Pilot Data Practices
The specific data rules for the founding pilot: what may be shared, what will not be accepted, and what happens to it.
- Version
- 1.7.0
- Last updated
- 19 September 2026
- Effective date
- 19 September 2026
What this page is
The founding pilot has stricter data rules than a finished product would, on purpose. This page sets them out in the same words you will be asked to acknowledge in writing before you share anything real.
Reading this page is not agreeing to it. Nothing is shared and no work begins until you have acknowledged these practices in writing and a GLR operator has confirmed it. That order does not change.
What the pilot may handle
Ordinary business lead-recovery information about your own operation. For example:
- business contact records you own — a name, a business email address, a business phone number
- lead and enquiry lists for your own business
- publicly available business information
- your own past-lead spreadsheets
That is the whole category. It is your business data about your business.
What the pilot will not accept
These are refused rather than handled carefully. If any of them arrives, work stops until it is removed:
- health or medical information of any kind
- legal case information, or anything used to make a legal decision
- financial account information, or anything used to make a financial decision
- emergency, life-safety, or safety-critical information
- government identifiers, social security numbers, and payment card numbers
- any other regulated or highly sensitive category
- information about people you are not authorised to share
- anything beyond what the agreed work actually needs
This is a boundary for the pilot as it stands today, not a permanent statement about what GLR could ever support. Widening it would need professional legal review first, and that has not happened.
Never send passwords, keys, or secrets
GLR will never ask you to send a password, private key, API key, access token, sign-in file, or other secret through email, chat, spreadsheets, documents, or ordinary customer records.
Approved services may use their own secure authorization process, such as an OAuth connection, so the service can access only what you approve. Any connection credentials created through that process must be handled through the approved credential system and must never be copied into messages, documents, or customer data.
If anyone asks you to send a password or secret directly, something has gone wrong and you should stop and report it.
Only what the work needs
Only the smallest set of information the agreed work requires is collected or kept. Nothing extra is asked for, copied, or held on to in case it turns out to be useful later.
The reasoning is simple enough to state: information that is not held cannot be lost.
Kept separate, and used only with approval
Your information is kept isolated to your account. There is no mixing between customers, and no route by which another customer could reach it.
During the pilot, no real information is processed without an explicit, named operator approval recorded at the time. Nothing runs unattended.
That is the pilot, and it is deliberately stricter than the finished product will be. The design goal is that the ordinary path runs automatically and a person steps in on exceptions. The pilot has not reached that, and it is not described as though it has.
What we write, and draft-only messages
Your Google Sheet is yours. The service sets it up for you — it creates the tabs your leads are kept in, adds columns, writes the heading row and formats them — and from then on it reads and adds to it as part of the agreed work. It does not delete tabs or remove rows. No other customer-record system of yours is written to.
Messages are draft-only. The service prepares a draft; you read it, change it if you want, and send it yourself. It cannot send on your behalf and does not have permission to.
Your mailbox is not connected at all. GLR holds no email credential and has no access to your mail — so 'cannot send' is a fact about what GLR holds, not a setting that could be changed.
How long it is kept, and what deletion does
Information is kept for the engagement plus a wind-down period of 30 days, and then deleted. It is deleted sooner if you ask in writing. Nothing is kept indefinitely.
Deletion is a hard delete: the records are removed, not hidden, archived, or made anonymous.
Two internal records outlive it, and neither holds your data: a short pseudonymous note that a deletion happened, kept for up to 90 days so that restoring an older backup cannot undo it; and records of occasions when the system refused to act, which carry no reference to a customer at all and therefore cannot be traced to you. The Privacy Policy explains both in full.
The 30 days is GLR's own figure and no lawyer has read it. Today it is applied by a person rather than by an automatic timer, because no scheduler has been built to run it.
If something goes wrong
If information is exposed, mishandled, sent to the wrong place, or a password turns up somewhere it should not be, tell the GLR operator running your pilot immediately. GLR does the same in the other direction: the matter is contained, escalated, and you are told.
If any of the conditions on this page cannot be met, or anything is unclear, work stops rather than continuing. Uncertainty is never resolved by pressing on.
No promises attached
This page describes how information is handled. No guarantee of leads, bookings, recovered revenue, response rates, deliverability, return on investment, or legal compliance is made by it or anywhere else.
The pilot is limited, and it will change
This is an early, bounded version of the product offered to a small number of businesses. Parts of it are done by a person. Some capabilities described in the packages are not switched on yet, and the practices on this page may change before the product is generally available.
Where something changes in a way that affects you, GLR tells you and asks again rather than assuming your earlier acknowledgment covers it.
This wording is GLR's own and is not attorney-reviewed. GLR has approved it and applies it to the founding pilot from the effective date shown at the top of this page; no lawyer has read it.