Privacy Policy

Last updated: September 20, 2026

1. Who we are and what this policy covers

Lead Scorer is operated by Nymphar.AI, a French SAS, SIREN 928 692 136, RCS Bobigny, at 14 rue Anatole France, 93350 Le Bourget, France. For privacy questions and rights requests, write to miljan@lead-scorer.com or to that postal address. You do not need a Lead Scorer account to contact us.

This policy covers our website, application, Chrome extension, APIs, MCP server and AI features. It concerns visitors, account holders and people whose professional profiles or communications are processed through the service.

We act as a controller for account administration, billing, support, service security and processing whose purposes we determine. For customer campaigns, messages and other workspace data processed on a customer's instructions, we act as a processor and that customer is the controller. A data processing agreement is required for this relationship; this notice is not that agreement.

Professional profile and company records can be matched across imports and enrichment requests. A profile or enrichment result may therefore be reused when another customer is authorised to access that record. Removing a profile from one customer's CRM does not necessarily erase the underlying shared record. Contact us for a request concerning your personal data across the service.

2. Data and sources

  • Account and billing: name, email, profile image, authentication information, organisation details, subscription, invoices, payments and usage balances. Google sign-in supplies the identity information you authorise. Payment card details are handled by Stripe; Lead Scorer uses payment and customer references and payment status.
  • Prospects and companies: names, professional roles, employers, profile URLs and identifiers, biographies, professional history, locations, business contact details, company information, public posts and engagement signals. Sources include your imports, connected accounts, public websites and registers, and research or enrichment providers described in section 4.
  • Workspace and AI: lists, tags, notes, targeting criteria, scores and explanations, research, prompts, conversations with agents, instructions, workspace memory, generated drafts, files and images.
  • Connected communications: sender and recipient details, email or LinkedIn conversation content, attachments, timestamps, reply and delivery information, connection status and objections. Inbox synchronisation can include conversations with people outside your campaigns. Connect a mailbox only if you are authorised to process those communications.
  • Technical and support data: IP address, browser and device information, device identifiers, pages and actions, timestamps, errors, API/MCP activity, operation costs and messages you send to support. AI diagnostic events can include excerpts of prompts and generated responses.

Account identifiers and authentication data are needed to create and secure an account; billing information is needed for paid services. Other data depends on the feature you choose. Declining an integration or an optional input may prevent that feature from working. Do not intentionally supply sensitive personal data, criminal-offence data or children's data for prospecting.

3. Purposes and legal bases

  • Provide the service: manage accounts, subscriptions and requested operations, including integrations and AI features. We rely on performance of our contract when you are the contracting individual, and our legitimate interest in serving business customers for their authorised representatives' account details.
  • Support and protect the service: answer requests, diagnose failures, prevent misuse, enforce quotas and investigate incidents. Our legitimate interests are maintaining a reliable service, protecting accounts and resolving support requests. These interests must be balanced against the rights of the people concerned.
  • Accounting and legal obligations: keep required transaction records and respond to binding legal requests. The basis is compliance with applicable legal obligations. Handling legal claims may also rely on our legitimate interest in establishing or defending our rights.
  • Customer-directed prospecting: discover, organise, enrich and score contacts, prepare communications and perform authorised campaigns. The customer must establish the lawful basis for its processing and provide the required information to the people concerned. Its contract with us is not itself a lawful basis for processing a prospect's data.
  • Optional browser analytics and replay: understand product usage and diagnose user journeys. Non-essential tracking requires prior consent. Accepting the Terms of Service or reading this policy does not provide that consent. See the tracking section below.

Publicly accessible data remains personal data. Its collection and reuse require a valid legal basis, appropriate information and respect for objections. For processing whose purposes we determine ourselves, we remain responsible for those requirements; they cannot be transferred to customers by these terms.

4. Recipients and service providers

Data is accessible to authorised personnel and providers as needed for their role, to customers entitled to access the relevant records, and to recipients of communications or content you send or publish. Which providers receive data depends on the features used and their configuration.

  • Cloud infrastructure and storage providers: hosting, databases, file storage and technical operations involving account, workspace and service data.
  • Payment and billing providers: checkout, subscriptions, invoices and payment processing involving customer identity, billing details and transactions.
  • Email delivery and account-integration providers: account notifications, connected email or professional social-network accounts, inbox synchronisation, messaging and publishing, involving contact details, account information and communications.
  • AI model and inference providers: research, extraction, scoring, drafting and agent operations involving prompts, relevant professional records, workspace context and content supplied for those operations.
  • Web research and professional-data enrichment providers: searching public sources, enriching profiles and companies, and discovering business contact details, using relevant names, profile links, company details or search queries.
  • Contact verification providers: checking the validity of email addresses or telephone numbers submitted for verification.
  • Podcast search and transcript providers: research and retrieval using queries and episode identifiers, which may include professional names or context.
  • Analytics, support and diagnostic software providers: usage measurement, error diagnosis, support, session replay where enabled, and AI/API/MCP observability. Data may include account identifiers, events, support exchanges and prompt or response excerpts, as explained elsewhere in this policy.

These services may involve processing within and outside the European Economic Area, including in the United States; see section 5 for information on international processing. Customers can consult the named providers, their activities and the data involved in the Service Provider Annex after signing in. It is also available from account settings.

You do not need an account to exercise your privacy rights or request information about the recipients of your personal data. Contact miljan@lead-scorer.com, including if you cannot access the customer annex.

Some providers also act as independent controllers for their own account, security, payment or source-database purposes. Their own privacy notices apply to those activities. An external AI assistant or MCP client you connect receives the information returned to it and handles it under its own terms. Disconnecting it does not automatically delete copies it has already received.

Content Studio images prepared for publication may be accessible through a public media URL. Do not use that publishing storage for confidential files. Campaign attachments use a separate access-controlled storage path. Data may also be disclosed where required by law or necessary to handle a legal claim.

5. International processing

Providers and connected services may process data outside the European Economic Area, including in the United States. European hosting of one component does not mean all processing stays in Europe. A transfer requires an applicable GDPR mechanism, such as a relevant adequacy decision or the European Commission's standard contractual clauses with any necessary additional safeguards.

Contact us for the processing locations and safeguards applicable to a particular provider and for a copy of the relevant contractual safeguards, subject to redaction of confidential information. This policy does not itself establish a transfer mechanism or certify a provider's eligibility for one.

6. Retention and deletion

Retention depends on the purpose, customer instructions and applicable legal requirements. Cancelling a paid subscription, disconnecting an integration, removing a CRM entry and requesting erasure are different operations.

  • Account and workspace data: used during the account relationship to provide the selected features. Request closure, export or erasure by contacting us. Customer-directed data is subject to the applicable processing agreement and instructions, with exceptions required by law.
  • Shared professional records: removing a lead from your CRM removes your access and associated campaign enrolments; it does not automatically erase a shared profile. Erasure requests require a review of the underlying record, related copies and any lawful reason for retention.
  • Invoices and accounting evidence: French law requires retention for ten years from the close of the relevant financial year. This does not justify retaining all prospect or message data for ten years.
  • Support, security and diagnostic records: the relevant criteria are resolution of the request or incident, the period needed to investigate faults or abuse, and any applicable legal claim or evidence requirement. Analytics and AI traces also depend on the provider's configured retention settings; contact us for the period applicable to your data.
  • Objection records: a minimal suppression record may be retained to honour a person's request not to be contacted again, for as long as needed for that purpose. It must not be reused for prospecting.
  • Local extension data and downloaded files: local state remains until cleared or the extension is removed. Exported files remain wherever you save them. Neither action deletes data already synchronised to the service.

An erasure request must also consider backups and copies held by our processors. We will explain any applicable retention exception and how it affects your request. Copies independently held by message recipients, publishing platforms or an external client are subject to their own obligations.

7. Cookies, local storage and analytics

The language preference cookie (ls_locale) stores your English or French selection for up to one year. It is used for that preference, independently of optional analytics consent.

Authentication cookies and local settings support sign-in, security and requested functionality. The extension also stores a device identifier and usage counters to apply free-tool quotas. Blocking necessary storage can prevent those features from working.

After you accept analytics cookies, PostHog can use browser storage for detailed analytics, errors and session replay, and associate activity with your signed-in account ID, name and email. This identified processing is optional.

We measure visits and basic interactions from your first page view, including if you decline analytics cookies or do not answer the banner. This cookieless measurement does not store an analytics identifier in your browser or attach your account ID, name, email or customer data to events. PostHog derives a daily visitor identifier on its servers from the IP address, browser user agent, hostname and a daily salt. It cannot reliably recognise a returning visitor across days or devices.

Use Cookie preferences in Settings to accept or withdraw consent. We store your choice, its date and version in local storage (ls_analytics_consent) for 180 days. Withdrawal removes PostHog analytics storage, stops replay and account identification, and returns to cookieless measurement. Previously collected data and server-side operational logs are not deleted.

Server-side operation records include API/MCP activity and AI diagnostic traces. They are distinct from browser cookies; disabling browser tracking does not delete those records. Customer campaign delivery, reply or engagement information is processed for the customer, who must comply with any notice and consent requirements for recipient tracking.

8. Chrome extension

The extension reads LinkedIn data for the synchronisation or export features you use: connections, messages and profile views where enabled, profile posts, search results and post engagers. Requests run through your browser's LinkedIn session. The extension can hold captured request headers, including session and CSRF information, in memory to make those requests.

Chrome local storage holds extension settings, your Lead Scorer API key, cached data, synchronisation state, quotas and a generated device identifier. The API key authenticates requests to the configured Lead Scorer app. Synced records and usage information are sent to that app; the backend then uses the providers described in this policy for the features you request.

The distributed extension requests these permissions:

  • storage: settings, credentials, cached data and operation state.
  • webRequest: observe LinkedIn request headers used by the integration.
  • tabs: locate or open the LinkedIn and Lead Scorer pages used by a feature.
  • downloads: save requested exports.
  • notifications: report operation progress or completion.

Host permissions cover LinkedIn and lead-scorer.com. You can change capture settings or disable or uninstall the extension to stop its future activity. Revoke the associated API key if it should no longer authorise access. These actions do not disconnect an email or LinkedIn account connected separately through the application.

9. AI and profiling

Scoring compares professional and company information with a customer's targeting criteria, such as role, industry, company size and relevant business signals. It produces a priority score and explanation that can influence who receives outreach. This is a form of profiling. Generated results may be inaccurate and should be reviewed by the customer.

AI features send relevant prompts, context and records to the selected model provider. Diagnostic traces may also include that content. Only include data needed for the task. The service is designed for professional outreach, not solely automated decisions producing legal or similarly significant effects. You can request access to or correction of personal data and object to direct marketing, including related profiling.

10. Your rights and how to exercise them

Subject to the conditions of applicable law, you can request access, rectification, erasure, restriction and portability of your personal data, object to processing based on legitimate interests, and withdraw consent without affecting processing lawfully carried out before withdrawal. You can object to direct marketing and related profiling at any time.

Write to miljan@lead-scorer.com with enough information to locate the data, such as the relevant email or profile URL. Do not send passwords or API keys. We may request proportionate identity information if we have reasonable doubts about the requester's identity.

If the request concerns a customer's campaign, you can also use the unsubscribe mechanism in its message or contact the sender. Where we act as processor, we assist the responsible customer in handling your request. Where we act as controller, we handle the request ourselves. A request about a shared record can be sent directly to us even if you do not know which customer used it.

We respond to rights requests without undue delay and normally within one month. If the law permits an extension because of complexity or the number of requests, we will explain it within that first month; the extension may be up to two additional months. You can complain to the CNIL or the competent supervisory authority where you live or work. You do not have to contact us first to exercise that right.

11. Security and policy updates

The service uses authentication, access controls and encrypted HTTPS connections for its public endpoints. No system can guarantee absolute security. Report suspected exposure or unauthorised access to our contact address so it can be investigated. Notification duties for personal data breaches depend on our role and applicable law.

We will update this policy when processing changes, indicate the revision date and notify account holders of material changes through the service or email. New processing requiring consent must obtain it separately. For contractual conditions, see our Terms of Service.