You sign in with Google, so Munodha does not receive or store a Google password. The service verifies the Google sign-in token, keeps a signed session cookie in your browser for up to 30 days, and stores a one-way hash of your Google account identifier with the number of free prospect results you have used. The cookie contains the Google account identifier and email needed to maintain the session.
From the CarryLeads release that adds sign-in records, the service also keeps a private sign-in record keyed on that same one-way hash, not on your email. It holds when the service first and last observed you signing in, how many sign-ins it has seen, and the name, email address and email-verified flag exactly as Google supplied them at your latest sign-in, where Google supplied them. Google’s flag means Google verified the address at some point, not that you still control it. “First observed” means first seen by this record, not proof of a new signup, because earlier sign-ins are not backfilled. Sign-in uses the same Google button as before: no new Google permissions, no Gmail or Contacts access, and no Google access or refresh tokens are kept.
The same release keeps a timestamped log of successful sign-ins and of a fixed list of interactions: opening the app, clicking sign in, submitting a search, and using the email, text or copy hand-off buttons. Each entry records the server’s time of receipt, the hashed account key when you are signed in, and an opaque visit identifier. An entry for opening the app may also record the source, medium, campaign and content labels from the link you followed, limited in length and with anything that looks like an email address or phone number replaced. The log does not record your IP address, browser details, page address, what you type into the search form, or lead content. To connect a sign-in with the campaign and clicks earlier in the same browser visit, the service sets an HttpOnly visit cookie holding a random, signed identifier. A visit ends 30 minutes after its last event and at most 12 hours after it began, and signing in or out ends it. No IP, device or cross-browser matching is used, so these records are not a complete history of how you found or used CarryLeads.
Names and email addresses in these records stay private to Munodha in owner-only files on the service host. No web address reads them, and they are not written to server logs, Google Analytics or URLs. By default, reports cover the last 90 days of logged events, and name and email are cleared from accounts with no sign-in for 365 days, leaving only the hashed count. Removal by age is not automatic: it happens when Munodha runs a manual clean-up on the server, so older entries can remain until then. The interaction log is also capped at two files of about 5 MB each, and once that is full the oldest entries are removed, which can be sooner than 90 days.
Your search terms go to Google Places to find public business listings. Business and prospect context goes to OpenAI when you request editable outreach copy. If optional company enrichment is made available and you choose it, company name and location may go to Apollo. Search results and drafted copy are returned to your browser and are not retained by the current standalone service.
CarryLeads does not sell this data, use it for advertising, or send outreach for you, and signing in is not treated as permission to send you marketing email. To request access to or deletion of your standalone records, email support@munodha.com from the Google account you used so we can verify the request. Deletion removes your sign-in record, your logged events, and the anonymous events of visits linked to your sign-ins. It keeps the hashed quota record of how many free results you have used, so the allowance is not reset, and a backup of the earlier hashed-only sign-in record (times and counts, no name or email) may remain until it is removed by hand.