Privacy Policy

Last updated 7 September 2026

What Collectly is

Collectly is an accounts-receivable assistant. It reads a business’s own invoices and the email conversations attached to them, works out what is happening with each unpaid invoice, and drafts follow-up emails for a person to approve and send.

This policy describes what data Collectly handles, why, where it goes, and how to remove it. It is written to be checked against the software’s actual behaviour rather than to sound reassuring.

Google user data we access

When you connect a Gmail account, Collectly requests three scopes and uses each of them for one specific purpose:

  • gmail.readonly — to search your mailbox for messages involving addresses belonging to customers you have added, and to read those threads so Collectly can tell a payment promise from a dispute. This is the narrowest scope Google offers that permits searching a mailbox; there is no finer-grained read scope available.
  • gmail.compose — to prepare follow-up drafts.
  • gmail.send — to send a follow-up after you have reviewed and approved it, from your own address, replying into the existing thread.

Collectly only searches for messages involving customers you have explicitly added. It does not index your whole mailbox, and it does not read messages that have no connection to a customer record you created.

Limited Use disclosure

Collectly’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically, Collectly does not:

  • sell Google user data, ever;
  • use Google user data for advertising, profiling, or any purpose beyond providing the receivables features described here;
  • allow humans to read your email, except where you explicitly ask us to for support, where required by law, or to investigate a security incident;
  • use Google user data to train generalised machine-learning models.

What we store, and for how long

  • Email content. Messages on threads linked to a customer are stored so Collectly can show you the conversation and reason about it. This includes sender, recipients, subject, timestamp and body text.
  • Access tokens. Your Gmail refresh token is encrypted with AES-256-GCM before it is written to the database, decrypted only inside the server module that calls Gmail, and never sent to a browser.
  • Invoices and customers. Whatever you enter, import from CSV, or sync from a connected billing system.
  • Account data. Name, email address, and a hashed password.

Data is retained while your account exists. Deleting a workspace deletes its invoices, customers, email records and provider connections. Security audit logs, which record who performed an action but never message contents, amounts or tokens, are retained separately.

Who else sees this data

Collectly uses a small number of processors, and this is the complete list:

  • Anthropic — email content and invoice details are sent to Anthropic’s API so the assistant can analyse a situation and draft a reply. This is the core of the product and cannot be switched off while the assistant is in use. Anthropic does not train models on API inputs.
  • Neon — managed PostgreSQL, where the data above is stored.
  • Netlify — application hosting.
  • Stripe — subscription billing, and optionally invoice import if you connect it. Stripe never receives your email content.
  • Intuit and Xero — only if you connect them, and only to read invoices. Collectly never writes to your accounting system.

We do not sell data, and we do not share it with advertisers.

How it is protected

  • OAuth tokens encrypted at rest with AES-256-GCM.
  • Session cookies are httpOnly and unreadable from page scripts.
  • Every request re-verifies which workspace you belong to on the server, so data cannot cross between organisations.
  • Transport is HTTPS throughout.
  • Audit logs deliberately exclude message bodies, amounts and tokens.

No system is perfectly secure. If we become aware of a breach affecting your data we will tell you promptly and describe what happened.

Revoking access and deleting data

You can disconnect Gmail at any time from Settings, which clears the stored tokens immediately. You can also revoke Collectly independently from your Google account permissions page.

To delete your account and everything in it, email the address below. We will action it and confirm when it is done.

Contact

Questions about this policy, or a deletion request: nikowaliaweimer@gmail.com.