Privacy Policy
Last drafted: 2026-09-30 · Effective date: [EFFECTIVE DATE]
1. Who we are
[COMPANY NAME] (“Gladhear”, “we”, “us”) provides a web tool that helps local businesses (home-service companies, dental and other healthcare practices, and others) draft replies to their public online reviews. Contact: [CONTACT EMAIL - placeholder hello@gladhear.com; owner must set up this mailbox], [POSTAL ADDRESS]. Effective date: [EFFECTIVE DATE]. Governing law and regulator contact: [JURISDICTION].
2. Important: no patient health information, not HIPAA-certified (healthcare businesses)
Gladhear is not HIPAA-certified (no such certification exists for software), we do not offer a Business Associate Agreement, and the service is not designed to receive protected health information (PHI). Please paste only the public text of a review (and its star rating and display name). Do not paste patient records, treatment details, or other private health information into Gladhear, including the free reply generator. Our reply drafts are written and automatically checked to avoid patient details and to never confirm that someone is a patient, but automated checks are imperfect and you remain responsible for what you publish.
3. What we collect and why
| Data | Why | Where it comes from |
|---|---|---|
| Account: your name, work email, business/agency name, password (stored only as a salted scrypt hash), sign-in sessions (random token, stored hashed), one-time sign-in / verification / password-reset tokens (stored hashed) | To run your account and keep it secure | You |
| Location settings: business type (dental, med-spa, chiropractic/PT, home services or other), location name, office phone and email, Google Place ID or review link, tone preference, approver and escalation contact details (name, email, phone), notification channels | To draft replies, send approval links, and build your review-request link and QR code | You |
| Reviews you paste, forward or send to your private ingest URL: star rating, reviewer display name, review text; and the drafts, edits and approved replies we produce; timestamps and an audit log of actions (for example “reply approved”) | To provide the reply and approval workflow | You (customer-supplied data) |
| Reviews obtained from Google through the Google Business Profile API (only if you connect Google): star rating, reviewer display name, review text, review resource identifier, and the drafts made from them | To draft, approve and post replies | Google, on your instruction — see section 5 and our Google API data use page |
| Google OAuth tokens (only if you connect Google), stored encrypted | To act on your Google Business Profile on your behalf until you disconnect | |
| Review-link clicks: a timestamp and the location; we do not store the visitor’s IP address or any identifier for these clicks | To show how often your review link is used | Visitors to your link |
| Waitlist: your email address and which page you used | To contact you about Gladhear | You |
| Billing (when payments are switched on): handled by Stripe; we store a Stripe customer reference and your plan/status, not your card number | To charge for the service | You / Stripe |
We do not use advertising or analytics trackers on the app. We use one strictly necessary cookie (mr_session, HTTP-only) to keep you signed in. Approval links are private links that act as a password for that one reply; anyone who has the link can act on that reply until it expires (7 days) — treat them like passwords.
Technical logs: our web server may keep operational logs (for example request paths, timestamps, and IP addresses) for security and troubleshooting. [HOST/LOG RETENTION — fill in once the hosting provider is chosen.] The app keeps abuse-limiting counters in memory only; they are not written to the database.
4. Free public reply generator (no login)
The free tool on our site takes the review text and star rating you type (and an optional business name, industry and tone), sends them to our AI provider to generate a draft, runs our safety checks, and returns the draft to your browser. We do not store the text you enter or the draft we return — there is no database write and we do not put it in our logs. The text is processed transiently by our AI provider ([LLM PROVIDER — currently xAI for the demo; final provider to be confirmed]) under that provider’s terms. We keep in memory only a per-IP counter to limit abuse. If you join the waitlist from that page, we store your email address (section 3).
5. Google user data
If you choose to connect your Google account, we ask for one permission (scope): https://www.googleapis.com/auth/business.manage. Google does not currently offer a narrower permission for reading and replying to reviews, so this permission is broader than what we use; we use it only to (a) list the Business Profile accounts and locations you can access, (b) read reviews for the locations you link, and (c) publish a reply only after a person at your practice has approved that specific reply and clicked “Post to Google”. Our use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Details, storage limits and deletion: Google API data use.
6. Who receives your data (service providers)
We share data only with providers that help us run the service, and only what each needs:
- AI text generation ([LLM PROVIDER]): the review text, star rating, your business name, business type and tone setting, so it can write a draft. Reviewer display name and your contact details are not needed for generation and are used only in local safety checks, except that your office phone/email may be included in low-rating drafts so the reviewer can contact you. Whether a provider may retain or train on API inputs depends on its terms — we will only use providers whose API terms [DO NOT TRAIN ON CUSTOMER DATA — verify before launch]. For Google-sourced reviews, the provider is used only to generate the reply draft for you.
- Email delivery ([EMAIL PROVIDER, e.g. Resend]) and SMS/WhatsApp delivery (coming soon; not enabled in the current version — [TWILIO or other] if launched): your approval links and account emails (to the addresses you or your approvers provided). Messages about Google-sourced reviews deliberately leave out the reviewer name and star rating.
- Payments (Stripe): billing details you enter at checkout.
- Hosting and database ([HOSTING PROVIDER]) storing the service’s data.
- Professional advisers or authorities where required by law, or to protect our rights, or in a business transfer (with notice).
We do not sell your data, do not use it for advertising, and do not use Google user data for advertising or to train AI models.
7. How long we keep data
- Data from Google’s API: stored temporarily and automatically deleted no later than [28] days after it was fetched (Google’s limit is 30 calendar days), or immediately when you disconnect Google or delete your account. Deletion covers the review copy and the drafts derived from it. We do not include Google-sourced content in statistics, digests or any other aggregate.
- Customer-supplied reviews and your other data: kept while your account is active. When you use “Delete account” we delete your organisation, locations, reviews, replies, settings and account data immediately from the live database. [BACKUPS: describe backup retention and its deletion delay — must not preserve Google-sourced content beyond 30 days.]
- Sign-in sessions expire after 14 days; one-time tokens expire within hours (verification 24 h, password reset 1 h, magic sign-in 15 min).
- Waitlist emails: until you ask us to remove you or we finish contacting waitlist members.
8. Security
We use industry-standard measures appropriate to a small service: HTTPS in transit [once deployed], salted password hashing, hashed one-time tokens, Google OAuth tokens encrypted at rest with AES-256-GCM, access restricted by organisation, rate limiting, and security headers. No system is perfectly secure, and we cannot guarantee absolute security. Staff do not read your review content except with your consent, to investigate abuse or security issues, or where required by law.
9. Your choices and rights
You can edit your settings, disconnect Google at any time in the app (which revokes our access and deletes Google-sourced data) or at myaccount.google.com/permissions, change your password, and delete your account in the app. Depending on where you live, you may have rights to access, correct, delete, export or object to processing of personal data, and to complain to a regulator. Contact [CONTACT EMAIL - placeholder hello@gladhear.com; owner must set up this mailbox]. [LEGAL REVIEW: add jurisdiction-specific sections, e.g. GDPR/UK GDPR legal bases and transfer mechanisms, CCPA/CPRA, Indonesia PDP Law, as applicable.]
10. Children
Gladhear is for businesses and is not directed to children. We do not knowingly collect children’s personal data.
11. International transfers
Our providers may process data in other countries. [LEGAL REVIEW: state locations and transfer safeguards once providers are chosen.]
12. Changes
We will post updates here and change the effective date; for material changes we will notify account holders by email.