SentryReply privacy policy

in effect 26 august 2026

Privacy.

SentryReply is one person — me, Rali Filali. This page is the whole account of what the system touches: your Google account, and the buyers who write to you. It is short because the system is small, and specific because a vague privacy policy is worth nothing.

01 · who you are dealing with

One person, one address.

SentryReply is operated by Rali Filali, sole proprietor, 500 4th St NW, Ste 2760, Albuquerque, NM 87102, United States.

Every question about this page goes to [email protected], and I am the one who reads it. There is no support queue and no data-protection department to route you through.

02 · two kinds of people

The agent, and the buyer.

The agent is the customer: she connects her Gmail, and the system answers from her mailbox. Sections 03, 04 and 09 are about her data.

The buyer never signs up for anything and never hears from me — she writes to a listing, and an agent answers her. Her information passes through this system on its way to that answer. Section 05 is about her.

03 · google data

Four permissions,
and not a fifth.

When you connect your Gmail, Google shows you exactly this list. Nothing below is a promise I make about my own restraint — each line is a boundary Google enforces on the access it granted me.

gmail.send
Send mail as you. This permission has no method for reading a message. Not one I choose not to call — one that does not exist in it.
userinfo.email
The email address of the account that just authorized, so I know whose token I am holding. It does not touch the mailbox.
calendar.freebusy
Busy or free, hour by hour. Never a title, a place, or a guest. It is the narrowest calendar access Google offers, and it exists so a proposed showing never lands on a slot you already gave away.
calendar.app.created
Create one calendar — “SentryReply Showings” — and write only inside it. Your existing calendars and every event already in them are out of reach for this token.

Not requested, and therefore impossible: reading your inbox, changing or deleting your mail, reading your calendar's contents, touching an event I did not create, your contacts, your Drive.

SentryReply's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In practice: that data is used to run the feature you connected it for, it is never sold, never used for advertising, never used to train any model, and no human reads it except where you ask me to fix something.

04 · what i keep about you

One row. This one.

Authorizing writes a single record: your name as you typed it, your Gmail address, the Google refresh token, the date you connected, the status of that token, and the ingestion address assigned to you — ten random hex characters, never derived from your name.

Then whatever you fill in on the profile page: your phone number, the hours you are willing to show, and a few lines of local context you want the replies to know. That is the entire record.

I never see a password. Google holds your login and hands back a token; that exchange happens between you and Google, and a token is revocable in one click (section 11) in a way a password is not.

05 · what passes through about the buyer

Only what the portal
already put in the email.

A portal notifies you of a lead at your ingestion address. From that notification the system reads the buyer's name, her email address, her phone number when the portal includes one (Zillow's relay usually does not), the listing she asked about, and the text of her message.

That text, the reply sent back, the timestamps, and whether she has answered are kept — because the fourteen days of follow-up exist to stop the moment she answers, and stopping requires remembering.

She is never profiled, never scored against other buyers, never added to any list of mine. The only thing that happens to her message is that you answer it faster.

06 · where it physically sits

Three places, all named.

Rate-limit counters (an email address, an IP address) live in Cloudflare's key-value store and expire on their own — an hour for the IP, a day for the address.

07 · who else can see it

The whole list.

That is the complete list. There is no analytics vendor, no CRM, no data broker, no advertising network — and no lead of yours is ever visible to another agent.

08 · the model that writes

What the model is given.

To draft a reply, the buyer's message, your profile lines and your free/busy windows are sent to Google's Gemini API. Not your mailbox — it cannot be read — and not your calendar's contents, which the permission in section 03 does not expose.

It runs on the paid tier, whose terms state that content submitted to it is not used to train Google's models. The draft leaves under your name and is yours; nothing of it is kept here beyond the record described in section 05.

09 · the live test drive

The form on the home page.

You type a name, an email address, one of your listings and an inquiry; the same pipeline drafts a reply and sends it to that address. No account is created, and none of it enters the agent or lead tables.

What does persist, precisely: your email address sits in a Cloudflare counter for twenty-four hours so the demo cannot be run twice from it, your IP address in another for one hour, and I receive a notification with the name, address and listing you entered — which means it lands in my own inbox. Ask me and it is gone.

10 · cookies and tracking

No analytics. At all.

No analytics script, no tracking pixel, no advertising cookie, no third-party session. I do not know how many people read this page.

Three cookies exist, all first-party, all tied to one action: __Host-sr_oauth_state and __Host-sr_oauth_name, set for fifteen minutes while you authorize, and __Host-sr_invite, which carries your invitation link for as long as that link is valid, at most thirty days. None of them follows you anywhere.

Fonts and two animation libraries load from Google Fonts and jsDelivr, which see your IP address the way any content network does. Cloudflare, as the host, logs requests in the ordinary way.

11 · how it ends

Revoking takes one click.
Deleting takes one email.

Cut the access: go to myaccount.google.com/permissions and remove SentryReply. The token dies at Google's end, immediately, and nothing further can be sent from your mailbox — my agreement is not required and my cooperation is not needed.

Erase the record: write to [email protected]. Your row, your leads, the Sheet lines and the server's execution logs are deleted within thirty days, in practice the same day. I will confirm when it is done.

Lead records are kept while you are a customer, because the follow-up sequence reads them. They go with the rest when you ask.

12 · security, and its limits

What is true, and what
I will not pretend.

Your password never transits here. The authorization flow is protected against forged returns, its cookies are HttpOnly, Secure and host-locked, everything travels over TLS, and the server's admin interface is unreachable from the public internet.

And the honest half: I am one person, not a certified vendor. There is no SOC 2 report behind this page, no third-party audit, no insurance policy covering a breach. If your brokerage requires those, I am not there yet — and you should know that before you connect, not after.

If data of yours is ever exposed, you will hear it from me directly, with what happened and what I did about it.

13 · your rights

Same address, no form.

If you are in California: you may request the personal information held about you, ask for its deletion, and ask that it be corrected. I do not sell or share personal information as the CCPA defines those words — there is no buyer in section 07 because there is no sale.

If European law applies to you: access, rectification, erasure, portability and objection, answered within thirty days. Some of the data already sits on a server in Germany.

Either way it is one email, there is no fee, and I will not ask you to fill in a portal.

14 · changes

You will be told.

If this policy changes in a way that matters — a new permission, a new company in section 07, a new use of your data — every connected agent gets an email from me before it takes effect. The date at the top of this page is the date of record.

15 · contact

Write to me.

[email protected]
Rali Filali · +1 941 541 6899 · 500 4th St NW, Ste 2760 · Albuquerque, NM 87102

last updated 26 august 2026 · one person still reads this address