What the current preview stores
Simply Reply is currently a disconnected product preview. It does not request a Google sign-in, import live reviews, publish replies, create a production customer account, or send browser push notifications.
When you answer Business Brain questions or move through Guided Launch, those records are stored in this browser’s local storage. They stay on this browser unless you export or erase them from Settings. The installed app caches only its static offline safety screen and icons—not reviews, drafts, training answers, or approval decisions.
What a future Google connection would access
A production connection is intended to request the minimum Google Business Profile permission needed to list the profiles you manage, let you choose one location, read that location’s reviews, and publish only replies you explicitly approve. Simply Reply will not ask for your Google password.
Before that connection is enabled, this notice must be replaced with a legally reviewed policy that names the operator, identifies every data category and service provider, publishes exact retention periods, and explains the complete deletion and revocation process.
How product data is intended to be used
- Train the response manager on owner-verified business facts and policies.
- Prepare review-response drafts and explain which verified sources support them.
- Route sensitive reviews to the owner and require approval before publishing.
- Record review, approval, edit, publishing, and safety events for accountability.
- Deliver alerts the owner has chosen to enable.
Google user data will not be used for advertising, sold to data brokers, or used for an unrelated secondary purpose. Any material change would require an updated disclosure and renewed consent before the new use begins.
Retention, export, and deletion
In preview mode, data remains in this browser until you clear browser storage or use the reset control in Settings. You can download the same Simply Reply preview records before erasing them.
Live account retention periods, backup-deletion timing, Google token revocation, workspace export, and verified account deletion are launch blockers. They are not active yet.
Security approach
The product is being designed to minimize permissions, keep connection tokens out of browser code, encrypt sensitive data in transit and at rest, isolate each business workspace, and preserve an audit trail for public actions. Those controls require staging security and tenant-isolation testing before real customer data is accepted.
Your choices
- Skip setup questions without publishing anything.
- Download or erase the current browser preview from Settings.
- Decline browser notification permission.
- Withhold Google authorization until the production disclosure is published.
- Review and approve every response before any future publication.
What must be completed before launch
The verified operator name, postal address, privacy contact, subprocessors, jurisdiction-specific rights, retention schedule, incident process, and effective date still require counsel and operational sign-off. Public registration and live Google access should remain disabled until that review is complete.
This design follows the transparency, minimum-permission, limited-use, and secure handling principles in the Google API Services User Data Policy and the FTC’s privacy and security guidance.