Last updated: August 3, 2026
Pipeline is a networking CRM for students and the organizations they belong to. This policy explains what we collect, why, and what control you have over it.
We are Pipeline ("we," "us"). You can reach us any time at cameron@getpipeline.app.
Account information. Your name, email address, and password (stored hashed - we never see it). If you sign in with Google, we receive your name, email, and profile image from Google.
Profile and preferences. Career targets, networking goals, your school and program, notification preferences, email signature, and - if you use it - a writing-style profile so drafts sound like you.
Contacts you add. Names, companies, roles, email addresses, phone numbers, LinkedIn URLs, locations, schools, birthdays, interests, tags, and any notes you write.
Your activity. Conversations you log (type, date, notes, outcomes), follow-up dates, tasks, job applications you track, and messages you draft or schedule through Pipeline.
Payment information. If you purchase a paid product, payment is handled entirely by Stripe. We receive only a confirmation that payment succeeded. Your card details are never sent to Pipeline and we do not store them.
Like any contact manager, Pipeline stores the professional contact details you choose to save. This is typically business contact information such as name, employer, job title, work email address, phone number, LinkedIn URL, graduation year, and your own notes about the relationship.
You are the source of this information, and you control it. Contacts you add privately are visible only to you. Contacts you choose to submit to a shared organization pool are visible to approved members of that organization, and an officer reviews them before they are added.
We act as a processor for this information on your behalf. We do not sell it, use it for advertising, use it to train AI models, or contact these individuals ourselves. Pipeline does not send email on its own; messages are sent only by you, from your own account.
To request removal of contact information relating to you, write to cameron@getpipeline.app. A Pipeline account is not required to make this request.
If you connect Gmail, Pipeline requests these permissions:
| Permission | What it allows | Why |
|---|---|---|
gmail.send |
Send email as you | So outreach you write in Pipeline sends from your own address |
userinfo.email / openid |
See your email address | To identify which account is connected |
We request send-only access. Pipeline cannot read your inbox, your drafts, or any message you did not compose in Pipeline. That capability is not requested and not technically available to us.
We store the OAuth tokens Google issues so scheduled messages can send at the time you chose. You can disconnect Gmail at any time in Settings, which deletes those tokens from our systems and stops Pipeline from sending on your behalf. You can also remove Pipeline's access directly from your Google Account security settings.
Pipeline's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, Google user data is used only to provide and improve the user-facing features described above. We do not transfer it to third parties except as necessary to provide those features, comply with law, or in connection with a merger or acquisition. We do not use it for advertising. We do not use it to develop, improve, or train generalized AI or machine learning models. No human reads your Google user data except with your explicit permission or where required by law.
Pipeline's Coach helps you prepare for conversations and draft messages. To do that, we send relevant context - the contact's profile, your notes and logged conversations with them, your goals, and your writing style - to an AI provider.
By default this is Anthropic (Claude). You may instead supply your own API key for Anthropic, OpenAI, Google, or Perplexity in Settings, in which case requests go to that provider under your own account.
What this means in practice: your notes and contact details are transmitted to the AI provider to generate a response. Our providers do not train their models on data submitted through their APIs. We store token counts to monitor cost - never the content of your prompts or responses.
If you would rather no contact data reach an AI provider, leave Coach disabled. Every other part of Pipeline works without it.
To operate the product - store your network, generate prep sheets and drafts, send and schedule your messages, remind you who to follow up with, and show your progress.
To operate organization features - shared contact pools, membership and roles, and aggregate activity counts for your organization.
To keep the service working and secure - authentication, abuse prevention, rate limiting, and debugging.
To communicate with you - account emails such as verification and password reset, and product updates you can opt out of.
We do not sell your personal information. We do not serve ads. We do not share your private contacts with other members of your organization unless you explicitly submit a contact to a shared pool.
If you join an organization on Pipeline:
Officers can see your membership, role, graduation year, and the number of contacts you have submitted to the shared pool. They cannot see your private contacts, your notes, your logged conversations, or your messages.
Contacts you submit to the shared pool become visible to approved members of that organization. Notes you attach to a pooled contact are visible to those members as well - please write them accordingly.
Organization-level activity totals are aggregate. Pipeline does not rank members against one another.
If you leave an organization, you lose access to its pool. Contacts you already added to your own list remain yours.
We use a small number of service providers, each handling only what their function requires:
| Provider | Purpose |
|---|---|
| Supabase | Database, authentication |
| Vercel | Application hosting |
| Anthropic | AI Coach (default provider) |
| Sending email you compose, if you connect Gmail | |
| Resend | Account emails such as verification and password reset |
| Stripe | Payment processing |
| Sentry | Error monitoring so we can find and fix crashes |
| PostHog | Product analytics, if enabled |
Our error monitoring is configured not to collect personal information. It records the type and location of a failure, never request contents, and email addresses are stripped from error text before it leaves your browser.
We may also disclose information if required by law, to protect someone's safety, or in connection with a merger or acquisition - in which case this policy continues to apply until replaced with notice to you.
We keep your information while your account is active. When you delete your account, we delete your profile, contacts, logged conversations, tasks, drafts, and organization memberships.
Two things persist by design: contacts you submitted to a shared organization pool remain with that organization, since they belong to the group rather than to you; and we retain limited records where law requires, such as payment records.
Our database is backed up automatically each day. Backups are kept on a rolling basis for up to seven days and are then deleted, so information you remove may persist in a backup for a short period before it ages out.
You can access everything Pipeline holds about you from within the app; correct anything by editing it; delete your account in Settings; and disconnect Gmail at any time. If you would like a copy of your data in a portable format, email us and we will provide one.
Depending on where you live - including under GDPR or CCPA - you may have additional rights such as data portability, restriction of processing, or objection. Email cameron@getpipeline.app and we will honor them. We do not charge for these requests and will respond within 30 days.
We do not sell personal information, so there is nothing to opt out of in that respect.
Data is encrypted in transit and at rest. Every database table enforces row-level security so users can only reach their own data. API keys you supply are encrypted before storage. Passwords are hashed and checked against known-breached password lists.
No system is perfectly secure. If we discover a breach affecting your personal information, we will notify you promptly.
Pipeline is intended for college students and professionals and is not directed at anyone under 13. We do not knowingly collect information from children under 13. If we learn we have, we will delete it.
If we change this policy materially, we will update the date above and notify you in the app or by email before the change takes effect.
cameron@getpipeline.app
For requests to remove information about a person who is not a Pipeline user, use the same address - no account required.
This document was drafted to reflect Pipeline's actual data practices as of the date above. It is not legal advice. Before relying on it for institutional agreements or in a regulated context, have it reviewed by a qualified attorney.
See also: Terms of Service