Last updated: February 2026 · Contact: privacy@myleadsconvert.us
My Leads Convert ("we", "us", "our") operates the platform at myleadsconvert.us. The platform helps you define an Ideal Customer Profile (ICP), source real US nonprofit organizations from public IRS 990 filings via ProPublica, draft grounded outreach emails with AI assistance, and manage outreach campaigns. This policy explains how we collect, use, and protect personal information.
Note on the real nonprofit data we surface
The organizations shown under "Mine real leads" are real, US-registered nonprofits pulled from ProPublica's public Nonprofit Explorer API. Their names, EINs, addresses, NTEE codes, and 990 filing amounts are public record because 501(c) organizations are required by federal law to file Form 990 with the IRS annually. This data is about legal entities (organizations), not natural persons, and we do not fabricate individual contacts on top of it. Section 2A below spells out what this means for you and for the organizations we surface.
1. Information We Collect
a. Information you provide
Account info: name, email, password (stored only as a one-way bcrypt hash), email-verification state.
ICP inputs: industry, target role, company size, geography, keywords.
Campaign content: subject lines and message bodies you author or save from batch drafts.
Settings: your Demo-mode toggle and account preferences.
Support communications you send us.
b. Information generated or sourced in your account
Real nonprofit records ("Mine real leads"): sourced from ProPublica's public Nonprofit Explorer API. These are real, third-party organization records — not content you generated and not your personal information. Each record contains only publicly-filed IRS Form 990 data: organization name, EIN, city/state, NTEE activity code, latest reported revenue, and 990 filing year, plus a link back to the ProPublica public record. We do not fabricate contact names, emails, or personal information for these records. See Section 2A for the full sourcing breakdown and your responsibilities when acting on this data.
AI-generated demo leads (only when you enable Demo mode in Settings): plausible-sounding but fabricated lead records used for pitch decks, UI walkthroughs, and product testing. They are clearly badged "Demo" in the UI and never mix with real records.
Outreach drafts ("Draft outreach email", "Batch draft"): subject line, body, and grounding disclaimer generated by Claude from the verified 990 data of the selected lead(s). Drafts are visible only to you and stored transiently unless you save them into a campaign.
Activation timestamp: the moment your first real ProPublica lead is added to your workspace is recorded once (first_mine_at) and used only in aggregate, admin-only funnel analytics.
c. Information collected automatically
Server logs: IP address, browser type, pages visited, error traces.
Authentication cookies: access_token and refresh_token, both HTTP-only, SameSite=Lax, and Secure on production HTTPS (controlled by the COOKIE_SECURE environment flag).
Local browser storage: two small flags (mlc-fresh-start-dismissed, mlc-first-mine-celebrated) used to remember that you've seen a one-time onboarding hint. No personal data, no tracking IDs.
Basic device information.
We do not run advertising trackers or behavioral-ad pixels.
2. How We Use Your Information
Provide, operate, and improve the platform.
Authenticate you and secure your account.
Query ProPublica's public API to source real nonprofit records that match your ICP.
Generate grounded outreach drafts and (in Demo mode only) AI sample leads.
Compute aggregate, admin-only activation funnel analytics (total users vs. activated users, median time-to-first-real-lead). No individual behavior is exposed to other users.
Respond to support requests.
Detect fraud and abuse; comply with legal obligations.
We do not sell your personal information. We do not use your ICP, saved leads, or campaign content to enrich any shared database available to other customers.
2A. Real Nonprofit Data — Sourcing, Rights & Responsibilities
Because the leads under "Mine real leads" are real US-registered nonprofits (not fabricated samples), this section clarifies what that means for both you and the organizations we surface. This section is specific to ProPublica-sourced records; it does not apply to opt-in Demo-mode AI leads.
a. Source, scope, and attribution
Source: ProPublica's Nonprofit Explorer API, a public dataset built from filings that 501(c) organizations submit to the US Internal Revenue Service on Form 990. See projects.propublica.org/nonprofits.
What we surface: organization name, EIN, city/state, NTEE activity code, latest reported revenue amount, 990 filing year, and a link back to the organization's ProPublica public record. Every real lead in your workspace carries a green "Real" badge and links to its ProPublica page so you can verify the underlying filing.
What we do NOT surface: individual staff names, personal email addresses, direct phone numbers, LinkedIn URLs, or any other information about specific people at these organizations. Contact fields are left blank on real leads (the UI shows "Contact TBD") — you are responsible for researching the right person to reach on the organization's own website before sending any outreach.
Real data is not "your" data: real nonprofit records are third-party public records about legal entities. They are not personal information belonging to you as a user of the platform. You do not acquire ownership of the underlying public data by mining it into your workspace; you gain a copy that lives in your workspace until you delete it.
b. Legal basis & nature of the data
Form 990 filings are public records mandated by the US Internal Revenue Code (26 U.S.C. § 6104) and made available by the IRS. ProPublica republishes them under its Nonprofit Explorer service.
Nonprofit organizations are legal entities. In most jurisdictions (including under the CCPA/CPRA and GDPR), information about legal entities is not "personal information" or "personal data". However, some fields (like an executive director's name embedded in a public 990) may relate to identifiable individuals — where that occurs, those individuals have chosen to be listed on a public tax filing.
We do not enrich, augment, cross-reference, or otherwise expand ProPublica records against other databases. What ProPublica exposes publicly is what you see.
c. ProPublica's terms and API etiquette
Your use of real nonprofit records is subject to ProPublica's Terms of Use and Nonprofit Explorer terms in addition to this policy. We do not warrant the completeness, timeliness, or accuracy of ProPublica's data — filings can be years out of date and typographical errors in 990 submissions are common.
We send ProPublica only the minimum needed to run your search: a keyword and (optionally) a US state filter. We identify ourselves with a polite User-Agent header. Per-user rate limiting on our side protects ProPublica from unintended abuse.
d. Your responsibilities when contacting organizations we surface
When you send outreach to a real nonprofit sourced through the platform, you — not My Leads Convert — are the sender. You are responsible for:
Complying with all applicable outreach laws in your jurisdiction and the recipient's: CAN-SPAM Act (US commercial email), CASL (Canada), GDPR/PECR (EU/UK), and any state or sector-specific rules.
Honoring unsubscribe requests, "do not contact" preferences, and the organization's published contact policies (many nonprofits publish specific channels for solicitations, partnerships, or press).
Verifying that a listed 990 revenue or address is still current before using it in outreach copy. Filings can lag reality by 12–24 months.
Reading the AI-drafted email before you send it. Every outreach draft ships with a "what was verified vs. not" disclaimer for exactly this reason.
Not misrepresenting your affiliation with, or endorsement by, any organization we surface.
e. If an organization asks to be removed
Because the underlying data is public IRS record, we cannot remove an organization from the IRS 990 filings or from ProPublica's public index. What we can do is: (i) block that organization from appearing in any user's future "Mine real leads" results, and (ii) delete existing copies of that record from active user workspaces to the extent feasible. If you represent a nonprofit that would like to be suppressed from the platform, email us at privacy@myleadsconvert.us with your organization name and EIN, and we will process the request within 30 days.
3. AI and Machine Learning
When you use AI features, we send tightly-scoped inputs to Anthropic (Claude Sonnet 4.5, via the Emergent Universal Key). Specifically:
For outreach drafting ("Draft outreach email" and "Batch draft"): the target organization's public 990 facts (name, city/state, EIN, NTEE code, latest revenue year), plus your own name, industry, keywords, and role focus from your ICP. We do not send recipient names, private email addresses, or inbox contents. The system prompt explicitly forbids Claude from inventing recipient names or programs.
For Demo-mode AI leads (opt-in): your ICP fields only.
Our AI provider does not train foundation models on your inputs when used through the Emergent Universal Key.
4. Cookies & Local Storage
We use only strictly-necessary authentication cookies (see Section 1c). Deleting them will log you out. We also use two small local-storage flags to remember that you've dismissed a one-time onboarding hint or already seen your first-mine celebration; clearing your browser storage will reset them. If we ever add optional analytics cookies, we will present a consent banner first.
5. Third-party Data Sources & Sub-processors
a. Data sources (read-only)
ProPublica Nonprofit Explorer — public IRS 990 filing data. When you click "Mine real leads", we send your ICP keyword and optional US state to ProPublica's public search API and receive matching organization records. We do not send your personal information; ProPublica will however see our server's IP address as a normal part of any HTTPS request. Your use of this data is also subject to ProPublica's Terms of Use. See Section 2A for the full breakdown of what is and isn't sourced, and your responsibilities when acting on real nonprofit records.
b. Service sub-processors
We share information only with these service providers, strictly as needed to operate the platform:
MongoDB Atlas — primary database.
Emergent — application hosting and LLM key routing.
Anthropic — AI drafting and (in Demo mode) sample lead generation.
Resend — transactional email delivery.
Cloudflare / DNS providers — routing and DDoS protection.
6. Data Retention & Your Controls
Account data: retained while your account is active.
Real, AI-demo, and seed leads: retained until you delete them. You can delete a single lead from the drawer, bulk-delete selected leads, or use the "Clean up" menu to wipe demo, archived, seed, or all leads at once.
Outreach drafts: only persisted if you explicitly save them into a campaign; otherwise they exist only for the lifetime of the response.
Password-reset and email-verification tokens: automatically purged (1 hour and 24 hours respectively).
Server logs: typically 30 days.
7. Security
Passwords hashed with bcrypt.
TLS/HTTPS for data in transit; encryption at rest via infrastructure providers.
HTTP-only, Secure (in production), SameSite=Lax session cookies.
Rate limiting and brute-force lockout on authentication endpoints.
Per-user rate limiting on the lead-mining endpoints to prevent abuse of ProPublica and our AI budget.
Single-use, SHA-256-hashed tokens for password reset and email verification.
Role-based access controls (only admins can view the aggregate activation funnel).
Admin account credentials are set by the account owner — the platform does not auto-reset admin passwords.
No system is fully secure. Report suspected issues to privacy@myleadsconvert.us.
8. Your Rights
Depending on your jurisdiction, you may have the right to access, correct, delete, restrict, port, or object to processing of your personal data, and to withdraw consent. Many of these can be exercised in-app: you can update your name/email in Settings, self-delete every lead in your workspace via the "Clean up" menu, and delete your account by contacting us. For anything else, email privacy@myleadsconvert.us. We respond within timeframes required by law (typically 30 days).
9. Children
The platform is intended for professionals over the age of 18 and is not directed to children. We do not knowingly collect personal information from anyone under 16.
10. International Transfers
The platform is hosted in the United States. If you access it from elsewhere, your data may be transferred to and processed in the US and other jurisdictions where our providers operate. Where required, we rely on Standard Contractual Clauses and the EU-U.S. Data Privacy Framework.
11. California & EU Residents
California residents have rights under the CCPA/CPRA including to know, delete, correct, and opt-out of sale/share of personal information (we do not sell or share). EU/UK/Swiss residents have rights under GDPR/UK-GDPR and may lodge complaints with a local data-protection authority.
12. No Payments
My Leads Convert is currently a free MVP. We do not process payments, store payment card numbers, or run any pricing tier. If we add paid plans in the future, we will update this policy and disclose any payment processor before charging.
13. Changes to This Policy
We may update this policy from time to time. Material changes will be posted here with an updated "Last updated" date. Continued use of the platform after a change constitutes acceptance.
14. Contact
Questions or requests: privacy@myleadsconvert.us
This policy is provided as a good-faith description of our current data practices and is not legal advice. Please consult a privacy attorney qualified in your jurisdiction before treating it as a binding legal document.