Privacy Policy
HitnReply ("HitnReply," "we," "us," or "our") operates the website at hitnreply.com and the HitnReply application at app.hitnreply.com (together, the "Service"). This policy explains what we collect, why, how long we keep it, and how to get it deleted.
If you would rather ask a person, write to info@hitnreply.com. We answer every message about data ourselves.
1. Your connected inbox, in full
HitnReply sends cold outreach from a Gmail or Google Workspace inbox you already own. Connecting that inbox is optional, and everything else in the Service works without it. This section describes exactly what happens when you do connect one, because it is the part that matters most and the part we are most often asked about.
It answers four questions in order: how HitnReply accesses, uses, stores, and shares anything to do with your inbox.
How we access it: an app password, not a Google sign-in
HitnReply does not use "Sign in with Google", does not use the Gmail API, and does not request any Google permission or scope. There is no Google consent screen, and Google issues us no access token or refresh token, because we never ask Google for one.
Instead, you create a Google app password yourself, inside your own Google account, and paste it into HitnReply. HitnReply then connects to Google's own outgoing mail server (smtp.gmail.com) over an encrypted TLS connection and sends your message the same way a desktop mail client does. That is the entire mechanism.
A Google app password is a credential for your Google account. Unlike a permission scope, Google does not restrict it to sending only. HitnReply uses it for exactly one thing, connecting to Gmail's outgoing mail server to send the messages you scheduled, and the software contains no code capable of reading, searching, downloading, or deleting anything in your mailbox. But we would rather you knew that this is a promise we keep and a boundary we have built, not a restriction Google enforces on us. You can withdraw the credential at any moment, from your own Google account, without our involvement.
We do not ask for and never receive access to your Google Contacts, Drive, Calendar, or any part of your Google profile beyond the email address of the inbox you connected.
How we use it
Solely to send the emails you have composed, to the recipients you have chosen, at the times you have scheduled. We also use it once at the moment you connect, to check with Google that the credential works, so that we can tell you straight away rather than failing silently later. That check sends no email. We do not use your credential or your inbox for advertising, for profiling, for building or improving any model, or for any purpose you would not expect from a tool whose entire job is sending the email you wrote.
How we store it
The app password is encrypted at rest with AES-256-GCM, and is never displayed back to you after you enter it, never written to a log, and never included in any export. It has to be decryptable rather than hashed, because sending requires presenting it to Google, and we would rather say so than imply a protection we do not have. When you press Stop sending from this inbox, it is deleted from our database immediately.
Alongside it we store the email address of the connected inbox, its display name, the sending limits you set, and a record of each message sent from it: recipient, subject, the sequence it belonged to, and the time it went out. We keep that record so the Service can show you what it has done, pace your sending safely, and stop sending to someone who has replied or asked not to be contacted again.
How we share it
We do not share your credential or your inbox data with anyone. It is not sold, rented, traded, or passed to advertising platforms, data brokers, or analytics providers, and no third party receives it in the ordinary running of the Service.
Our limits on use
Because HitnReply does not use Google APIs, the Google API Services User Data Policy does not govern this. We hold ourselves to the following anyway, and all of it is true without exception:
- Anything to do with your connected inbox is used only to provide features that are visible and prominent in HitnReply itself.
- It is never transferred to advertising platforms, data brokers, or information resellers.
- It is never used to determine creditworthiness or for lending purposes.
- It is never used to train, fine-tune, or improve any generalized artificial intelligence or machine learning model.
- No human at HitnReply reads it, except where you have explicitly asked us to look at something in order to support you, where it is necessary to investigate a security incident or abuse, or where the law requires it.
If HitnReply ever does begin using a Google API, this policy will be updated before that happens, and you will be asked to grant permission through Google's own consent screen rather than being moved across quietly.
Withdrawing the credential and deleting what we hold
There are two independent ways to stop HitnReply sending, and either one is enough on its own:
- From HitnReply. Press Stop sending from this inbox on the Accounts page. The app password is deleted from our database immediately.
- From Google, without involving us. Delete the app password at myaccount.google.com/apppasswords. This works whether or not you still have a HitnReply account, and it stops HitnReply sending regardless of what HitnReply believes or holds. Changing your Google account password revokes it too.
Deleting your HitnReply account, from Settings, deletes every connected inbox, every stored app password, every sequence, every lead, and the record of what was sent. This is immediate and cannot be undone by us.
2. Everything else we collect
Your account. Your name, email address, and a hashed password. We never store your password in a readable form and cannot recover it, only reset it.
What you put into the Service. The contact lists you import, the email templates you write, the sequences you build, and the notes and tags you add. This is your material and we treat it as yours.
Billing. Paid plans are handled by Lemon Squeezy, which acts as the merchant of record and processes payment details on its own systems. We never see or store your card number. We receive your subscription status, plan, and renewal date so we know what your account is entitled to.
Technical records. Ordinary server logs: IP address, browser, the pages requested and when. We use these to keep the Service running and to investigate abuse, and we do not use them to build a profile of you.
3. The people you contact
Cold outreach means you are processing other people's personal data through our Service. Under the GDPR, you are the data controller for your contact lists and HitnReply is your processor. That distinction has real consequences for you:
- You must have a lawful basis for contacting each person on your list.
- You must honour opt-out and deletion requests promptly. HitnReply gives you a suppression list to do this, and it is applied automatically to every sequence.
- You must comply with the law where your recipients are, including CAN-SPAM in the United States, the GDPR and ePrivacy rules in the EU and UK, and CASL in Canada.
We are not able to check any of this on your behalf, and we do not vet your lists. If a recipient contacts us directly about data you hold, we will point them to you and, where the law requires us to act, assist you in responding.
4. Who else touches your data
We keep this list short on purpose, and it is complete:
- Our hosting provider, which runs the servers and stores the database.
- Google, which delivers the email you send through your own connected inbox.
- Lemon Squeezy, for payments on paid plans.
- A transactional email provider, used only for our own system messages to you: address verification and password resets.
Each is bound to use the data only to provide its service to us. We will update this list before adding anyone to it.
5. How long we keep things
Account data, sequences and leads are kept while your account exists. The record of sent messages is kept for as long as the account exists so that the Service can report honestly on what it did; practice data from before real sending was enabled is discarded after 90 days. Server logs are kept for 14 days. When you delete your account, all of it goes.
6. Security
Your HitnReply account password is hashed with scrypt and a per-user salt, so we cannot read it. Google app passwords are encrypted at rest with AES-256-GCM. Mail is handed to Gmail over an encrypted TLS connection whose certificate we verify. All traffic runs over HTTPS. Sessions expire and can be revoked. Access to production systems is limited to people who need it.
No system is perfectly secure, and we will not pretend otherwise. If a breach affects your data we will tell you, and the relevant regulator where required, without waiting to be asked.
7. Your rights
Wherever you live, you can ask us for a copy of what we hold about you, ask us to correct it, or ask us to delete it. If you are in the EU, the UK, or California, you have these rights by law, along with the right to object to processing and to complain to your local supervisory authority.
Most of it you can do yourself from Settings without asking anyone. For anything else, write to info@hitnreply.com and we will respond within 30 days.
We do not sell personal information, and we do not share it for cross-context behavioural advertising.
8. Where your data lives
HitnReply is operated from Armenia and our servers are located in the European Union. If you are outside those places, your data is transferred there in order to provide the Service, under the safeguards required by applicable law.
9. Children
HitnReply is a business tool and is not directed at anyone under 16. We do not knowingly collect their data, and will delete it if we learn we have.
10. Changes
If we change this policy in a way that affects how we handle your data, we will email you before it takes effect rather than quietly changing the date at the top.
11. Contact
HitnReply
Email: info@hitnreply.com
Website: hitnreply.com