Skip to content

Security

You are handing over your mailbox. Here is exactly what happens to it.

Collectly reads conversations with your customers and sends email in your name. That is a lot of trust to ask for, so this page is specific rather than reassuring.

  • Two Gmail permissions, and no more

    Collectly requests read access, to read replies in threads involving customers you have added, and send access, to send a follow-up you have approved, or a routine low-risk reminder without approval if automatic sending has been turned on. It does not request permission to create, modify or delete anything in your mailbox — no drafts, no labels, no deletions. Drafts are held inside Collectly instead. Alongside those two, the connection asks for Google's standard sign-in scopes — openid, email and profile — which give no access to mail and exist so the mailbox is recorded against the right address.

  • It does not index your mailbox

    The scheduled sweep asks Gmail only for messages from the customer addresses you added. Gmail can also notify Collectly the moment new mail arrives, and that notification does not say who the mail is from — so the thread is fetched, checked against your customer list, and discarded without being stored if it matches nobody. A thread with no connection to a customer record you created is not kept.

  • Mailbox credentials are encrypted

    OAuth tokens are encrypted with AES-256-GCM before they are stored, using a key held in the deployment environment rather than in the database. Disconnecting in Settings asks Google to revoke the grant and clears the stored tokens; the local clear happens either way, so a disconnected mailbox never keeps a usable credential here. If the provider does not confirm the revocation, Settings says so on the spot and links the page where you can remove the grant yourself, because a grant that is still live on their side must not be reported here as gone.

  • Workspaces are isolated

    Every record in Collectly belongs to one organization, and every query is scoped to it. There is a test suite specifically covering that isolation, because a leak between two customers' data would be the worst failure this product could have.

  • Nothing sends without a person, by default

    Every account starts in approval mode. Even with optional automatic sending enabled, Collectly will not chase a paid or disputed invoice, will not escalate to an upset customer, and will not write while a payment promise is still good.

  • Payments are handled by Stripe

    Collectly does not store card details. Subscription billing runs through Stripe Checkout, and card data never reaches our servers.

  • Email content goes to one model provider

    Message content and invoice detail are sent to Anthropic's API, because that analysis is what Collectly is for. The endpoint is pinned in code, so no hosting provider's AI gateway can sit in between. Under Anthropic's commercial terms, API inputs and outputs are not used to train its models. The privacy policy names every other processor, including the one that sends your password-reset mail.

  • Data has a retention window, and a job that enforces it

    Email bodies are cleared after a year, the model's raw response after a month, and the IP address and user-agent on audit records after ninety days. A nightly job does it. One deliberate exception: a body attached to an invoice that is still open or disputed is kept however old it is, because the exact words are the evidence in a live argument. The privacy policy lists every window.

What we do not claim

Collectly is an early-stage product built by a small team. We do not hold SOC 2 or ISO 27001 certification, and we are not going to display badges we have not earned. If your business requires a formal security review before connecting a mailbox, contact us and we will answer honestly about where we are.

See also the privacy policy for what data is stored and for how long.

Reporting a vulnerability

If you think you have found a security flaw in Collectly, email hello@collectlyai.org with SECURITY in the subject line. There is no dedicated security address yet, and publishing one we do not read would be worse than sharing the one we do. Please do not post it publicly before it is fixed.

Useful to include, as far as you have it: what you found, the URL or endpoint involved, how to reproduce it, and whether you reached any data that is not yours.

What you can expect: we read every report, and we will reply to tell you whether we have reproduced it. We do not commit to a response time or a fix time, because this is a small early-stage product and a deadline we could not keep would be worth less than saying so. There is no bug bounty and we do not pay for reports. We will credit you if you want credit and the fix is public, and say nothing about you if you would rather we did not.

Nothing on this page is a safe-harbour commitment — that is a legal undertaking and we have not made one. What we can say without it: we have no interest in pursuing anyone who finds a flaw in good faith, tells us privately, and does not use it. If a test would go further than reading and reporting, ask first and we will answer.

Stop spending your week chasing invoices

Bring in your unpaid invoices, connect the mailbox you send them from, and see what Collectly makes of them.

Cancel any time. If you cancel within 14 days of your first payment, we refund it in full — no questions asked.