Security and trust
How we look after your email and your data
Letting someone send email for your business is a real decision. Here is exactly what we do - and what we don't.
Your everyday email is never touched
- We send from a separate sending address set up with you, so the email your customers, invoices and quotes rely on is never used for outreach.
- We never ask for a password and never access your main inbox. You approve the connection to the new mailboxes once, and you can withdraw it at any time from your own Google or Microsoft admin.
- Replies are forwarded to you the moment they arrive.
Where your information lives
- Your brief, your files and your outreach history are kept in a private database in London, and the application that works on them runs in London too.
- Everything is encrypted while it travels and while it is stored.
- A few specialist services - AI, email sending, payments - may handle data outside the UK and EU. We use them only under data processing terms, with recognised safeguards for international transfers.
Who can see it
- You, and the people you invite to your account.
- The small IceFire team running your campaigns. Staff accounts need a code from their phone as well as a password.
- The database cannot be reached from a browser at all; every request is checked on our servers against who is asking, and one client can never see another's information.
Your account
- Passwords are stored only as a one-way hash, never in a form anyone can read.
- Turn on two-step sign-in from Account security, and every sign-in asks for a code from your phone as well.
AI that doesn't learn from you
- We use AI to research and draft. Your material is used only to run your outreach, each task carries only your own material, and the AI services we use are set not to train on it.
- People oversee every campaign, and you can see - and approve, change or stop - every email before it goes.
Your prospects, treated properly
- We approach businesses about things relevant to them, from public business sources, under UK GDPR's legitimate interests and PECR.
- Every email offers a simple way to opt out, honoured across all your campaigns. We never cold-email individuals or sole traders who are not acting as a company.
Leaving
- Month to month after your first three months, with 30 days' notice. We hand you your prospect list and outreach history, and delete your files within 30 days.
The services behind it
- Database and file storage, in London; application hosting, in London; an email-sending platform; an AI model provider; and a payment provider.
- Ask and we will send you the named list with our data processing agreement. We will tell you before we add a new one.
Straight answers
We're a small company, and we don't hold formal certifications like ISO 27001. What we do instead is keep things simple and contained: a separate sending address, no passwords, your data in one place in the UK, and people you can talk to. If you need a data processing agreement or have a security question, email hello@icefire.ai and you'll get a straight answer from a person.
The full detail is in our terms, including how we handle your data under UK GDPR.