Apollo
apollo.ioApollo.io is a B2B sales intelligence and engagement platform built on a large contributory database of business contact information. Its core business model involves ingesting user-submitted contact and prospect data to enrich a database that is resold to all customers, and Apollo is a registered data broker in California and other states. The privacy policy is broad and vendor-favorable regarding data use (including AI/ML training, profiling, advertising, and third-party sharing), while the only accessible ToS is a narrow affiliate program agreement rather than the core platform terms — leaving key data-ownership and confidentiality questions unaddressed. Professional and regulated-industry users should exercise significant caution and seek contractual protections (e.g., a DPA and enterprise agreement) before submitting proprietary or sensitive contact data.
AI Transparency Facts
Independent analysis by TermsWatchdog · © 2026 TermsWatchdog
Input Data Ownership
When customers submit contact/prospect data, Apollo explicitly reserves the right to absorb that data into its Contributory Database and make it available to all other Apollo customers. This effectively strips users of exclusive control over the data they upload, which is unusual and unfavorable. The core platform Terms of Service was not accessible, so ownership language could only be inferred from the privacy policy.
Output Data Ownership
The privacy policy notes Apollo generates 'derived personal information' (inferences, profiles, lead scores) about individuals and may use it internally or offer it to others. Ownership of AI-generated outputs and enriched records is not clearly assigned to the customer, and the core ToS defining output rights was inaccessible. This ambiguity presents moderate risk.
Training Data Usage
Apollo explicitly uses Service Information and business contact data as inputs to both its own AI/ML models and third-party AI providers for features like personalization, lead scoring, and agentic workflows. While an opt-out/objection right is mentioned, the default is that user-submitted data feeds model development. This is a high-risk posture for anyone submitting proprietary or client data.
Data Retention & Deletion
Apollo retains personal data indefinitely 'for as long as it is useful' and keeps suppressed data in a suppression file even after deletion requests. Users can request deletion via the Privacy Center, but there are no defined retention schedules, deletion SLAs, or sector-specific retention commitments (Apollo explicitly disclaims sector-specific retention requirements). The indefinite, purpose-driven retention model is user-unfavorable but deletion mechanisms do exist.
Third-Party Data Sharing
Apollo is a registered data broker and shares customer-submitted data with its contributory database (available to all customers), business/data partners, and advertising and data enhancement companies. While database sharing is arguably integral to the service, the disclosed sharing extends to advertising and data platforms and Apollo's registered data-broker status indicates commercialization of personal data beyond the narrow service purpose. Users have limited control over this downstream sharing.
Opt-Out Rights
Apollo provides several opt-out mechanisms: a Privacy Center for database removal and access requests, cookie banner controls, ad-network opt-outs, and an explicit right to object to AI/profiling processing. However, opt-outs for the contributory database do not remove data already held by other parties, and some opt-outs (e.g., interest-based ads) are noted as not stopping data collection entirely. The mechanisms exist but are partial in scope.
Compliance & Certifications
Apollo certifies to the EU-U.S. Data Privacy Framework (including UK Extension and Swiss-U.S. DPF) and references CCPA and GDPR compliance, along with Standard Contractual Clauses and Transfer Impact Assessments. However, no security certifications such as SOC 2, ISO 27001, or HIPAA are mentioned in the accessible documents, and the DPF is a self-certification framework rather than a third-party audit. Coverage is partial and skewed toward privacy-transfer frameworks rather than security attestations.
Model Explainability & Auditability
The privacy policy references AI/ML use, profiling, and lead scoring, and points to a separate AI Policy for a list of providers, but provides no transparency into model behavior, explainability, or enterprise audit rights over the AI systems. There is no commitment to model auditability for customers. The absence of meaningful explainability disclosure is a risk signal.
Security Practices & Breach History
The security section is minimal and disclaims responsibility, placing the burden on users to protect their own credentials without detailing encryption, access controls, penetration testing, or incident response. No breach history, trust center, or dedicated security page is referenced in the accessible documents. Notably, Apollo has been publicly associated with a large 2018 data exposure, and the policy's silence on concrete controls is a significant gap.
Enterprise vs. Consumer Risk Delta
The privacy policy distinguishes between Apollo acting as a controller versus a processor for its customers, and references 'other agreements' governing Service Information, implying enterprise contracts may alter data handling. However, no specific free-vs-paid tier data-handling differences are documented in the accessible materials, and the core enterprise ToS/DPA was inaccessible. This ambiguity is a moderate risk.
Human Review of User Inputs
The policy broadly reserves the right to use, analyze, and troubleshoot Service Information and to record marketing/sales interactions and meetings, but it does not clearly state whether staff routinely read customer prompts or platform inputs. Combined with audit rights in the affiliate terms, some access is contemplated, but the scope of human review of core platform inputs is not explicitly defined. The ambiguity itself is a risk.
Regulatory & Litigation Exposure
Apollo discloses that it may disclose personal information to law enforcement, government agencies, and courts in response to lawful requests, including for national security and law enforcement purposes under the DPF. The affiliate ToS contains a binding arbitration clause and class-action/jury-trial waiver (with a 30-day opt-out) that limits user legal recourse for that program. These are common but user-limiting provisions.
PII & SPI Data Inventory
Apollo collects extensive PII including names, emails, phone numbers, job titles, employers, locations, IP addresses, device identifiers, geolocation, payment/credit card data, and browsing/usage behavior, and generates derived inferences and profiles. Much of this is collected about third-party prospects (not just account holders) and fed into a resold database as a registered data broker. While Apollo claims it processes 'non-sensitive' data, the breadth of PII collection, inference generation, and broker-model distribution warrants a high-risk rating.
You've read all 15 risk ratings for Apollo. Create a free account to see the exact policy wording behind each rating.