Privacy Policy
Lede is a tool for finding journalists and sending them pitches. This policy explains what information Lede collects, why it collects it, who it is shared with, and how you remove it. It applies to the Lede web application at app.trylede.co and the API that serves it.
Information we collect
Account information. When you create an account we receive your name, email address, and profile image from our authentication provider, Clerk. If you sign in with Google or Microsoft, we receive only your basic profile and email address from that sign-in — never your password.
Campaign content. Everything you put into Lede in order to produce a pitch: the description of your announcement, press release text, talking points, spokesperson details, embargo dates, boilerplate, and any files you attach.
Journalist records. Names, outlets, job titles, beats, published work, public social profiles, and work email addresses of journalists, gathered from public web sources and from information you enter yourself. Journalists are the subject of this data rather than users of Lede; see “Journalist data” below.
Pitch and outreach records. The subject line and body of each pitch you send, the recipient address, the time it was sent, and its delivery status. Where a reply, open, or bounce is detected, we store the message identifiers that link it to your pitch, the subject line, and an excerpt of the reply so you can see it inside Lede.
Technical information. Standard server logs, and error reports collected by Sentry when something breaks. Error reports may incidentally include the URL you were on and your account identifier.
Lede does not use advertising trackers, does not sell personal information, and does not build advertising profiles.
Google user data
Connecting a Gmail account is optional. Lede works without it; connecting one lets Lede send your pitches from your own address so that replies land in your own inbox.
When you connect Gmail, Lede requests exactly these scopes and no others: https://www.googleapis.com/auth/gmail.send, which permits sending mail on your behalf and grants no ability whatsoever to read, list, search, download, or delete anything in your mailbox; and userinfo.email with userinfo.profile, which identify which account you connected so we can label it in the interface and stop you from connecting the same mailbox twice.
What Lede does with it. The access token is used for one operation: sending a pitch or follow-up that you have reviewed, at the moment you press send. Nothing is sent without an explicit action by you. A copy of each sent message appears in your own Gmail Sent folder, because it was genuinely sent by your account.
What Lede stores. Your Google email address, the OAuth tokens needed to keep the connection alive, and, for each message we send, the message identifier Gmail returns. Tokens are held by our email infrastructure provider, Aurinko, and are never displayed to anyone, including us. We store no message bodies retrieved from Gmail, because we have no permission to retrieve any.
Disconnecting. You can disconnect Gmail at any time from Settings inside Lede, which deletes the stored connection and revokes the token. You can independently revoke access from your Google account’s security settings at myaccount.google.com/permissions. Revoking stops all future sending immediately; records of pitches already sent remain in your Lede account until you delete them.
Limited Use. Lede’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: we do not transfer or sell Google user data to third parties for advertising, market research, or credit assessment; we do not use it to serve advertisements; and no human reads it except where you have explicitly asked us to for support, where it is necessary for security purposes or to comply with applicable law, or where the data has been aggregated and anonymised.
Microsoft and Outlook
The same arrangement applies if you connect an Outlook or Microsoft 365 account: Lede requests permission to send mail on your behalf, uses it only when you press send, and stores the connection until you disconnect it. Microsoft account permissions can be reviewed and revoked at myaccount.microsoft.com.
How we use your information
To run the product you signed up for: to find journalists who plausibly cover your subject, to draft pitches you then edit, to send those pitches from your connected mailbox, to show you what happened to each one, and to improve the ranking of suggestions based on which journalists you accept and reject. We also use it to keep the service running securely, to diagnose faults, and to contact you about your account. We do not use your campaign content or your correspondence to train third-party AI models.
Service providers
Lede is a small product built on other companies’ infrastructure. The following providers process data on our behalf, each limited to what their function requires: Clerk for authentication and account management; Aurinko for the mailbox connection and message sending; Google (Gemini) for generating pitch drafts and classifying replies; Tavily for the web searches used to research journalists; Railway for application hosting and the database; Vercel for hosting the web front end; and Sentry for error monitoring. Each acts as a processor under contract and is not permitted to use your data for its own purposes. We do not otherwise share, rent, or sell your information; we may disclose it if compelled by valid legal process, and we would tell you unless prohibited from doing so.
Journalist data
Lede holds professional contact information about journalists — their work email, outlet, and published work — for the legitimate purpose of connecting them with sources relevant to their beat. This is business contact information, gathered from public sources and from what users supply. A journalist who wants their record removed can write to support@trylede.co and we will remove them from our records and suppress them from future suggestions. Users of Lede remain responsible for their own compliance with the rules on unsolicited email in their jurisdiction.
Retention and deletion
We keep your data for as long as your account is open. Deleting a campaign removes its pitches, journalist cards, and outreach records. Deleting your account removes everything associated with it from our production database within thirty days; encrypted backups roll off within a further ninety days. To delete your account, write to support@trylede.co.
Security
Data is encrypted in transit with TLS and at rest by our hosting providers. Mailbox credentials are held by Aurinko rather than in our own database wherever the integration permits, access to production systems is limited to the operator of the service and protected by multi-factor authentication, and every request to the API is authenticated and scoped to the requesting account. No system is perfectly secure; if a breach affects your data we will notify you promptly.
Your rights
You can ask us for a copy of the data we hold about you, ask us to correct it, or ask us to delete it. If you are in the UK, EEA, or a US state with comparable law, you also have the right to object to processing and to lodge a complaint with your data protection authority. Write to support@trylede.co and we will respond within thirty days.
Children
Lede is a business tool and is not directed at anyone under 16.
International transfers
Lede’s infrastructure and its providers operate in the United States and the European Union. If you use Lede from elsewhere, your information will be transferred to and processed in those places under the standard contractual protections our providers offer.
Changes
If this policy changes in a way that materially affects how we treat your information, we will update the date at the top of this page and email account holders before the change takes effect.
Contact
Questions about this policy, or about anything Lede holds about you, go to support@trylede.co.