Legal · last updated 18 April 2026
Privacy policy
What we collect, what we can and cannot see, and how to get it all deleted.
What Hultora does
Hultora is an AI sourcing assistant that helps procurement teams find suppliers and send requests for quotes. When you submit a sourcing request, Hultora searches supplier databases and the public web, selects candidate suppliers using AI, and, with your permission, sends RFQ emails from your connected email account on your behalf.
Information we collect
- Account information: your email address and a hashed password.
- Sourcing data: the products, quantities, notes and supplier information you enter or that the AI discovers on your behalf.
- Email OAuth tokens: if you connect Gmail or Outlook, we store the access and refresh tokens issued by Google or Microsoft. We never see your password for those services.
- Usage and activity: request history, supplier interactions and pipeline status, stored so you can review what the system did on your behalf.
Email access, and the scopes we request
When you connect an email account, Hultora requests the minimum OAuth scopes it needs to send RFQs.
gmail.send: send email on your behalf from your Gmail account. This scope does not grant read access to your inbox.userinfo.email: read the email address on your Google account, so we can display it in the dashboard.Mail.Send(Microsoft Graph): send email on your behalf from Outlook.User.Read(Microsoft Graph): read your basic profile so we can display your email address.
Hultora's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
How we use your data
- To carry out the sourcing work you request: find suppliers, draft RFQs, send emails.
- To display your sourcing activity back to you in the dashboard.
- To maintain and debug the service. Error logs may contain minimal metadata about failed operations; we do not use email content for this.
We do not use your email content or supplier data to train AI models, sell it to third parties, or use it for advertising.
Data sharing
We share data only with the subprocessors we need to operate the service.
- Supabase: stores your account, sourcing data and OAuth tokens, in the EU.
- Anthropic: the AI model that drafts RFQs and selects suppliers. Request contents are sent via API; Anthropic does not train on API inputs by default.
- Google and Microsoft: if you connect Gmail or Outlook, RFQ emails are sent through their APIs using your account.
- Serper: a Google-search API used to discover public supplier information from search result pages.
We do not sell your data. We do not share data with advertisers.
Storage and retention
Your data is stored in Supabase, hosted in the European Union. OAuth tokens are stored encrypted at rest by the database provider and transmitted only over HTTPS. Requests and sourcing activity are retained for as long as your account is active. If you delete your account, we remove your account, sourcing data and revoke stored OAuth tokens within 30 days.
Your rights
- Disconnect email at any time from the Email Settings page. This deletes the stored OAuth tokens and revokes our ability to send on your behalf.
- Export your data: write to us and we will send a copy of everything we hold about you.
- Delete your account: write to us and we will remove your account, sourcing data and tokens within 30 days.
- Revoke Google access at any time from your Google Account permissions page.
- Revoke Microsoft access at any time from your Microsoft account.
Contact
Questions, data requests or security reports: hello@hultora.com. We aim to respond within 7 working days.