What ReferralPulse collects, how it is used, and the rights you have over it. Written in plain language, backed by real controls.
Welcome to ReferralPulse. This policy explains how your personal information is collected, used, and shared when you use the ReferralPulse web application, mobile apps, and any related services.
By using these services you agree to the collection, use, and disclosure of your information as described below. If you do not agree, please do not use ReferralPulse.
ReferralPulse is a referral management platform built for professionals including attorneys, financial advisors, CPAs, and insurance agents. The platform helps you manage your professional referral network, track referrals, and strengthen business relationships.
When you create an account, ReferralPulse collects:
To provide referral management services, ReferralPulse collects:
ReferralPulse automatically collects:
When you connect third-party services like a CRM, calendar, or email mailbox, ReferralPulse may receive data from those services in accordance with the authorization you grant. Connecting a Gmail mailbox, for example, means ReferralPulse can read messages between you and your partners and send drafts you approve on your behalf. See section 6 for full detail on Google integrations, including the optional Calendar and Gmail connections, and section 5 for the complete list of third-party services in use.
ReferralPulse does not use your data to train AI models. Your information is processed only to provide the service to you.
ReferralPulse uses artificial intelligence to enhance your experience:
When you use AI features, the following may be processed by AI providers such as OpenRouter, OpenAI, and Anthropic:
ReferralPulse AI systems make the following automated assessments:
These assessments are recommendations only. No automated decisions are made without your review and approval.
You can disable AI features in your privacy settings. When disabled:
ReferralPulse uses the following third-party services:
Each service operates under its own privacy policy. You are encouraged to review those policies directly.
ReferralPulse offers Sign in with Google as an authentication option. This section describes how data received from Google APIs is handled, in compliance with the Google API Services User Data Policy, including the Limited Use requirements.
When you sign in with Google, ReferralPulse requests access to basic profile information only:
ReferralPulse does not request access to Google Drive or any other Google services beyond basic authentication, except for two optional integrations that are never requested during sign-in: the Google Calendar integration (section 6.2) and the Gmail mailbox integration (section 6.3). Each integration is a separate, deliberate connect step from the settings or onboarding page, with its own consent screen, and either can be revoked independently.
If you choose to connect Google Calendar from your settings page, ReferralPulse requests read-only access to your primary calendar (calendar.readonly scope). You can disconnect at any time and Google will also show the connection at myaccount.google.com where you can revoke it directly.
If you choose to connect your Gmail mailbox from the settings or onboarding page, ReferralPulse requests the gmail.modify OAuth scope. This is the single scope that allows ReferralPulse to read messages from your mailbox and send messages on your behalf. It does not include Gmail settings, account configuration, or any other Google service. You can disconnect at any time, and Google will also show the connection at myaccount.google.com where you can revoke it directly.
gmail.modify scope is used only to read messages and to insert new messages you have approved.Google profile data (name, email, profile picture URL) is stored in a secure database hosted on Neon PostgreSQL with encryption at rest. Access is restricted to authenticated sessions tied to your account.
Gmail message bodies receive an additional layer of protection. Each connected account has its own randomly generated 256-bit encryption key, which is itself wrapped under a ReferralPulse master key (envelope encryption). Message bodies are encrypted with AES-256-GCM before being written to the vault, and the only process that can decrypt them is the ReferralPulse pipeline running in memory when generating drafts or extracting partner data. The vault table is wiped on a daily schedule for entries older than 30 days, and disconnecting your mailbox immediately destroys your per-account key.
ReferralPulse's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, ReferralPulse confirms that:
You can revoke ReferralPulse access to your Google account at any time through your Google Account permissions. You can also delete your ReferralPulse account from within the app, which will remove all stored Google user data. Calendar and Gmail can be revoked individually from the settings page; revoking either does not disconnect the other and does not sign you out.
ReferralPulse does not sell your personal information. Information may be shared in the following circumstances.
With third-party service providers who perform services on behalf of ReferralPulse (see section 5), subject to confidentiality obligations.
In connection with a merger, acquisition, or sale of assets, your information may be transferred. You will receive notice before your information becomes subject to a different privacy policy.
ReferralPulse retains your information for as long as necessary to provide the service and fulfill the purposes described in this policy. Specific retention periods:
Regardless of your location, you have the following rights over your personal information:
To exercise these rights, contact privacy@referralpulse.ai or use the controls in your account settings. Responses are provided within 30 days.
If you are a California resident, you have additional rights under the California Consumer Privacy Act and the California Privacy Rights Act.
ReferralPulse does not sell your personal information. ReferralPulse does not share your personal information for cross-context behavioral advertising.
ReferralPulse honors Global Privacy Control signals. If your browser sends a GPC signal, it is treated as a valid opt-out request.
If you are located in the European Economic Area, the United Kingdom, or Switzerland, you have additional rights under the General Data Protection Regulation.
ReferralPulse processes your data based on:
In addition to the rights in section 9, you have:
For GDPR-related inquiries, contact the data protection representative at dpo@referralpulse.ai.
ReferralPulse is based in the United States. If you access the service from outside the United States, your information may be transferred to, stored in, and processed in the United States or other countries where the service providers operate.
For transfers from the EEA, UK, or Switzerland to countries not deemed adequate by the European Commission, ReferralPulse relies on:
You may request a copy of the relevant transfer mechanism by contacting privacy@referralpulse.ai.
ReferralPulse implements industry-standard security measures to protect your information:
No system is completely secure. If you believe your account has been compromised, contact security@referralpulse.ai immediately.
ReferralPulse is designed for business professionals and is not intended for users under the age of 16. Personal information is not knowingly collected from children under 16. If information from a child under 16 is discovered, it will be deleted promptly. If you believe a child has provided personal information, contact privacy@referralpulse.ai.
This policy may be updated from time to time to reflect changes in practices or for legal, operational, or regulatory reasons.
When changes are made:
Continued use of the service after the changes take effect constitutes acceptance of the updated policy.
If you have questions, concerns, or requests regarding this policy or data practices, the ReferralPulse privacy team is available at the addresses below.
Privacy-related inquiries receive a response within 30 days.
Privacy-first by design. Every feature built around your consent, your control, and your peace of mind.