross-site tracking cookies, or third-party analytics cookies, which is why you are not asked to accept anything.

sa_access
Your signed-in session token. HttpOnly, expires with the token (about one hour).
sa_refresh
Renews your session without asking you to sign in again. HttpOnly, 30 days.
sa_csrf
Cross-site request forgery protection token. 30 days.
sa_email
The email address of the signed-in account, so the interface can display it. 30 days.
sa_imp, sa_imp_expires, sa_imp_email, sa_imp_return_to
Set only while a platform administrator is accessing a workspace for support, and capped at 60 minutes. Every such access is written to the audit log.
sinoai_locale
The interface language you chose. One year. Set as soon as you use the language switcher, including before you sign in.

9. Service providers we share data with

We use a small number of providers to run the service. Each receives only what it needs, and each is bound by contract to process data only on our instructions.

Google LLC
Gmail API, to deliver the outreach you send, and Google sign-in identity for the connection itself. Used only if you connect a Google account.
Cloudflare, Inc.
Object storage (R2) for raw collected source documents and for the export files you generate.
Hetzner Online GmbH (Falkenstein, Germany)
Hosting of the application servers, database and job queues.
Transactional email provider
Delivery of service email such as address verification, password resets, invitations and alerts. This is separate from your outreach, which goes through your own Gmail account.
Error monitoring
Diagnostic reports when something fails. Reports are scrubbed of credentials and secrets before they leave our systems.
Search and data providers
Search APIs used to discover candidate companies, and — only where you enable them — delegated data providers. These receive the search terms derived from your criteria, not your account data.
AI text generation provider
Where the feature is enabled, drafting assistance for outreach copy and classification of lead records. It receives the lead and company details relevant to the request and your instructions. It never receives Google user data, and Google user data is never used to train any model.

We also disclose data where we are legally required to, and to professional advisers, or in connection with a merger or acquisition — in which case this policy continues to apply until you are given notice of any change.

We do not sell personal data, and we do not share it with advertisers or data brokers.

10. How long we keep data

Account data
For as long as your account is open, then deleted or anonymised — except records we are required to keep, such as audit and financial records.
Workspace lead data
Until you delete it or close the workspace. Deleted records are first marked deleted and then removed.
Raw collected source documents
Automatically expired 50 days after collection.
Export files you generate
Automatically expired 7 days after generation.
Google refresh tokens
Marked revoked and no longer used the moment you disconnect; erased when your account is deleted.
Security and audit records
Append-only and retained for security and compliance purposes. They record who did what and when, never credentials or message contents.
Accounts declined at approval
Deleted 7 days after the decision.
Suppression entries
When an address or domain is suppressed — including at the request of the person concerned — we keep the minimum record needed to make sure it is not collected or contacted again. Deleting that record would defeat its purpose.
Backups
Held on a rolling cycle and overwritten. A deleted record can persist in a backup until the cycle completes.

11. How we protect data

  • Traffic is encrypted in transit with TLS.
  • Secrets — OAuth refresh tokens, integration credentials, webhook signing secrets — are encrypted at rest with a key held outside the database.
  • Passwords are hashed with Argon2id and a server-side pepper.
  • Every customer record is isolated by workspace and enforced by database row-level security, not only by application code.
  • The application connects to the database as a restricted role that cannot bypass those rules.
  • Administrative access across workspaces is possible only for platform administrators, is time-limited, and writes an audit record every time.
  • The audit log is append-only and hash-chained, so an entry cannot be altered or removed without detection.
  • Sign-in is rate limited and accounts lock after repeated failures; mutating requests carry cross-site request forgery protection.
  • User-supplied URLs are checked before we fetch them, so the service cannot be used to reach internal network addresses.
  • Credentials and message contents are excluded from logs, exports and audit entries.

No service can promise perfect security. If a breach affects your personal data and the law requires it, we will notify you and the relevant supervisory authority without undue delay.

12. Your rights as an account holder

Depending on where you live — including under the GDPR in the EU/EEA and the UK, and under the PIPL in China — you have the right to:

  • Access the personal data we hold about you, and receive a copy.
  • Correct data that is inaccurate or incomplete.
  • Delete your account and the personal data we hold about you, subject to the retention exceptions in section 10.
  • Restrict or object to processing, including processing based on legitimate interests.
  • Receive your data in a portable, machine-readable form.
  • Withdraw a consent you gave, without affecting processing that already took place.
  • Complain to your data protection supervisory authority.

You can act on several of these directly in the product: revoke Google access from Settings, revoke API keys and sessions, export or delete records in your workspace, and close your account. For anything else, write to [email protected]. We will verify your identity and respond within 30 days.

13. If your details are in a customer's lead database

You may be reading this because you received an email sent through LingxuAI, or found our crawler in your server logs, and you have never had an account with us. You still have rights, and this section explains how to use them.

For that data we act on behalf of our customer, who decides who to contact. You do not have to work out which customer that is. Write to us and we will handle it.

Why you were not told at the time: we did not obtain these details from you. They were collected from publicly available sources — company websites, business directories, public registries and public social profiles. Article 14 of the GDPR would normally require us to contact each person individually to say so. Because these records are gathered in bulk and often carry no reliable way to reach the individual behind them, doing that would involve disproportionate effort within the meaning of Article 14(5)(b). This policy is the public disclosure we provide instead, and this section is the route to object.

Send a request to [email protected], including the email address, phone number or domain concerned. We will:

  • Locate the records that match, across all customer workspaces.
  • Delete them, and pass your request to the customer or customers responsible so they act on their own copies.
  • Add the address or domain to a suppression list, so it is not collected again and cannot be contacted through the platform.
  • Instruct our crawler not to revisit the site, where a domain is concerned.

You may object to processing based on legitimate interests at any time. Where you object to direct marketing, that right is absolute — we will stop, without asking you to justify the request.

If you would rather prevent collection at the source, our crawler obeys robots.txt. The exact directive to block it is published at /crawler.

14. International transfers

Our providers operate in several countries, so your data may be processed outside the country you live in. Where personal data leaves the EEA or the UK, we rely on the European Commission's Standard Contractual Clauses or another approved transfer mechanism. Where Chinese personal information is transferred abroad, we comply with the cross-border requirements of the PIPL.

15. Children

LingxuAI is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, contact us and we will delete it.

16. Changes to this policy

We update this policy when the product changes. The effective date at the top always reflects the current version. If a change materially affects your rights or how we use your data, we will notify you by email or in the application before it takes effect.

17. Contact us

Data controller
[COMPANY LEGAL NAME]
Privacy and data protection
[email protected]
Data subject requests
[email protected]
Product support
[email protected]
Postal address
[REGISTERED ENTITY NAME], [BUILDING NUMBER] Xiongchu Avenue, Hongshan District, Wuhan, Hubei 430079, CN