1. Who we are
The service known as Milo is operated by Stallwart, with a registered address at Coimbatore, Tamil Nadu, India. In this policy “we”, “us” and “our” refer to that entity. For personal data covered by the EU or UK GDPR, we act as the data controller for the information you provide about yourself and as a data processor for the information you place in your workspace about your prospects.
Questions or requests about privacy go to stallwartofficial@gmail.com. We aim to respond within seven business days and always within the statutory response window.
2. Scope of this policy
This policy covers the Milo marketing site, the Milo application, and the background services that make the product work (email sending, research, billing, and support). It does not cover third-party sites we link to or the internal email systems of the recipients of your outreach.
3. What we collect
We collect the least amount of personal data we need to run the service. Concretely:
Account information
Your name, email address, and password hash (via our authentication provider). We never see or store your password in plain text.
Company profile
The information you enter or that we extract from your public website during onboarding: what you sell, your voice, your logo and accent color, and the physical address you place at the bottom of outbound email (required by CAN-SPAM and by most equivalent laws).
Mailbox credentials (OAuth)
When you connect Gmail or Outlook we receive OAuth access and refresh tokens from Google or Microsoft. We store them encrypted with AES-256-GCM at rest and use them only to send messages you have approved, read the threads you have started, and refresh access when a token expires. We never read your inbox at large. You can disconnect a mailbox at any time from the app, which revokes and deletes the tokens.
Prospect and lead data
Business names, categories, ratings, review excerpts, addresses, phone numbers, and publicly-listed contact emails discovered from public business directories and public business websites. This is business information anyone can look up. Where those records include a natural person’s contact detail (for example the owner’s public email), we treat it as personal data under the GDPR and honor the rights below.
Message content
The subject and body of every outbound email you draft, send, or receive through the service. We store it so you can review, edit, approve, and track replies. Replies fetched from your mailbox are stored in your workspace only.
Billing information
When you buy credits we receive the amount, the pack, the currency, and a Stripe customer identifier. Card numbers are never sent to us. Stripe processes and stores that information directly under its own privacy terms.
Usage and technical data
Pages viewed, actions taken, error reports, IP address, browser user agent, device type, and timestamps. We use this to diagnose problems, prevent abuse, and improve the product.
What we do not collect
- We do not sell personal data.
- We do not use your prospects, drafts, or replies to train third-party models.
- We do not read messages in your mailbox outside the threads you have started.
- We do not run advertising trackers on the marketing site.
4. How we use it
We use personal data only for the following purposes:
- Deliver the service. Sign you in, run discovery, research prospects, draft messages, send messages from your mailbox, ingest replies, and keep an accurate account of the work performed.
- Meter and bill fairly. Track credit consumption per action so you only pay when work runs. Refund credits automatically on transient failures.
- Keep sending trusted. Enforce daily send caps, warm-up ramps, bounce handling, and suppression of unsubscribed addresses across your account.
- Support and communicate. Reply to your emails, send account notices, deliver receipts, and warn you when your balance is low.
- Protect the service. Detect abuse, secure the platform, and respond to legal requests where legally required.
5. Legal bases (EU and UK GDPR)
Where GDPR applies, we rely on the following bases:
- Contract. To provide the account, run the service, and bill you for it.
- Legitimate interests. To secure the platform, prevent fraud, maintain deliverability, and improve the product. Where we rely on legitimate interests we balance them against your rights and give you a way to object.
- Consent. Where the law requires it, for example non-essential cookies. You may withdraw consent at any time.
- Legal obligation. To comply with tax, accounting, anti-fraud, and lawful requests from authorities.
6. Sharing and subprocessors
We only share personal data with vendors who help us run the service, under written data protection terms. Each is limited to what it needs. The current list:
- Supabase. Managed Postgres, authentication, row-level access controls. EU or US region (per project configuration). See their privacy notice.
- Google (Gmail API). Sending outreach from your connected Gmail inbox. Global. See their privacy notice.
- Public business directory data provider. Structured public information about local businesses (name, address, category, ratings) used for prospect discovery. Global. See their privacy notice.
- Microsoft (Outlook via Microsoft Graph). Sending outreach from your connected Outlook inbox. Global. See their privacy notice.
- Web content extraction service. Reading public business websites and your own site during onboarding to extract signals and enrich context. US. See their privacy notice.
- OpenRouter. Routing large-language-model calls for research summaries and email drafts. US. See their privacy notice.
- Stripe. Processing credit-pack purchases. Card data is handled by Stripe, not by us. Global (see Stripe DPA). See their privacy notice.
- Upstash. Managed Redis for background job queues and short-lived caching. EU or US region. See their privacy notice.
- Resend. System email (account emails, password resets, receipts). US and EU. See their privacy notice.
- Cal.com. Optional booking integration. Booking events reach us as a signed webhook when you enable it. Global. See their privacy notice.
- Vercel. Hosting the marketing site and the application front end. Global CDN. See their privacy notice.
We do not share personal data with anyone else, except as required by law, to protect the safety of a person, or as part of a business transfer where the buyer assumes this policy or a comparable one.
7. Where your data lives
Application data (accounts, workspaces, drafts, sent messages, replies, suppression lists) is stored in a managed Postgres database in an EU or US region depending on the project’s configured location. Background jobs run through a managed Redis instance in the same region. Static assets and the marketing site are served from a global CDN. The specific region your account uses is documented in the account settings and can be shared on request.
Third-party subprocessors process data in the regions listed in the previous section. Where a subprocessor operates globally (for example the AI model gateway or the payment processor), we rely on the contractual safeguards described under International transfers.
8. How long we keep it
- Account data lives while your account is active and for up to 90 days after you delete it, unless a longer period is required by law.
- Workspace data (leads, drafts, sent messages, replies) is kept for as long as your account is active. On deletion we remove or anonymize it within 90 days.
- OAuth tokens are deleted immediately when you disconnect a mailbox or delete your account.
- Suppression lists (unsubscribes and bounces) are kept indefinitely at the account level so a deleted contact cannot be re-emailed if they later reappear in a search.
- Billing records are retained for the period required by applicable tax law, typically six to ten years.
- Backups may retain data for up to 35 days after deletion, after which they are overwritten.
9. How we secure it
Security is not a checkbox. The core controls we run today:
- All traffic to the marketing site and the application is served over TLS.
- Mailbox OAuth tokens are encrypted with AES-256-GCM at rest before they are written to the database.
- Postgres row-level security limits every read and write to the account that owns the row.
- Webhooks from payment and booking providers are verified with cryptographic signatures and idempotency keys before we accept them.
- Sensitive credentials live in a secrets manager. Access is limited to the services that need them, logged, and rotated on a schedule.
- We patch dependencies regularly and monitor errors so incidents surface fast.
See our Security overview for a fuller picture. If you believe you have found a vulnerability, email stallwartofficial@gmail.com with details and we will respond promptly.
10. Your rights
Depending on where you live, you have some or all of the following rights:
- Access the personal data we hold about you.
- Correct data that is wrong.
- Delete your account and the personal data attached to it.
- Restrict or object to specific processing.
- Receive a portable copy of your data.
- Withdraw consent where consent is our legal basis.
- Lodge a complaint with your local data-protection authority (for example the ICO in the UK or your national DPA in the EU).
To exercise any of these rights, email stallwartofficial@gmail.com. We may need to verify your identity before we act on the request.
California residents (CCPA / CPRA). You have the right to know what we collect, to delete it, and to opt out of sale or sharing. We do not sell personal information and we do not share it for cross-context behavioural advertising. You may still exercise the rights above by emailing us.
11. International transfers
Some of our subprocessors are based outside the EU or the UK. Where personal data is transferred out of the EEA or the UK we rely on the European Commission’s Standard Contractual Clauses (and the UK International Data Transfer Addendum), together with additional safeguards where appropriate. We are willing to provide a copy of the relevant clauses on request.
12. Data processing agreement
If you are a business customer subject to GDPR, UK GDPR, or an equivalent framework, you are entitled to a Data Processing Agreement (DPA) with us that incorporates the current Standard Contractual Clauses and the UK International Data Transfer Addendum where relevant. Our DPA is available on request: email stallwartofficial@gmail.com with your legal entity name and the account email, and we will send it for signature. Any material change to the DPA is notified in-app and by email in advance.
13. Cookies
The marketing site uses a minimal set of first-party cookies for session state and for measuring aggregate site usage. We do not run advertising trackers. The application uses cookies required to keep you signed in and to preserve your preferences.
14. Children
The service is a business tool. It is not directed at children under 16 and we do not knowingly collect personal data from them. If you believe a child has provided personal data, contact us and we will remove it.
15. Changes to this policy
We may update this policy from time to time. When we make a material change we will update the effective date at the top and, where the change materially affects you, notify you by email or in-app before it takes effect.
16. Contact
Privacy questions or requests: stallwartofficial@gmail.com. Postal address: Stallwart, Coimbatore, Tamil Nadu, India.
This policy is governed by the laws of the courts of Coimbatore, Tamil Nadu, India. See our Terms of Service for the rules that apply to your use of the service.