Security & data
What we do with your mailbox and your data.
Connecting a mail account to a young product is a real decision. This page describes what happens today — including the parts that are not finished — so you can make that decision with accurate information.
Mailbox credentials
Pitching currently works by connecting your own mail account over SMTP, with IMAP for reading replies. That means InsightFuse asks you for a host, port, username and password.
- Use an app-specific password. Gmail, Outlook, Fastmail and most business providers let you generate a password scoped to one application, which you can revoke without changing your main account password. Use one.
- Connections use STARTTLS. Mail is submitted to your provider over an encrypted connection.
- OAuth is not available yet. Google and Microsoft OAuth sign-in is the next item on our security roadmap. Until it ships, password-based connection is the only option, and we would rather say so than imply otherwise.
If you are not comfortable with this
You do not have to connect a mailbox to use InsightFuse. Search, media lists and CSV export all work without it — you can export a list and pitch from your existing tools.
Pitch content
Pitches are relayed through your own mail server at the moment you send them, so mail goes out under your domain and your sending reputation. We do not archive message bodies on our servers. What we retain is the send record — recipient, subject, list and timestamp — so the dashboard can show you who has already been contacted.
Your account data
- Export. Media lists export to CSV at any time.
- Deletion. Request account deletion from the settings page, or email hello@insightfuse.com. We remove your account, lists and send history.
- We do not sell your data or share your lists with other customers.
Where we are not yet
Business buyers ask about these, and the honest answers are short:
- SOC 2: not certified, and no audit currently in progress.
- Two-factor authentication: not available yet; on the roadmap alongside OAuth.
- Data processing agreement: available on request by email, not yet self-serve.
- Single sign-on: not available.
If your procurement process requires SOC 2 or SSO, InsightFuse is not the right fit for your organisation yet. We would rather tell you now than during a security review.
The journalist database
Our records are compiled from publicly available professional profiles and outlet information. Journalists can request removal from the database by emailing hello@insightfuse.com; we process removals on the next database rebuild.
Reporting a vulnerability
Email hello@insightfuse.com with details. We do not run a paid bounty programme, but we will respond and credit you if you would like to be credited.