SPEARIS

APPLICATION PRIVACY

Application privacy notice

This notice explains how Spearis Marketing, based in Miami, Florida, handles information in its business automation application at app.spearismarketing.com. It is separate from the public marketing website's privacy policy.

Information the application handles

Google permissions and purpose

Google identity permissions identify the account giving consent. Gmail send-only permission lets the application send the configured initial post-completion email and an explicitly initiated owner-mailbox test. It does not grant permission to read, modify, or delete inbox messages. Spearis does not use this connection to read incoming replies.

A separate agency connection requests access to specific files selected through Google Picker (the drive.file permission). Google permits viewing and changing those selected files within the authorized account's existing rights; Spearis uses the connection only to read configured spreadsheet sources, not to create, edit or delete files. Client spreadsheets should be shared with the agency account as a Viewer. The application does not request access to all Drive files. A short-lived file-access token is provided to Google Picker in the signed-in operator's browser; refresh tokens and the OAuth client secret remain server-side.

Spearis uses this information to configure and deliver the agreed service, confirm account identity and permission, prevent duplicate or unwanted messages, apply pauses and opt-outs, resolve failures, and maintain operational and security records.

Limits on use and sharing

Spearis Marketing's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

Google user data is not sold, used for advertising or unrelated marketing, or used to train generalized artificial intelligence or machine-learning models. The email service does not send Google user data to an AI model.

Authorized Spearis personnel access information only as needed to provide support with permission, operate the requested service within permitted access, investigate security or abuse, or meet applicable legal obligations. Google user data is not browsed for unrelated purposes.

Google processes account authorization, spreadsheet requests, and email delivery. Render hosts the application and its database. These providers process information needed to supply their services. Email recipients and their mail providers receive the content addressed to them. Spearis may disclose information where required by law or necessary for security, subject to the restrictions applicable to Google user data.

Social Content service

When a business uses Social Content, Spearis stores its content profile, uploaded media references, notes, permission confirmations, caption versions, approvals, schedules and publishing results. Photos and videos are stored privately in Cloudflare R2 under client-specific references. Short-lived links allow authorized viewers and the publishing provider to retrieve the selected media.

When a Spearis operator requests AI drafting, the supplied content profile and submission notes are sent to OpenAI to suggest captions. This feature does not read Gmail or use customer spreadsheet records. Media files are not sent to the caption model. Generated wording requires human review; it is not published automatically. Spearis requests that generated responses are not stored through the API response-storage option; provider security retention may still apply.

Buffer receives the approved captions and temporary media links to publish to the business's configured social channels. Published content is visible according to those channels' settings. Withdrawing permission or pausing Spearis stops future handoffs but cannot recall a post already handed to Buffer; removal may require action in Buffer or the social account.

Storage and security

The hosted application stores configuration, job, permission, activity and audit records in a database. Saved Google authorization tokens are encrypted, with the encryption key held separately in hosting configuration. HTTPS protects browser connections. Operators sign in to the internal dashboard; invited client accounts can access only their assigned business portal. Revoking a portal account does not itself disconnect Google or pause an automation; contact Spearis for those changes. No system can guarantee absolute security.

Retention, disconnection, and deletion

Information is retained as needed to provide the service and maintain permission, suppression, duplicate-prevention, audit, security, and legally required records. The application does not currently apply a universal automatic deletion period. Disconnecting Google does not automatically delete previously stored job or activity records.

You can revoke Google access using Google Account connections. You can also ask Spearis to pause the service, disconnect an account, correct information, or delete service data by emailing spearismarketing@gmail.com. We verify the requester's authority and review what can be removed, what must be retained and why, and any applicable backup retention. Revoking access stops further authorized Google API access; it does not recall email already sent.

Business and recipient requests

Businesses are responsible for supplying accurate job data and appropriate permission for the messages they request. Customers may contact the business that sent their message or Spearis with questions or opt-out requests. This service is intended for businesses and is not directed to children.

We may update this notice when the service or its practices change. Questions and requests can be directed to Spearis Marketing, Miami, Florida, at spearismarketing@gmail.com.