Privacy Policy
1. Scope of this policy
This Privacy Policy (the “Policy”) describes how Gelee AI, Inc. (“Gelee”, “we”, “us” or “our”) collects, uses, discloses, transfers, retains, safeguards and disposes of personal information in the course of commercial activities. It applies to:
- the website at gelee.ai and every page and subdomain of it (the “Site”);
- the free tools we publish, including the LinkedIn audit, bio rewriter, follower audit, posting-time tool, viral post predictor and archetype quiz (the “Tools”);
- the Gelee platform and the outbound programs we operate for customers (the “Services”); and
- our sales, marketing, support and recruitment activities, including bookings made through our calendar and applications made through our careers pages.
This Policy does not apply to third-party websites, platforms or applications that we link to or integrate with, including LinkedIn. Their handling of your personal information is governed by their own policies, and we encourage you to read them.
Where we act on the documented instructions of a customer, the customer’s own privacy policy governs the purposes for which your personal information is used. Section 3 explains that division, and Section 16 explains how to be removed regardless of which of us holds the instruction.
2. Who we are, and how to reach us
Gelee AI, Inc. is the entity responsible for the personal information described in this Policy where we act as a controller. We have designated an individual accountable for our compliance with applicable privacy legislation, as required by the Personal Information Protection and Electronic Documents Act(Canada) (“PIPEDA”) and its provincial equivalents. That individual can be reached at anjali@gelee.ai, and correspondence marked “Privacy Officer” will be routed to them.
We will acknowledge a written privacy request within five business days and respond substantively within thirty (30) days, or within the shorter period required by the law applicable to you. Where we require an extension permitted by statute, we will tell you before the original period expires, and we will tell you why.
3. The two roles we play
Gelee handles personal information in two distinct capacities, and your rights differ depending on which one applies. We state both plainly because the distinction is the single most consequential thing in this Policy.
3.1 As a controller
When you visit the Site, use a Tool, book a call, subscribe to our emails, apply for a role or become our customer, we determine why and how your personal information is handled. We are the controller, or in PIPEDA terms the organization accountable for it.
3.2 As a processor, or service provider
When a customer runs an outbound program on our platform, that customer decides who is contacted, on what basis, and with what message. We act on their documented instructions under a written agreement that restricts our use of the information to the provision of the Services. In that capacity we are a processor under the GDPR and UK GDPR, a service provider under the CCPA as amended by the CPRA, and an organization acting on behalf of another under PIPEDA. We do not sell that information, we do not share it for cross-context behavioural advertising, and we do not use it to build products for anyone other than the customer whose instruction it came under.
4. Definitions
- Personal information means information about an identifiable individual, and includes personal data as defined in the GDPR and personal information as defined in the CPRA.
- Prospect means an individual whom a customer has instructed us to identify, evaluate or contact through the Services.
- Signal means a publicly observable event we monitor on a customer’s behalf, such as a funding announcement, a job posting, engagement with a public post, or a repeat visit to that customer’s own website.
- Seat means a LinkedIn account a customer has connected to the Services.
- Do-not-contact list means the suppression records that prevent an individual or organization from being contacted through the Services.
5. Personal information we collect
5.1 Information you give us
- Identity and contact: name, business email address, company, role, telephone number where you provide it, and your LinkedIn profile URL.
- Intake and onboarding: ideal-customer profile, target titles and markets, writing samples used to train a voice model, objection handling notes, calendar link, exclusion lists, and any other content you submit to configure the Services.
- Free-tool inputs: LinkedIn profile URLs, About-section text, post drafts, follower exports, industry, timezone and quiz answers, together with the email address you give to receive a result.
- Booking information: the name and email you enter into our calendar, and the meeting you selected.
- Recruitment: the answers, links and files you submit through our careers pages.
- Correspondence: the content of emails, support requests and messages you send us, and our replies.
- Billing: the business and payment details necessary to invoice a customer. Card details are handled by our payment processor and are not stored by us.
5.2 Information collected automatically
- Usage: pages viewed, links and buttons clicked, referring page, time on page, scroll depth, and the campaign tags present on the link that brought you here.
- Device and network: browser, operating system, device type, screen size, language, approximate location derived from IP address, and the IP address itself, which we hash where we use it for rate limiting.
- Identifiers: the cookie and local-storage values described in Section 9.
5.3 Information about prospects, processed for customers
This is the category most likely to concern a reader who is not our customer, so we set it out in full. On a customer’s instruction we collect and process:
- Professional profile information: name, headline, current role, employer, industry, seniority, location, public follower count and LinkedIn profile URL.
- Employer information: company name, size, sector, website and publicly reported funding history.
- Signals: publicly announced financing events; job postings published by the employer; engagement with public posts, including likes, comments and reposts; membership of public groups; attendance at public events; and public follows of companies or individuals.
- Website visitor identification: where a customer has enabled it on their own website and has represented to us that they have the necessary notice and, where required, consent in place, we receive signals about visits to that website and resolve them to an organization, and where possible to a likely contact at that organization, using third-party identity-resolution providers.
- Interaction history: connection requests, messages sent from a customer’s seat, replies received, message timestamps, and the classification our systems assign to a reply, such as interested, not now, or referred.
- Meeting outcomes: whether a meeting was booked, rescheduled, attended or cancelled.
- Suppression records: the identifiers necessary to keep a do-not-contact instruction working, which we retain even after other data is deleted, because a suppression that is forgotten is not a suppression.
We do not knowingly collect special categories of personal data, such as information revealing racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic or biometric data, health, or sexual orientation, and we instruct customers not to use the Services to target individuals on those bases.
6. How we collect it
- Directly from you, when you complete a form, book a call, email us, or configure the Services.
- Automatically, through cookies, pixels and server logs, as described in Section 9.
- From platforms you authorize, principally LinkedIn, through the integration provider that connects your seat, and from the calendar and CRM systems you elect to connect.
- From publicly accessible sources, including public profiles, public posts, public job boards and public funding announcements. Where PIPEDA’s publicly available information exemption is relied upon, we rely on it only to the extent the source and the use fall within the Regulations Specifying Publicly Available Information.
- From data providers, for company enrichment and website-visitor identification. We require these providers to represent that they have a lawful basis for the data they supply.
- From our customers, when they upload a list, connect a CRM, or give us a suppression list.
7. Why we use it, and our lawful basis
Where the GDPR or UK GDPR applies, we rely on the bases identified below. Where PIPEDA applies, we rely on your express or implied consent, or on an exception permitted by the Act, and we identify the purpose at or before the time of collection.
- To provide and operate the Services, including finding, scoring and contacting prospects on a customer’s instruction, drafting messages, answering replies and booking meetings. Basis: performance of a contract with our customer, and our and our customer’s legitimate interest in direct business-to-business marketing.
- To train a voice model for a single customer on the writing samples that customer provides. The model is scoped to that customer’s account. Basis: performance of a contract. We do not use one customer’s content to train a model available to another.
- To send transactional messages, such as audit results, magic links, and account notices. Basis: performance of a contract, or your request.
- To send our own marketing, where you have asked for it or where an exemption applies. Basis: consent, or legitimate interests. You may withdraw at any time; see Section 8.
- To measure and attribute which pages, posts and buttons lead to enquiries. Basis: consent for non-essential cookies, and legitimate interests for first-party measurement.
- To secure the Services, prevent abuse, enforce rate limits, detect fraud and maintain audit logs. Basis: legitimate interests, and legal obligation.
- To comply with law, respond to lawful requests, and establish, exercise or defend legal claims. Basis: legal obligation, and legitimate interests.
- To assess applications for employment. Basis: steps taken at your request prior to entering a contract.
Where we rely on legitimate interests, we have carried out a balancing assessment and will provide a summary of it on request.
8. Electronic messages, and CASL
Canada’s Anti-Spam Legislation governs commercial electronic messages sent to or from Canada. Where we send a commercial electronic message on our own behalf, we do so on the basis of your express consent or of implied consent arising from an existing business relationship or from the conspicuous publication of your business address in circumstances where the message is relevant to your role. Every such message identifies us, gives our contact information, and contains a functioning unsubscribe mechanism that we honour within ten (10) business days and in practice immediately.
Where we send messages through a customer’s seat, the customer is the sender for the purposes of that legislation and is responsible for the basis on which the message is sent. Our agreements require customers to have that basis, to identify themselves, and to honour withdrawal of consent. We provide the tooling to do so, and Section 16 gives you a route to us directly if a customer does not.
9. Cookies, pixels and similar technologies
- Strictly necessary. Session and security values required for the Site to function and to resist abuse. These cannot be disabled through our interface.
- First-party attribution.
g_attrecords how you first reached us, being the page you landed on, the referring site and any campaign tags on the link, and persists for 180 days.g_sesrecords your most recent visit and the last few articles you opened, and persists for 90 days. If you later give us your email address, these values are stored alongside it so that we can tell which of our work brings people to us. - Analytics. Vercel Analytics, which does not track you across other sites.
- Advertising. The Meta Pixel, used for conversion measurement and for retargeting on Meta platforms. This may constitute a “sale” or “share” of personal information under the CPRA, and California residents may opt out as described in Section 15.
- Local storage. Preferences such as a dismissed prompt or a saved form draft, held on your device.
You may block or delete cookies through your browser. Doing so may degrade the Site. To stop our own attribution cookies specifically, set a g_optout=1 cookie for this domain and we will cease writing them. We honour the Global Privacy Control signal where your browser sends it. Visitors in the European Economic Area, the United Kingdom and Quebec: pending deployment of a consent banner, write to us and we will suppress advertising and attribution technologies for you.
10. Artificial intelligence and automated processing
The Services use large language models to draft and to classify. Prompt content is processed by our model provider under a written agreement that prohibits its use to train that provider’s general models. Drafting is scoped to the customer whose account it belongs to.
We do not make decisions that produce legal effects concerning you, or that similarly significantly affect you, based solely on automated processing. Scoring a prospect and classifying a reply are prioritisation aids; a human customer decides whether to proceed, and a customer may review, edit or stop any message. Where a reply cannot be handled with confidence, it is escalated for human attention rather than answered. Individuals in jurisdictions granting a right to an explanation of automated processing may request one under Section 15.
11. Disclosure, and the providers we use
We do not sell personal information for money. We disclose it only as follows.
- To service providers under written agreement, limited to what each needs: Anthropic (language model inference on prompt content); Supabase (database hosting); Vercel (application hosting and analytics); Upstash (rate-limit cache); Resend (transactional email); iClosed (meeting booking); our LinkedIn integration provider (account connection and message delivery); our identity-resolution and company-enrichment providers; and Meta (advertising measurement through the Pixel).
- To integrations you enable, such as your calendar or CRM, at your direction.
- To our customer, where you are a prospect in a program that customer instructed.
- To professional advisers, being our lawyers, accountants, insurers and auditors, under duties of confidence.
- To public authorities, where compelled by valid legal process, or where necessary to establish, exercise or defend legal claims, or to protect the vital interests of any person. We will notify you of a compelled disclosure unless prohibited from doing so.
- To a successor, in connection with a merger, financing, reorganisation or sale of assets, subject to this Policy continuing to apply, and subject to the notice PIPEDA requires for a business transaction.
12. Transfers outside your country
Gelee AI, Inc. is based in the United States and engages providers located in the United States, Canada and the European Economic Area. Personal information may therefore be stored or processed outside the province, state or country in which you are located, and while it is there, it may be accessible to the courts, law enforcement and national security authorities of that jurisdiction. This paragraph is provided in satisfaction of the transparency obligation PIPEDA imposes in respect of transfers for processing.
For transfers of personal data out of the European Economic Area or the United Kingdom, we rely on the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, or an adequacy decision, as applicable, together with supplementary measures where our transfer assessment identifies the need for them. A copy of the relevant mechanism is available on request.
13. How long we keep it
- Site and analytics data: up to 26 months from collection.
- Free-tool submissions: up to 24 months, for product improvement and abuse prevention, unless you ask us to delete them sooner.
- Marketing contacts: until you withdraw consent, and then only the minimum required to keep you suppressed.
- Customer account data, voice models and conversation history: for the term of the subscription and for thirty (30) days after it ends, after which it is deleted or irreversibly anonymised.
- Prospect and campaign data processed for a customer: for the term of that customer’s subscription and for thirty (30) days after it ends.
- Do-not-contact records: indefinitely, because their entire function is to persist. They contain only what is necessary to recognise a suppression.
- Recruitment records: twelve (12) months from the close of the role, unless you ask us to keep them on file.
- Records required for tax, accounting, insurance or limitation-period purposes: for the period the applicable law requires, which in Ontario is generally not less than seven (7) years for financial records.
- Backups: up to 90 days, after which they expire on their own cycle. A deletion request is applied to live systems immediately and takes effect in backups as those backups expire.
14. How we protect it
We maintain administrative, technical and physical safeguards appropriate to the sensitivity of the information. These include:
- encryption in transit using TLS, and encryption at rest;
- role-based access control on a least-privilege basis;
- tenant isolation enforced at the database layer;
- audit logging of access to customer data;
- secret management outside source control;
- dependency and vulnerability monitoring; and
- confidentiality obligations binding on our personnel and on our providers.
No safeguard is absolute. We do not represent that our systems cannot be compromised, and you should not send us information you would not want disclosed in the event of a breach.
15. Your rights, by where you live
15.1 Everyone
You may ask us what personal information we hold about you, ask us to correct it, ask us to delete it, ask us to stop using it for marketing, and withdraw a consent you have given. Write to anjali@gelee.ai from the address the information is associated with, or tell us enough to let us find you. We will not charge you for a first request, we will not require you to create an account, and we will not treat you differently for having asked.
15.2 Canada
Under PIPEDA and the substantially similar provincial statutes in Alberta, British Columbia and Quebec, you have a right of access to your personal information and a right to have inaccurate information corrected, and a right to challenge our compliance. Under Quebec’s Law 25 you additionally have rights of portability and de-indexing, and a right to be informed where a decision is based exclusively on automated processing. Where we refuse a request in whole or in part, we will tell you why, in writing, and tell you how to complain.
15.3 European Economic Area and United Kingdom
You have the rights of access, rectification, erasure, restriction of processing, data portability and objection, including an absolute right to object to direct marketing, and the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of what came before.
15.4 California
You have the rights to know, to access, to delete, to correct, to opt out of the sale or sharing of personal information, to limit the use of sensitive personal information, and not to be retaliated against for exercising them. We do not sell personal information for money. Our use of the Meta Pixel may constitute sharing for cross-context behavioural advertising, and you may opt out by emailing us, by sending a Global Privacy Control signal, or by disabling advertising cookies. We do not knowingly sell or share the personal information of consumers under sixteen.
15.5 Verification, and authorised agents
We will take reasonable steps to verify your identity before acting, proportionate to the sensitivity of the request, and we will not use verification information for any other purpose. An authorised agent may act for you with written authority that we may confirm with you directly.
16. Being removed from outreach
If you have received a message sent through Gelee and want it to stop, you have three routes and all of them work.
- Reply to the message asking not to be contacted. Our systems treat that as a suppression instruction and stop.
- Use the unsubscribe mechanism where one is present.
- Email anjali@gelee.ai. We will add you to a global do-not-contact list that applies across every program we operate, for every customer, and we will pass your request to the customer whose program contacted you so that they can honour it in their own systems.
A global suppression takes effect within one business day. We keep the minimum identifiers necessary to enforce it, and we keep them for as long as we operate the Services, because deleting them would allow the contact to resume.
17. Children
The Site, the Tools and the Services are directed to businesses and to individuals acting in a professional capacity. They are not directed to anyone under the age of eighteen, and we do not knowingly collect personal information from a child. If you believe a child has provided us with personal information, contact us and we will delete it promptly.
18. Breach notification
We maintain an incident response process. Where a breach of security safeguards creates a real risk of significant harm to an individual, we will report it to the Office of the Privacy Commissioner of Canada and notify affected individuals as soon as feasible, and we will maintain records of every breach as PIPEDA requires. Where the GDPR or UK GDPR applies we will notify the competent supervisory authority within seventy-two (72) hours where the threshold is met, and affected individuals without undue delay where the risk is high. Where we act as a processor, we will notify the customer without undue delay so that they can meet their own obligations.
19. Complaints
Please raise any concern with us first. If you are not satisfied with our response, you may complain to the Office of the Privacy Commissioner of Canada, to your provincial commissioner, to the Information Commissioner’s Office in the United Kingdom, to the supervisory authority of the European Union member state of your residence or place of work, or to the California Privacy Protection Agency, as applicable to you.
20. Changes to this policy
We may amend this Policy. The effective date at the top records the current version, and we keep prior versions. Where a change materially affects how we use personal information already collected, we will give notice by email to account holders or by a notice on the Site before the change takes effect, and where the law requires consent for the new use, we will obtain it.
21. Governing law
This Policy is to be read together with any agreement between you and Gelee. Nothing in it limits a right you have under a statute that cannot be contracted out of, and nothing in it deprives you of the protection of the mandatory law of your place of habitual residence.
22. Contact
Gelee AI, Inc., attention Privacy Officer. anjali@gelee.ai