Legal
Privacy policy
Last updated
This policy explains what personal data Larvabot collects, why, who helps us process it, how long we keep it and what you can do about it. It covers our website (larvabot.com), the Larvabot dashboard (app.larvabot.com) and the small tracking script members add to their own sites.
Questions or requests: hello@larvabot.com.
#Who we are
Larvabot is an outreach tool for indie hackers and small projects. For data about our website visitors and our members, we decide how it's used, so we are the controller. For data members collect with Larvabot about the people they contact (their leads, contacts and site visitors), the member decides how it's used, so the member is the controller and we process it on their behalf. See People our members contact.
#What we collect
#When you visit larvabot.com
- Analytics. If you accept analytics cookies, we use Google Analytics to understand which pages are read and how people find us. It sets cookies and receives your IP address, browser details and pages visited. If you decline, it doesn't load. See the cookie notice.
- Server logs. Our hosting provider records technical request data (IP address, time, page, browser) for security and to keep the site running.
- Waitlist sign-ups. If you join the early-access list we store your email address, which form you used and a country derived from your connection. We don't store your IP address with it. We send you a welcome email and, later, an invitation.
#When you have a Larvabot account
- Account details: your name, email address and a password hash (never the password itself), plus sign-in times and your plan.
- Your settings: the API keys, mail account details and tokens you add. Secrets are encrypted before they're stored and only their last four characters are ever shown again.
- Your projects: the sites you add, their profiles, campaigns, drafts, notes and reports.
- Usage and logs: how many calls each connected service made (to keep you inside free quotas) and a log of background jobs, so you and we can see what ran.
#People our members contact
To find and contact people, Larvabot processes information that is already public or that the member provides:
- Leads: the public page that was found, a summary of it, and contact details published on that page or its contact and about pages. If the member connects an email-finding service (such as Hunter, Prospeo or Tomba), that service may supply a business email address.
- Conversations: the link, title, a short excerpt and the public username of posts where someone asked for something a member's project does.
- Contacts: names, phone numbers, emails and notes the member imports about people they already know.
- Telegram groups: if a member connects their own Telegram account, recent messages in groups they have joined are read and only the relevant ones are kept.
- Emails: messages the member approves and sends, and replies or bounces that arrive in the inbox they connect.
Every outreach email includes a one-line opt-out and a List-Unsubscribe header, and a reply stops all follow-ups. If you were contacted by a Larvabot member and want your details removed, reply to their email or write to hello@larvabot.com and we'll help.
#Visitors to our members' websites
Members can add a small tracking script to their own site to see which outreach brought visitors. It records the page, the referring site, any ref or utm tags, a country and the time. It sets no cookies, stores no IP addresses and doesn't follow anyone between visits or sites.
#Why we use it (legal bases)
| Purpose | Basis |
|---|---|
| Providing your account and the service you signed up for | Performing our contract with you |
| Security, fraud prevention, fixing problems | Legitimate interests |
| Website analytics | Your consent, given in the cookie banner |
| Waitlist and invitation emails | Your request, and legitimate interests |
| Processing leads and contacts for members | On the member's instructions; the member is responsible for having a lawful basis |
| Meeting legal obligations | Legal obligation |
We don't sell personal data, and we don't use members' data or their contacts' data for advertising.
#Who processes data for us
We use a small number of providers to run Larvabot:
| Provider | What for |
|---|---|
| Vercel | Hosting the website and dashboard |
| Neon | Database |
| Cloudflare | DNS, email routing and bot protection on sign-in forms |
| Google Analytics | Website analytics on larvabot.com |
| Our email provider (Brevo) | Sending account emails such as invitations and password resets |
Services members connect themselves. Larvabot works with the member's own accounts at AI, search, email and community services (for example Google Gemini, Groq, Tavily, Brevo or Gmail). When Larvabot uses them, the content needed for the task (a page to read, a draft to write, a search query, an email to send) is sent to that service under the member's own account and that service's terms and privacy policy.
Some providers are based outside your country, including in the United States. Where the law requires it, we rely on appropriate safeguards such as standard contractual clauses.
#How long we keep it
- Account and project data: while your account is open. When an account is deleted, its projects, leads, emails, contacts and keys are deleted with it.
- Job logs and usage counts: as long as they're useful for running the service, and deleted with the account.
- Waitlist entries: until you're invited or ask us to remove you.
- Analytics: according to our Google Analytics retention setting.
- Backups and logs held by our providers roll over on their own schedules.
#Security
Connections are encrypted, secrets are encrypted at rest with a key kept separately from the database, passwords are hashed with a unique salt, and every page and action checks that you can only see your own data. No system is perfectly secure, but we work to keep yours safe and will tell affected people promptly if something goes wrong.
#Your rights
Depending on where you live, you may have the right to access, correct, delete or export your personal data, to object to or restrict some processing, and to withdraw consent at any time. Write to hello@larvabot.com and we'll respond within the time the law allows. If you're not happy with our answer, you can complain to your local data protection authority.
If your data is in a member's project (for example as a lead or contact), we'll pass your request to that member and help them handle it.
#Children
Larvabot is not meant for anyone under 16, and we don't knowingly collect their data.
#Changes
If we change this policy in a meaningful way, we'll update the date at the top and, for members, let you know by email or in the dashboard before the change takes effect.