Privacy Policy
Last updated July 20, 2026
Terlido is operated by Doteli LLC. This policy explains what we collect, why we collect it, how long we keep it, and how you can get it deleted. The sections on Google and Microsoft mailbox data are the ones most people are looking for — both are spelled out in full below.
1. Who we are
Terlido (“we”, “us”) is a sales outreach platform operated by Doteli LLC, 30 N Gould St, STE R, Sheridan, WY 82801, United States. For users in the EEA and UK, Doteli LLC is the data controller for account data, and a data processor for the contact data you upload and the mailbox content we access on your behalf.
Questions, access requests, and deletion requests: hi@terlido.com.
2. Google user data
When you connect a Gmail or Google Workspace mailbox, you grant Terlido access through Google’s OAuth flow. We request only the scopes we actually use:
gmail.send— to send the campaign, warmup, and reply emails you schedule from your own mailbox, so they come from your address rather than a shared relay.gmail.modify— to read your inbox and spam folder so we can detect replies, bounces, and out-of-office responses and stop sequences automatically; and to act on warmup mail sent between mailboxes on our own network: moving it out of Spam into the Inbox, marking it Important, and marking it read. This is the mechanism that rebuilds your sending reputation.
These scopes do not permit permanent deletion, and Terlido never deletes your mail. We do not read, index, or act on personal correspondence that is unrelated to the campaigns you run in Terlido, beyond the reply and bounce matching described above.
3. Microsoft user data
When you connect an Outlook, Hotmail, or Microsoft 365 mailbox, you grant Terlido access through Microsoft’s OAuth flow. We request:
Mail.Send— to send your campaign, warmup, and reply emails from your own mailbox.Mail.ReadWrite— to read your Inbox and Junk folder for reply, bounce, and out-of-office detection, and to act on warmup mail sent between mailboxes on our own network: moving it from Junk to the Inbox, flagging it as important, and marking it read.User.Read— to read the mailbox’s own address and display name so we can label it correctly in your workspace.offline_access— to refresh the above access while campaigns run on schedule, without asking you to sign in again each time.
Microsoft’s consent screen describes Mail.ReadWrite as including the ability to delete mail. That is how Microsoft defines the permission — it is the narrowest scope that allows moving a message out of the Junk folder, which the warmup feature requires. Terlido never deletes your mail. Our application contains no delete operation for any mailbox provider; the only changes we make are the folder move, importance flag, and read flag described above.
4. What we store
- Account data — your name, email address, workspace name, and billing details. Payment card details go directly to Stripe and never touch our servers.
- Mailbox credentials — OAuth access and refresh tokens, or IMAP/SMTP passwords where you connect a non-Google mailbox. These are encrypted at rest with AES-256-GCM and are never displayed back to you or to us in plaintext.
- Lead and contact data — the prospect records you import or enrich, including names, email addresses, companies, and any custom fields you add.
- Campaign and message content — your templates and sequences, the emails we send on your behalf, and the body text of replies we match to a campaign, so you can read and respond to conversations inside Terlido.
- Engagement events — opens, clicks, replies, and bounces tied to the messages you send.
- Product analytics — page views and feature usage. We do not send email content, lead data, or any mailbox data to our analytics provider.
5. How we use it
We use your data to run the product you are paying for: sending your sequences on schedule, pacing them to protect your deliverability, detecting replies so contacts stop receiving follow-ups, reporting on campaign performance, and billing you. We also use aggregate, non-identifying usage data to decide what to build next.
We do not sell your data. We do not share your lead lists with other customers. We do not use the content of your mailbox to train AI models.
6. Sub-processors
We rely on a small number of vendors to operate the service:
- Amazon Web Services — application hosting and database storage.
- Google LLC — Gmail API access for Google mailboxes you connect.
- Microsoft Corporation — Microsoft Graph access for Outlook and Microsoft 365 mailboxes you connect.
- Stripe — subscription billing and payment processing.
- PageDuel — product analytics, limited to usage events.
Where you enable an optional integration — a CRM, a LinkedIn account, or a data enrichment provider — data flows to that provider only for as long as the integration is connected, and only the fields that integration needs.
7. Retention and deletion
We keep your data for as long as your account is active. You can disconnect a mailbox at any time from the app, which revokes our token and deletes the stored credential immediately. You can also revoke Terlido’s access directly from your Google Account permissions page or, for Microsoft mailboxes, from microsoft.com/consent.
When you delete your account, we delete your workspace data — leads, campaigns, message content, and credentials — within 30 days. Backups roll off within a further 30 days. We retain billing records for as long as tax and accounting law requires.
8. Security
Mailbox credentials and integration secrets are encrypted at rest with AES-256-GCM. All traffic to the application is served over TLS. Access to production systems is restricted to personnel who need it to operate the service. No system is perfectly secure, and we will notify affected users without undue delay if a breach affects their data.
9. Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. Email hi@terlido.com and we will respond within 30 days. If you are in the EEA or UK you also have the right to complain to your local supervisory authority.
If you are a prospect who received an email sent through Terlido and want your data removed, write to hi@terlido.com and we will suppress your address across the platform and pass the request to the sender.
10. Changes to this policy
We will update this page when our practices change, and will update the “last updated” date above. If a change materially affects how we handle your data, we will notify account owners by email before it takes effect.