Privacy Policy
Last updated: 10 July 2026
nomad. ("the app", "we", "us") is a multi-tenant software service that helps its business customers run LinkedIn outreach and manage a lightweight contact CRM. Each customer's data is held in a separate, isolated database. This policy explains what information the app accesses, how it is used, and how it is protected. Access is limited to authorized users who have been invited by a customer organization; the app is not an open consumer service.
Information the app accesses
- Google account email — used to identify the connected Google account and show which account is linked.
- Google Drive files and folders — when you connect Google Drive, the app creates a folder for each contact and lets you upload, view, and delete files stored in your own Google Drive. The app accesses Drive only to provide this file-storage feature at your direction.
- LinkedIn data — accessed through a third-party provider (Unipile) to power messaging and profile features, at your direction.
- Contact records you enter — names, email addresses, phone numbers, notes, and related details you add to the CRM.
How information is used
Information is used solely to provide the app's features to the customer who entered it — storing and retrieving files, showing contacts, and sending messages that customer's users initiate. Information is not sold or rented, is not used for advertising, and is not used to train generalized artificial-intelligence models.
Google user data — Limited Use
nomad.'s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- Google Drive data is used only to provide and improve the file-storage feature you have chosen to use.
- We do not transfer Google user data to third parties except as necessary to provide or improve that feature, to comply with applicable law, or as part of a merger or acquisition — and never to serve advertisements.
- We do not use Google user data for personalized advertising.
- We do not allow humans to read your Google user data unless we have your consent for specific files, it is necessary for security purposes or to comply with the law, or the data has been aggregated and anonymized.
Where information is stored
File contents are stored in the connected Google Drive account. Everything else (contact records, notes, settings) is stored in a private, per-customer database on servers the service operator controls. The app relies on the following service providers to deliver its features, each governed by its own privacy policy: Google (sign-in and Drive), Unipile (LinkedIn access), Google Gemini (AI drafting), Cloudflare (encrypted off-site backups), and — where a customer enables them — ActiveCampaign (email contacts) and Plug & Pay (payment processing). Only the data required for a given feature is shared with the provider that powers it.
Data retention and deletion
- Deleting a file in the app removes it from Google Drive.
- Deleting a contact removes its record and its associated Google Drive folder and files. If Google Drive is temporarily disconnected at the moment of deletion, the folder is queued and removed automatically the next time Drive is reconnected.
- Erasing a contact permanently removes every record about that person across the app — contact details, cached LinkedIn profile, scored prospect, profile audit, cached messages, and outreach history — along with their Google Drive folder.
- Retention: data that can be re-fetched on demand (cached LinkedIn profiles, message history, the chat index, saved searches, and profile audits) is automatically aged out after a retention period — enabled by default and configurable per data type. The contact records the operator maintains are kept until deleted.
- You can disconnect Google Drive at any time in the app's settings, which stops all further access, and revoke the app's access to your Google Account at myaccount.google.com/permissions.
Your rights
Individuals whose personal data is held in a customer's CRM may, on request to that customer organization (which acts as the data controller), exercise their rights under applicable data-protection law (including the EU/UK GDPR):
- Access & portability — the customer organization can export everything held about a person as a machine-readable file (with precise locations reduced to country level).
- Erasure — the customer organization can permanently erase all data held about a person.
- Objection — a person can ask not to be contacted. The app keeps a do-not-contact list, stored only as one-way hashes (holding no readable personal data), that blocks any future import or outreach to them.
To make any of these requests, contact [email protected].
Contact
Questions about this policy can be directed to [email protected].
See also our Terms of Service.