Last updated 4 August 2026
Privacy policy
Pesterly asks your clients for documents on your behalf and sends those messages from your own mailbox. This page says exactly what that involves, what we can see, and what we deliberately cannot.
The short version
- Pesterly requests one Gmail permission: permission to send. It cannot read your inbox, your replies, or any message it did not itself send.
- We never sell personal data, and we never use it to train machine learning models.
- We never show ads, and we do not put tracking pixels in the emails Pesterly sends on your behalf.
- You can disconnect a mailbox, or revoke Pesterly from your Google account, at any moment and without asking us.
Who we are
Pesterly is operated by AI Consulting Group. If you want anything on this page explained, corrected, or acted on, write to privacy@pesterly.com and a human will answer.
Google account data, and the scopes we ask for
When you connect a mailbox, Google shows you a consent screen. These are the only permissions on it:
- https://www.googleapis.com/auth/gmail.sendSend email on your behalf.
- This is the product. Every chase leaves your mailbox, threaded into the conversation your client already replies to, and lands in your Sent folder as though you wrote it. Without this permission Pesterly can do nothing at all — and we will never quietly send from our own domain instead.
- https://www.googleapis.com/auth/drive.fileSave uploaded documents into your own Google Drive.
- When your client uploads a document it goes straight into a Pesterly folder in your Drive — we do not keep a copy. This scope grants access only to files and folders Pesterly itself created; it cannot see, list or open anything else in your Drive, and that boundary is enforced by Google rather than by this policy.
- openid · userinfo.email · userinfo.profileYour email address and name.
- To create your account, to know which address to send from, and to sign your name at the bottom of the messages. Nothing else is read from your Google profile.
We do not request gmail.readonly, gmail.modify, gmail.compose, full mailbox access, or the full drive scope. This is a deliberate product decision with a cost attached: because Pesterly cannot see replies, a chase sequence stops when a file is uploaded or when you pause it, never because your client emailed you back. We think never holding a key to your mail is worth that.
Your Google refresh token is encrypted with AES-256-GCM before it is written to our database, is never logged, and is never returned to a browser.
Limited Use
Pesterly’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: we use Google user data only to provide and improve the features you asked for, we do not transfer it to others except as required to run the service or by law, we do not use it for advertising, and no human at Pesterly reads it except with your explicit permission for support, or where required for security or law.
What else we store
- Your account: firm name, email address, and — if you did not sign in with Google — a bcrypt hash of your password. We never store a readable password.
- Your clients: the names, email addresses and company names you enter or paste in, so Pesterly knows who to ask.
- Requests: the document checklists you write, and a record of which messages were sent and when.
- Uploads: only the filename, size and a pointer. The document itself goes straight into your own Google Drive — we never keep a copy, and deleting it there deletes it, full stop.
- A link-opened event: when a client opens their upload page. Corporate mail scanners fetch links before a human sees them, so we ignore requests that look automated rather than reporting them to you as real opens.
Your clients
Your clients never create an account and are never asked for a password. They receive one link, see the list of what is outstanding, and upload. We collect nothing about them beyond what you entered, the files they chose to send, and the fact that the page was opened.
For that data you are the controller and Pesterly is the processor: it is your client relationship, and we act on your instructions.
Who we share it with
Only the services required to run Pesterly: Google (to send your mail), our hosting and database providers, and — if you subscribe — our payment processor, which receives your billing details directly and never gives us your card number. That is the entire list. We do not sell data, and we have no advertising partners.
How long we keep it
For as long as your account is open. Disconnect a mailbox and its token is deleted immediately. Ask us to close your account and we delete your firm, clients, requests and uploaded files within 30 days, except where we are legally required to retain a record.
Revoking access
Two ways, both instant, neither requiring our involvement. In Pesterly, go to Settings and disconnect the mailbox. Or in your Google Account, open Data & privacy → Third-party apps with account access, and remove Pesterly. Sending stops that second.
Your rights
You can ask for a copy of your data, ask us to correct it, or ask us to delete it. Write to privacy@pesterly.com. If you are in the UK or EU you also have the right to complain to your data protection authority.
Changes
If we change this policy in a way that materially affects you, we will email you about it rather than quietly changing the date at the top.