1.Who we are and who this policy covers
BlastWiz is operated by BuiltforMCA.com("BlastWiz", "we", "us"). You can reach us at [email protected].
BlastWiz is a business tool. Companies ("customers") give their sales reps BlastWiz accounts. Reps use BlastWiz to text, call and email the merchants they work with. This policy covers the reps and administrators who use BlastWiz, and the merchants whose messages pass through it.
For information about merchants, BlastWiz acts on behalf of its customers. The customer decides which merchants to contact and what to say. BlastWiz stores and processes that information to provide the service to the customer.
2.Information BlastWiz handles
To provide the service, BlastWiz handles:
- Account details. The name, email address, role and company of each person with a BlastWiz account, and the sign-in details needed to keep the account secure.
- Contacts the customer uploads. Lead and contact lists, including merchant names, phone numbers, email addresses and the other fields the customer chooses to upload.
- Text messages. The texts and picture messages sent and received through BlastWiz, their delivery status, and opt-outs.
- Calls. A record of calls placed through BlastWiz. Outbound calls placed through BlastWiz are recorded, and the recording is stored.
- Email. Emails the AI Agent sends for a rep and, if the rep connects Gmail, the emails described in the Gmail section below.
- Usage and audit logs. Records of actions taken in the app, such as who sent a campaign or changed a setting, and technical logs used to run and fix the service.
- Cookies. The app uses cookies that are needed to keep you signed in.
- Contact form. What you type into the contact form on this website, so we can reply.
We use this information to provide, secure and support the service for our customers.
The providers that help us run the service, and so handle this information for us, are:
- Supabase, for the database, sign-in and file storage.
- Amazon Web Services, for the servers.
- Twilio and SignalHouse, for text messages. Twilio also carries calls and call recordings.
- Resend, for sending email.
- Grafana Cloud, for technical logs.
- Formspree, for the contact form on this website.
3.Google user data: the Gmail connection
The feature
BlastWiz includes an AI Agent that follows up with merchants for a rep, by text and by email. Emails go out under the rep's own address, so a merchant's reply arrives in the rep's Gmail inbox. So that the agent can see those replies and answer them, a rep can choose to press Connect Gmail. Connecting is optional. The agent keeps working by text without it.
The one permission
BlastWiz asks Google for one permission: read-only access to Gmail (https://www.googleapis.com/auth/gmail.readonly). It asks for no other Google permission. With this permission BlastWiz cannot send, delete, label, move or change anything in Gmail, and it does not.
Before Google's own screen appears, BlastWiz shows the rep what will be read, stored and shared, and the rep has to tick a box to agree.
What BlastWiz looks at, and what it reads
Google's read-only permission technically covers the whole mailbox. BlastWiz's software narrows what it reads, like this:
- Only new mail. BlastWiz starts from the moment the rep connects. It does not go back through mail that was already in the mailbox.
- A check about once a minute. BlastWiz asks Gmail which messages are new. While the AI Agent has no open conversation for that rep, BlastWiz does not list or look at any message.
- Headers only, to decide. For each new message, BlastWiz reads the headers and nothing of the body: who it is from and to, the subject, the date, the identifiers that show which email it replies to, and the technical headers that mark automatic mail and show whether Gmail could verify the sender. Drafts, spam, trash and chats are skipped without even that.
- Everything that does not match is dropped. If a message does not belong to a merchant conversation the AI Agent is working for that rep, BlastWiz does not open it, and does not save or log its sender, recipients, subject or content. To check whether a message is a reply to the agent, BlastWiz looks up the message identifiers from its headers in its own database.
BlastWiz opens a message in full only when it is one of these:
- An email from the address of a merchant the AI Agent is working for that rep.
- A reply to an email the AI Agent sent. This includes a reply from a different address, for example a merchant's accountant who was forwarded the email.
- An email the rep sent from Gmail to one of those merchants. BlastWiz reads it so the agent can step back and let the rep take over.
Automatic replies, delivery failure notices and mailing-list mail are not opened in full, even when they match.
Attachments.If the customer has connected its deal system, BlastWiz downloads the PDF documents a merchant, or another person replying to the agent's email, attaches to those emails. It takes PDF files only, up to 30 MB each and up to 10 files per email. Photos and other kinds of file are not kept: BlastWiz records only that they were attached, with their file name, type and size. It does not take attachments from emails the rep sent, or from an email whose sender Gmail could not verify.
The mailbox address.BlastWiz reads the Gmail address and its "send mail as" addresses, to check that the mailbox is the one on the rep's BlastWiz profile and to recognise the rep's own emails.
How BlastWiz uses it
BlastWiz uses this information only to run the feature the rep can see in BlastWiz:
- To show the email in the rep's conversation with that merchant.
- To let the AI Agent write and send the next reply to that merchant.
- To file the PDF documents attached to those emails to the merchant's deal in the customer's deal system, so the rep does not have to download and upload them by hand.
- To pause the agent when the rep emails the merchant directly.
- To stop emailing a person who asks by email not to be emailed.
- To alert the rep, for example when a file could not be filed.
What BlastWiz does not do with Gmail data
- We do not sell it.
- We do not use it for advertising.
- We do not use it to train, create or improve artificial intelligence or machine learning models.
- We do not share it with data brokers or information resellers.
4.Google's Limited Use requirements
BlastWiz's use of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements.
The use of information received from Google Workspace scopes will adhere to the Google User Data Policy, including the Limited Use requirements.
You can read the policy these statements refer to at Google API Services User Data Policy.
5.What we store and for how long
- Access token. When a rep connects Gmail, Google gives BlastWiz a token that allows read-only access. We store it encrypted (AES-256-GCM) in our database. The short-lived tokens made from it are held in server memory only.
- Connection details.The Gmail address, its "send mail as" addresses, the permission granted, when the mailbox was connected and last checked, and a marker that tells us where we last checked. The marker contains no message content.
- Imported emails.For each email opened in full: the sender and recipient addresses, the subject, the text of the email with quoted earlier messages removed, the time, the email's identifiers, and how many files were attached. They are saved with the rep's conversation with that merchant.
- PDF documents.BlastWiz keeps a copy of each PDF it downloads in its private file storage, and sends it to the customer's deal system. It also keeps a record of each attachment: its name, type, size and whether it was filed.
- Alerts.An alert to the rep can quote a short part of a merchant's email.
We keep imported emails and documents until the customer has them deleted. A customer can ask us to delete them at any time (see section 9). When a customer's account is deleted, its imported emails and its Gmail connections are deleted with it.
7.Who can see imported emails
- The rep who connected Gmail sees the imported emails in their own BlastWiz conversations.
- Administrators at the rep's company can see the imported emails on any conversation in that company, and can sign in to a rep's account to give support.
- Other reps at the company cannot see them. Other companies cannot see them.
BlastWiz staff who run the service have technical access to the systems that store this data, and a small number of BlastWiz administrators can sign in to a customer's account to give support. They do not read imported emails unless the rep or the customer has asked us to look at specific messages, or it is necessary for security purposes such as investigating a bug or abuse, or the law requires it.
8.Security
- Connections to BlastWiz, to Google and to the AI model provider use encryption in transit (HTTPS).
- Google access tokens are encrypted before they are stored. They are never sent to the browser and never shown on any screen.
- Only the rep can connect their own mailbox. BlastWiz accepts a mailbox only if its address is the email address on that rep's BlastWiz profile. For any other Google account it cancels the access at Google straight away and keeps nothing.
- Text from an email is given to the AI model as marked, untrusted data, not as instructions. Characters that could be used to break out of that marking are replaced first. Whatever the AI writes is checked by fixed rules before it is sent.
- An email whose sender Gmail could not verify is not answered, and its attachments are not taken.
9.Disconnecting Gmail and deleting data
A rep can disconnect Gmail at any time in BlastWiz: open Settings, then My AI Agent profile, then Disconnect Gmail. An administrator at the rep's company can also disconnect it. A rep can also remove BlastWiz's access from their Google Account at https://myaccount.google.com/permissions.
When a rep disconnects in BlastWiz, BlastWiz asks Google to cancel the access and deletes the stored token and connection details straight away. BlastWiz stops reading the mailbox. Emails and documents that were already imported are kept as part of the customer's records until the customer has them deleted.
To ask for imported emails and documents to be deleted, email [email protected]. We will delete them within 30 days, unless the law requires us to keep them. Step by step instructions are on the Gmail help page.
10.If you are a merchant
If a business contacted you through BlastWiz, that business is our customer and decides how your information is used. To stop text messages, reply STOP to the text. To stop emails, reply to the email and ask not to be emailed, or use the unsubscribe option your email app shows.
For anything else, contact the business that wrote to you. If you cannot reach them, write to [email protected] and we will pass your request on.
11.Changes to this policy
If we change how BlastWiz uses Google user data, we will update this policy and ask connected reps to agree again before the new use begins. For other changes, we will update this page and the date at the top.
12.Contact
BuiltforMCA.com, [email protected]. Our terms of service are on this website too.