Privacy Policy
Effective date:
This policy explains how Mergestorm, Inc. (“Mergestorm”, “we”, “us”), a Delaware corporation, collects, uses, and shares information when you use StormGTM, including the website at https://stormgtm.com, the Barometer lead review API, the stormgtm CLI, the stormgtm-mcp server, and related services (together, the “Service”).
Two roles
For your account, billing, and website use, we are the controller of your personal data. For the email addresses and lead context you submit for checking, you decide what to send and why; we process that data on your behalf as a processor (or “service provider” under the CCPA), only to provide the Service to you. You are responsible for having a lawful basis to collect and check the leads you submit.
What we collect
Data you submit for checking
- Email addresses you send to the API, dashboard, CLI, or MCP server.
- Optional lead context, such as name, company, company domain, job title, source URL, GitHub login, LinkedIn URL, and notes.
- Outcomes you report after sending (for example bounced, delivered, or replied), with optional detail such as an SMTP response.
- Batch webhook URLs and account-level policy settings.
Data we generate while checking
- DNS records, mail-server responses to our SMTP probe, and the resulting verdict, score, reasons, and facts.
- For deep-tier checks: public GitHub commit and profile data, public web search results, and the reviewer model's rationale.
Account and usage data
- Your account email address, which you use to sign in with a one-time link.
- API key metadata (name, prefix, created and last-used times). Keys themselves are stored only as hashes.
- Credit balance, purchases, and usage records, such as the number and tier of checks you run.
- Technical logs: IP address, user agent, request paths, timestamps, and errors, used for security and operations.
Payment data
Payments are handled by Stripe. We receive a customer ID, the pack you bought, the amount, and the payment status. Card numbers and bank details go directly to Stripe and never reach our servers. Stripe's use of your data is governed by its own privacy policy.
Cookies and analytics
We set one strictly necessary cookie: an HTTP-only session cookie that keeps you signed in to the dashboard. It expires when your session ends or you sign out. We do not use advertising cookies.
When enabled, we use Google Analytics 4 to understand aggregate website traffic, such as which pages are visited. Analytics does not load if your browser sends a Do Not Track or Global Privacy Control signal, and it never loads inside the API, CLI, or MCP server. You can also block it with any standard content blocker without affecting the Service.
How we use data
- To run the checks you request and return results to you.
- To improve verdict accuracy for everyone, using outcomes stored under a salted hash of the address and aggregate, non-identifying domain-level signals.
- To operate your account: sign-in, credits, billing, receipts, and support.
- To secure the Service: rate limiting, abuse detection, and enforcing our Acceptable Use Policy.
- To send transactional email, such as sign-in links and payment receipts. We do not send marketing email without your consent.
- To comply with law and enforce our Terms of Service.
We do not sell personal data, share it for cross-context behavioral advertising, or use data you submit for checking to build lists, contact your leads, or train third-party models.
Legal bases under the GDPR: performance of our contract with you (account, checks, billing), our legitimate interests (security, fraud prevention, and improving accuracy), your consent (optional analytics where required), and compliance with legal obligations.
The SMTP probe
To check a mailbox we connect to the recipient domain's mail server and ask whether it would accept the address. We disconnect before any message is sent. No email is ever delivered to the addresses you check.
Subprocessors
We share data with these providers only as needed to run the Service:
| Provider | Purpose | Location |
|---|---|---|
| DigitalOcean, LLC | Hosting, compute, storage, and the SMTP probe host | United States |
| Stripe, Inc. | Payment processing, receipts, and fraud prevention | United States |
| Resend, Inc. | Delivery of sign-in links and account email | United States |
| Google LLC | Website analytics (Google Analytics), only when enabled | United States |
| DeepSeek | Reviewer model for deep-tier checks | People's Republic of China |
| GitHub, Inc. | Public commit and profile lookups for deep-tier checks | United States |
| Brave Software, Inc. | Exact-match web search for deep-tier checks | United States |
Deep-tier checks send the email address and the lead context needed for the lookup to GitHub, Brave Search, and the DeepSeek reviewer model. Fast checks do not use these three providers. If you do not want lead data to reach them, use the fast tier. We will update this list before adding a new subprocessor.
Retention
- Check results, batch results, and the context you submitted are kept while your account is open so you can retrieve them, and deleted within 30 days after you delete them, close your account, or ask us to.
- Hashed outcome records are kept for up to 24 months to keep future checks accurate.
- Cached DNS and public-evidence lookups expire automatically, typically within days.
- Server logs are kept for up to 30 days, unless needed longer to investigate abuse or a security incident.
- Billing records are kept for as long as tax and accounting law requires, typically seven years.
Security
Data is encrypted in transit with TLS. API keys, sign-in tokens, and session identifiers are stored only as hashes. Access to production systems is limited to personnel who need it. No system is perfectly secure; if a breach affects your personal data, we will notify you and regulators as the law requires.
International transfers
We are based in the United States and process data there and wherever our subprocessors operate. For transfers from the EEA, UK, or Switzerland we rely on the European Commission's Standard Contractual Clauses or another lawful transfer mechanism.
Your rights
GDPR and UK GDPR. If you are in the EEA or UK, you can ask to access, correct, delete, restrict, or port your personal data, object to processing based on legitimate interests, and withdraw consent at any time. You can also complain to your local data protection authority.
CCPA and CPRA. If you are a California resident, you can ask what personal information we collected, used, and disclosed, ask us to delete or correct it, and opt out of sale or sharing. We do not sell or share personal information, and we will not discriminate against you for exercising these rights. You may use an authorized agent.
If you are a lead someone checked. We process your address on behalf of the customer who submitted it. Contact that customer first; if you cannot, write to us and we will pass your request on and help where we can.
To exercise any right, email privacy@stormgtm.com. We will verify your request, usually by confirming it from your account email, and respond within 30 days, or sooner where the law requires.
Children
The Service is for businesses and is not directed to anyone under 16. We do not knowingly collect personal data from children.
Changes
If we change this policy we will update the effective date above, and for material changes we will email account holders before the change takes effect.
Contact
Mergestorm, Inc., attn. Privacy · privacy@stormgtm.com