What Expulse keeps, and why.
Effective 17 August 2026
Expulse processes account identity, workspace settings, connected sender metadata, lead and campaign data, message activity, suppression records, billing records, credit history, audit events, and operational diagnostics to provide and secure the service.
Identity and billing
Auth0 handles authentication and Stripe handles card and tax information. Expulse stores stable identity and billing references, entitlement state, invoice summaries, and audit history; Expulse does not store full card details.
Connected providers
When you connect Google Workspace, Microsoft 365, SMTP/IMAP, Unipile, or MCP clients, Expulse stores encrypted credentials or tokens needed to perform requested operations. Only the sender owner or a workspace administrator may reconnect or edit credentials.
Sales data and suppression
You control the leads, drafts, campaigns, replies, and suppression records placed in your workspace. Suppression is preserved across campaigns so an unsubscribe is not silently undone.
Retention and deletion
At effective cancellation, Expulse pauses execution and revokes provider and MCP refresh credentials. Customer data and purchased credits remain until the account owner exports or explicitly requests deletion. A deletion request starts a short recovery window before permanent removal.
Security and subprocessors
Expulse uses hosting, authentication, payment, email-delivery, provider-integration, and monitoring services. Production logs exclude request bodies and secrets. A current subprocessor list and data-processing addendum will be supplied before general availability.
Your controls
Authenticated workspace owners can export workspace data, export or import suppression lists, revoke provider access, revoke sessions, and request account deletion. Contact privacy@expulse.app for access or correction requests.