Reply Capture — Privacy Disclosure
Last updated: May 2026. This page explains exactly how SealDeal accesses your connected mailbox.
What we read
When you connect your Gmail or Microsoft 365 mailbox, SealDeal polls your inbox every 5 minutes. For each incoming message, we read only the thread-linking headers:
In-Reply-To— the message ID of the email being replied toReferences— the chain of ancestor message IDs
We compare these IDs against a list of emails we sent on your behalf. If a match is found, we fetch the body of that specific reply so your AI assistant can draft a response.
What we do NOT read
- Your existing inbox (emails you received before connecting)
- Emails that are not replies to messages we sent
- Emails you send to other people
- Personal or internal emails unrelated to outreach
- Attachments
Any message whose thread headers do not match a message we sent is discarded immediately — its content is never read, stored, or logged.
How matched replies are used
Matched reply content is used exclusively to:
- Display the reply in your Outreach inbox so you can see it in context
- Pause the outreach sequence (so we stop sending follow-ups)
- Help the AI draft a suggested response for your review
You always review and approve any AI-suggested response before it is sent. We do not auto-send replies based on your connected mailbox content.
Data retention
Inbound reply content is stored in your organization's account and retained in line with your account data retention settings. You can delete individual messages or purge all outreach data from your admin dashboard at any time.
Audit access
SealDeal platform administrators can view aggregated usage statistics (e.g. how many replies were polled per day) but cannot access the content of your emails. Content access is restricted to authenticated users in your organization.
Token storage
Your OAuth access and refresh tokens are encrypted at rest using AES-256-GCM. We store tokens only to perform polling on your behalf. You can disconnect your mailbox at any time from Preferences, which immediately deletes the stored tokens.
Scope details
| Provider | Scope requested | Why |
|---|---|---|
| Gmail | gmail.modify | Read + send mail (modify supersedes send) |
| Microsoft 365 | Mail.Read, offline_access | Read inbox, refresh tokens |
| IMAP | IMAP4 LOGIN | Read INBOX folder only |
Questions
If you have questions about how we access your data, contact us at privacy@sealdeal.ai.