Privacy Policy
Last updated: July 23, 2026
This policy explains what personal data GR8MINDS ("we", "us") processes when you use Pipeline Engine (the "Service"), and what rights you have. We act as the data controller for your account data, and process business-contact data on your behalf as part of the Service.
1. Data we collect about you
- Account data: email address, password (stored hashed by our authentication provider), workspace and company details you provide.
- Billing data: plan, payment status and transaction references. Card details are entered directly on Cardcom's secured payment page — we never see or store your card number.
- Usage data: actions in the product (scans, reveals, pipeline changes) and standard server logs, used to operate quotas, improve the product and prevent abuse.
2. Business-contact data processed for you
The core of the Service is researching companies and surfacing business contacts (name, role, business email, business phone, LinkedIn profile). This data is compiled from publicly available sources and licensed B2B data providers, on the basis of legitimate business interest, and is made available only inside your workspace for your own outreach. We do not sell this data, and each successful lookup is metered to your account. You are responsible for using it lawfully (see our Terms).
3. Service providers (sub-processors)
We use a small set of providers to run the Service:
- Supabase — database and authentication
- Vercel — hosting and content delivery
- Anthropic — AI research and text generation
- Cardcom — payment processing
- B2B data providers used for research and contact discovery (e.g. Lusha, Hunter, ContactOut, Apollo, lemlist, ZeroBounce, BuiltWith)
Each provider receives only what it needs to perform its function. Some providers process data outside your country; we rely on their standard contractual safeguards for such transfers.
4. Cookies
We use essential cookies only — session cookies that keep you signed in. We do not run third-party advertising or tracking cookies.
5. Retention and deletion
Your data is retained while your workspace is active. When a workspace is deleted (by you or on your request), its data — including researched leads and contacts — is deleted from our production database. Backups expire on a rolling basis. To request deletion, email us.
6. Your rights
Subject to applicable law (including the GDPR if it applies to you and Israel's Privacy Protection Law), you may request access to, correction of, or deletion of your personal data, object to certain processing, or request a copy of your data. If you appear as a business contact in a customer's workspace, you may contact us to have your details removed from our systems. We answer requests at ai@gr8minds.co.il.
7. Security
Data is encrypted in transit, access is scoped per workspace (row-level security), and payment card data never touches our servers. No system is perfectly secure; we work with established providers and follow their security practices.
8. Children
The Service is for business users aged 18 and over.
9. Changes
We may update this policy from time to time; material changes will be announced in the Service or by email. The date above reflects the latest version.
10. Contact
Privacy questions and requests: ai@gr8minds.co.il.