Legal
Privacy Policy
This policy explains how Sourcy Inc. (“Sourcy,” “we,” “us”) collects, uses, shares and protects information in Sourcy Data: the business and contact catalog, the audiences and campaigns you build, AI voice calls, the website visitor pixel, and the AI assistants you connect through our MCP server.
Our role
Sourcy is a controller for your account and billing information, and for the catalog records it compiles from public sources (see Where catalog records come from, below). For the content you create — saved audiences, campaign drafts, call agent configurations, CRM leads you import — Sourcy acts as your processor: you decide what to do with it, we store and run it on your behalf.
Information we collect
- Account and billingYour name, work email, password (stored as a hash, never in plain text), and billing records through Stripe.
- Catalog recordsBusiness and, for some searches, individual contact information compiled from public licensing and government sources: name, address, phone, email, industry, and regulatory identifiers such as an EIN, NPI, or license number when the source publishes them.
- Your activity and contentSaved audiences and searches, campaign drafts and results, replies to your campaigns, call recordings and transcripts, custom fields, and leads you import from a connected CRM.
- Website visitor identificationIf you use the pixel on your own site, we identify the company that visited, never the individual visitor: no IP address or personal contact of a visitor is kept.
- AI assistant connectionsCovered separately in AI assistants you connect (MCP), below.
- Technical telemetryIP address, browser, device, timestamps, authentication events, and logs, used to secure and operate the service.
Where catalog records come from
Catalog records come from public government and professional-licensing sources, not from a person who agreed to be in our database. If you believe a record about you or your business is inaccurate, or you want it corrected or removed, write to us at the address below. We review each request against what the underlying source allows; we do not have an automated self-service removal tool today.
How we use information
We use information to provide, secure, and improve Sourcy Data; process billing; respond to support; prevent fraud and abuse; and comply with legal obligations. We do not sell personal information for advertising, and we do not build advertising profiles from what happens inside the product.
Artificial intelligence
Sourcy Data uses OpenAI to draft email and SMS copy and to help configure an AI calling agent, from the inputs you give those tools. OpenAI processes that content to return the requested output and, under its API terms, does not use it to train its models.
AI-drafted copy and AI call results may be incomplete or inaccurate. Review them before sending a campaign or acting on a call result.
AI assistants you connect (MCP)
A user can connect Sourcy Data to an AI assistant such as ChatGPT or Claude through our Model Context Protocol (MCP) server. How to connect, what it can do, and how changes are confirmed is explained on AI assistants.
- What we receiveYour sign-in and the permissions you approve on the consent screen, and, for each request, the tool the assistant calls and the inputs it sends. We do not receive the conversation itself, the assistant's memory, or its files.
- What the assistant receivesOnly the result of the tool it calls, limited to the permissions you approved. Contact details are returned only for businesses your account already revealed and for your own CRM leads. The contact details of an individual in the catalog, government identifiers such as an EIN or NPI, passwords, API keys, and payment details are never returned.
- How we use itTo run the tool you asked for and to keep every proposed change waiting for your confirmation. Campaigns are never launched from the chat, and a deletion or anything that spends credits is approved in Sourcy Data.
- SharingTool results go to the assistant you chose, at your direction. Its provider processes them under your own agreement with that provider, not under this policy.
- Your controlsYou can revoke your own connection at any time on the MCP page in Sourcy Data. An administrator can revoke any connection on the account or turn off AI assistant access entirely.
Service providers
Our production configuration uses the following categories of providers. Each receives only what it needs to do its job.
| Service | Provider |
|---|---|
| Hosting, database and file storage | Amazon Web Services |
| Payments | Stripe |
| Email sending | Resend |
| SMS | Twilio, when SMS is enabled on your account |
| AI voice calls | Retell, when you use an AI calling agent |
| Email verification | ZeroBounce, when you verify email addresses |
| AI-drafted copy and call configuration | OpenAI |
| Your own connected accounts | GoHighLevel, Salesforce, Saleshandy or Smartlead, only if you connect them — processed under your agreement with them, not shared further by us |
These providers are bound by contractual or legal confidentiality obligations.
Email, SMS and calls you send
When you use Sourcy Data to send email or SMS, or to run an AI calling campaign, you choose the recipients and the content, and you are responsible for the consent and opt-out obligations that apply to that outreach. An unsubscribe link or “Reply STOP” instruction is added automatically, and anyone who opts out is suppressed from future sends on your account.
Cookies and local storage
We use a session cookie for sign-in and a cookie that remembers your language preference. We do not use advertising cookies or build cross-site advertising profiles.
Retention and deletion
We keep account data and the content you create while your account is active, and for a limited period afterward to meet legal, security, and billing obligations. We do not currently commit to a fixed number of days: write to us to request deletion of specific information, and we will act on it as the law and our own records allow.
Security
We use safeguards appropriate to the information involved, including TLS in transit, password hashing, encrypted storage of integration credentials, OAuth 2.1 for AI assistant connections, and access controls scoped to your account. No system is perfectly secure; if a breach affects protected information, we will notify affected customers and authorities as required by law.
Where information is processed
Sourcy operates from Florida, United States, and information is processed in the United States and wherever our service providers operate.
Age limitation
Sourcy Data is a business service and is not directed to anyone under 18. We do not knowingly collect personal information directly from children.
Privacy rights and requests
- If you have an account with usYou may request access to, correction of, or deletion of your account information, or object to certain processing. Write to the address below; we may verify your identity before completing a request.
- If you appear in the catalog and are not our customerYou may ask us to correct or remove a record about you, as described in Where catalog records come from, above.
Changes to this policy
We may update this policy as Sourcy Data or applicable law changes. We will post the revised policy on this page.
Questions about this policy
Do you sell my information?
No. We do not sell personal information for advertising, and we do not build advertising profiles from activity inside Sourcy Data.
Can I ask you to delete my data?
Yes. If you have an account, write to [email protected]. If you appear in the catalog and are not our customer, we review correction or removal requests against what the underlying public source allows.
What happens to my data if I connect an AI assistant?
The assistant only receives the result of the tool it calls, limited to the permissions you approved, and nothing is changed, sent, or deleted without your confirmation. See AI assistants you connect (MCP), above, and the AI assistants page for the full picture.
Related
Searching the catalog is free
Create an account to search and preview records at no cost. AI connectors come with the plans that include them.