This policy explains how Roman Shostak LLC, the company that operates LeadFilter AI (“LeadFilter AI,” “we,” “us”), handles personal data across the LeadFilter AI website, dashboard, and screening API, why we process it, and the choices and rights you have.
This policy applies to the LeadFilter AI website, the dashboard at app.leadfilter.zsetup.com, and the screening API at api.leadfilter.zsetup.com(together, the “Service”). It covers personal data of account holders and the data submitted to the Service for screening.
The operator of the Service is Roman Shostak LLC, Sharjah Media City (Shams), Sharjah, United Arab Emirates (commercial licence no. 2429518.01). For any privacy question you can reach us at privacy@leadfilter.zsetup.com.
We handle personal data in two distinct roles:
For lead content, you are responsible for providing any privacy notices to, and having a lawful basis for, the individuals that content describes. Where those individuals wish to exercise rights over that data, we will refer them to you as the controller and assist you as required by the DPA.
request_id.The lead text and optional context you submit for screening — described in the next section.
When you call the API, you send lead text and optional context (such as email, company, source, or country). This content may contain personal data about the individuals who contacted you. You are the controller of that data; LeadFilter processes it on your behalf to return a screening result.
We do not sell lead content, we do not use it to build persistent profiles of the individuals it describes beyond the per-request screening result, and we do not use it to train or improve our or any third party's machine-learning models. To produce a result, lead content is sent to our classification provider (Google) for that single request only.
For each analyzed request we always store the normalized screening result and request metadata — the request_id, any customer-provided external_id, a one-way hash of the input, and any optional context you send (email, company, source, country, and your metadata). The original raw lead text is stored only when raw-text storage is enabled in your account settings, which is on by default for new accounts, for the retention window you configure (initially 7 days). You can disable raw-text storage or change the window at any time, but the result and request metadata above are retained even when raw text is not.
As a controller, we process account and usage data for the purposes below. Under the GDPR and UK GDPR, our lawful bases are noted in parentheses.
request_id ties a result to its logs (legitimate interests in keeping the Service safe and reliable).Providing account, authentication, API-key, and billing data is necessary to create an account, sign in, use the API, and administer paid plans; if you do not provide it, we cannot make the Service available to you.
For lead content, the lawful basis is determined by you as the controller; we process it only under your instructions and the DPA.
The Service uses automated, probabilistic models to produce a spam-likelihood score, a verdict, and a short reason from the lead content you submit. This is a form of automated processing and may involve profiling of the individuals described in that content.
In practical terms, the model analyzes the lead text and any context you provide for patterns associated with spam, vendor or SEO outreach, and low-quality, fake, or irrelevant submissions, and returns a score, verdict, reason, and categories. Customers typically use this to decide which inquiries to review first; LeadFilter itself takes no action on, and makes no final decision about, any individual.
needs_review verdict when confidence is low.request_id, any customer-provided external_id, input hash, the optional context you sent such as email, company, source, country, and metadata, plus metering): retained so you can audit and review past checks, and as needed for billing, security, and legal purposes. Deleting raw lead text does not delete these.To request deletion or export of account-associated data beyond the dashboard controls, contact privacy@leadfilter.zsetup.com.
We rely on a small set of vetted providers to operate the Service. Each is bound by a data processing agreement and may process data only to provide its service to us:
These providers may process data in the United States and other countries. Where personal data is transferred outside the EEA or the UK, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (and the UK Addendum), together with additional measures where needed. We will give notice of new subprocessors as described in the DPA so you can object.
x-api-key header (or as a bearer token), never in URLs.Depending on your jurisdiction, you may have rights to access, correct, export, delete, or restrict personal data, and to object to certain processing. You can manage much of your account directly from the dashboard — update account and screening settings, create or revoke API keys, delete the stored raw text for a check, and cancel your subscription.
For requests that the dashboard does not cover — including full account deletion or a complete data export — contact privacy@leadfilter.zsetup.comand we will action your request and verify your identity as required by law. For lead content, where you are the controller, we will refer the individual's request to you and assist you under the DPA.
If you are a California resident, the CCPA/CPRA gives you rights to know the categories and specific pieces of personal information we collect, the sources and business purposes, and the categories of recipients; to request deletion or correction; and to be free from discrimination for exercising these rights.
We use only strictly necessary cookies. The dashboard sets a single authentication session cookie (leadfilter.session_token), which is HttpOnly and, in production, Secure. We do not use advertising, analytics, or third-party tracking cookies, pixels, or session-replay tools, so no cookie-consent banner is required to use the Service.
Questions about this policy or our data practices can be sent to privacy@leadfilter.zsetup.com, or by mail to Roman Shostak LLC, Sharjah Media City (Shams), Sharjah, United Arab Emirates (commercial licence no. 2429518.01).
LeadFilter AI is operated from the United Arab Emirates and is not specifically directed at individuals in the European Union or United Kingdom. If you are in the EEA or UK and believe your personal data has not been handled lawfully, contact us at privacy@leadfilter.zsetup.com; you also retain the right to lodge a complaint with your local data protection supervisory authority. If our processing later becomes subject to the EU or UK GDPR in a way that requires a local representative, we will appoint one and update this policy.