Privacy Policy
Harry The Marketer · Last updated 6 August 2026
This policy explains how Harry The Marketer (“we”, “the service”) handles information when you use the platform and when you connect a Google account so the campaign agent can send and read email on your behalf.
1. Who is responsible for what
For your account details and how the service itself operates, we act as the controller. For the lead and prospect data you upload and the campaigns you run, you are the controller and we act as your processor — we handle that data on your instructions. See the Data Processing Addendum for the processor terms.
2. What we collect
| Category | Examples | Why |
|---|---|---|
| Account | Email address, display name, profile picture, identity provider subject | Authenticate you and scope your workspace |
| Workspace content | Leads, playbook diagrams, campaigns, goals, business context, team invitations | Operate the features you use |
| Mailbox credentials | Google OAuth access and refresh tokens, connected mailbox address | Send and read mail for your campaigns |
| Email data | Sent message content and metadata, replies pulled from connected mailboxes, classified intent, thread identifiers | Advance each lead through your playbook and show you the thread |
| Engagement | Open and click events on emails you send, unsubscribe events | Report campaign performance and honour opt-outs |
| Operational telemetry | Engine tick durations, AI call latency and failures, delivery outcomes | Keep the pipeline healthy; shown on your Monitoring page |
We do not use advertising trackers, third-party analytics scripts, or cross-site cookies. See the Cookie Policy.
3. Google user data
When you connect Gmail we request only these scopes:
gmail.send— send campaign and reply emails from your mailboxgmail.readonly— read replies so the engine can classify intent and advance playbooksuserinfo.email/userinfo.profile— identify which mailbox you connecteddrive.file— create and update the one prospect spreadsheet you ask for, and nothing else in your Drive. This scope grants access only to files this app itself creates, which is why Harry creates the spreadsheet for you rather than asking you to pick an existing one.
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, Gmail data is used only to provide and improve the user-facing features you enabled; it is not transferred to others except as needed to provide those features, to comply with applicable law, or as part of a merger or acquisition; it is not used for advertising; and it is not read by humans except with your explicit consent, to resolve a support issue you raised, for security purposes, or where required by law.
Gmail content is not used to train generalised machine-learning models. Where you enable AI features, the relevant message text is sent to the AI provider configured for your deployment solely to compose a reply or classify an intent for your campaign — see Sub-processors.
4. Legal bases (UK/EU GDPR)
- Contract — providing the service you signed up for
- Legitimate interests — securing the platform, preventing abuse, and operating the service reliably
- Consent — connecting a Google mailbox, which you may withdraw at any time by disconnecting it
- Legal obligation — where we must retain records or respond to lawful requests
Where you upload prospect data, you are responsible for having a lawful basis to process and to contact those people.
5. Storage, security, and location
Data is held in the deployment you use. OAuth tokens are stored server-side and are never exposed to the browser. Sessions are signed, HTTP-only cookies. Self-hosted operators control their own storage location, backups, and encryption at rest; for hosted deployments, the region is stated in your order form. Details of the technical measures are on the Security page.
6. Sharing
We do not sell personal data and we do not share it for cross-context behavioural advertising. We share data only with the sub-processors needed to run the service (listed at /sub-processors), with your own team members inside your workspace, and where required by law.
7. Retention and deletion
- Disconnecting a mailbox immediately removes its OAuth tokens from our database.
- Deleting a lead, campaign, or goal removes it and its dependent records.
- Closing your account deletes your workspace content; residual copies in encrypted backups age out on the backup cycle.
- Operational telemetry is self-pruning and retains only the most recent records.
- Self-hosted deployments: deleting the database file removes everything.
To request deletion or a copy of your data, email privacy@harrythemarketer.com. If you joined someone else's team workspace, the workspace owner controls that content.
8. Your rights
Depending on where you live you may have rights to access, correct, delete, port, or restrict processing of your personal data, and to object to it. Contact privacy@harrythemarketer.com and we will respond within the period your law requires. You may also complain to your local supervisory authority.
If you received an email sent through this platform and want your data removed, use the unsubscribe link in that email — it takes effect across every campaign in the sending workspace immediately — or contact the sender directly.
9. International transfers
Where data moves between jurisdictions, we rely on the transfer mechanisms available to us, including the Standard Contractual Clauses, and require equivalent commitments from sub-processors.
10. Children
The service is for business use and is not directed at anyone under 16.
11. Changes
We will post material changes on this page and update the date above. Continued use after a change means you accept it.
12. Contact
Elnakeeb Pty Ltd — privacy@harrythemarketer.com