Disperse
DashboardCampaignsLeadsInsightsInboxSettings
Extension not installedInstall
© 2026 Disperse. All rights reserved. · Developed by Turtlelabs
PrivacyTerms

Privacy Policy

Last updated: 3 June 2026

This Privacy Policy explains how Disperse, a product developed and operated by Turtlelabs ("Disperse", "we", "us", or "our") collects, uses, stores, shares, and protects personal data when you use our website, dashboard, and Chrome extension (together, the "Service"). We are the Data Fiduciary in respect of the personal data we determine the purpose and means of processing, and we are committed to handling your data in accordance with the laws of India.

1. Who this policy applies to

This policy applies to everyone who creates an account, visits our website, installs our Chrome extension, or otherwise interacts with the Service. By using the Service you confirm that you have read and understood this policy. If you do not agree with it, please do not use the Service.

2. Laws we follow

We process personal data in accordance with applicable Indian law, including:

  • the Digital Personal Data Protection Act, 2023 (the "DPDP Act") and rules made under it;
  • the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (the "SPDI Rules"); and
  • the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, to the extent applicable.

Where this policy refers to "personal data", it means any data about an individual who is identifiable by or in relation to such data, as defined under the DPDP Act.

3. Personal data we collect

  • Account and identity data — your name, email address, and the credentials you set when you register. Authentication and session management are handled by our own systems.
  • Billing data — if you subscribe to a paid plan, billing is handled by our payment processor (such as Razorpay or Stripe). We do not store your full card or bank details on our servers; we retain only limited records such as invoices and subscription status.
  • Usage, log, and device data — IP address, browser and device type, pages and features used, timestamps, and diagnostic or crash information.
  • LinkedIn account and activity data — your LinkedIn session cookies (used to act as your own session; see section 7), and activity you generate through the extension, such as profiles viewed, connection requests sent, and the content of outreach conversations (including replies received from prospects). See section 7 for how this is handled.
  • Lead data — information about the prospects you choose to source, save, or contact (for example name, headline, employer, and public profile details). See section 8 for the respective roles of you and Disperse in respect of this data.
  • Communications — messages and information you send to us, for example through support requests.

We do not intentionally collect sensitive personal data (such as financial account passwords, health, or biometric data) beyond what is described above. Please do not submit such data to us.

4. How and why we use your data

We use personal data only for specified, lawful purposes, namely to:

  • create and administer your account and provide the Service;
  • operate, maintain, secure, and improve the Service and develop new features;
  • process payments and enforce subscription plan limits;
  • send you transactional communications such as receipts, security alerts, and service notices;
  • provide customer support and respond to your requests and grievances;
  • detect, prevent, and address fraud, abuse, and security incidents; and
  • comply with legal obligations and enforce our Terms of Service.

We process personal data on the basis of your consent and, where permitted, for the "legitimate uses" recognised under the DPDP Act (for example, where you have voluntarily provided data for a purpose and have not objected, or to comply with law). We do not use your data for advertising and we do not sell your personal data.

5. Consent and how to withdraw it

Where we rely on your consent, you give it freely and may withdraw it at any time. Withdrawal is as easy as giving consent. To withdraw consent, change your account settings or email us at [email protected]. Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal, and may mean we can no longer provide some or all of the Service.

6. Cookies and analytics

We use strictly necessary cookies to keep you signed in and to operate the Service. With your consent, we use analytics and diagnostics tools, currently PostHog (product analytics) and Sentry (error and crash reporting), to understand usage and improve reliability. You can control or block cookies through your browser settings; disabling necessary cookies may affect functionality.

7. LinkedIn data and how the extension works

LinkedIn actions are carried out through the Disperse Chrome extension using your own logged-in LinkedIn session, so activity originates from your own browser and network. To keep your account state in sync and to perform limited server-side reads while your browser is closed (for example, detecting when a connection request is accepted), the extension transmits your LinkedIn session cookies (specifically li_at and JSESSIONID) to our backend, where they are stored encrypted at rest and used only to act as your own session against LinkedIn on your behalf. We do not ask for or store your LinkedIn password. You can disconnect at any time from the extension, which stops this synchronization; you can also invalidate the stored session by logging out of LinkedIn, which expires the cookie. Profile and message data surfaced during your activity is processed to power your campaigns, and the structured records you save (for example a saved lead) are stored on our servers as described in this policy.

8. Lead data and your responsibilities

When you source, upload, or contact prospects through the Service, you decide whose data you collect and why. In respect of that lead data, you act as the Data Fiduciary and Disperse acts as a Data Processor processing the data on your instructions to provide the Service.

You are responsible for having a valid legal basis to collect and contact your leads, for honouring their rights and any opt-out or do-not-contact requests, and for complying with the DPDP Act and other applicable laws (including anti-spam and unsolicited-communication rules) in your outreach.

9. How we share data

We share personal data only as described below, and never for sale:

  • with service providers (Data Processors) who process data on our behalf under contract and only on our instructions (see section 10);
  • where required to comply with law, a binding order of a court or government authority, or to establish, exercise, or defend legal claims;
  • to protect the rights, safety, and security of our users, the public, or Disperse, including to prevent fraud or abuse; and
  • in connection with a merger, acquisition, financing, or reorganisation, subject to this policy continuing to apply to your personal data.

10. Service providers we use

We rely on the following categories of processors, each bound by its own obligations:

  • payment processing and billing (such as Razorpay, Stripe);
  • product analytics (PostHog) and error monitoring (Sentry);
  • transactional email delivery (Resend);
  • cloud hosting and infrastructure (such as Vercel and Google Cloud Platform).

We engage processors that agree to protect personal data to a standard consistent with this policy and applicable law.

11. Cross-border transfers

Some of our service providers store or process data on servers located outside India. Where we transfer personal data outside India, we do so in accordance with the DPDP Act and only to jurisdictions that are not restricted by the Central Government, and we take steps to ensure your data continues to be protected.

12. How long we keep your data

We retain personal data only for as long as necessary for the purposes set out above or as required by law. In particular:

  • lead data associated with your account is deleted within 90 days after your subscription ends;
  • account and billing records are retained while your account is active and for any period required to meet legal, tax, or accounting obligations; and
  • you may request deletion of your account data by writing to [email protected].

We may retain anonymised or aggregated data that can no longer identify you for analytical purposes.

13. How we protect your data

We implement reasonable security practices and procedures as required by the SPDI Rules and the DPDP Act, including encryption in transit, access controls, and the local-first design described in section 7. No method of transmission or storage is completely secure, and we cannot guarantee absolute security, but we work to protect your data and to address incidents promptly.

14. Your rights as a Data Principal

Subject to the DPDP Act, you have the right to:

  • obtain confirmation of, and access to, the personal data we process about you;
  • seek correction, completion, or updating of your personal data;
  • seek erasure of your personal data where it is no longer needed for the purpose collected;
  • nominate another individual to exercise your rights in the event of death or incapacity;
  • readily access a means of grievance redressal (see section 15); and
  • withdraw your consent at any time.

To exercise any of these rights, email [email protected]. We may need to verify your identity before acting on a request, and we will respond within the timelines required by law.

15. Grievance redressal

If you have any concern or complaint about how we handle your personal data, you may contact our Grievance Officer:

Grievance Officer: Turtlelabs Support Team

Email: [email protected]

We will acknowledge your complaint within 24 hours and endeavour to resolve it within 15 days of receipt, in line with applicable rules. If you are not satisfied with our response, you may escalate your complaint to the Data Protection Board of India once it is operational, in accordance with the DPDP Act.

16. Children

The Service is intended for users who are 18 years of age or older and is not directed at children. We do not knowingly process the personal data of a child (a person below 18 years of age) without verifiable consent of a parent or lawful guardian, and we do not undertake tracking, behavioural monitoring, or targeted advertising directed at children. If you believe a child has provided us personal data, please contact us so we can take appropriate action.

17. Personal data breaches

In the event of a personal data breach, we will take reasonable steps to contain and remediate it and will notify the Data Protection Board of India and affected Data Principals where required by, and in the manner prescribed under, the DPDP Act.

18. Changes to this policy

We may update this policy from time to time. When we make material changes, we will revise the "Last updated" date above and, where appropriate, notify you by email or through the Service. Your continued use of the Service after the changes take effect constitutes acceptance of the updated policy.

19. Contact us

For any questions about this policy or your personal data, contact us at [email protected].