Privacy Policy
Last updated: July 22, 2026
What We Collect
Name, email, business name, and city/metro provided at signup. Payment information is processed by Stripe; we do not store credit card details.
How We Use It
To deliver newsletter content, send service-related emails, and process payments. We do not sell, rent, or share your information with third parties for marketing purposes.
Third-Party Services
We use Stripe (payments), Google Workspace (email), and email delivery infrastructure. Each has its own privacy policy.
Google API Services and Gmail Data
For customers who choose to connect their Gmail account for automated newsletter delivery, we use Google's OAuth 2.0 authentication and Google Workspace APIs. We are committed to compliance with the Google API Services User Data Policy, including the Limited Use requirements.
What we request
We request three OAuth scopes during Gmail connection:
userinfo.email— to identify the connected Google accountuserinfo.profile— to display the connected account's namegmail.send— to send newsletters from the connected Gmail account
What we do with Gmail data
We use the gmail.send scope exclusively to send weekly newsletters from the customer's Gmail account to the contact list they have explicitly uploaded to our platform. Each newsletter is:
- Generated by our system using local real estate market data and the customer's onboarding information
- Reviewed and approved by the customer (or auto-sent per the customer's chosen delivery preference)
- Sent only to contacts the customer has uploaded via CSV
- Sent no more than once per week per customer
What we do NOT do
- We do NOT read, access, or store the customer's inbox contents
- We do NOT access sent items, drafts, labels, folders, or any Gmail metadata beyond the sent-message confirmation ID
- We do NOT modify, delete, or alter existing emails in the customer's account
- We do NOT send emails to any recipients the customer has not explicitly authorized via their uploaded contact list
- We do NOT use Gmail data to train machine learning models
- We do NOT share, sell, or transfer Gmail data to third parties for advertising, marketing, or any other purpose
- We do NOT allow humans at AgentLetterCo to read Gmail data except: (a) with the customer's specific consent for support purposes, (b) to comply with applicable law, or (c) as necessary for security investigation
How we protect Gmail data
OAuth access tokens and refresh tokens are encrypted at rest using AES-GCM encryption with keys managed as Cloudflare Workers Secrets. Tokens are never logged in plaintext and are transmitted only over TLS-encrypted connections to Google's APIs. Access to production infrastructure is limited to authorized personnel.
Retention and deletion
We retain OAuth tokens only for as long as the customer maintains an active subscription and Gmail connection. When a customer:
- Revokes access via their Google account settings, or
- Clicks the disconnect option in their AgentLetterCo dashboard, or
- Cancels their subscription
we immediately mark the tokens as revoked in our database and stop using them for any purpose. Revoked tokens are purged from our active systems within 30 days.
Compliance with Google's Limited Use requirements
AgentLetterCo's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use Google user data only to provide or improve user-facing features that are prominent in our application's user interface. We do not use Google user data to develop, improve, or train generalized AI or ML models.
How to revoke access
You can revoke AgentLetterCo's access to your Gmail account at any time by:
- Visiting your Google account permissions page at https://myaccount.google.com/permissions and removing AgentLetterCo, OR
- Clicking the disconnect option in your AgentLetterCo dashboard
Either action will immediately prevent us from sending further newsletters from your account.
Email Tracking
Newsletters sent through AgentLetterCo include a 1×1 tracking pixel that detects when an email is opened, and external links in newsletters are rewritten to pass through our redirect service so we can detect clicks. When an open or click occurs, we record an opaque subscriber ID, a timestamp, the browser or email client's User-Agent string, the IP address, and (for clicks) the destination URL. We store a one-way hash of the recipient's email address in these records, not the address itself.
This data exists for one purpose: to give the real estate agent who sent the newsletter engagement metrics for their own mailing list. It is not sold or shared with third parties.
If you receive these newsletters and prefer not to be tracked: disabling image loading in your email client prevents open tracking, and typing or copying a destination URL directly into your browser (rather than clicking the rewritten link) avoids click tracking. Unsubscribing stops everything — unsubscribed recipients receive no further emails and therefore no further tracking.
A note on accuracy: open rates may be inflated by email clients that pre-fetch tracking pixels (notably Apple Mail Privacy Protection). We do not adjust reported open rates for this, but sending agents should interpret open metrics directionally rather than as literal engagement counts.
Your Rights
You may request deletion of your data at any time by emailing hello@agentletterco.com. Deletion occurs within 30 days.
Cookies
This website uses minimal cookies for analytics purposes only.
Contact
Email hello@agentletterco.com.