Skip to main content

Privacy Policy

Last updated: 2026-07-21

This Privacy Policy explains how Keendai (“Keendai”, “we”, “us”), a service operated by H2Op, collects, uses, shares, and retains information when you visit our websites or use the Keendai application. Keendai is a business-to-business lead-generation platform: customers define an Ideal Customer Profile, and we mine public business data, enrich it with vendor APIs, score it with AI, and deliver ranked lead lists that the customer can review and export.

1. What this policy covers

This policy applies to your use of:

This policy does not cover third-party services you choose to connect to your workspace to receive your leads, such as a CRM, a spreadsheet, or an outreach tool. When you connect one of these and export or sync leads to it, that service receives the data you send and handles it under its own privacy policy and your agreement with it.

2. Information we collect

2.1 Account information you provide

When you sign up for Keendai we collect your name, email address, and authentication identifiers. You can sign in with Google OAuth, Microsoft OAuth, or an email-and-password credential managed by Firebase Authentication. If you sign in with Google or Microsoft, we receive the basic profile fields the provider returns (name, email, profile photo URL) and an identity token. We do not request, store, or use any additional Google scopes beyond basic sign-in.

2.2 Workspace and Ideal Customer Profile data

Inside the application you create a workspace and one or more Ideal Customer Profiles (ICPs). An ICP describes the kind of business you want to reach: an offer pitch, verticals, geography, contact-channel requirement, and optional advanced settings. We store this configuration so we can run mining on your behalf and so you can edit it later.

2.3 Lead data we fetch on your behalf

When you start a mining run, our worker fetches publicly available business information from Google Maps Places and Instantly Lead Finder, then enriches resolved business contacts via Apollo (person resolution), Hunter (email discovery and verification), and Telnyx Lookup (phone line type metadata). The data we fetch is business contact information about decision-makers at the businesses your ICP targets: business name, address, phone, website, business email, the public name and title of a contact, and employee-count or industry bands where available. We do not knowingly mine consumer or personal-use contact data.

To add context to a delivered lead, we also make a single automated request to the lead business’s own publicly available website and read its page text. We pass a short excerpt of that public text (up to a few thousand characters) to an AI model to extract a few factual highlights about the business — for example services offered, locations, or languages stated on the site. This “Intel” is drawn only from the business’s own public website, is delivered to you as plain facts, and is not used to train general-purpose AI models. If a business has no website or nothing distinctive to extract, no Intel is produced.

2.4 Billing data

Both subscription billing (monthly plans) and one-time Lead Pack purchases are handled by Stripe. When you check out, Stripe collects your payment-method information directly. We receive a Stripe customer ID, subscription status, one-time-purchase (Lead Pack) receipts, invoice metadata, the Stripe Price or product identifier of what you purchased, and the last four digits of your card via Stripe’s API. We never see, store, or have access to full payment-card numbers. For Lead Packs, we also store the pack size, purchase date, and 90-day expiry date alongside your workspace ledger so we can apply the leads you purchased and re-credit any duplicates, missing contacts, or undeliverable emails (see our Terms, Section 5).

2.5 Usage and security data

We automatically record IP address, browser and device type, request paths, request IDs, and timestamps in our application logs. We use these for security, abuse prevention, rate limiting, and debugging. Sensitive payload fields (raw email contents, prospect contact PII) are redacted from operational logs.

2.6 Guest (pre-signup) data

You can try a limited lead search before creating an account. When you do, we create a temporary, anonymous guest identity and a temporary guest workspace so the search can run, and we record the search inputs and the same usage and security data described in Section 2.5. If you ask to see your full results, we collect the email address you provide at that step. A guest search runs the same public-business mining described in Section 2.3. If you create an account, your guest workspace and its results are adopted into your new account; if you do not, the guest workspace and its results are automatically deleted after 7 days (see Section 5). An email address you submit to receive a preview is used to send you that preview and a sign-up link through our email provider, and is retained in that email system; email privacy@keendai.com to have it removed.

3. How we use information

We do not sell personal information for money. We do not use your data, or data we obtain from Google APIs, to train general-purpose machine-learning models.

Legal basis.The business contact information in a lead list concerns people in their professional capacity at the businesses your ICP targets. Where data protection law requires a legal basis, we rely on our and our customers’ legitimate interest in business-to-business outreach, balanced against the rights of the individuals concerned, and we honor the removal right described in Section 6. Note that our use of advertising-measurement cookies (Section 9) may be considered a “share” of personal information under some U.S. state privacy laws; you can limit this using the controls in Section 9.

4. Sharing with third parties

We share information with the third-party service providers below. Vendors marked “sub-processor” act on our behalf to deliver the Service under a contract that requires confidentiality and appropriate security measures. Vendors marked “advertising” or “analytics” receive the events described and process them under their own privacy policies and terms as independent controllers.

VendorRoleWhat we share
Google Cloud PlatformSub-processorAll workspace data is hosted on Google Cloud (Cloud Run, Firestore, Cloud Tasks, Cloud Storage, Secret Manager) in the us-central1 region.
Firebase AuthenticationSub-processorIdentity provider for Google OAuth, Microsoft OAuth, and email-and-password sign-in. Receives your email and authentication factors.
StripeSub-processorReceives your billing email, name, billing address, and payment-method details that you enter on Stripe’s hosted checkout and customer portal.
ApolloData sourceReceives the business domain or company name we are resolving on your behalf; returns publicly listed contact name, title, and LinkedIn URL.
HunterData sourceReceives a business domain or candidate email; returns email-discovery results and deliverability verdicts.
Instantly Lead FinderData sourceReceives ICP-shaped queries on your behalf; returns business contact records from Instantly’s lead database.
TelnyxData sourceReceives a phone number; returns line-type and carrier metadata. We do not place calls or send SMS through Telnyx as part of Keendai.
Google Gemini (via Google Cloud)Sub-processorReceives the ICP context and a candidate’s public business signals to produce a fit score, and receives an excerpt of a lead business’s own public website text to extract factual highlights (“Intel”). Customer prompts and prospect data are not used by Google to train general-purpose models.
Google Maps PlatformData sourceReceives geography and category queries on your behalf; returns public Places data we use to construct candidate lead records.
DiscordOperator alertingReceives internal alerts (workspace IDs and event types only). No customer contact data, no prospect contact data, no payment data.
Google (Analytics & Ads)Analytics & advertisingOn our marketing site, via a tag manager, we load Google Analytics and Google advertising tags. They receive page-view, click, and conversion events and a cookie or advertising identifier, used to measure traffic and the effectiveness of our ads. See Section 9 and Google’s privacy policy.
Meta (Facebook) PixelAdvertisingOn our marketing site, we load the Meta Pixel, which receives page-view and conversion events and a cookie or identifier so we can measure and target ads on Meta platforms. See Meta’s privacy policy.
MicrosoftAnalytics & advertisingOn our marketing site we load Microsoft Clarity (anonymized session analytics) and the Microsoft Advertising tag (ad-conversion measurement). They receive click, scroll, page-navigation, and conversion events. See Microsoft’s privacy statement.

We may add, remove, or change these providers as the Service evolves. When we make a material change to the sub-processors that handle personal data on our behalf, we will update this list and give notice as described in Section 11. If you are a business customer who needs a data processing agreement, ours is available at keendai.com/dpa.

We may also disclose information when required by law, valid legal process, or to protect the rights, property, or safety of Keendai, our customers, or others. In the event of a merger, acquisition, or sale of assets, your information may be transferred to the successor entity, subject to this policy.

5. Data retention

6. Your rights

You may request the following at any time, regardless of where you live, by emailing privacy@keendai.com:

We will respond to verifiable requests within 30 days. If you are a person whose business contact information has been included in a customer’s lead list (a “prospect”), you have the same rights with respect to that data; email privacy@keendai.com and we will remove your business contact record from our system.

7. Children’s privacy

Keendai is a business product. The Service is not directed to children under 13, and we do not knowingly collect personal information from anyone under 13. If you believe a child has provided us with personal information, please contact us at privacy@keendai.com and we will delete it.

8. International data transfers

Keendai is hosted in the United States. All workspace data, including data we fetch on your behalf from third-party data sources, is processed and stored in the Google Cloud us-central1 region. If you access the Service from outside the United States, you understand that your data will be transferred to and processed in the United States, where data-protection law may differ from the law of your country.

9. Cookies and tracking

We use a small number of strictly necessary cookies to keep you signed in and to protect your session (a Firebase Authentication session cookie and a CSRF token). We use Google reCAPTCHA on signup forms to deter automated abuse; reCAPTCHA may set its own cookies and process limited browser metadata under Google’s privacy policy.

On our marketing site (keendai.com) we load analytics and advertising-measurement tags through a tag manager. These include session and traffic analytics (Microsoft Clarity, which records anonymized clicks, scrolls, and page navigation and does not capture form input values; and Google Analytics) and advertising-measurement pixels (Google Ads, the Meta Pixel, and Microsoft Advertising). These tags set cookies or read advertising identifiers and send page-view, click, and conversion events to the providers named in Section 4 so we can understand site usage and measure whether our ads work. Because our marketing site and the application are served from the same web app, these analytics and advertising-measurement tags may also load while you are signed in; we do not display advertising inside the application. The choices below let you limit these tags.

Your privacy choices

You can limit or opt out of the analytics and advertising cookies described above:

10. Security

No system is perfectly secure. If we discover a security incident affecting your data, we will notify you and any required authority as soon as reasonably possible and in any event within the timeframe required by applicable law.

11. Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date at the top. For material changes that affect how we use personal information, we will notify the workspace owner by email and place a banner in the application before the changes take effect.

12. Contact

Keendai is operated by H2Op. If you have any questions about this policy or about how we handle your data, contact us at: