Privacy Policy
Effective date: August 1, 2026

Contact Gleaner (“Contact Gleaner,” “we,” “us,” or “our”) is a service operated by TMR Solutions LLC, a North Carolina limited liability company. This Privacy Policy explains what information we access, how we use it, who we share it with, and the choices you have. You accept this Privacy Policy by affirmatively accepting it when prompted — for example, by reviewing it and selecting “I attest & agree” in the acceptance dialog that Contact Gleaner presents when you sign in, and again whenever it is materially updated. By doing so, the user attests and covenants that they have read, understood, and agreed to this policy.
1. Who we are
TMR Solutions LLC operates Contact Gleaner at www.contactgleaner.com. For any privacy question, contact us at support@contactgleaner.com.
2. Geographic scope and eligibility
Contact Gleaner is offered exclusively to users who are not residents of, and are not physically located in, the State of California or any member state of the European Union or European Economic Area (“Excluded Jurisdictions”). The Service is not directed at, and may not be used by, California consumers or residents as defined under the California Consumer Privacy Act (CCPA), or by residents or data subjects located in the EU or EEA.
The user attests and covenants that at the time of registration and at all times during use of the Service: (a) they are not a California resident or consumer; (b) they are not physically located in California, the EU, or the EEA; and (c) they are not accessing the Service on behalf of a person or entity located in any Excluded Jurisdiction. If you become a resident of an Excluded Jurisdiction after registering, you must immediately discontinue use of the Service and contact us at support@contactgleaner.com to close your account.
TMR Solutions LLC reserves the right to terminate accounts of users who are or become residents of Excluded Jurisdictions. This restriction will be revisited and updated as the Service expands its geographic offering.
3. What Contact Gleaner does
Contact Gleaner connects to your email mailbox, reads the email signatures and contact details in your messages and calendar, uses AI to extract names, titles, companies, phone numbers, and email addresses, and then saves the approved results as contacts in your own address book at that same provider. The goal is simple: contacts you already received in email appear in your address book without manual typing. Contact Gleaner also reads the contacts you already have so it recognizes them and does not add them a second time, and it reads your working-hours setting so it can run scans around your workday.
Supported mailbox providers. The Service works with the mailbox providers listed below. We may add providers over time; this list is updated when we do. Where this policy refers to “your connected account,” it means the mailbox provider account you connect from this list, and the mailbox, calendar, and address book in that account.
- Microsoft — Microsoft 365 / Outlook work or school accounts, and personal Microsoft accounts (Outlook.com, Hotmail, Live).
- Google — Gmail and Google Workspace accounts, where Google sign-in is enabled for your account. Google user data is subject to the additional disclosures in §4a.
4. Information we access and store
Information you provide
- Your name and email address, provided by your mailbox provider when you sign in.
- Payment information, which you enter directly with our payment processor, Stripe. We never see or store your full card number.
- Anything you send us through the feedback form (your message, optional screenshot, and email address).
Information we access from your mailbox
With your permission (granted when you sign in with your mailbox provider), we access your email messages, calendar events, and contacts in order to find and extract contact details. We request the minimum permissions needed: read access to mail and calendar, read/write access to contacts (so we can add the contacts you approve), and, where your provider offers it, read access to your mailbox settings (for the working-hours setting described below). We do not request permission to send email or modify your messages. The exact permissions differ by provider — for Microsoft accounts these are Microsoft Graph permissions; for Google accounts, see §4a, which lists each permission and why it is needed.
To schedule scans around your workday, we also read your working-hours setting — your working days, start and end times, and time zone — where your provider makes it available (for Microsoft accounts, the MailboxSettings.Read Graph permission). We use this only to time scans, and for no other purpose.
So that we never add a contact you already have, Contact Gleaner reads your existing contacts (your address book) using the contacts permission you already grant when you connect your account — no additional permission is requested for this. We recognize the people you already have so we do not add them to your contacts a second time. When an incoming email contains details for someone already in your contacts that you did not previously have — for example a phone number or job title — we surface it for you to approve; we do not change your existing contacts without your action (unless you turn on Fully Automatic — see §6a). To do this we store a copy of your contacts and a privacy-preserving index of their email addresses (hashed — never kept as readable text), encrypted at rest. This information comes only from your own mailbox, never from data brokers or third parties.
What we keep in our own system
- Your account record: your mailbox provider user ID, email, display name, and subscription tier.
- Mailbox access tokens: stored encrypted at rest so the service can scan on your behalf. These are never shown in our app or shared.
- Extracted contact data: the contact details we pull from your mailbox so we can de-duplicate and avoid re-processing the same items.
- Billing records: your Stripe customer and subscription identifiers and plan status (not card numbers).
- Feedback submissions: messages you choose to send us.
- A copy of your existing contacts and a hashed index of their email addresses, so we can recognize people you already have and avoid adding duplicates (encrypted at rest).
- Your settings and preferences: communication and digest preferences, automation settings, time zone and working hours, and connection-status timestamps.
Sign-in and security logs
Each time someone attempts to sign in to Contact Gleaner — including attempts that do not result in an account — we record information about the attempt: the email address used, its organization domain, the organization and user identifiers supplied by the mailbox provider, the IP address, the result of the attempt and technical details of the attempt (such as an error code), and the date and time. We use this to protect the Service against abuse and fraud and to understand interest in the Service. We do not store the person’s name in these records. We retain records of sign-in attempts that do not result in an account for up to six (6) months and then delete them; records of successful sign-ins are part of your account activity and are kept as described elsewhere in this policy.
4a. Google user data (Gmail, Contacts, and Calendar)
This section applies if you connect a Google account (Gmail or Google Workspace). It describes specifically how Contact Gleaner accesses, uses, stores, and shares Google user data, and it applies in addition to the rest of this policy. If you do not connect a Google account, Contact Gleaner does not access any Google user data about you.
What we access, and why each permission is needed
Contact Gleaner requests only the permissions below. We request no other Google permissions.
gmail.readonly— read your Gmail messages. We read the content of your messages for one purpose: to find contact details in email signatures. Signatures appear in the body of a message, so a narrower permission that reads only headers or metadata (such asgmail.metadata) cannot provide this feature. We do not send, modify, or delete your mail.contacts— read and write your Google Contacts. We read your existing contacts so that we recognize people you already have and do not add them a second time, and we create or update the contacts you approve. We do not delete contacts.calendar.readonly— read your Google Calendar. We read event attendees so we can capture the people you meet with. We do not create or change events.openid,userinfo.email,userinfo.profile— sign-in identity. Your name and email address, used to identify your account and to make sure your own signature is never saved to you as a contact.
How we use it
We use Google user data only to provide the contact-extraction features described in this policy — the features that are the visible purpose of Contact Gleaner: finding contact details in your mail and calendar, showing them to you for approval, and saving the ones you approve to your Google Contacts. We do not use Google user data for advertising, we do not sell it, and we do not use it to build profiles or to determine creditworthiness.
How we store it
We do not store the full content of your Gmail messages. Message content is read, parsed for a signature, and discarded; what we retain is the extracted contact details (such as name, title, company, phone, and email address), encrypted at rest. We also store your Google access tokens, encrypted at rest, so the Service can scan on your behalf; a copy of your existing contacts and a hashed index of their email addresses, so we can avoid creating duplicates; and, so that we never process the same message twice, the identifier of each message or calendar event we have already handled — an identifier only, never the subject, body, or a snippet of a message.
How we share it
We share Google user data only as needed to provide the features above:
- Anthropic — to find a signature, we send text from your message to Anthropic’s Claude AI, which extracts the contact details from it. When we can locate the sender’s own signature — either because the message declares it, or because their sign-off line marks where it starts — that signature is the only text that leaves your tenant; your correspondence never goes to the AI at all. This applies to a meaningful share of messages. Otherwise we send up to 1,500 characters of the message: we remove formatting and, in the normal case, quoted reply chains, and truncate the text to that length. Because a signature can appear anywhere in a message when we cannot locate it this way, the text we send in that case is the body text of the message, not only the signature block itself. This is a reduction in how much of your message’s business content we send, not a reduction in the sensitivity of what we send — a signature is typically the most identifying part of a message, so limiting to it concentrates identifying details rather than diluting them. We send message text to Anthropic for this parsing step and for no other purpose. This step cannot be separated from the feature. Anthropic acts as our service provider, and it does not use this data to train its models on our behalf.
- Railway — our application hosting and database provider, where the extracted data described above is stored, encrypted at rest.
We do not transfer Google user data to any other third party, except where required by law, where necessary to investigate abuse or a security issue, or in connection with a merger or acquisition after providing notice and obtaining your consent as required by Google’s policies.
Limited Use
Contact Gleaner’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We limit our use of Google user data to providing and improving the user-facing features that are prominent in Contact Gleaner’s interface, as described above.
- We do not transfer Google user data except as necessary to provide or improve those features (the service providers named above), to comply with applicable law, or as part of a merger or acquisition in accordance with Google’s requirements.
- We do not allow humans to read your Google user data, except: where you have given us affirmative agreement to do so (for example, if you ask us for support on a specific contact or message); where it is necessary for security purposes, to investigate abuse, or to comply with applicable law; or where the data has been aggregated and anonymized for internal operations. Routine signature parsing is performed by automated systems, not by a person reading your mail.
- We do not use Google user data to serve advertisements, and we do not sell it or transfer it for any other purpose.
Your controls
You can disconnect your Google account at any time from your Google Account permissions page at myaccount.google.com/permissions, which immediately stops all scanning. Deletion of your data is handled as described in §8.
4b. Relationship Insights
Contact Gleaner offers an optional Relationship Insights page, available on paid plans, that summarizes patterns in how you communicate with your contacts — for example, who you exchange email with most often, how long it has been since your last exchange or meeting with someone, and which established contacts have gone quiet. This is a separate use of your connected account’s data from the contact-extraction features described in §4: it analyzes the pattern of your communication over time rather than extracting details from individual messages. Both uses are limited to your own connected account, and how much of your mailbox history we process is governed by your subscription plan and any additional features you have subscribed to or purchased — higher tiers and add-on features (such as Deep Glean, which scans further back through your mailbox) cover more of your history, and the interaction log described below reflects whatever depth of scanning your plan and features provide.
To power this page we keep a log of interaction events built from message and calendar metadata: for each message or meeting, a one-way cryptographic hash of the other person’s email address (never the readable address), whether the message was sent or received (or that a meeting occurred), the message or meeting’s actual date and time, a hash of the conversation thread identifier, and nothing else. This log does not contain message subjects, message bodies, contact names, or readable email addresses. We begin building this log when you connect your account, whatever your plan — including the free tier — so that if you later subscribe, your insights are available immediately rather than requiring your mailbox history to be re-scanned. The log is built once from your existing mailbox history, reaching back up to the deepest scan depth the Service offers (currently up to five years): we read each message’s sender/recipient addresses and its date and time (and each calendar event’s attendees and start time) — the same metadata fields described above, and nothing more — and record them in the hashed form described above. After that the log accrues from the scanning your plan and features provide — the regular scans described in §4, and any deeper scanning included in your subscription or add-on purchases (such as Deep Glean, whose deeper reach extends your relationship history correspondingly) — so interactions those scans discover are added to the log as they are found, however far back they occurred. We retain this log for as long as you have an account; it is deleted with the rest of your data as described in §8. Aggregated per-contact statistics derived from this log (counts, most-recent dates) are stored the same way, keyed by the same one-way hash.
The Insights page includes a Draft button that uses Anthropic’s Claude AI to suggest a short opening line for re-engaging a contact. This runs only when you click it, and it is composed only from information Contact Gleaner already holds under §4 and §5 — the contact’s name, title, and company as extracted from your mail, how long it has been since your last contact, and any job-change history we have surfaced to you — never from reading additional messages. Anthropic processes this data as our service provider under the same terms described in §6. Nothing is sent to anyone, and no draft is ever emailed, without your action.
4c. IT-approval request tool (marketing site)
Our website offers a “Request IT approval” tool for visitors whose Microsoft 365 tenant requires administrator approval before they can sign in. This tool opens a pre-written email in the visitor’s own email application and does not itself collect any information. If the visitor checks the accompanying box (checked by default, and always visible before anything is sent), we separately store the email address they provide and the domain derived from it, so we can follow up if their approval process stalls. This applies whether or not the visitor ever signs in to or subscribes to the Service — it is collected from the marketing website itself, independent of the account-related information described in §4. We retain this information for up to twelve (12) months, or until the visitor asks us to delete it, whichever comes first; contact support@contactgleaner.com to opt out or request deletion at any time.
5. How we use your information
- To scan your mailbox and extract contact details.
- To write approved contacts back to your connected account.
- To run your account, process payments, and provide support.
- To schedule scans around your working hours and time zone.
- To improve the reliability and accuracy of the service.
- To send you service-related messages — for example, billing or support replies, an optional periodic Morning Update / Roundup summarizing the contacts we found or saved (you choose the frequency, or turn it off), and occasional service notices such as a prompt to reconnect your mailbox if your connection lapses.
We do not sell your data, and we do not use the contents of your mailbox for advertising.
6. AI processing
We use Anthropic’s Claude AI to read email signatures and extract contact details. Text from your messages is sent to Anthropic only for this signature-parsing step. We do not use external data brokers or third-party lookups to enrich contacts. Anthropic processes this data as our service provider and does not use it to train its models on our behalf. The user attests and covenants that they understand AI-generated contact details may contain errors and that they accept responsibility for reviewing all extracted contacts before use.
6a. Automated processing and Fully Automatic mode
If you turn on Fully Automatic mode, you authorize Contact Gleaner to save new contacts and apply updates to the contacts in your connected account on your behalf, without reviewing each one first. We only auto-save contacts we can complete with confidence; possible duplicates and incomplete entries are held for your manual review. You can turn Fully Automatic off at any time, and we ask you to confirm the setting each month. This is automated processing that you control; it produces no legal or similarly significant effects. When Fully Automatic is off, nothing is written to your contacts without your explicit approval of each one.
7. Who we share information with (subprocessors)
We share data only with the service providers needed to run Contact Gleaner. A current list with links to each provider’s terms and privacy policy is published at contactgleaner.com/third-party. Current subprocessors:
- Microsoft — where you connect a Microsoft account: the source of your mail/calendar/contacts and your sign-in identity.
- Google — where you connect a Google account: the source of your mail/calendar/contacts and your sign-in identity (see §4a).
- Anthropic — AI signature parsing (see above).
- Railway — application hosting and our PostgreSQL database.
- Vercel — hosting of our website front-end.
- Stripe — payment processing.
- Resend — delivery of transactional and support email.
- Sentry — error monitoring and telemetry.
We may also disclose information if required by law, or to protect the rights, safety, or property of our users or TMR Solutions LLC.
8. Data retention
Upon cancellation or deletion of your account, your personal data will become immediately inaccessible. TMR Solutions LLC will permanently delete your stored data — including extracted contact data and mailbox access tokens — within sixty (60) days, and in no event more than ninety (90) days, except where a longer retention period is required by law, legal hold, dispute resolution, or is otherwise determined to be necessary at the discretion of TMR Solutions LLC. The user attests and covenants that they understand this deletion is irreversible and that TMR Solutions LLC has no obligation to retain or recover deleted data. Limited billing records may be retained longer where required for tax, accounting, or legal purposes. We also retain a record of your acceptance of our Terms of Service and this Privacy Policy — including the date and time, the version of each document you accepted, and the IP address used — for the life of the Service and for as long as needed to establish or defend legal claims, even after your account is deleted. Contacts already written to your connected account remain yours and are unaffected by deletion of your Contact Gleaner account.
Organization accounts and the Company Contact Vault. Where your organization uses the Company Contact Vault, contacts contributed to the Vault are the organization’s records, not the individual contributor’s. Deleting an individual user’s account removes that user’s personal data — including their mailbox access tokens and personal review queue — but does not delete records already contributed to the organization’s Vault. Vault records are retained for the life of the organization’s subscription and deleted within sixty (60) days, and in no event more than ninety (90) days, after the organization’s subscription is cancelled or terminated, except where a longer period is required by law, legal hold, or dispute resolution — see the Company Contact Vault Terms for the full detail. TMR will remove a specific Vault record on a legitimate, verified erasure request, including one from the individual the record describes, within sixty (60) days, and in no event more than ninety (90) days.
9. Your rights and choices
- Disconnect at any time: the user attests and covenants that they understand they may revoke Contact Gleaner’s access from their mailbox provider’s account security settings at any time (for Google accounts, at myaccount.google.com/permissions), which immediately stops all scanning.
- Access, export, or delete your data: contact support@contactgleaner.com and we will help you access, export, or delete your personal data. Records held in an organization’s Company Contact Vault are the organization’s records; requests concerning those are handled under Section 8 and the organization’s agreement.
- Users outside the Excluded Jurisdictions defined in §2 who have questions about their data rights may contact us at support@contactgleaner.com.
10. Security
We protect your data with industry-standard measures: encrypted connections (HTTPS), mailbox access tokens encrypted at rest, OAuth-only sign-in (we never store a password), rate limiting, and least-privilege access permissions. No system is perfectly secure, but we work to safeguard your information and limit what we collect.
10a. Breach notification
In the event of a security incident that results in unauthorized access to or disclosure of your personal data, TMR Solutions LLC will notify affected users within 30 days of becoming aware of the breach. Notice will be sent to the email address on file for your account. TMR Solutions LLC will take reasonable steps to investigate and remediate any confirmed breach.
11. International users
Contact Gleaner is operated from the United States, and your information is processed and stored in the United States. As set forth in §2, the Service is not available to EU or EEA residents. Users accessing the service from outside the U.S. (and outside the Excluded Jurisdictions) attest and covenant that they consent to this transfer and processing.
12. Children
Contact Gleaner is a business tool not intended for anyone under 18, and we do not knowingly collect data from children. The user attests and covenants that they are 18 years of age or older.
13. Changes to this policy
We may update this policy from time to time. When we do, we will revise the effective date above and, for material changes, provide additional notice.
14. Contact us
Questions about privacy? Email support@contactgleaner.com or write to TMR Solutions LLC, North Carolina, USA.