Apollo logo

Apollo

apollo.io
High Risk
Updated July 31, 2026

Apollo is a B2B sales/marketing intelligence platform operated by ZenLeads Inc. that maintains a large contributory database of business contacts. The consumer-facing privacy policy discloses that Apollo is a registered data broker, sources data from third parties and public scraping, uses submitted data to enrich a database it resells to all customers, and applies AI/ML (including third-party AI providers) to that data. For the individuals whose data populates the database, opt-out exists but the default posture is broad collection, inference, resale, and use for advertising. The affiliate ToS supplied is narrow (referral program only) and does not describe the core product's data handling. Business users should note that the enterprise DPA is materially stronger — a no-training-into-sale carve-out, SOC 2 Type II audited controls, Data Privacy Framework certification, a 72-hour breach SLA and a 90-day deletion window — but the DPA also declares Apollo an independent Controller of the contributory database, meaning enrichment of Apollo's own resale database persists outside the customer's control. Overall risk is high for regulated or privacy-sensitive use without contractual protections.

AI Transparency Facts

Independent analysis by TermsWatchdog · © 2026 TermsWatchdog

Input Data Ownership

Moderate Risk

The privacy policy states that when Customers submit data, Apollo may use it to grow, enrich and verify its Contributory Database, which is then made available to all other customers. This indicates Apollo asserts broad usage rights over submitted data rather than treating it as the exclusive property of the submitting customer, though ownership as such is governed by a Terms of Service not supplied here.

Confidence
60%

Output Data Ownership

Moderate Risk

The supplied documents do not clearly address ownership of AI-generated outputs (email personalization, insights, lead scores). The policy refers to derived personal information and inferences that Apollo generates and retains, suggesting Apollo treats generated/derived data as its own. No clear grant of output ownership to the user is stated.

Confidence
40%

Training Data Usage

High Risk

The privacy policy explicitly states Apollo uses Service Information and business contact data as inputs to internally developed models and third-party AI providers, and to create new products and tools. Submitted data is also used to enrich a database resold to all customers. An opt-out/objection right is mentioned but the default is training and profiling use.

Confidence
80%

Data Retention & Deletion

Moderate Risk

The privacy policy provides a general, open-ended retention standard (data is kept as long as useful) rather than a defined schedule, and states the data is non-sensitive and not subject to sector-specific retention rules. Deletion is available via a Privacy Center/Remove request, but Apollo retains suppression-file data and notes deletion does not reach third parties who already hold the data.

Confidence
70%

Third-Party Data Sharing

High Risk

Sharing is central to Apollo's model — its contributory database is sold/made available to all customers, and Apollo is a registered data broker. Beyond the service-integral sharing, the policy also discloses sharing with advertising and data platforms, data enhancement/marketing partners, and 'business and data partners in the course of creating new data services.' This extends beyond what the user's own use requires and includes adtech/data-broker style disclosure, warranting RED.

Confidence
78%

Opt-Out Rights

Moderate Risk

The policy does provide concrete opt-out mechanisms: a Privacy Center to opt out of the database, a Remove request, CCPA opt-out of sale/sharing, GDPR objection rights, an AI/profiling opt-out, and advertising opt-outs via NAI/DAA. However opt-outs are largely reactive (individuals must find and request them), suppression data is retained, and opt-out does not reach third parties who already hold the data — limiting effectiveness.

Confidence
72%

Compliance & Certifications

Moderate Risk

The consumer privacy policy references CCPA and GDPR compliance obligations and data-broker registration but names no third-party certifications or audit reports. It adheres to Google API user-data policy. No SOC 2, ISO, or EU AI Act attestation appears in the consumer documents (those appear only in the enterprise DPA). Against the marketing_adtech baseline, CAN-SPAM and TCPA are referenced in the affiliate ToS; core adtech frameworks like IAB TCF are not claimed.

Confidence
60%

Model Explainability & Auditability

High Risk

The consumer documents describe AI features (email personalization, insight generation, lead scoring, agentic workflows) and profiling but provide no transparency into model logic, no explainability commitments, and no enterprise auditing of AI decisions. It only points to an external AI Policy not supplied here. Given automated profiling of individuals, the silence is a meaningful gap.

Confidence
55%

Security Practices & Breach History

Moderate Risk

The consumer privacy policy is weak on security specifics — it disclaims that measures will eliminate risk and pushes responsibility onto users, with no encryption or control detail. It references no breach history. (Substantive controls — encryption in transit/at rest, access controls, SOC 2 Type II audit, incident logging — appear only in the enterprise DPA's Exhibit 2, not the consumer policy.)

Confidence
60%

Enterprise vs. Consumer Risk Delta

Moderate Risk

The consumer privacy policy does not distinguish free versus paid tiers in data handling. It applies uniformly to Customers/Users. A material delta does exist between these consumer terms and the enterprise DPA (see enterprise object), but within the consumer documents themselves no tier-based difference is disclosed.

Confidence
45%

Human Review of User Inputs

Moderate Risk

The consumer privacy policy does not squarely state that staff may read user prompts/outputs, but it broadly reserves rights to analyze, troubleshoot and record data, and to record events/meetings for training purposes. The enterprise DPA (not consumer) confirms a subset of employees can access customer data. The consumer silence on human review of AI inputs is a gap.

Confidence
45%

Regulatory & Litigation Exposure

Moderate Risk

The privacy policy discloses that Apollo may share information with law enforcement, government agencies and courts when it deems disclosure appropriate or legally required, and in corporate events like bankruptcy or acquisition. No specific litigation or government-request history is disclosed. The broad, discretion-based disclosure language raises exposure concerns.

Confidence
55%

PII & SPI Data Inventory

High Risk

Apollo collects extensive PII on individuals who are not its direct users — names, work emails, phone numbers, job titles, employers, locations, IP addresses, device identifiers and inferred geolocation — sourced from third parties and public scraping, then enriched with inferences and resold. While Apollo characterizes this as non-sensitive business data, the scale, involuntary collection of non-users, profiling, and broker resale place this at high risk. The policy claims no sector-sensitive data but geolocation and device IDs are collected.

Confidence
75%

Policy–Product Currency

Low Risk

The privacy policy is dated September 16, 2025 — under 12 months before the analysis date — and demonstrably covers the AI capabilities the product ships: it addresses AI/ML processing, lead scoring, agentic workflows, third-party AI providers, and profiling, matching the marketing surface's AI-powered features. This is strong coverage plus recency.

Confidence
80%

Cross-Document Consistency

Moderate Risk

Two consumer documents were supplied (Affiliate ToS and Privacy Policy) plus an enterprise DPA. The Affiliate ToS covers only the referral program and does not conflict directly with the Privacy Policy. One notable tension: the DPA's Exhibit 2 states 'Apollo never sells personal data to any third party,' while the consumer Privacy Policy describes Apollo as a registered data broker and describes sharing with advertising/data partners — reconcilable under differing legal definitions but worth flagging. Only minor tensions are present; no clear cross-document license/retention contradiction within the consumer set.

Confidence
55%

You've read all 15 risk ratings for Apollo. Create a free account to see the exact policy wording behind each rating.