Legal
Privacy Policy
Last updated September 16, 2026
Scope
This policy describes how Armada (“Armada,” “we,” “us”) handles information on https://www.goarmada.co and in the product at app.goarmada.co (including staging hosts such as staging.goarmada.co, hosted API and MCP at mcp.goarmada.co, and related subdomains). It covers the Armada software, marketing site, and the Armada LinkedIn Connect browser extension. It is not for Armada Agency, which has its own pages. Partner supply (Armada Accounts) is covered primarily at accounts.goarmada.co/privacy; extension practices that also apply to Accounts are summarized here for Chrome Web Store reviewers.
For your own account, billing, and site-usage data, Armada is the controller. For lists, sequences, inbox content, recordings, and other customer content you put in a workspace, you are the controller and we process that material to run the Service for you.
The Service is hosted in the United States. If you use it from another country, you understand that information is processed in the US and in other countries where our processors run.
What we collect
You give us information when you:
- create a workspace or sign in (WorkOS handles authentication)
- buy a plan, credits, phone numbers, SMS packs, or LinkedIn seats
- fill marketing forms, including product-update signup and gated resource downloads
- email hello@goarmada.co or book a demo
- connect mailboxes (Gmail / Microsoft), Google or Microsoft calendars, LinkedIn, X, Slack, CRM, enrichment, calendars, or AI keys
- use the Armada LinkedIn Connect extension to link a LinkedIn session
- upload lists, write sequence copy, run Find / enrichment, or use in-app / MCP agents
- place calls or send SMS from Armada (including call recordings when your workspace has recording on)
- install the website pixel or otherwise use Visitors / inbound
That can include name, work email, company, billing details (handled by Stripe), usage events, list rows and message content you store, OAuth tokens for connected accounts, calendar free/busy and events we create on your behalf, phone numbers and SMS content, call recordings and transcripts, visitor events from your pixel, API keys you mint, and keys you connect. We also collect ordinary weblogs (IP address, user agent, pages viewed) and, when you allow it, analytics cookies from Vercel Analytics.
Lists and outreach often include personal data about people who are not Armada users (prospects). You must have a lawful basis to store and contact them. We process that data only to provide the Service to your workspace.
How we use it
We use this information to run the product, bill you, prevent abuse, send transactional mail (receipts, seat status, security), and, if you opted in, product notes or a resource list. We do not sell personal information. We do not rent your lists to other senders. We do not use Google user data, Microsoft Graph data, or LinkedIn session data for advertising, credit scoring, or unrelated data brokerage.
Bring-your-own keys and OAuth credentials are encrypted at rest and used to call the provider you chose. We do not return those secret values to the browser after save.
Some product features send customer content (for example list rows, sequence copy, or a thread you ask us to draft from) to large-language models via OpenRouter or a key you connect, solely to generate the output you requested in the product or via MCP. We do not use Google user data or Microsoft Graph data to develop, improve, or train generalized AI or machine-learning models. We do not sell that data to model providers for training.
Google user data (Gmail and Calendar)
When you connect Google from Armada (Settings → Accounts for mail; Settings → Meetings for calendar), we request only the Google OAuth scopes needed for those features. App sign-in itself uses WorkOS, not Google Sign-In for mailbox or calendar access.
Gmail. With your consent we use gmail.readonly to sync inbound messages and threads into Armada Unibox, and gmail.send to send mail you initiate or approve from a connected mailbox (replies, sequences, and related seat sends). We access message content and metadata only to operate inbox, reply, and outbound features for your workspace, including optional AI drafts you request on those threads.
Google Calendar. With your consent we use calendar.readonly to read free/busy and events for availability and meeting proposals, and calendar.events to create or update meeting holds and bookings you schedule through Armada.
Storage and sharing. OAuth refresh tokens are stored encrypted, scoped to your workspace. Message and calendar data is processed to power the product UI and backend workers (for example email sync and send). We do not sell Google user data. We do not transfer Google user data to third parties except (a) infrastructure processors that help us run the Service under contracts that limit use, (b) when you direct an integration (for example CRM write-back or an AI draft you request), or (c) when required by law. Human access to Google user data is limited to security, abuse investigation, and support when you ask us to help, or where required by law, and is subject to internal access controls.
Retention and deletion. Connected-account tokens remain until you disconnect the mailbox or calendar or delete the workspace. You can disconnect Google in the product, revoke Armada in your Google Account permissions, or email hello@goarmada.co to request deletion of workspace data. We remove operational Google-derived data on a commercially reasonable timeline except records we must keep for security, billing, or law.
Armada's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Microsoft user data (Outlook / Microsoft 365)
When you connect Microsoft from Armada (Settings → Accounts for mail; Settings → Meetings for Outlook Calendar), we request Microsoft Graph OAuth permissions needed for those features. App sign-in itself uses WorkOS, not Microsoft as the primary login for mailbox or calendar access.
Mail. With your consent we use Mail.Read to sync inbound messages and conversations into Armada Unibox, and Mail.Send to send mail you initiate or approve from a connected mailbox (replies, sequences, and related seat sends). We also use User.Read, openid, email, profile, and offline_access to identify the connected account and refresh tokens without repeated consent prompts. We access message content and metadata only to operate inbox, reply, and outbound features for your workspace, including optional AI drafts you request on those threads.
Outlook Calendar. With your consent we use Calendars.Read to read free/busy and events for availability and meeting proposals, and Calendars.ReadWrite to create or update meeting holds and bookings you schedule through Armada, plus the same identity / offline scopes above for the connected Microsoft account.
Storage and sharing. OAuth refresh tokens are stored encrypted, scoped to your workspace. Message and calendar data is processed to power the product UI and backend workers (for example email sync and send). We do not sell Microsoft user data. We do not transfer Microsoft user data to third parties except (a) infrastructure processors that help us run the Service under contracts that limit use, (b) when you direct an integration (for example CRM write-back or an AI draft you request), or (c) when required by law. Human access is limited to security, abuse investigation, and support when you ask us to help, or where required by law, and is subject to internal access controls. We do not use Microsoft Graph data for advertising or unrelated data brokerage. We do not use Microsoft Graph data to develop, improve, or train generalized AI or machine-learning models.
Retention and deletion. Connected-account tokens remain until you disconnect the mailbox or calendar or delete the workspace. You can disconnect Microsoft in the product, revoke Armada in your Microsoft account privacy / app permissions, or email hello@goarmada.co to request deletion of workspace data. We remove operational Microsoft-derived data on a commercially reasonable timeline except records we must keep for security, billing, or law.
Armada uses Microsoft Graph data only to provide or improve the user-facing mailbox, inbox, and calendar features described above, and only for the Microsoft account you choose to connect.
Armada LinkedIn Connect (Chrome extension)
The Armada LinkedIn Connect extension's single purpose is to help you link a LinkedIn account to Armada (product seats or Armada Accounts partner vault). It does not automate LinkedIn, scrape your feed, or inject scripts into LinkedIn pages.
When you start a connect from Armada, the extension reads LinkedIn session cookies (li_at, and optionally li_a for Recruiter) and your browser user agent, then sends them over HTTPS to Armada endpoints you authorize (product or Accounts). The extension does not keep those cookies after the handoff. Armada stores connection material encrypted server-side to operate the LinkedIn seat or partner listing, including refresh / reconnect flows you enable. We do not sell LinkedIn session data or use it for advertising. We do not use it to train generalized AI models.
You can remove the extension in Chrome, disconnect the seat or vault in Armada, or email hello@goarmada.co (product) or accounts@goarmada.co (partner) for help.
Phone, SMS, and recordings
If you buy numbers or SMS through Armada, Telnyx (and related carriers) process numbers, call audio, SMS bodies, and delivery metadata to place and receive those messages. When workspace recording is on, we store recordings so you can play them in the dialer and inbox. You are responsible for any recording disclosure or consent your jurisdiction requires. We do not sell call audio or SMS content.
Website pixel and Visitors
If you install our pixel, it collects page-view and related events from your site (and identifiers you send) so you can see visitors and engagers in Armada. You must disclose that tracking on your own site where the law requires it. We process pixel events as your processor.
API keys, MCP, and agents
If you create an Armada API key or connect MCP (hosted at mcp.goarmada.co or via the stdio package), we log authenticated tool and API use for billing, abuse prevention, and debugging. Keys are shown at creation; we store hashes, not the raw secret, after that. You are responsible for who holds a key.
Processors
We use vendors to host the app, send email, take payment, store data, run queues and workers, place calls/SMS, connect social accounts, and (if you subscribe) run the newsletter. They only get what they need to do that job. Depending on which features you use, that can include Stripe, WorkOS, Vercel, Neon, Amazon Web Services, Telnyx, Unipile, OpenRouter, Google, Microsoft, and similar infrastructure or channel providers. If you connect Gmail, Outlook, LinkedIn, X, Slack, CRM, enrichment APIs, or OpenRouter, those companies process data under their terms as well.
Retention
We keep account and billing records for as long as the workspace exists and as long as tax or dispute rules require. You can ask us to delete a workspace by emailing hello@goarmada.co; we will remove operational data on a commercially reasonable timeline except for records we must keep. Disconnecting a mailbox, calendar, or LinkedIn seat stops new sync from that connection; historical inbox or sequence records in the workspace remain until you delete them or the workspace.
Your rights
Depending on where you live, you may have rights to access, correct, delete, or export personal information, or to object to certain processing. Email hello@goarmada.co. Marketing mail includes an unsubscribe link.
If you are in California or another US state with a consumer privacy law: we do not sell personal information and we do not share it for cross-context behavioral advertising. You may request to know, delete, or correct personal information we hold as controller, or appeal a denial, by emailing hello@goarmada.co. We will not discriminate against you for exercising those rights. For prospect data in a customer workspace, contact that customer; we will assist them as processor.
Children
The Service is not for anyone under 18. We do not knowingly collect information from children. If we learn we did, we delete it.
Security
We use HTTPS, access controls, and encryption for credentials and OAuth tokens. No internet product is perfectly secure. Report a vulnerability to hello@goarmada.co.
Cookies
Essential cookies keep you signed in and remember theme. Affiliate referral cookies (for example armada_ref) remember a promo code so checkout can apply it. After you unlock a gated guide on /resources, an httpOnly cookie remembers that unlock for 90 days so you can reread and download the PDF. Analytics cookies help us see which marketing pages are used. You can block non-essential cookies in your browser; the site still loads. The Chrome extension uses short-lived extension storage only for pairing state during a connect, not for long-term cookie storage.
Changes
We will change the “Last updated” date when this policy changes. Material changes to how we use personal information will be called out on this page or by email when we have a contact address.
Contact
Privacy questions: hello@goarmada.co. See also Terms of Service.
Questions: contact or email hello@goarmada.co.

