Apollo's new Terms let it scan the inbox you sync

Stani Mihov
Founder & CEO
·

TL;DR
Vendor: Apollo
Document: Terms of Service
Date detected: June 26, 2026
Key change: A new "Email Scanning and Opt Out" section lets Apollo scan synced inboxes and contact lists, reuse the extracted data, and retain it after opt-out
Apollo's Terms of Service gained several customer-affecting clauses in a single update. The most significant is a new section that authorizes Apollo to scan the email inboxes and contact lists you sync, reuse what it extracts, and keep previously collected data even after you opt out.
The change
On June 26, 2026, Apollo updated its Terms of Service, the first revision since February. Venpo detected the change automatically as soon as the revised Terms were posted.
The update added several new clauses, but the most consequential is a brand new section under Data Privacy and Security titled "Email Scanning and Opt Out." It authorizes Apollo to access and scan the email inbox and contact lists you sync, use what it extracts to improve its services and enrich its databases, and share aggregated information with third parties.
Apollo sits in the prospecting and sales-intelligence layer of a large number of go-to-market teams. A change to what it can do with synced inbox and contact data is exactly the kind of update that rarely reaches the people who approved the tool in the first place.
What changed
The June 26 revision introduced five customer-affecting additions and one change in the customer's favor:
A new "Email Scanning and Opt Out" section authorizing Apollo to scan synced inboxes and contact lists, reuse the extracted data, and retain previously collected data after opt-out
A new Publicity clause letting Apollo use your name, logo, and trademarks across its marketing, sales, investor, and social materials
A new Case Studies clause letting Apollo publish a case study on your use of the product, with only five business days for you to flag confidential information, inaccuracies, or trademark misuse
A new Order of Precedence line voiding any term in your quote, bid, or purchase order unless it is written into the Order Form itself
A new restriction against removing, altering, or obscuring intellectual property notices embedded in the platform
The one change in the customer's favor: termination for cause now requires a material breach, not just any breach, before either party can end the agreement after the cure period.
The inbox scanning clause is the real story
Most of these additions are the kind of one-sided language that accumulates in vendor terms over time. The email scanning section is different in degree. Its operative text reads: Apollo may access and scan your email inbox and contact lists after they are transmitted and stored on its system, extracted information may be aggregated and shared with third parties, and upon revocation Apollo will stop collecting new data but may retain previously collected data as permitted by law.
Three things stand out. The scanning covers both inbox content and contact lists once synced. The extracted data can be reused to enrich Apollo's own databases and shared in aggregate with third parties. And opting out stops future collection without requiring deletion of what was already taken.
The clause also shifts responsibility onto the customer: you are responsible for providing the required notices and obtaining consents from the contacts whose information Apollo processes.
Why this matters
Terms of Service are the contract that governs the entire relationship with a vendor, and they change with little notice and real consequence. This is the exact category of change covered in our analysis of the hidden risk of vendor legal changes, and it is why vendor contract monitoring belongs in the same tier as security review.
When a sales-intelligence tool gains explicit permission to scan synced inboxes and contacts, the data exposure surface grows, and the documentation that security and compliance teams approved at onboarding falls out of date the moment the new Terms take effect. A team that vetted Apollo six months ago approved a materially different agreement than the one in force today.
The data-sharing model is disclosed across Apollo's own terms and its Data Processing Addendum: Customer Data you provide can be added to Apollo's contributor database and shared with other customers, while you gain access to the broader database in return. The new email scanning section extends that model to the inbox and contact data you connect.
Potential impact for SaaS companies
Companies whose teams sync email or contacts into Apollo may want to review whether:
their data processing records and DPAs still match what Apollo's Terms now permit
they can provide the notices and consents the clause makes them responsible for, particularly under CCPA and similar laws
synced inbox and contact data falls within what their security review originally approved
the new publicity and case study clauses are acceptable, given the five business day review window
For teams that maintain their own customer-facing disclosures, this can cascade: a vendor's new data practice may need to appear in your own documentation. Tracking that manually across a full vendor portfolio is exactly where continuous vendor risk monitoring becomes a structural necessity rather than a periodic task.
How Venpo detected it
Venpo continuously monitors vendor legal documents and detects changes as they happen. When Apollo posted its revised Terms, Venpo immediately:
detected the new and modified clauses as soon as the document was published
identified the new email scanning section and isolated its operative language
flagged the change as a privacy-relevant expansion of how synced data can be used
rated each clause and surfaced the one change that favors the customer
Instead of discovering a new data-use permission during the next annual review, or during a customer security questionnaire, teams understood the change on the day it took effect.
Business outcome
Companies that caught this change early were able to:
update their vendor and data processing records to reflect the new email scanning permission
confirm whether they can meet the notice and consent obligations the clause assigns to them
review the publicity and case study clauses before any marketing use occurred
brief security and compliance before the next audit or customer review
Instead of reacting to a gap found during due diligence, they adapted on their own schedule. This is the difference between operating with current information and operating on assumptions from the last review cycle.
Key takeaway
A Terms of Service update can change what a vendor is allowed to do with your data overnight, and the only way to know it happened is to be watching the document when it changes. Apollo's June 26 revision added a section that lets it scan the inbox and contacts you sync, reuse the extracted data, and keep what it already collected after opt-out. Venpo detected it automatically as the new Terms went live. A closer look at why scheduled reviews keep missing this kind of change is in our comparison of manual vs automated vendor monitoring.
The change
On June 26, 2026, Apollo updated its Terms of Service, the first revision since February. Venpo detected the change automatically as soon as the revised Terms were posted.
The update added several new clauses, but the most consequential is a brand new section under Data Privacy and Security titled "Email Scanning and Opt Out." It authorizes Apollo to access and scan the email inbox and contact lists you sync, use what it extracts to improve its services and enrich its databases, and share aggregated information with third parties.
Apollo sits in the prospecting and sales-intelligence layer of a large number of go-to-market teams. A change to what it can do with synced inbox and contact data is exactly the kind of update that rarely reaches the people who approved the tool in the first place.
What changed
The June 26 revision introduced five customer-affecting additions and one change in the customer's favor:
A new "Email Scanning and Opt Out" section authorizing Apollo to scan synced inboxes and contact lists, reuse the extracted data, and retain previously collected data after opt-out
A new Publicity clause letting Apollo use your name, logo, and trademarks across its marketing, sales, investor, and social materials
A new Case Studies clause letting Apollo publish a case study on your use of the product, with only five business days for you to flag confidential information, inaccuracies, or trademark misuse
A new Order of Precedence line voiding any term in your quote, bid, or purchase order unless it is written into the Order Form itself
A new restriction against removing, altering, or obscuring intellectual property notices embedded in the platform
The one change in the customer's favor: termination for cause now requires a material breach, not just any breach, before either party can end the agreement after the cure period.
The inbox scanning clause is the real story
Most of these additions are the kind of one-sided language that accumulates in vendor terms over time. The email scanning section is different in degree. Its operative text reads: Apollo may access and scan your email inbox and contact lists after they are transmitted and stored on its system, extracted information may be aggregated and shared with third parties, and upon revocation Apollo will stop collecting new data but may retain previously collected data as permitted by law.
Three things stand out. The scanning covers both inbox content and contact lists once synced. The extracted data can be reused to enrich Apollo's own databases and shared in aggregate with third parties. And opting out stops future collection without requiring deletion of what was already taken.
The clause also shifts responsibility onto the customer: you are responsible for providing the required notices and obtaining consents from the contacts whose information Apollo processes.
Why this matters
Terms of Service are the contract that governs the entire relationship with a vendor, and they change with little notice and real consequence. This is the exact category of change covered in our analysis of the hidden risk of vendor legal changes, and it is why vendor contract monitoring belongs in the same tier as security review.
When a sales-intelligence tool gains explicit permission to scan synced inboxes and contacts, the data exposure surface grows, and the documentation that security and compliance teams approved at onboarding falls out of date the moment the new Terms take effect. A team that vetted Apollo six months ago approved a materially different agreement than the one in force today.
The data-sharing model is disclosed across Apollo's own terms and its Data Processing Addendum: Customer Data you provide can be added to Apollo's contributor database and shared with other customers, while you gain access to the broader database in return. The new email scanning section extends that model to the inbox and contact data you connect.
Potential impact for SaaS companies
Companies whose teams sync email or contacts into Apollo may want to review whether:
their data processing records and DPAs still match what Apollo's Terms now permit
they can provide the notices and consents the clause makes them responsible for, particularly under CCPA and similar laws
synced inbox and contact data falls within what their security review originally approved
the new publicity and case study clauses are acceptable, given the five business day review window
For teams that maintain their own customer-facing disclosures, this can cascade: a vendor's new data practice may need to appear in your own documentation. Tracking that manually across a full vendor portfolio is exactly where continuous vendor risk monitoring becomes a structural necessity rather than a periodic task.
How Venpo detected it
Venpo continuously monitors vendor legal documents and detects changes as they happen. When Apollo posted its revised Terms, Venpo immediately:
detected the new and modified clauses as soon as the document was published
identified the new email scanning section and isolated its operative language
flagged the change as a privacy-relevant expansion of how synced data can be used
rated each clause and surfaced the one change that favors the customer
Instead of discovering a new data-use permission during the next annual review, or during a customer security questionnaire, teams understood the change on the day it took effect.
Business outcome
Companies that caught this change early were able to:
update their vendor and data processing records to reflect the new email scanning permission
confirm whether they can meet the notice and consent obligations the clause assigns to them
review the publicity and case study clauses before any marketing use occurred
brief security and compliance before the next audit or customer review
Instead of reacting to a gap found during due diligence, they adapted on their own schedule. This is the difference between operating with current information and operating on assumptions from the last review cycle.
Key takeaway
A Terms of Service update can change what a vendor is allowed to do with your data overnight, and the only way to know it happened is to be watching the document when it changes. Apollo's June 26 revision added a section that lets it scan the inbox and contacts you sync, reuse the extracted data, and keep what it already collected after opt-out. Venpo detected it automatically as the new Terms went live. A closer look at why scheduled reviews keep missing this kind of change is in our comparison of manual vs automated vendor monitoring.
Real-time change notifications
Stay ahead of every legal change
Get updates, product news and expert tips on navigating legal changes
Dispute resolution clause now requires mandatory arbitration in all regions
Data retention period extended from 2 years to 5 years for all services
New restrictions on AI-generated content in product descriptions
Third-party data sharing expanded to include analytics partners
Real-time change notifications
Stay ahead of every legal change
Get updates, product news and expert tips on navigating legal changes
Dispute resolution clause now requires mandatory arbitration in all regions
Data retention period extended from 2 years to 5 years for all services
New restrictions on AI-generated content in product descriptions
Third-party data sharing expanded to include analytics partners
