Legal

Privacy Policy

Last updated: July 26, 2026 · Webeeyo Softwers Pvt. Ltd.

1. Introduction & scope

Stynar is an AI-powered outbound email platform operated by Webeeyo Softwers Pvt. Ltd. ("Webeeyo", "Company", "we", "us", or "our"), a company based in Pune, Maharashtra, India. This Privacy Policy explains how we collect, use, store, and protect information when you use the Stynar web application, APIs, and related services (the "Services").

Depending on the context, we act either as a data controller or a data processor. For your account, billing, and product usage data we act as a controller. For the prospect/lead data and email content you upload and send through Stynar, we act as a processor acting on your instructions — you remain responsible for having a lawful basis to contact those prospects.

By creating an account, connecting a mailbox, or otherwise using the Services, you agree to this Policy. During account registration, you are required to explicitly accept this Policy and our Terms of Service via a dedicated confirmation step. If you do not agree, please do not use the Services. We may update this Policy from time to time; material changes will be communicated in-app or by email, and the "Last updated" date below will change.

2. Information we collect

Account & billing data: your name, email address, hashed password, organization details, tax identifiers (such as GSTIN where applicable), subscription plan, and payment records. We do not store full card numbers — payments are handled by our payment processor.

Connected mailbox data: when you connect Gmail or Outlook via OAuth, or a mailbox via SMTP/IMAP, we store the access/refresh tokens or credentials needed to send on your behalf and to sync replies. Credentials and tokens are encrypted at rest.

Leads & campaign content: prospect records you import (name, email, company, role, and custom fields), the email sequences and templates you create, and the AI prompts and generated copy associated with your campaigns.

Replies & inbox data: messages your prospects send in reply, which we sync into your unified inbox, classify, and analyze for meeting intent so the platform can help you book meetings.

Deliverability & usage data: sending logs, bounce and complaint signals, open/click tracking events, plus standard diagnostic data such as IP address, browser, and audit logs used to secure and operate your workspace.

Consent & preference data: when you create an account, we record your explicit acceptance of the Terms of Service and Privacy Policy, including a timestamp of acceptance. We also store your Cookie Preferences (including any choices made through our Cookie Preferences system) and, where provided, your consent to receive marketing communications. This data is used to honour your preferences and to demonstrate compliance with applicable privacy law.

3. How we use your information

To provide the Services: send your sequences, run automated follow-ups, sync replies into your unified inbox, detect meeting intent and book meetings, and manage your leads and campaigns.

AI personalization: we pass relevant prompt and web-research context to our AI providers (OpenAI and Anthropic) and our web-search provider (Tavily) to generate personalized email content. We use the model you select for each generation.

Deliverability: we use sending and reputation signals to support SPF/DKIM/DMARC setup, gradual volume ramp-up, and inbox-placement health, and to pause sending when we detect problems.

Billing, security & improvement: to process subscriptions and credits, prevent abuse and fraud, and improve the Services using aggregated, de-identified data that does not identify you or your prospects.

4. Legal bases (GDPR) & Indian DPDP Act

Where the GDPR applies (prospects or users in the EEA/UK), we process personal data under one or more of: performance of a contract (to deliver the Services), legitimate interests (to secure and improve the platform and prevent abuse), legal obligation (tax and compliance), and consent (where required, e.g. optional features). Optional browser storage and preference data (such as your selected interface theme) are processed on the basis of consent, managed through our Cookie Preferences system. You can review and update your Cookie Preferences at any time from within the application.

We also operate in line with India's Digital Personal Data Protection Act, 2023 (DPDP). As the processor of your uploaded prospect data, you (the customer) are responsible for ensuring you have a valid lawful basis to contact those individuals.

5. Limited Use disclosure — Google API Services

Stynar's use and transfer of information received from Google APIs (including the Gmail API and Google Calendar API) to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Google Workspace user data accessed through these APIs — including email content, reply threads, and calendar/meeting data — is used solely to provide and improve the specific Stynar features you have requested: sending and scheduling your campaigns, syncing and classifying replies into your unified inbox, detecting meeting intent, and generating AI-assisted email drafts. This data is never sold, and is never used, transferred, or disclosed for advertising or credit-scoring purposes.

Stynar and its AI sub-processors (OpenAI and Anthropic) do not use raw or derived Google Workspace user data to develop, improve, or train generalized or foundational machine-learning or AI models. Any AI processing of this data is limited to generating the specific output you requested within your active session (e.g. a personalized email draft or a reply classification) and is not repurposed for model training.

Human access to Google Workspace user data is restricted to what is necessary for security, legal compliance, or with your explicit consent for support purposes, consistent with the policy referenced above.

6. We never sell your data — sub-processors

We do not sell, rent, or trade your leads, campaign content, replies, or mailbox tokens. We never share your prospect lists with other customers. We only share data with vetted sub-processors needed to run the Services, under appropriate data-processing terms:

• Amazon Web Services (AWS) — cloud hosting, database storage, and authentication.

• Razorpay — payment processing and subscription billing (PCI-DSS compliant).

• OpenAI and Anthropic — AI models used to generate email content and detect meeting intent.

• Tavily — web search used to gather public context for AI personalization.

• Google (Gmail / Google Workspace) and Microsoft (Outlook / Microsoft 365) — OAuth mailbox access for sending and reply sync.

7. Data security

We protect data with industry-standard measures. Connected mailbox credentials and OAuth tokens are encrypted at rest, secrets are held in a managed secrets store rather than in source code, and all data in transit is protected with TLS.

Access to production systems is restricted on a least-privilege basis. Access to customer data follows the same principle — it is restricted to authorized personnel only when necessary to operate, debug, or support the Services. We do not claim any formal certification (such as SOC 2) at this stage; we follow recognized security best practices and continue to strengthen our controls as we grow. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

8. International data transfers

Our infrastructure runs on AWS and certain sub-processors operate outside India. Where personal data of EEA/UK individuals is transferred internationally, we rely on appropriate safeguards such as Standard Contractual Clauses. By using the Services, you understand that your data may be processed in countries other than your own.

9. Data retention

We retain your data for as long as your account is active and as needed to provide the Services. When you delete leads or content, they are removed from active systems within a reasonable period.

On account termination, we delete or anonymize your workspace data within 30 days, except where we must retain limited records to meet legal, tax, or accounting obligations. OAuth tokens are revoked when you disconnect a mailbox or close your account.

You can permanently delete your account directly from the Settings page within the application. Upon deletion, your data will be deleted or anonymized in accordance with the 30-day timeline described above, subject to any records we are legally required to retain.

10. Data governance

Stynar is committed to responsible data governance throughout the data lifecycle. Our data practices are guided by the following principles:

• Data minimisation: we collect only the data necessary to deliver the Services and no more.

• Secure processing: data is handled with appropriate technical and organisational safeguards, including encryption in transit and at rest.

• Retention policies: data is held only for as long as necessary, as described in Section 8, after which it is deleted or anonymized.

• Responsible deletion: when data is no longer needed — whether because a campaign was removed, an account was closed, or a retention period has expired — it is securely deleted or anonymized according to our internal procedures.

11. Your rights

Subject to applicable law, you may request to access, correct, export, or delete your personal data, and to restrict or object to certain processing. Much of this is available directly in your account settings (for example, exporting or deleting leads, or permanently deleting your account from the Settings page).

To exercise any right, email privacy@stynar.email from your registered email address. Identity verification may be required before we fulfil your request. We respond within the timelines required by applicable law.

12. Cookies & tracking

Stynar uses essential first-party cookies and browser storage technologies (including localStorage) required for authentication, session management, application security, and core functionality. These are strictly necessary for the Services to operate and do not require consent.

Optional Preferences storage is used only when you grant consent through our Cookie Preferences system. For example, your selected interface theme may be stored in browser storage so it persists across sessions. You can review and change your Cookie Preferences at any time from within the application.

Stynar currently does not use Analytics or Marketing cookies. We do not place advertising trackers, third-party analytics pixels, or cross-site tracking technologies.

When you enable open or click tracking on a campaign, Stynar adds a tracking pixel or rewrites links so we can report opens and clicks to you. You can turn tracking off per campaign in your sending settings.

13. Contact us

If you have questions or requests about this Privacy Policy or your data, contact us:

• Company: Webeeyo Softwers Pvt. Ltd. (operating Stynar)

• Location: Pune, Maharashtra, India

• Privacy: privacy@stynar.email

• General: hello@stynar.email

Questions or data requests? Contact us →