Privacy Policy
Last updated: June 10, 2026
Who we are
NightlyX (“we”, “us”) provides autonomous sales-outreach software at nightlyx.co. For data we hold, the controller is NightlyX. Contact: josh@nightlyx.co.What we collect
- Account data — your email address and a hashed password, used to sign you in.
- Workspace content — the campaign profile you write (company, offer, ideal-customer criteria), leads you import or source through connected tools, campaign content, and conversation threads with your prospects.
- Integration keys — API keys you connect (e.g. Instantly, HeyReach, Apollo, MillionVerifier). These are encrypted with AES-256-GCM before they reach the database and are never displayed back or shared.
- Usage data — basic logs needed to run and secure the service (timestamps, rate-limit counters, error logs).
We do not run third-party advertising trackers and we do not sell personal data.
How we use it
- To run your campaigns: drafting outreach in your voice, sending via the platforms you connect, and handling replies.
- To process content with AI providers (OpenAI, Anthropic) — your data is sent to them only to generate your outreach and replies, under their API terms, which exclude using API data to train their models.
- To verify lead email addresses through MillionVerifier and source leads through Apollo, when you connect those tools.
- To secure the service: authentication, rate limiting, abuse prevention, audit logs of agent actions.
Prospect data
If your information is in a NightlyX user's workspace as a prospect, that user is the controller of that data; we process it on their behalf. Every outreach email includes an unsubscribe mechanism, and unsubscribes are honored permanently per workspace. To have your data removed from a specific sender's list, use their unsubscribe link or contact us and we will route the request.Where it lives
Data is stored with Supabase (Postgres) with row-level security isolating every workspace. Hosting is on Vercel. Integration keys are encrypted at rest; transport is TLS everywhere.Your rights
- Export — request a machine-readable copy of your workspace data (GDPR Art. 20) via the in-app GDPR export endpoint or by emailing us.
- Deletion — delete your entire account and every workspace you own from Settings → Account → Delete account. This is immediate and irreversible (GDPR Art. 17).
- Correction & access — edit your data in-app, or contact us.