This Privacy Policy explains how GTM Brigade (“GTM Brigade”, “we”, “us”) collects, uses, stores, and shares information when you use our platform and our connector for AI assistants such as Claude and ChatGPT (the “Connector”).
Scope
GTM Brigade is a business-to-business platform used by organizations to manage LinkedIn engagement and analytics. This policy covers both the GTM Brigade application and the Connector. The Connector can both read and change your GTM Brigade data, including creating a workspace and configuring it, and it can take a number of actions that reach outside GTM Brigade — see the connector documentation for the full tool list.
Information the Connector accesses
When you use the Connector, it can access — on your behalf, and only for the account you sign in with:
- Your identity within GTM Brigade: your name, email address, and the organizations you belong to, used to authenticate you and scope results.
- Your LinkedIn analytics stored in GTM Brigade: counts of your posts, comments, and reactions; profile-level metrics such as impressions, reach, followers, and engagement received; your posts and their performance; your targets and activity score.
- Team, roster, and Company Page data (organization owners only): aggregate, per-member, and Company Page metrics, and the list of members in organizations you own.
- Leads and lead lists: the profiles in your organization's lead database, their enrichment and engagement data, and your lead lists and ICP definitions.
- Watchlist and feed content: the profiles your team monitors, the posts collected for them, and the comment suggestions attached to those posts.
- Content and knowledge base: your posts and drafts, your learned writing style, and your organization's knowledge-base assets. Personal knowledge-base assets remain isolated to the user who owns them.
- Billing information: your plan, credit balances, consumption breakdowns, and invoices. The Connector cannot make purchases or change your plan.
- Setup and integration status: the workspaces you belong to, what is still unconfigured in a workspace, and whether your outreach providers, your organization's CRM, and Slack and Teams notifications are connected and working. Checking an outreach or CRM connection re-validates the stored credential against that provider, so the check itself reaches that provider.
- Automation workflows: your workflows, their draft and published versions, and the results of individual runs.
The Connector accesses only data you are already entitled to see in the GTM Brigade application. It enforces the same permissions, determined on our servers from the account you signed in with and never from anything the AI assistant sends us: members see their own work; team-wide and administrative data is available only to organization owners.
Changes and actions the Connector can make
With your authorization, the Connector can change data in your GTM Brigade account — create a workspace and complete its setup, set your company context and your personal writing style, create and edit content, schedule posts, add, assign, and delete leads, manage watchlists and lead lists, create and edit ICPs, configure comment automation, add or delete knowledge-base assets, and build automation workflows. These stay within your account.
Two of those deserve calling out because they replace rather than add. Applying the ICPs proposed from your company website overwrites your organization's existing ICP criteria and lead-scoring configuration. Rebuilding the list of proposed leads replaces the stored candidate list, and a rebuild that fails replaces it with an empty one; the same list is read by the signup wizard's profile-selection step. Both are flagged to your AI assistant as destructive, and the ICP one previews what it would replace before it commits.
Thirteen tools have effects outside GTM Brigade and process data accordingly. Nine of them are visible to other people or write into another system:
- Publishing a post, posting a comment and reacting to a post publish immediately and publicly on LinkedIn under your own LinkedIn identity, using the LinkedIn account you connected in the app.
- Approving a comment-automation draft schedules that comment for publication on LinkedIn as you.
- Inviting a team member sends an invitation email to the address you provide, which means we process that person's email address on your instruction.
- Pushing a lead to your CRM transfers that lead's personal data — name, email address, company, job title, and LinkedIn profile URL — out of GTM Brigade and into your organization's connected HubSpot, Salesforce, Pipedrive or Attio account, where it becomes subject to that provider's terms and your own configuration rather than this policy. Two details distinguish this from the other actions. First, it is performed using your organization's shared CRM credentials, not the acting user's own connection, so the record is created by the organization rather than by an individual; for that reason it is restricted to organization owners. Second, the lead must have an email address — it is the key we match on, so that repeat pushes update the existing CRM record instead of creating duplicates, and a lead without one is refused. In Salesforce the record created is a Lead, not a Contact.
- Publishing, resuming, or test-running an automation workflow arms a graph that then acts on its own, repeatedly, as you — which may include publishing and commenting on LinkedIn, sending outreach messages, and writing to your CRM — without a further confirmation each time it runs. Test-running executes the draft for real; there is no simulation mode.
The remaining four reach a third party without publishing anything: adding web pages to the knowledge base makes our servers fetch the URLs you provide, so those sites receive a request from us and their content is stored in your knowledge base; discovering leads reads the people who reacted to or commented on a LinkedIn post or account; connecting an outreach provider sends the API key you paste to Aimfox, HeyReach, lemlist or SendPilot to be validated before it is stored encrypted against your own user account, and it is never echoed back, logged, or displayed again; and reading your integrations re-checks each stored credential against the provider that issued it.
Scheduling a post does not publish immediately, but GTM Brigade will publish it to LinkedIn on your behalf at the scheduled time unless you unschedule it first.
Actions taken through the Connector are recorded in the same activity, credit, and audit records as the equivalent actions taken in the application, attributed to your account. Outward-facing actions and AI generations are additionally subject to per-user hourly limits.
How we use information
- To authenticate you and authorize access to the correct organization's data.
- To answer the questions and carry out the actions you request through the connected AI assistant.
- To operate, secure, and improve the GTM Brigade platform and Connector.
We do not sell your personal information, and we do not use the data accessed through the Connector for advertising.
How information is shared
- With the AI assistant you connect: when you ask a question, the data you requested is returned to that assistant (e.g. Anthropic's Claude or OpenAI's ChatGPT) so it can present the answer to you. Your use of that assistant is governed by its provider's privacy policy.
- With LinkedIn: when you use the Connector to publish a post, comment, react, approve an automated comment, schedule a post, or run an automation workflow that does any of those, the content of that action is sent to LinkedIn and published under your LinkedIn identity, exactly as it would be from the application. Discovering leads reads public engagement data from LinkedIn rather than sending anything to it.
- With AI model providers: when you ask the Connector to generate a post or a comment, the relevant prompt material — which may include your knowledge-base content and writing style — is sent to the model providers GTM Brigade uses, on the same terms as generation inside the application.
- With your CRM provider: if you push a lead to your CRM, that lead's personal data is transmitted to HubSpot, Salesforce, Pipedrive or Attio — whichever your organization has connected — under your organization's own CRM credentials. GTM Brigade acts on your instruction; the data is thereafter held in your CRM account and governed by your agreement with that provider.
- With your outreach provider: if you connect Aimfox, HeyReach, lemlist or SendPilot through the Connector, the API key you provide is sent to that provider to be validated, and subsequent status checks re-validate it. The key is stored encrypted against your own user account rather than the organization's.
- With websites you ask us to read: if you add web pages to your knowledge base by URL, our servers request those pages, so the sites concerned receive a request from GTM Brigade. Only public pages can be read; anything behind a login or paywall fails.
- With people you invite: if you send an organization invitation, we email the address you provide.
- Service providers: we use infrastructure and analytics providers (for example, cloud hosting and error monitoring) that process data on our behalf under contract.
- Legal reasons: we may disclose information where required by law or to protect our rights, users, or the public.
We do not otherwise share your data with third parties for their own purposes.
Data storage and security
GTM Brigade data is stored on managed cloud infrastructure in the European Union. Access is protected by authentication and role-based access controls. Connector access uses OAuth 2.1 with PKCE; access tokens are bound to the Connector and to your account, are short-lived, and can be revoked at any time by removing the Connector in your AI assistant. Connector permissions are granular — the scopes you grant on the consent screen are enforced individually by every tool, so a connection cannot reach data or actions you did not authorize.
Data retention
We retain your account and analytics data for as long as your organization maintains an active GTM Brigade account, and as needed to comply with legal obligations, resolve disputes, and enforce agreements. Connector authorization tokens are retained only for their validity period and are deleted when they expire or when you revoke access. When an account is deleted, its associated data is removed in accordance with our data-deletion procedures.
Your choices and rights
- Revoke Connector access at any time by removing the connector in Claude or ChatGPT.
- Depending on your location, you may have rights to access, correct, export, or delete your personal data. Contact us to exercise them.
Contact
For privacy questions or requests, or for product support, email ovidiu.ionita@gtmbrigade.com.
Changes to this policy
We may update this policy from time to time. Material changes will be reflected by the “last updated” date above.