Privacy Policy · Effective September 11, 2026

How Petrichor handles personal data.

This policy explains what we collect, why, who we share it with and what rights you have. It covers visitors, customers and their teams, and the business contacts whose professional details appear in our lead data.

01

Who we are

Petrichor is operated by BluBubl Limited (254 Chapman Rd, Ste 101-B, Ofc 104, Newark, DE 19702, United States), referred to below as "Petrichor", "we" or "us". We are the controller of the personal data described in this policy unless a section says otherwise.

Petrichor is an autonomous go-to-market agent for business-to-business sales. It finds companies and business contacts that match a customer's ideal customer profile, drafts and sends outreach from the customer's own connected email and LinkedIn accounts, reads replies, and learns from outcomes.

This policy applies to trypetrichor.com, app.trypetrichor.com, api.trypetrichor.com and every service we run behind them. For privacy questions, requests or complaints, write to alex@trypetrichor.com.

02

Who this policy covers

  • Visitors: anyone browsing our website, using the demo chat on the landing page, or requesting a demo.
  • Customers and users: people who create an account, and members of a team workspace an account admin invites.
  • Prospects: business contacts whose professional details appear in our lead data or are processed by us when a customer runs outreach. If this is you, the section Notice to people in our lead data is written for you.

Where a customer uploads their own data (for example a CRM export or a CSV of contacts) or connects their own accounts, we process that data on the customer's documented instructions as a processor. The customer is the controller for that data and for every message sent from their accounts. Our Data Processing Addendum governs that relationship.

03

The data we collect

Data you give us

CategoryExamplesWhen
AccountEmail address, name, a salted hash of your password (never the password itself), or the email, name and account identifier Google returns when you sign in with GoogleSign-up and sign-in
Team and billingTeam name, member roles, plan, Stripe customer and subscription identifiers, invoices. Card details are entered on Stripe's hosted pages and never touch our serversWhen you invite teammates or subscribe
Workspace contentYour website URL, product and ideal-customer descriptions, files you upload (CSV, PDF, documents), CRM exports, campaign instructions, and everything you type in the chat with the agentWhile you use the product
Connected accountsAccess tokens for email, LinkedIn, sending and CRM tools you connect, plus the messages, contacts and events those tools expose so the agent can send, detect replies and syncWhen you connect an integration
Demo chatYour messages on the landing page, the leads generated for you, and a temporary guest account that lets you carry the work into a real accountWhen you use the hero chat without signing in
Demo requestFirst name, last name, work email, job titleWhen you submit the book-a-demo form
SupportAnything you send us by email or in the in-app helpWhen you contact us

Data we generate or collect automatically

  • Usage and logs: IP address, browser and device type, API endpoints requested, timestamps and error traces for security, debugging and capacity planning. With Analytics consent, our first-party service also records page paths with query strings removed, pricing views, demo-form milestones, signup and selected product actions. We use no third-party analytics, advertising tags or session replay; see the Cookie Policy.
  • Agent activity: the plans, searches, drafts, sends, replies and spend the agent records while working for you, so that you can audit what it did and so it can learn what works.
  • Browser storage: the small set of keys listed in the Cookie Policy (session credential, theme, demo session, drafts). We set no first-party cookies.

Data about prospects

Our lead data holds business-context information about people at companies: name, job title, seniority, employer, work location, tenure, business email and phone where available, LinkedIn URL, public professional headline and activity, and company facts (industry, size, funding, hiring, technology). We obtain it from the sources described in Notice to people in our lead data. We do not collect special-category data, financial account data or data about people acting in a private capacity.

04

How we use data and on what legal basis

PurposeData usedLegal basis (GDPR / UK GDPR)
Provide the service: accounts, workspaces, chat, lead search, campaigns, learningAccount, workspace content, connected accounts, agent activityPerformance of a contract (Art. 6(1)(b))
Send and manage outreach on your instruction from your accountsConnected accounts, prospect data, message contentPerformance of a contract; you are the controller of the campaign itself
Run the demo chat for visitorsDemo chat messages, guest sessionPerformance of a contract (the demo you asked for) and legitimate interest in showing the product
Build and maintain business-contact lead dataProspect dataLegitimate interest (Art. 6(1)(f)): enabling relevant B2B sales contact; see the balancing summary below
AI processing: drafting, classification, scoring, planningChat content, workspace content, prospect dataPerformance of a contract and legitimate interest in providing an accurate agent
Billing, credits, fraud and abuse preventionAccount, team and billing, usageContract; legal obligation (tax, accounting); legitimate interest in protecting the service
Security, debugging, service integrityUsage and logsLegitimate interest in keeping the service secure and reliable
Consented first-party website/product analytics and sales journey contextPage paths, event timestamps and selected actions; identity only after a signed login/demo associationConsent (Art. 6(1)(a)); withdrawal stops future optional capture
Product improvement on aggregated or de-identified usageUsage, agent outcomesLegitimate interest; we do not use customer content to train foundation models
Respond to demo requests and supportDemo request, supportContract or steps prior to a contract; legitimate interest
Product announcements to account holdersAccount emailLegitimate interest; you can opt out at any time
Comply with law and enforce our termsWhatever is necessaryLegal obligation; legitimate interest

Where we rely on legitimate interest we have weighed it against your interests and rights. For the lead data the key factors are: only business-context data is processed, no sensitive data is held, the contact is made in a professional capacity about business matters, data subjects can object at any time and are suppressed everywhere when they do, and customers are contractually bound to lawful, non-deceptive outreach that honours opt-outs.

05

AI and automated processing

Petrichor is built on large language models. Text you write, your workspace context, and prospect records are sent to the model providers listed in our subprocessor list to draft messages, classify replies, score fit, plan searches and summarise documents. We use these providers' business API endpoints and, where the provider offers it, we opt out of our inputs being used to train their models. We do not use your content to train foundation models ourselves.

Fit scores and reply classifications are used to prioritise and organise sales work. They are not used to make decisions that produce legal or similarly significant effects on any person. Every message the agent sends goes from your accounts under your instructions and autonomy settings, and you remain responsible for reviewing what it does.

If you believe an automated output about you is wrong, contact us and we will review it with a human.

06

Notice to people in our lead data

This section is the information we owe you under Article 14 GDPR if your professional details appear in our lead data or in a message sent through the service.

What we hold about you

Your name, job title, seniority, department, current employer and tenure, work location, business email address and business phone number where available, LinkedIn profile URL, public professional headline and public posts, and facts about your employer. Nothing about your private life, health, beliefs or finances.

Where it comes from

  • Public professional profiles and posts, company websites, press releases, public job boards and regulatory filings.
  • Licensed business-data providers, listed in our subprocessor list (for example Apollo.io, Exa, FullEnrich, LeadMagic, Hunter.io).
  • Our customers' own CRM records and contact lists, which they upload or connect. For that data the customer is the controller and Petrichor processes it on their instructions.

Why we process it

To help business-to-business sellers identify companies that fit their offer and reach the people responsible for that area at those companies, in a professional context, with relevant and non-deceptive messages. Our legal basis is legitimate interest (Article 6(1)(f) GDPR); the balancing summary is in How we use data.

How long we keep it

Prospect records are refreshed against their sources and removed when they no longer describe a current business role or when the source is no longer available. Records tied to a customer's campaign are kept while that customer's account is active so replies and opt-outs can be honoured, and are deleted or anonymised when the customer deletes them or closes their account. Suppression records (proof that you asked not to be contacted) are kept indefinitely because they exist to protect you.

Your rights and how to use them

You can object to this processing at any time, ask for access to what we hold, ask us to correct or erase it, or ask us to restrict it. Email alex@trypetrichor.com with the name and email address or profile URL you want us to look up. We will confirm within one month, suppress your record across all customer workspaces, and pass the request to the customer who contacted you where they hold their own copy. You do not need to give a reason and there is no charge.

Every outreach message sent through the service must carry a working way to opt out. Replying "unsubscribe" or "stop" to a message, or using the opt-out link where one is present, suppresses you from that customer's campaigns as well.

You can also complain to your national data protection authority. The European Data Protection Board lists them; in the UK it is the ICO.

07

Who we share data with

  • Subprocessors: vendors that host, run models, deliver email, process payments or supply business data on our behalf, bound by contracts that limit use to our instructions. The current list, with purpose and location, is in the Data Processing Addendum. Today it includes DigitalOcean, OpenAI, DeepSeek, OpenRouter, Google LLC, Stripe and the others listed there.
  • Services you connect: when you connect Gmail or Google Workspace, LinkedIn, HeyReach, Instantly, HubSpot or another tool, data flows to and from that service under its own terms and privacy policy. You can disconnect at any time from Integrations, which revokes our access.
  • Your team: workspaces are shared; teammates and team admins see the leads, campaigns, chats and documents in the workspace according to their role.
  • Recipients of your outreach: messages the agent sends carry your name, your sender address and the content you or the agent wrote.
  • Legal and safety: authorities, courts or other parties when the law requires it, or when necessary to protect the rights, safety or property of any person or of the service.
  • Corporate transactions: a successor in a merger, acquisition or asset sale, who will remain bound by this policy for data collected under it.

We do not sell personal data, and we do not share it with third parties for their own advertising. We do not use cross-context behavioural advertising.

08

International transfers

BluBubl Limited is a United States company and our servers are in the United States. If you are in the European Economic Area, the United Kingdom or Switzerland, your data is transferred to the United States and to the other countries listed in the subprocessor list. Some model providers process data outside the EU and the US.

For transfers out of the EEA, UK and Switzerland we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum) with each recipient, or on an adequacy decision or the EU-US Data Privacy Framework where the recipient is certified. Business customers can request a copy of the transfer terms through the Data Processing Addendum.

09

How long we keep data

DataRetention
Account, team and workspace contentWhile your account is active. Deleted or anonymised within 30 days of a verified deletion request or account closure, except where we must keep it for tax, accounting or dispute purposes.
Connected-account tokensUntil you disconnect the integration or close your account, at which point the token is revoked and deleted.
Demo chat and guest sessionsGuest sessions expire automatically after a short period unless you carry them into an account. Expired guest data is deleted.
Demo requestsUntil we have followed up and for up to 24 months afterwards so we do not contact you twice.
Billing recordsAs long as tax and accounting law requires, typically 7 years.
Server logsA limited period, normally under 90 days, for security and debugging.
Prospect recordsSee Notice to people in our lead data.
BackupsDeleted data may persist in encrypted backups for a limited period before being overwritten in the normal rotation.
10

Security

All traffic is encrypted in transit with TLS. Credentials for accounts you connect are encrypted at rest with authenticated encryption and keys held separately from the database. Passwords are stored only as salted hashes. Access to production is limited to named staff with a need, over authenticated connections, and staff access inside a customer account (for support) is logged and only happens with the customer's permission.

No system is perfectly secure. If we learn of a breach that affects your data we will notify you and any competent authority without undue delay, as the law requires. If you discover a vulnerability, write to alex@trypetrichor.com.

11

Your rights (EEA, UK and Switzerland)

  • Access: a copy of the personal data we hold about you.
  • Rectification: correction of inaccurate or incomplete data.
  • Erasure: deletion of your data where there is no overriding reason to keep it.
  • Restriction: pausing processing while a dispute is resolved.
  • Portability: your account data in a machine-readable format. You can export leads and workspace data from the app at any time.
  • Objection: to processing based on legitimate interest, including any direct marketing, at any time.
  • Withdraw consent: where processing is based on consent, without affecting processing that already happened.
  • Complain: to the supervisory authority where you live or work.

To exercise a right, email alex@trypetrichor.com from the address on your account, or from any address together with enough information for us to find your record. We respond within one month, extendable by two months for complex requests, and we may ask you to verify your identity. Requests are free unless they are manifestly unfounded or excessive.

12

United States state privacy rights

If you live in California or another state with a comprehensive privacy law, you have the right to know what personal information we collect, use and disclose, to access it, to correct it, to delete it, to opt out of its sale or sharing for targeted advertising, and not to be discriminated against for exercising these rights.

We do not sell personal information and we do not share it for cross-context behavioural advertising, so there is nothing to opt out of on that front. In the past twelve months we have collected the categories described in The data we collect for the purposes in How we use data, and disclosed them to the service providers listed in the subprocessor list.

To exercise a right, email alex@trypetrichor.com. We verify requests by matching the details you give us against the account or record concerned. You can use an authorised agent if you give them written permission and we can verify your identity. We respond within 45 days, extendable once by 45 days.

Where we act as a service provider for a customer, we will refer requests about that customer's data to them.

13

Cookies and browser storage

We set no first-party cookies and run no advertising tags or session replay. Optional first-party page and product activity runs only after Analytics consent. The site keeps a small number of items in local storage for sign-in, theme, demo chat, consent and—when enabled—an opaque analytics session. The full inventory, third-party services that may set their own cookies when you use them (Google sign-in, Stripe checkout), and how to change your choices are in the Cookie Policy.

14

Children

Petrichor is a business tool and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child has given us personal data, contact us and we will delete it.

15

Changes to this policy

We will update this policy when our practices, vendors or the law change. The effective date at the top tells you which version you are reading. For material changes we will notify account holders by email or with a notice in the app before the change takes effect.

16

Contact

BluBubl Limited, 254 Chapman Rd, Ste 101-B, Ofc 104, Newark, DE 19702, United States.

Privacy requests, data subject rights and notices: alex@trypetrichor.com.