Privacy Policy

Last updated: June 10, 2026

Who we are

NightlyX (“we”, “us”) provides autonomous sales-outreach software at nightlyx.co. For data we hold, the controller is NightlyX. Contact: josh@nightlyx.co.

What we collect

  • Account data — your email address and a hashed password, used to sign you in.
  • Workspace content — the campaign profile you write (company, offer, ideal-customer criteria), leads you import or source through connected tools, campaign content, and conversation threads with your prospects.
  • Integration keys — API keys you connect (e.g. Instantly, HeyReach, Apollo, MillionVerifier). These are encrypted with AES-256-GCM before they reach the database and are never displayed back or shared.
  • Usage data — basic logs needed to run and secure the service (timestamps, rate-limit counters, error logs).

We do not run third-party advertising trackers and we do not sell personal data.

How we use it

  • To run your campaigns: drafting outreach in your voice, sending via the platforms you connect, and handling replies.
  • To process content with AI providers (OpenAI, Anthropic) — your data is sent to them only to generate your outreach and replies, under their API terms, which exclude using API data to train their models.
  • To verify lead email addresses through MillionVerifier and source leads through Apollo, when you connect those tools.
  • To secure the service: authentication, rate limiting, abuse prevention, audit logs of agent actions.

Prospect data

If your information is in a NightlyX user's workspace as a prospect, that user is the controller of that data; we process it on their behalf. Every outreach email includes an unsubscribe mechanism, and unsubscribes are honored permanently per workspace. To have your data removed from a specific sender's list, use their unsubscribe link or contact us and we will route the request.

Where it lives

Data is stored with Supabase (Postgres) with row-level security isolating every workspace. Hosting is on Vercel. Integration keys are encrypted at rest; transport is TLS everywhere.

Your rights

  • Export — request a machine-readable copy of your workspace data (GDPR Art. 20) via the in-app GDPR export endpoint or by emailing us.
  • Deletion — delete your entire account and every workspace you own from Settings → Account → Delete account. This is immediate and irreversible (GDPR Art. 17).
  • Correction & access — edit your data in-app, or contact us.

Retention

We keep your data while your account exists. Deleting your account removes your workspaces, leads, campaigns, conversations, and integration keys immediately. Backups roll off within 30 days.

Changes

We'll update this page when our practices change and adjust the date above. Material changes will be announced in-app.