Privacy Policy

Last updated 18 August 2026

Who we are

Intro (“Intro”, “we”) is a relationship-intelligence service operated by Roi Lavan, 650 Castro Street, Ste 120, Mountain View, CA 94041, United States, who controls the data described in this policy (the “data controller” where the EU/UK General Data Protection Regulation applies). Contact: roi@unlockintro.ai.

Intro is invite-only. Accounts are created by the operator; there is no public sign-up.

What Intro is for

Intro builds a private map of the professional relationships you already have, so you can find the person in your own network who can help with a specific need — an introduction, a hire, a customer, an investor. It does this by analysing evidence of contact that already exists in your accounts and files.

Data Intro collects

Account data

Your name, email address, and a hashed password (if you use password sign-in). Sign-in through Google shares your name, email address and profile picture with us.

Google user data

If — and only if — you choose to connect your Google account, Intro requests the following read-only scopes. Connecting is optional and separate from signing in.

ScopeWhat Intro readsWhy
gmail.readonlyMessage headers only — sender, recipients, date, subject line, thread identifier, and the technical headers that identify bulk mail. Message bodies are not read or stored.To determine who you actually correspond with, how often, and how strong each relationship is.
calendar.readonlyEvent titles, start and end times, and participant names and email addresses.Meetings are strong evidence of a real relationship and contribute to relationship strength.

One narrow exception. If you enable job-lead features, Intro fetches the full content of messages from a fixed list of automated job-alert senders (for example LinkedIn, Indeed and Glassdoor notification addresses) in order to extract the job listings and public profile links inside them. Only the extracted listings and links are kept; the message content itself is discarded and never stored. No other message is ever fetched in full.

Data you import yourself

Contact exports (for example LinkedIn connections), CRM spreadsheets, mailbox exports produced by Google Takeout, and — if you choose to use them — message archives from iMessage or WhatsApp. Short-message archives do include message text, because the text is the only signal those channels carry.

Enrichment data

Publicly available professional information about the people and companies in your network — role, employer, location, profile headline — obtained from third-party enrichment providers.

Operational data

Usage events, error reports and an audit log of significant actions (searches, edits, administrative actions), used to run and debug the service.

How Intro uses this data

  • To identify the people in your network and merge duplicate records for the same person.
  • To compute a relationship-strength score for each contact from the frequency, recency, direction and format of your contact with them.
  • To derive searchable facts — employer, role, expertise, location — and to make your network searchable in plain language.
  • To surface paths to a target person or company, and to suggest who could make an introduction.
  • To operate, secure, debug and support the service.

Intro does not sell your data, does not use it for advertising, does not serve ads, and does not use it to build profiles for anyone other than you.

Google API Services User Data Policy

Intro’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically, and without qualification:

  • Google user data is used only to provide and improve the user-facing features described above.
  • Google user data is never transferred to others except as necessary to provide those features, to comply with applicable law, or as part of a merger or acquisition in which the receiving party is bound by this policy.
  • Google user data is never used for advertising of any kind.
  • Google user data is never used to develop, improve, or train generalised artificial intelligence or machine learning models.
  • No human reads your Google user data, except with your explicit consent for a specific support issue, where required by law, or on aggregated and anonymised data for security or abuse handling.

Who Intro shares data with

Intro uses a small number of service providers. Each receives only what it needs to perform its function.

ProviderPurposeWhat it receives
GoogleGmail and Calendar sync, and Google sign-inOAuth tokens and read requests
AnthropicLanguage-model features such as parsing and summarisationThe specific excerpts a feature needs — typically profile facts, subject lines and participant names
Voyage AISearch embeddingsThe profile, subject-line or summary text being indexed
ReverseContact, People Data LabsEnrichment of public professional profilesThe email address or LinkedIn URL being looked up
Brave SearchResolving company names to websitesCompany names
HetznerHosting (Finland, EU)Runs the server; does not access application data
Cloudflare R2Offsite backup storageBackups, encrypted before upload — never readable content
SentryError monitoringStack traces and request metadata
PostHogProduct analyticsFeature and page usage events

Where a language model or embedding provider is used, it processes the text solely to return a result for that request. Under the business terms Intro operates on, these providers do not use the content of API requests to train their models.

Company-level records (industry, domain, funding stage) and the cache of third-party enrichment lookups are shared across customer accounts so that public company facts are consistent and lookups are not repeated. These contain only publicly sourced information. Nothing private to your account — your contacts, messages, meetings or searches — is ever visible to another customer.

Where data is stored

Intro runs on a dedicated server hosted by Hetzner in Helsinki, Finland (European Union). Databases are not exposed to the public internet. Some service providers listed above process data in the United States; those transfers rely on the providers’ standard contractual clauses.

Security

  • All traffic is encrypted in transit with TLS.
  • Nightly backups are replicated offsite and are encrypted on the client side before upload, so the storage provider never holds readable data.
  • Every request is scoped to the authenticated account at the database level. Operator support access is technically read-only — all writes are blocked while viewing another account — and is recorded in the audit log.
  • Server access is restricted to the operator by SSH key. Passwords are stored only as bcrypt hashes.

A fuller technical description, including a plainly stated list of the controls Intro does not yet have, is available on request.

Retention

Intro keeps your data for as long as your account is active. When you delete your account or ask for deletion, your data — contacts, interactions, derived facts, relationship scores and search history — is removed from the live database. Backups age out on a rolling schedule of up to ten days, which bounds how long deleted data can persist in any backup copy.

Disconnecting Google stops all further syncing immediately. You may also request deletion of the Google-derived data already ingested, separately from deleting your account.

Your rights and controls

  • Revoke Google access at any time, either inside Intro or from your Google account permissions page.
  • Export your data in a machine-readable format.
  • Delete your account and its data, or remove an individual contact and prevent them being re-ingested.
  • Access, correct, restrict or object to processing, and to lodge a complaint with your local supervisory authority if you are in the EU or UK.
  • US state privacy rights. If you are a resident of California or another US state with a comprehensive privacy law, you have the equivalent rights of access, correction, deletion and portability described above. Intro does not sell personal information and does not share it for cross-context behavioral advertising, and we will never discriminate against you for exercising any of these rights.

To exercise any of these, write to roi@unlockintro.ai. Requests are answered within 30 days.

A note about other people's data

Intro necessarily holds information about the people you communicate with, who are not themselves users. Intro processes that information on your behalf and for your legitimate interest in managing your own professional relationships. It is never used to market to those people, never sold, and never shared with other customers. Anyone can ask, at the address below, to be removed from the service; removal also prevents that person being re-ingested by later syncs.

Children

Intro is a business tool and is not directed at anyone under 18. We do not knowingly collect data from children.

Changes

If this policy changes materially, the date at the top will change and account holders will be notified by email before the change takes effect.

Contact

Roi Lavan, 650 Castro Street, Ste 120, Mountain View, CA 94041, United States roi@unlockintro.ai