Outreach Privacy Policy
Effective September 20, 2026
Overview
Outreach assists with email drafting in Fastmail. It has no analytics, advertising, telemetry, or developer-operated data backend. The developer does not receive or sell user data.
Data handled locally
Outreach processes selected Fastmail email content and headers, composer recipients and sending identity, imported contact names and addresses, generated drafts, editable AI profile context, project settings, the configured Codex server address, and its bearer token.
Profiles, settings, contacts, Open/Send action timestamps, saved drafts, and imported records remain in Firefox extension-local storage. Up to 10 temporary per-email drafts are retained for 24 hours. Data is not stored using Firefox Sync by Outreach.
AI drafting and recipients
When the user requests generation, Outreach sends the selected email or contact information, visible addressing context, the user's instruction, and exactly one bundled or user-edited AI profile context to the user-configured Codex App Server. Codex may send that information to OpenAI for generation. The capability token is sent only to the configured WebSocket endpoint for authentication.
Outreach does not control the configured server operator's or OpenAI's retention, training, backup, or deletion practices. Users should generate only from content they are authorized to share.
Fastmail and clipboard actions
Outreach reads supported Fastmail pages to provide message and composer controls. Insert and Open in Fastmail place reviewed content into Fastmail. Send in Fastmail is an explicit per-contact command that verifies the visible identity, recipient, subject, and retained body before clicking Fastmail's Send control. Fastmail receives and processes email content, addressing, and delivery information under its own policies.
Copy actions place selected text on the system clipboard only when requested.
Connection security
Outreach supports ws:// and wss:// connections to the configured Codex server. Plain ws:// is unencrypted and can expose the bearer token and drafting data to network observers. Prefer localhost with an encrypted tunnel or wss:// for remote connections. The bearer token is stored locally without additional extension-level encryption; users should protect their Firefox profile and revoke exposed tokens.
User control, retention, and deletion
Users choose when to generate, insert, open, copy, save, or send. Contacts can be deleted individually or cleared together. Saved records remain until deleted or the extension is uninstalled. Uninstalling Outreach removes its extension-local data under normal Firefox behavior. Data retained by Fastmail, the configured server, OpenAI, backups, or the clipboard must be managed separately.
Children
Outreach is a productivity tool and is not directed to children.
Changes and contact
Material changes will be reflected in extension updates and the published privacy policy. Privacy questions may be sent to admin@btcwid.com.