Skip to document
Simply Reply
HomeData settings
Pilot draft · Operationally accurate for the current preview. Legal review and verified business contact details are required before launch.

Simply Reply · Trust center

Privacy notice

Last updated July 29, 2026

A plain-language record of what this preview stores today, what a future Google connection would require, and which promises are not yet ready to make.

In this document
Current previewFuture Google connectionHow data is usedSharing and saleRetention and deletionSecurityYour choicesBefore launch
RelatedTerms of use

What the current preview stores

Simply Reply is currently a disconnected product preview. It does not request a Google sign-in, import live reviews, publish replies, create a production customer account, or send browser push notifications.

When you answer Business Brain questions or move through Guided Launch, those records are stored in this browser’s local storage. They stay on this browser unless you export or erase them from Settings. The installed app caches only its static offline safety screen and icons—not reviews, drafts, training answers, or approval decisions.

Stored locallyTraining answers, added facts, setup progress
Not connectedGoogle accounts, profiles, reviews, replies
Not activeBilling, analytics, advertising, push delivery

What a future Google connection would access

A production connection is intended to request the minimum Google Business Profile permission needed to list the profiles you manage, let you choose one location, read that location’s reviews, and publish only replies you explicitly approve. Simply Reply will not ask for your Google password.

Before that connection is enabled, this notice must be replaced with a legally reviewed policy that names the operator, identifies every data category and service provider, publishes exact retention periods, and explains the complete deletion and revocation process.

How product data is intended to be used

  • Train the response manager on owner-verified business facts and policies.
  • Prepare review-response drafts and explain which verified sources support them.
  • Route sensitive reviews to the owner and require approval before publishing.
  • Record review, approval, edit, publishing, and safety events for accountability.
  • Deliver alerts the owner has chosen to enable.

Google user data will not be used for advertising, sold to data brokers, or used for an unrelated secondary purpose. Any material change would require an updated disclosure and renewed consent before the new use begins.

Sharing and sale

The current preview does not transmit its browser-local training records to Simply Reply. A production version will need a complete, named list of processors used for hosting, authentication, AI drafting, monitoring, and notifications. That list has not been finalized, so this draft does not pretend otherwise.

Simply Reply is not designed to sell personal information or Google user data.

Retention, export, and deletion

In preview mode, data remains in this browser until you clear browser storage or use the reset control in Settings. You can download the same Simply Reply preview records before erasing them.

Live account retention periods, backup-deletion timing, Google token revocation, workspace export, and verified account deletion are launch blockers. They are not active yet.

Security approach

The product is being designed to minimize permissions, keep connection tokens out of browser code, encrypt sensitive data in transit and at rest, isolate each business workspace, and preserve an audit trail for public actions. Those controls require staging security and tenant-isolation testing before real customer data is accepted.

Your choices

  • Skip setup questions without publishing anything.
  • Download or erase the current browser preview from Settings.
  • Decline browser notification permission.
  • Withhold Google authorization until the production disclosure is published.
  • Review and approve every response before any future publication.

What must be completed before launch

The verified operator name, postal address, privacy contact, subprocessors, jurisdiction-specific rights, retention schedule, incident process, and effective date still require counsel and operational sign-off. Public registration and live Google access should remain disabled until that review is complete.

This design follows the transparency, minimum-permission, limited-use, and secure handling principles in the Google API Services User Data Policy and the FTC’s privacy and security guidance.