Privacy Policy — AppiFire AI Outreach

This Privacy Policy explains how AppiFire collects, uses, stores, and shares information when you install and use AppiFire AI Outreach, our Chrome browser extension.

Effective date: July 10, 2026

If you use Appifire AI Chat for Shopify, see our separate Privacy Policy for Appifire AI Chat. This document applies only to the Chrome extension.

1. Scope

This policy applies to:

  • Users who install AppiFire AI Outreach from the Chrome Web Store or load it in developer mode.
  • Data processed on your device through the Extension popup, background service worker, and content scripts on pages you open (including mail.google.com and linkedin.com when you use optional compose features).

The Extension is a sales and outreach research tool. It runs when you open it on the active browser tab. It does not provide an AppiFire cloud account or sync service in the current version.

2. Information we collect and process

We group data by how it is collected. The Extension does not send routine telemetry or browsing history to AppiFire servers. Most data stays on your device unless you trigger a feature that calls a third party (described in Section 5).

2.1 Data from the active tab (when you run analysis)

When you open the Extension on an http or https page, we process:

  • Tab URL — full URL of the active tab (origin, path, and query string; URL fragment/hash is not used for caching).
  • Page title and meta description — from the page head.
  • Public page content — visible text and structure used for research signals, including detected business emails and phone numbers, platform and technology hints, sitemap and catalog hints, chat widget and marketing stack heuristics, social profile links, JSON-LD business fields when published on the page, and a plain-text page excerpt (normalized visible text, capped in length) used only if you use AI email generation.

We do not collect passwords, payment card data, or content from pages you never analyze with the Extension.

2.2 Same-origin fetches initiated by the Extension

To find contacts and site metadata, the Extension may request public resources on the same website you are analyzing, for example sitemap files, common contact or about paths, optional same-origin product or catalog JSON endpoints when exposed, and optional Internet Archive (web.archive.org) CDX data for an approximate earliest capture hint for the hostname. These requests use credentials: "omit" where applicable. They go to the target site or Archive.org, not to AppiFire.

2.3 Data you provide in Settings

Stored locally in Chrome extension storage (chrome.storage.local) on your device:

  • OpenAI API key (optional), OpenAI model selection
  • Email templates (name, subject, body)
  • Prompts — email template prompt, Gmail reply prompt, LinkedIn reply prompt, LinkedIn rewrite prompt
  • Knowledge base text (optional, used with some AI features)
  • Gmail compose helpers — account index, default From address, meeting link
  • Add Lead webhook URL (optional) — the HTTPS endpoint you configure for lead export (for example your own n8n, Zapier, or custom automation URL)
  • Cached analysis results (approximately one hour per normalized tab URL)
  • Cached sitemap counts (approximately one hour per origin)
  • Apollo company rows after you initiate a scrape on Apollo.io
  • AI email drafts saved per URL (when you use that feature)

2.4 Gmail (optional features on mail.google.com)

When you use optional Gmail compose enhancements, we process compose field content you paste or edit (for example original email text for Generate Reply) and settings you saved (From address preference, meeting link). The Extension does not use the Gmail API, does not read your inbox automatically, and does not send email without you confirming in Gmail.

2.5 LinkedIn (optional features on linkedin.com)

When you use Write Reply or Rewrite Message, we process recipient profile fields visible on the page, conversation thread text when loaded for reply generation, and draft message text you edit in the modal. Features run only on LinkedIn pages you have open and only when you click the relevant button.

2.6 Apollo.io (optional capture)

When you click Get Apollo Data on an Apollo.io tab, we process visible table rows in the company list (for example company name, website, LinkedIn URL, employees, industries, keywords, location, score). Data is stored locally until you export CSV or clear extension storage. It is not uploaded to AppiFire by default.

3. How we use information

We use the information above to:

  • Display website research in the Extension popup.
  • Cache results locally so you can reopen the popup on the same URL without re-scanning (for about one hour).
  • Pre-fill outreach workflows — email templates, Gmail compose URLs, and JSON/CSV export.
  • Generate AI-assisted drafts when you click AI features and have configured an OpenAI API key.
  • Export leads when you click Add Lead on eligible sites (see Section 5).
  • Improve reliability of on-device features (for example parsing contacts from large HTML pages).

We do not use Extension data for advertising profiles, and we do not sell personal data.

4. How we store information

DataWhere storedRetention
Analysis snapshotchrome.storage.local on your device~1 hour per tab URL (then deleted on read or prune)
Sitemap count cachechrome.storage.local~1 hour per site origin
Settings, templates, prompts, API keychrome.storage.localUntil you change or remove them, or uninstall the Extension
Apollo company rowschrome.storage.localUntil you clear data or uninstall
AI email draftschrome.storage.localUntil overwritten or uninstalled
Popup session memoryExtension memory onlyUntil popup closes or new analysis runs

Uninstalling the Extension removes data stored in extension storage. Data already sent to third parties (OpenAI, your webhook) is governed by those parties' policies and your account settings. We do not operate a central AppiFire server that stores your analysis history in the current version.

5. How we share information

We do not sell personal data. We share data only in these situations:

5.1 Third parties you invoke

Third partyWhenWhat is sent
OpenAI (api.openai.com)You click Generate AI Email, Generate Reply (Gmail), Write Reply (LinkedIn), or Rewrite Message (LinkedIn)Your API key, selected model, prompts, knowledge base (where applicable), analysis context and/or page excerpt, Gmail pasted text, LinkedIn profile/thread/draft text as described in Section 2
Your automation webhookYou click Add Lead on an eligible Shopify site with a detected email, and you have saved a webhook URL in SettingsFull analysis JSON for the current tab (including contacts and research fields) to the HTTPS webhook URL you configured (for example n8n, Zapier, or your own endpoint). AppiFire does not provide or operate this endpoint.
Websites you analyzeYou run analysisHTTP requests for public sitemap, contact pages, and related same-origin resources
Internet ArchiveLaunch-date hint probeHostname lookup via public CDX API

OpenAI's processing is subject to OpenAI's policies. You provide your own OpenAI API key and are responsible for your OpenAI account and usage charges.

5.2 Legal and safety

We may disclose information if required by law, court order, or to protect rights, safety, and security, to the extent applicable to AppiFire as the Extension developer.

5.3 No routine sharing with AppiFire

Apart from Add Lead (which you trigger) and support communications you initiate, the Extension does not upload your browsing history, analysis results, or settings to AppiFire servers automatically.

6. Permissions and why they are needed

  • activeTab — Act on the tab you are viewing when you open the Extension.
  • tabs — Read active tab URL and id to run analysis and return results to the popup.
  • scripting — Inject the analysis script on demand when you run analysis, and inject Apollo scrape when you request it.
  • storage — Save cache, templates, settings, and Apollo data locally.
  • Host access (<all_urls>) — Fetch public sitemaps and contact pages on sites you analyze.
  • Host access (https://api.openai.com/*) — Call OpenAI when you use AI features with your API key.
  • Content scripts on Gmail and LinkedIn — Optional compose and messaging helpers described above.

Broad host access is used so you can analyze customer domains without a fixed allowlist. Analysis and fetches run in connection with your use of the Extension, not as silent background monitoring of all tabs.

7. AI processing

AI features use OpenAI models to generate email or message drafts. Outputs are probabilistic and may be inaccurate. You must review all generated content before sending. You are responsible for compliance with applicable laws, email and messaging regulations, and third-party terms (including Google, LinkedIn, and OpenAI).

8. Security

We design the Extension to:

  • Transmit third-party API calls over HTTPS (TLS).
  • Store sensitive settings locally in Chrome extension storage on your profile.
  • Omit credentials on same-origin contact fetches where configured.

No method of transmission or local storage is completely secure. Protect your device, Chrome profile, and OpenAI API key.

9. Your choices and rights

You can:

  • Avoid AI features — Do not save an OpenAI API key, or do not click AI buttons.
  • Avoid Add Lead — Do not click Add Lead, or leave the webhook URL blank in Settings; no analysis JSON is sent to a webhook.
  • Clear cached data — Use the popup reload control to bypass the analysis cache, or remove extension storage in Chrome settings.
  • Remove all Extension data — Uninstall the Extension from chrome://extensions.
  • Export data — Copy or download analysis JSON or Apollo CSV to locations you control.

Depending on your location, you may have privacy rights (access, deletion, correction, objection, portability). Because most data is stored on your device and sent to third parties only when you act, contact us (Section 14) for requests relating to data AppiFire processes directly (for example support emails).

10. International transfers

If you use OpenAI, Internet Archive, or other third-party services, data may be processed in countries other than yours. Those providers' terms and safeguards apply.

11. Children's privacy

The Extension is intended for business and professional use. It is not directed to children under 13 (or the applicable age in your jurisdiction). We do not knowingly collect personal data from children through the Extension.

12. Changes to this policy

We may update this policy to reflect product, legal, or operational changes. We will post the updated version on this page and revise the effective date. Continued use after changes constitutes acceptance of the updated policy where permitted by law. For material changes, we may provide additional notice (for example in Extension release notes or the Chrome Web Store listing).

13. Chrome Web Store

This Extension is distributed via the Chrome Web Store. Google's terms and policies also apply to installation and updates. The privacy policy URL listed on our store listing points to this document.

14. Contact

For privacy questions or requests about AppiFire AI Outreach, visit appifire.com or use the contact or support channel listed on our website or on the Chrome Web Store listing.