Privacy Policy

How LeadStream handles account, workspace, and service data.

Effective: August 12, 2026

Scope

This policy applies to LeadStream websites and the LeadStream application.

Workspace customers control the records they add to LeadStream. Users should contact their workspace admin for questions about a specific workspace invite or record.

Data

LeadStream processes account data such as name, email address, membership, authentication state, and activity needed to run the service.

Workspaces may contain property records, people, contact details, notes, campaigns, calls, SMS conversations, tasks, imports, connected Gmail account metadata, linked email thread history, and follow-up history.

The LeadStream mobile app processes the device push token and app installation identifier needed for notifications and incoming calls. Camera, selected photo, microphone, and document access occurs only when the user invokes the corresponding capture, attachment, calling, or file workflow.

When a user connects Gmail, LeadStream may process Gmail message metadata, message bodies, participants, labels, attachments metadata, and attachment bytes requested on demand so the user can use visible Gmail features inside LeadStream.

When a user connects the LeadStream ChatGPT plugin, ChatGPT and OpenAI may receive the user's prompts, requested tool inputs, and bounded LeadStream records returned from that user's workspace for the requested action.

Visual CRM Copilot results may include property addresses and status, contact names and requested contact details, deal status and financial fields, task titles and due dates, tag labels, and short note excerpts. LeadStream sends the richer visual payload only as widget metadata; the conversation-visible result contains a smaller summary, but both are part of the ChatGPT tool result processed by OpenAI.

Use

LeadStream uses data to provide the application, authenticate users, deliver transactional account email, secure the service, troubleshoot issues, and maintain reliability.

LeadStream uses device identifiers and push tokens to route account notifications and incoming calls to the signed-in device. LeadStream does not use mobile device data for advertising or cross-app tracking.

LeadStream uses Google Workspace API data only for visible Gmail product features: private mailbox viewing, manual one-to-one sending and replies, owner-controlled mailbox actions, user-controlled lead linking, linked lead read-only history, sync status, and attachment access requested by the user.

LeadStream does not sell personal information.

LeadStream does not use Google Workspace API data for advertising, retargeting, creditworthiness, lending decisions, or training generalized AI or machine learning models.

Connecting the ChatGPT plugin does not start a background export or synchronization. LeadStream sends workspace data across the MCP connection only when ChatGPT invokes a tool for the connected user.

Providers

LeadStream uses service providers for hosting, authentication, email delivery, calling, SMS, storage, logging, and monitoring.

Providers receive data only as needed to operate the service.

When a user chooses the ChatGPT plugin, OpenAI processes the prompts, tool inputs, and tool results transmitted through ChatGPT under the user's OpenAI account and applicable OpenAI terms and privacy controls.

Google user data sharing and disclosure

LeadStream discloses Google Workspace API data only to the connected Gmail account owner and, when that owner manually links a Gmail thread to a lead, to authenticated users in the same LeadStream workspace who are authorized to view that lead. Unlinked mailbox data is not shared with workspace admins or teammates.

LeadStream may provide Google Workspace API data to infrastructure service providers that host, store, secure, log, or monitor the LeadStream service, but only as needed to provide those services under contractual confidentiality and security obligations. LeadStream may also disclose data when required by law or to protect users, the service, or the public.

LeadStream does not sell Google Workspace API data or transfer it to advertising networks, data brokers, information resellers, or AI model providers. Google Workspace API data is not included in LeadStream ChatGPT plugin tool results sent to OpenAI.

Security

LeadStream uses authenticated access, organization-scoped data, and operational safeguards.

The ChatGPT plugin uses OAuth scopes for read and narrowly authorized write access. LeadStream resolves organization access from the authenticated user's active membership rather than accepting a tenant identifier from ChatGPT.

Google OAuth tokens are stored server-side only, encrypted before persistence, and are not returned to the browser.

Google Workspace API data is transmitted over HTTPS and protected with access controls that keep unlinked Gmail mailbox data private to the connected account owner.

LeadStream keeps redacted audit records for Gmail security review and incident investigation. These records document service actions without storing Gmail subjects, bodies, recipients, attachment filenames, raw headers, OAuth tokens, token ciphertext, raw provider payloads, or authorization codes.

Every LeadStream tool call from ChatGPT creates one bounded security-audit record linked to the connected account and workspace. It records the tool, access type, outcome, time, duration, target category, safe record identifiers, and bounded counts needed for security review and troubleshooting.

ChatGPT security-audit records do not store raw searches, email addresses, phone numbers, mailing addresses, note text, nested update values, prompts, OAuth tokens, or full tool results. A scheduled cleanup deletes these records after 90 days.

Users should protect their credentials and report suspected unauthorized access to their workspace admin.

Google data retention and deletion

Google OAuth tokens are retained only while the Gmail account remains connected. Disconnecting Gmail revokes Google access when possible, permanently deletes stored token material, stops Gmail sync and watch renewal, and deletes all unlinked private mailbox cache from LeadStream.

While Gmail remains connected, unlinked private mailbox cache is retained for a rolling 90 days. Attachment metadata follows the same mailbox or linked-snapshot retention, and attachment bytes are fetched on demand rather than stored by default.

A Gmail thread that the account owner manually links to a lead is retained as CRM history for as long as that linked snapshot remains in the workspace. The Gmail account owner can end this retention at any time by unlinking the thread or deleting the linked snapshot. Disconnecting Gmail alone does not delete a snapshot the owner deliberately shared with a lead.

Gmail account connection metadata may remain as a workspace account record until the workspace data is deleted under the customer agreement or an applicable privacy request. Redacted Gmail security-audit records may be retained for security, legal, and compliance purposes after disconnect; they do not contain Gmail subjects, bodies, recipients, attachment filenames, raw headers, OAuth tokens, token ciphertext, raw provider payloads, or authorization codes.

Requests

Unexpected account invites can be ignored. Invite links expire automatically.

Workspace admins control workspace membership and workspace data requests.

Users can disconnect the LeadStream plugin in ChatGPT to stop future tool access. LeadStream supports OAuth token revocation and does not ask users to share LeadStream passwords with ChatGPT.

Disconnecting stops new ChatGPT tool calls and new audit records. Existing bounded ChatGPT security-audit records are not deleted immediately on disconnect; scheduled cleanup deletes them after 90 days. Contact support@leadstreamapp.com for an account or privacy request.

LeadStream's use and transfer of information received from Google Workspace APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.