RecruitAffiliates.ai Start free

Security

We only read the emails we started

Here's what we store, where it lives, and how your inbox connection works. Written plainly, so you can judge it yourself.

Your inbox

You send outreach from your own Gmail, Outlook, Yahoo or work mailbox. Replies land where you already read mail.

  • You sign in on Unipile's page, not ours. Unipile is a French company that connects mailboxes to software. We never see your mail password.
  • We only sync threads we started. Or ones you linked to an affiliate yourself. We never import your old mail.
  • Why Google still asks to "read and send". Google and Microsoft don't offer a "these threads only" permission. The limit is in our software. We explain each permission on screen before you connect.
  • Nothing sends without you. A campaign's first email waits for your approval.
  • It stops on its own. A reply, a bounce or an unsubscribe stops that person's emails at once.
  • At most 30 first emails a day from one inbox. A new inbox starts at 10 a day and builds up over two weeks.
  • No tracking pixels. We don't track opens or clicks.
  • Disconnect any time in Settings, then Inboxes. Or revoke it from your Google or Microsoft account.

What we store, and for how long

WhatHow long
Your account, brand details, saved affiliates, notes and dealsWhile your account is open. A finished trial stays read-only, never deleted
The subject and body of synced emails30 days. The timeline keeps a line saying a message was there
Raw data from our search providers90 days
YouTube data30 days unless it's refreshed by a new scan
UnsubscribesFor good, as a scrambled record, so nobody who said no is emailed again

Where it lives

  • The database is managed Postgres on Neon, in the United States, encrypted at rest.
  • Every connection uses TLS, the lock in your browser bar.
  • Mailbox secrets are held by Unipile, in the EU. They're not in our database.
  • Card details go straight to Stripe. We never see your card number.
  • Backups keep 7 days of history, so a mistake can be undone.

Every company that touches data for us is on the sub-processors page, with where it's based and the legal safeguard.

Who can see what

  • Your team, by role. The owner controls billing and the inbox, and only the owner can delete the account. An admin runs brands, the team and campaigns. A member finds affiliates, writes emails and works deals.
  • No other customer. Every query is checked against your organization. We test that with two customers side by side.
  • Limits on the server. A feature you're not on is refused by the server itself.
  • AI never sends. It sorts results and drafts emails. You approve what goes out. We don't train AI models on your data.

Deleting things

  • One affiliate: mark them not a fit to hide them. To delete their data for good, email support and we do it within 7 days.
  • Your whole account: email support and we finish within 30 days. We keep only invoices the law requires and the scrambled unsubscribe list.
  • If we found you as a creator and you'd rather we didn't: email support@recruitaffiliates.ai. We delete what we hold about you.

What we don't have

We're not SOC 2 or ISO 27001 certified, and no audit is under way. If your buying process needs one first, we're not the right fit yet. We'd rather say so now.

Found a problem? Email security@recruitaffiliates.ai. A person replies within two working days.

The legal detail is in the privacy policy, the data processing agreement and the cookie policy.

Try it on your own website

Your first 20 affiliates free. 7 days, no card.