Privacy Policy
Last updated: July 2026. Questions? [email protected]
1. Who We Are
Zupai is a Web3 outreach automation platform owned and operated by VestPi Marketing LTD (registration number 7984979). We help Web3 service companies automate their business development outreach via Telegram and LinkedIn. Our registered contact is [email protected].
2. Data We Collect
We collect the following categories of data:
- Account data: Name, email address, company name, role, and password (hashed, never stored in plain text).
- Company profile data: Services, USPs, case studies, pricing, tone preferences, and Calendly links you provide to personalise AI-generated outreach.
- Lead data: Publicly available information about Web3 projects sourced from CoinGecko, DexScreener, CryptoRank, ICODrops, and similar public sources. We do not purchase or broker personal data.
- Telegram account credentials: Encrypted session files for connected Telegram accounts used to send outreach. We do not store Telegram passwords.
- LinkedIn account data: Session cookies transferred via the Zupai LinkedIn Connector Chrome Extension. We do not store LinkedIn passwords. See Section 10 for details.
- Usage data: API call logs, DM send history, reply records, and pipeline activity for analytics and billing purposes.
3. How We Use Your Data
- To operate and improve the Zupai platform.
- To generate AI-personalised outreach messages using your company profile and lead research data.
- To send outreach messages via your connected Telegram and LinkedIn accounts.
- To track pipeline activity and provide analytics on your outreach performance.
- To calculate billing and enforce plan limits.
- To send platform notifications (new replies, account alerts) via Telegram if configured.
4. Data Sharing
We do not sell your data. We share data only with the following third parties necessary to operate the platform:
- Supabase — database hosting (PostgreSQL). Data is stored in the US-East region.
- Anthropic — AI message generation. Lead research briefs and company profile context are sent to Claude API for pitch generation. No data is retained by Anthropic beyond the API call.
- Telegram — messages are sent via the Telegram API using your connected accounts.
- LinkedIn — connection requests, messages, and InMails are sent via LinkedIn using your connected account session.
- Vultr — cloud server hosting.
- DataImpulse — residential proxy services for LinkedIn requests to protect account safety.
5. Data Retention
We retain your account data for as long as your subscription is active. On account deletion, all personal data, lead data, and conversation history is permanently deleted within 30 days. Session logs are retained for 90 days for security purposes.
6. Your Rights
You have the right to access, correct, export, or delete your data at any time. To exercise these rights, email [email protected]. We will respond within 7 business days.
7. Security
All data is transmitted over HTTPS. Passwords are hashed using SHA-256. Telegram session files and LinkedIn session cookies are stored encrypted. Database access is restricted to authenticated backend services only, with Row-Level Security enabled on all tables.
8. Cookies
We use a single session cookie (reachvault_session) to maintain your login state. No third-party tracking cookies are used. We do not use advertising cookies.
9. Changes to This Policy
We will notify active users by email of any material changes to this policy at least 14 days before they take effect.
10. LinkedIn Integration & Chrome Extension
Zupai offers LinkedIn outreach automation through our Chrome Extension ("Zupai LinkedIn Connector"). The extension acts only when you click Connect, and it works solely with your own accounts:
- When you click Connect, the extension reads your LinkedIn session cookies (the cookies your browser already holds after you have logged into linkedin.com, including
li_at) so that Zupai can act as you on LinkedIn at your request. It does not read or store your LinkedIn password, and you never enter your LinkedIn password into the extension.
- It also reads your Zupai session cookie (
reachvault_session) on your Zupai domain, solely to authenticate the connection request to your own Zupai account.
- These cookies are transmitted over HTTPS only to your Zupai server. They are never sold, and are not shared with any third party except the service providers listed in Section 4 that are necessary to operate LinkedIn outreach (LinkedIn itself and the residential-proxy provider used to protect your account).
- Your LinkedIn session is stored encrypted on our servers for the duration of your active session (approximately 30 days). You can disconnect at any time, which immediately deletes the stored session data.
- Subscription-type detection is performed only to apply appropriate rate limits and protect your account from restrictions.
The extension requests only the browser permissions needed for this single purpose: cookies (to read your LinkedIn and Zupai session cookies as described above), storage (to save your Zupai server URL and connection key locally on your device), activeTab (to reload your Zupai dashboard tab after a successful connection), and host access to linkedin.com and your Zupai domain. It does not collect browsing history, does not run on any other sites, and contains no advertising or third-party tracking.