Privacy Policy
LeadDiamond.dev is a B2B lead intelligence platform. This Privacy Policy explains what data we collect, why we collect it, how we use it, and your rights regarding your personal data. We are committed to transparency and compliance with the General Data Protection Regulation (GDPR) and applicable privacy laws.
1 Data Controller
LeadDiamond.dev acts as data controller for account data (your name, email, password) and anonymised platform analytics (Google Analytics, with your consent).
You act as the sole data controller for all business data you collect, process, and send outreach to using the Platform. LeadDiamond.dev does not access, store, or process your API keys, collected leads, or outreach data — these remain entirely within your own server environment.
2 Data We Collect
2.1 Account Data
When you create an account, we collect:
- Email address — used for authentication and communication
- Name — displayed in your account profile
- Password — stored as a cryptographic hash (bcrypt), never in plaintext
- Session tokens — to maintain your authenticated session
2.2 Business Data (Lead Intelligence)
When you run a search, the platform collects publicly available business information from Google Places API, including:
- Business name, address, phone number, website URL
- Google Maps ratings and review counts
- Business category and operating hours
- Geographic coordinates (latitude/longitude)
2.3 Technical Data
- IP address and browser user agent (stored in server logs)
- Session data stored in encrypted cookies
- API keys you provide (Google Places API, OpenAI, Google Gemini, email platform keys) — stored in your server's
.envfile. These keys are never transmitted to LeadDiamond.dev infrastructure. All API calls are made directly from your server to the respective providers.
3 How We Use Your Data
- Authentication — to verify your identity and maintain a secure session
- Service delivery — to run searches, audit websites, and generate AI email drafts
- Platform improvement — aggregate, anonymized analytics to improve features
- Security — to detect and prevent unauthorized access or abuse
- Legal compliance — to meet our legal obligations
We do not sell your data to third parties. We do not use your data for advertising purposes.
4 Third-Party APIs & Services
LeadDiamond.dev integrates with the following third-party services. All API calls are made from your own server using your own API keys — LeadDiamond.dev infrastructure never intermediates these calls. Your use of the platform implies acceptance of each provider's terms:
4.1 Google Places API
Used to search for businesses. Business search queries (city + category) are sent to Google's servers. Google's Privacy Policy applies to this data processing. Your Google API key is stored locally on your server and is never transmitted to our infrastructure.
4.2 OpenAI API
Used to generate personalized cold email drafts. Business audit data (website issues, category, name) is sent to OpenAI's API to generate email content. OpenAI's Privacy Policy applies. Your OpenAI key is stored locally on your server.
4.3 Google PageSpeed Insights
Website URLs are submitted to Google's PageSpeed API to retrieve performance scores. This is a read-only public API and requires no authentication.
4.4 Google Gemini API
Used to discover business social media profiles (Facebook, Instagram) via Google Search grounding. Business name and city are sent to Google's Gemini API to find public social profiles. Gemini's Terms of Service and Google's Privacy Policy apply. Your Gemini API key is stored locally on your server and never transmitted to our infrastructure.
4.5 Email Marketing Platform Integrations
When you connect a third-party email platform (Mailchimp, Klaviyo, HubSpot, ActiveCampaign, Brevo, ConvertKit, GetResponse, ConstantContact), lead contact data and AI-generated email drafts are sent directly from your server to that platform's API under your account and API credentials. LeadDiamond.dev does not intermediate, store, or have access to this data transfer. Each platform's own Privacy Policy applies to data you push to them.
4.6 OpenStreetMap / CartoDB
Map tiles are loaded from CartoDB's servers (based on OpenStreetMap data) to render the leads map. Your IP address may be sent to CartoDB when loading map tiles. CartoDB's Privacy Policy applies.
5 Data Retention
- Account data — retained for as long as your account is active. Deleted within 30 days of account deletion request.
- Business/lead data — stored on your own server under your control. You can delete individual records or entire search results at any time.
- Session data — expires after 120 minutes of inactivity.
- Server logs — retained for 30 days for security purposes.
6 Your Rights (GDPR)
If you are located in the European Economic Area, you have the following rights:
- Right of access — request a copy of the personal data we hold about you
- Right to rectification — correct inaccurate personal data
- Right to erasure — request deletion of your personal data ("right to be forgotten")
- Right to restriction — request that we restrict processing of your data
- Right to data portability — receive your data in a structured, machine-readable format
- Right to object — object to processing based on legitimate interests
- Right to withdraw consent — where processing is based on consent, withdraw it at any time
To exercise any of these rights, contact us at leaddiamond.dev@gmail.com. We will respond within 30 days.
7 Cookies & Tracking
We use the following cookies and storage:
- Session cookie (
leaddiamond_dev_session) — essential for authentication. HTTP-only, secure. Expires on session end. - CSRF token (
XSRF-TOKEN) — protects against cross-site request forgery. Essential for security. - Cookie consent (
kk_cookie_consent) — stores your cookie preference. Stored in localStorage. No expiry.
Analytics Cookies (with your consent)
We use Google Analytics 4 (G-EZMT47L2NH) to understand how visitors use the platform. This is activated only after you click "Accept all" in the cookie banner. If you click "Decline", no analytics data is collected.
When enabled, Google Analytics may collect: anonymised IP address, pages visited, time on site, browser type, device type. No personal identification data is sent. For details see Google's Privacy Policy.
We do not use advertising cookies, Facebook Pixel, or any retargeting technologies. Ad storage is always denied regardless of your cookie choice.
You can withdraw consent at any time by clearing localStorage key kk_cookie_consent in your browser settings.
8 Data Security
- All passwords are hashed using bcrypt with a cost factor of 12
- API keys are stored in environment variables, never in the database
- Sessions are encrypted using AES-256-CBC
- HTTPS is strongly recommended for all deployments
- Access is restricted to authenticated users only
- CSRF protection is applied to all state-changing requests
Despite our best efforts, no system is 100% secure. In the event of a data breach, we will notify affected users within 72 hours as required by GDPR.
9 International Data Transfers
When you use Google Places API or OpenAI API, your search queries may be processed on servers located outside the European Economic Area (EEA). Both Google and OpenAI participate in the EU-US Data Privacy Framework and provide appropriate safeguards under GDPR Article 46.
10 Children's Privacy
LeadDiamond.dev is a professional B2B tool intended for business use only. We do not knowingly collect data from persons under the age of 16. If you believe a minor has created an account, contact us immediately at leaddiamond.dev@gmail.com.
11 Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will:
- Update the "Last updated" date at the top of this page
- Notify active users via the platform dashboard
- Where required by law, seek fresh consent
Continued use of the platform after changes take effect constitutes acceptance of the revised policy.
12 Contact Us
For any privacy-related questions, requests, or complaints:
You also have the right to lodge a complaint with your local data protection authority (DPA) if you believe we have not handled your data correctly.