Last updated July 3, 2026
Privacy Policy
The short version: we collect what we need to run the service, we never sell your personal data or share it between customers, your uploaded contacts stay yours, and you can access, export or delete everything. The full legal detail follows.
Effective date: July 3, 2026. Last updated: July 3, 2026.
This Privacy Policy (the "Policy") describes howXuxil Inc., a corporation organized under the laws of the State of Delaware, United States, together with its affiliates (collectively "Xuxil", "Norbelys", "we", "us" or "our"), collects, uses, discloses, transfers, retains and protects Personal Information in connection with the website at norbelys.com (the "Site") and the email outreach platform at app.norbelys.com (together with all related applications, APIs, tools and services, the "Service"). This Policy forms part of, and is incorporated by reference into, our Terms of Service.
Please read this Policy carefully. By accessing or using the Site or the Service, you acknowledge that you have read and understood it. If you do not agree with it, do not use the Site or the Service.
1. Definitions
- "Personal Information"(also "personal data") means any information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular individual or household.
- "Controller"(or "business" under U.S. law) means the party that determines the purposes and means of processing Personal Information.
- "Processor"(or "service provider" / "contractor" under U.S. law) means a party that processes Personal Information on behalf of, and under the instructions of, a Controller.
- "Customer"means an organization or individual that has registered for an account to use the Service.
- "Customer Data"means the prospect lists, contacts, message content, templates and related data that a Customer uploads to, creates in, or transmits through the Service.
- "Recipient"means an individual to whom a Customer sends email through the Service.
- "Subprocessor"means a third party engaged by us to process Personal Information in connection with the Service.
- "Applicable Data Protection Law"means all laws and regulations relating to privacy and the protection of Personal Information that apply to a party, including the U.S. federal CAN-SPAM Act, the California Consumer Privacy Act as amended by the California Privacy Rights Act (together, the "CCPA"), other U.S. state privacy laws, the EU and UK General Data Protection Regulation ("GDPR"), and Canada's CASL, in each case as amended from time to time.
2. Our roles — Controller and Processor
We act in two distinct capacities, and the capacity determines your rights and our obligations:
- As a Controller / business.For Personal Information we collect about visitors to the Site and about the individuals who register for and administer Customer accounts, we determine the purposes and means of processing and are therefore the Controller.
- As a Processor / service provider.For Customer Data — including the contacts a Customer uploads and the messages a Customer sends — the Customer is the Controller and we are the Processor. We process Customer Data only on the Customer's documented instructions to provide the Service, as further described in the data processing terms referenced in Section 15. We do not sell Customer Data, do not share it between Customers, and do not use it for our own purposes.
3. Categories of Personal Information we collect
The categories we collect depend on how you interact with us.
3.1 Site visitors.
- Identifiers and online activity:IP address, device and browser type, operating system, referring URLs, pages viewed, approximate (city/region-level) location derived from IP, and interactions with the Site.
- Cookies and similar technologies:set by analytics (Google Analytics, Mixpanel, loaded via Google Tag Manager) and any advertising pixels, as described in Section 8.
- Communications:the content of messages you send us (for example, via hello@norbelys.com or contact forms).
Our free tools are designed to minimize data collection: the domain health checker queries public DNS resolvers directly from your device, and the DKIM generator creates keys locally in your browser — the domains you check and the private keys you generate never reach our servers.
3.2 Customers (account holders).
- Account and identity data:name, email address, password credentials and organization details, managed through our authentication provider (Clerk).
- Billing data:plan, billing contact and transaction history. Card payments are processed by our payment processor; we do not see or store full payment card numbers.
- Mailbox credentials and connection data:the OAuth tokens or SMTP/IMAP credentials you provide to connect a mailbox, stored encrypted and used solely to send and receive email on your behalf.
- Usage and log data:actions taken in the Service, timestamps, device and connection information, and diagnostic logs.
3.3 Customer Data (processed on the Customer's behalf).
- Recipient contact data:names, email addresses, telephone numbers, company and role information, and any custom fields a Customer uploads or maps.
- Message content:the subject lines, bodies, templates, variables and attachments a Customer creates and sends.
- Engagement events:delivery, bounce, open, click, reply, unsubscribe and complaint events for messages sent, including the classification signals we use to separate genuine human activity from automated/bot activity.
4. Sources of Personal Information
We obtain Personal Information from:
- you directly, when you visit the Site, register, or communicate with us;
- Customers, when they upload or transmit Customer Data that may include your Personal Information as a Recipient;
- your device and browser automatically, through cookies and similar technologies;
- our Subprocessors and integrations acting on our or a Customer's behalf (for example, authentication, payment and email-delivery providers); and
- public sources and mailbox providers, in the form of delivery and reputation signals (for example, bounce codes and postmaster feedback).
5. Purposes and legal bases for processing
We process Personal Information for the purposes below. Where the GDPR or a similar law applies, the corresponding legal basis is noted.
- To provide, operate and secure the Service— performance of a contract; our and our Customers' legitimate interests.
- To protect deliverability and sending reputation, and to prevent abuse, spam and fraud— legitimate interests; compliance with legal obligations (including CAN-SPAM).
- To bill Customers and process payments— performance of a contract; compliance with legal obligations.
- To provide support and communicate with you— performance of a contract; legitimate interests.
- To understand and improve the Site and Service, including analytics— legitimate interests; consent, where required for cookies.
- To comply with law and enforce our agreements— compliance with legal obligations; legitimate interests.
Where we rely on legitimate interests, we have balanced those interests against your rights and freedoms. Where we rely on consent, you may withdraw it at any time without affecting processing carried out before withdrawal.
6. How we use data — and what we never do
We use Personal Information only for the purposes described in this Policy. To be explicit about the limits we place on ourselves:
- We do not sell your Personal Information— not your account data, and not the contacts a Customer uploads. We do not trade in Personal Information, we are not a "data broker," and we do not register as one.
- We do not "share" your Personal Information for cross-context behavioral advertisingas those terms are defined under the CCPA.
- We do not share Customer Data between Customers.Each Customer's contacts, message content and results are logically isolated to that Customer's account (tenant) at the database layer, and no other Customer can access them.
- We do not use Customer Data to train artificial-intelligence or machine-learning models, and we do not use it for advertising.
7. The warmup network — disclosure
Every plan includes email warmup. To earn inbox placement for a new or previously cold mailbox, participating mailboxes across the Norbelys network exchange a small, controlled volume of ordinary, system-generated warmup messages — messages that are opened, replied to and, where necessary, rescued from spam folders — so that mailbox providers learn to recognize the address as a genuine human sender. We also run continuous inbox-placement ("seed") testing to measure where mail is landing and to steer the ramp automatically.
The warmup network exchanges only these Norbelys-generated warmup messages. It never exposes, transmits or discloses a Customer's uploaded contacts, prospect lists or campaign content to any other Customer. Warmup builds sending reputation; it does not move your data.
8. Cookies and similar technologies
The Site uses cookies and similar technologies that are strictly necessary to operate the Site, plus analytics and (where enabled) advertising cookies. Strictly necessary cookies do not require consent. Analytics and advertising cookies are used in accordance with Applicable Data Protection Law and, where required, your consent. You can control cookies through your browser settings and, where offered, our cookie controls; disabling some cookies may affect Site functionality. Where required by law, we honor recognized opt-out preference signals (such as Global Privacy Control) as a valid request to opt out of "sale"/"sharing."
9. Disclosures of Personal Information — Subprocessors and others
We disclose Personal Information only to the categories of recipients below, and only as needed:
- Subprocessors that operate the Service, including: cloud infrastructure, edge compute, storage and content delivery (Cloudflare); authentication and organization management (Clerk); payment processing; database hosting; product analytics and event processing; and email transport and inbound processing. Each Subprocessor is bound by a written contract requiring appropriate confidentiality and security and limiting use of the data to providing services to us.
- Professional advisors(lawyers, auditors, accountants) under duties of confidentiality.
- Authorities and other partieswhere we reasonably believe disclosure is required by law, legal process, or to protect the rights, safety or property of Xuxil, our Customers, Recipients or the public.
- In a corporate transaction— a merger, acquisition, financing, reorganization or sale of assets — Personal Information may be transferred as part of that transaction, subject to this Policy.
We do not disclose Personal Information to third parties for their own independent marketing purposes.
10. International data transfers
We are based in the United States, and our Subprocessors operate globally-distributed infrastructure, which means Personal Information may be processed in countries other than the one in which it was collected. Where we transfer Personal Information originating in the EU, EEA, UK or Switzerland to a country not recognized as providing an adequate level of protection, we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum), or another lawful transfer mechanism. You may request a copy of the relevant safeguards by contacting us.
11. Data retention
We retain Personal Information for as long as necessary to fulfill the purposes described in this Policy, unless a longer period is required or permitted by law. In general:
- Account and Customer Datais retained while the relevant account is active. When a Customer deletes its account, that organization's Customer Data — contacts, campaigns, messages and events — is deleted from our production systems within a commercially reasonable period, subject to routine backup cycles.
- Suppression and unsubscribe recordsmay be retained after account deletion where needed to continue honoring opt-outs and to demonstrate compliance.
- Billing and transaction recordsare retained as required by tax, accounting and legal obligations.
You can export your data at any time before deletion.
12. Security
We maintain administrative, technical and organizational safeguards designed to protect Personal Information appropriate to its sensitivity, including: encryption of mailbox credentials and secrets; logical isolation of each Customer's data at the database layer; restricted, logged access to production systems; and use of reputable infrastructure providers. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security. If a breach of security affecting your Personal Information occurs, we will notify affected parties and authorities as, and within the timeframes, required by Applicable Data Protection Law.
13. Your privacy rights
Depending on where you live and the applicable law, you may have some or all of the following rights with respect to Personal Information for which we are the Controller:
- Right to know / accessthe Personal Information we hold about you and how we process it.
- Right to correctinaccurate Personal Information.
- Right to deletePersonal Information, subject to legal exceptions.
- Right to data portability— to receive a copy in a portable format.
- Right to opt out of the "sale" or "sharing"of Personal Information and of targeted/cross-context behavioral advertising. As stated above, we do not sell or share Personal Information.
- Right to limit the use of sensitive Personal Information, where applicable.
- Right to restrict or object to processing, and rights relating to automated decision-making, where applicable.
- Right to non-discriminationfor exercising your rights.
- Right to withdraw consentwhere processing is based on consent.
How to exercise your rights.Email hello@norbelys.com . We will verify your request against the information we hold before acting on it, and we will respond within the timeframes required by Applicable Data Protection Law. You may use an authorized agent to submit a request on your behalf where the law permits; we may require proof of the agent's authority. If we decline a request, you may appeal by replying to our response; where a right of appeal exists under applicable law, we will reconsider and inform you of the outcome.
If you are a Recipient of Customer email.For Customer Data, the Customer is the Controller of your Personal Information, and you should direct access, correction and deletion requests to that Customer. We will assist the Customer in responding, and we will honor unsubscribe requests automatically and platform-wide. You can also unsubscribe directly using the opt-out mechanism in any message.
14. Additional U.S. state-law disclosures (including California)
For residents of California and other U.S. states with comprehensive privacy laws, and for the twelve months preceding this Policy's date:
- The categories of Personal Information we collect are described in Section 3 (identifiers; commercial information; internet/network activity; approximate geolocation; professional or employment-related information; and the contents of communications).
- The sources are described in Section 4, thepurposesin Section 5, and thecategories of recipientsto whom we disclose Personal Information for a business purpose in Section 9.
- We have not "sold" and have not "shared" Personal Information (as those terms are defined under the CCPA), and we do not knowingly sell or share the Personal Information of consumers.
- Wedo not use or disclose sensitive Personal Informationfor purposes other than those permitted without a right to limit under the CCPA.
- California's "Shine the Light" law: we do not disclose Personal Information to third parties for their direct marketing purposes.
Under the CCPA, "consumers" include California residents acting in a business or employment capacity; those individuals have the same rights described in Section 13.
15. Data processing terms for Customers
Where we process Customer Data as a Processor on a Customer's behalf, we do so in accordance with the data processing terms incorporated into our Terms of Service (or a separate data processing agreement where one has been executed). Those terms address, among other things, the subject matter and duration of processing, our obligation to process only on documented instructions, confidentiality, security, engagement of Subprocessors, assistance with data-subject requests, breach notification, and deletion or return of Customer Data on termination. Customers who require a signed data processing agreement or the list of current Subprocessors may contact us.
16. Children's privacy
The Service is a business tool intended for use by adults. It is not directed to children, and we do not knowingly collect Personal Information from anyone under 18 years of age (or under 16 where a lower threshold applies). If you believe a child has provided us Personal Information, contact us and we will delete it.
17. Third-party links and services
The Site and Service may link to, or interoperate with, third-party websites and services (for example, mailbox providers and integrations) that we do not control and that have their own privacy practices. This Policy does not apply to those third parties, and we are not responsible for their practices.
18. Changes to this Policy
We may update this Policy as the Service, our practices or the law evolve. When we do, we will revise the "Last updated" date above. Material changes will be communicated by a notice on the Site or by email to account holders before they take effect. Your continued use of the Site or Service after an update becomes effective constitutes acknowledgment of the revised Policy, to the extent permitted by law.
19. How to contact us
Xuxil Inc. is the entity responsible for the Personal Information described in this Policy where we act as Controller. For any privacy question, request or complaint, contact us at hello@norbelys.com . If you are in the EEA or UK and believe we have not resolved your concern, you also have the right to lodge a complaint with your local supervisory authority.