Security
What we access, and what we never touch.
Pact asks for the least it needs to run your pipeline. Here is exactly what that means for your account, your inbox, your data, and your payments.
Signing in
You sign in with Google. Pact receives only your name and email address. We do not see or store your Google password, and we never ask for it.
Gmail is optional
Connecting Gmail is your choice. When you do, Pact requests one permission: send (gmail.send). That lets outreach go out from your own inbox. Pact never reads your inbox, never lists your messages, and never requests any read or full-access scope.
Tokens encrypted at rest
The OAuth tokens that let Pact send on your behalf are encrypted at rest. They are used only to send the emails you set up, and you can disconnect Gmail at any time to revoke that access.
Your data is isolated
Each account's data is kept separate at the database level using PostgreSQL row-level security. One organizer cannot see another's pipeline, sponsors, or messages.
Export or delete anytime
Your pipeline is yours. You can export your data, and you can delete it. When you delete your account, we remove your data and revoke any connected access.
Every send can be unsubscribed
Every email Pact sends on your behalf carries a one-click unsubscribe. A recipient can opt out in a single click, and Pact respects it on every future send.
Payments run through Stripe
Billing is handled by Stripe. Card details go directly to Stripe and never touch Pact's servers.