← BACK TO LEAD SCRAPER

Privacy policy

Most of Lead Scraper runs on your own Mac and sends us nothing. This page is specific about the parts that don't.

LAST UPDATED 27 JULY 2026

The short version

  • Scraping runs on your Mac, over your connection. We never see which businesses you searched for.
  • Email drafting runs on your Mac via Apple Intelligence. Prompts and drafts are never transmitted anywhere.
  • On the free plan, nothing you scrape leaves your Mac at all.
  • On Solo and Pro, your leads and notes sync to our database so your other Macs can read them. That is the only reason we hold them.
  • We do not sell your data, and there are no advertising or analytics trackers on this website.

Who we are

Kollin Croyle operates Lead Scraper and is the data controller for the information described here. Reach us — including for any request under this policy — at cybertec44@yahoo.com.

What we collect

Your account. An email address and a password, which is hashed by our authentication provider and never stored or seen in readable form. If you sign in with Google we receive your email address and the name on your Google profile, nothing else. A company name and postal address, only if you enter them.

Billing. Stripe processes payments. Card numbers never reach our servers. We store the Stripe customer and subscription identifiers, your plan, its status, and when the current period ends.

Scrape count. Free accounts get 10 scrapes per calendar month, so we store a number: how many you have used this month. Not what you searched for, not where, not what came back. The counter has to live on our server because one kept on your Mac would be a file you could delete.

Synced data, on paid plans only. If you are on Solo or Pro, the app uploads a copy of your scrape results and CRM state so your other Macs can read them: business names, addresses, phone numbers, websites and ratings from public listings; your own contact statuses, notes and reminders; your outreach sequences and their contents; your saved scraping defaults and schedule.

What never reaches us

  • The contents of your scrapes, on the free plan. Sync is a paid feature and is inert without it.
  • Anything Apple Intelligence writes. Drafting happens on-device; no prompt, draft or lead ever goes to us or to a model vendor.
  • Your emails. Mail is sent through your own mailbox, under your own domain, and does not pass through our infrastructure.
  • Your card details. Stripe holds those.

This website

No analytics, no advertising pixels, no third-party trackers, and no cookies. Fonts are served from this site rather than a font provider, so nobody else learns that you visited. The only thing stored in your browser is whether you chose the light or dark theme, kept in local storage on your own device.

Who processes it

  • Supabase — database, authentication and file storage, hosted in the United States (us-east-1).
  • Stripe — payments and subscription billing.
  • Google — only if you choose to sign in with a Google account.

If you are in the UK or EEA, using the service means your data is transferred to and stored in the United States under the relevant standard contractual clauses.

Why we are allowed to hold it

Your account and billing records are processed to perform the contract between us — you cannot have an account without them. The scrape counter is processed on our legitimate interest in enforcing the limits of a free plan. Synced data is processed to perform the contract for a feature you chose to pay for, and stops the moment you stop syncing.

How long we keep it

Account and synced data are kept while your account exists. Ask us to delete the account and both go, from live systems immediately and from encrypted backups as those age out, within 30 days. Billing records are kept for as long as tax and accounting law requires, which is longer, and cannot be deleted on request.

Your rights

You can ask for a copy of what we hold, ask us to correct it, or ask us to delete it — email cybertec44@yahoo.com from the address on the account and we will action it within 30 days. You can export your leads to CSV from inside the app at any time without asking us. If you are in the UK or EEA you can complain to your data protection authority; if you are in California you have the rights described in the CCPA, including the right not to be discriminated against for exercising them. We do not sell personal information.

The businesses you scrape

Lead Scraper collects business contact details from public listings. Those businesses are not our users and have no account with us. When you scrape, contact or email them, you are the controller of that data and the obligations are yours — including CAN-SPAM in the United States, and a lawful basis, source disclosure and erasure handling under GDPR if any recipient is in the UK or EEA.

If a business contacts us directly about data held in a customer’s synced account, we will pass the request to that customer, since we cannot act on their behalf.

Security

Every table is protected by row-level security keyed to your user id, enforced by the database rather than by the app — a bug in the client cannot expose another customer’s leads. Session tokens are stored in the macOS Keychain, not in preference files. The administrative key that bypasses those rules exists only on the server and is never shipped in the app. All traffic is encrypted in transit.

No system is perfect. If we discover a breach affecting your data we will tell you and the relevant regulator without undue delay, and within 72 hours where the law requires it.

Children

Lead Scraper is a business tool and is not directed at anyone under 16. We do not knowingly collect their data; if we learn we have, we delete it.

Changes

If this policy changes in a way that materially affects you, we will email the address on your account before it takes effect. The date at the top always reflects the current version. This policy is governed by the laws of the State of Florida, United States.