Smerio / Legal

Privacy Policy

Initial version · Updated

1. Scope and contact

This policy covers smerio.com and the Smerio Hub, including account access, workspace configuration and the messaging laboratory. Smerio is the project name. The legal name and postal address of the operator responsible for these activities are pending confirmation in this provisional version. Contact support@smerio.com for privacy enquiries and requests.

Where a business uses Smerio to process information about its own contacts, that business determines the purposes of its messaging. Production processing on its behalf requires agreed data-processing terms and an appropriate legal basis; this preview does not replace those arrangements.

2. Information handled

  • Account information: account identifiers, email address, name and profile image when supplied by you or your sign-in provider, and authentication/session information. Clerk manages authentication; Smerio’s application does not store your account password.
  • Workspace information: business and brand details, website and contact details, sender drafts, integration settings and requirements you enter.
  • Messaging lab information: numbers, message text, simulated replies, status events, timestamps and usage records entered or generated during tests. Use synthetic test information and avoid sensitive personal data.
  • Technical and website information: IP address and browser/device information available to hosting or analytics services, page visits, interactions, referrers, and campaign or booking events where collected.
  • Correspondence: the information you send when requesting support, providing feedback or booking a conversation.

The current hosted messaging lab uses a simulated provider. A simulated delivery event does not mean that a message was sent to a phone.

3. Google sign-in

If you choose Google sign-in, Google and Clerk handle the authentication flow. Smerio uses the identity information made available through that flow to create or recognise your account and provide access to your workspace. Basic sign-in can include your Google account identifier, email, name and profile image.

The sign-in feature does not require access to Gmail messages, Google Drive files, contacts or calendars. Any future feature requiring additional Google permissions must explain its purpose and request those permissions separately. Account identity information is used for authentication, account operation and security, rather than advertising.

You can review and remove a connection in your Google Account connections. Removing Google access does not itself delete your Smerio account or previously stored workspace records; request deletion through the contact below.

Where the GDPR applies, account and requested service operation rely on taking steps at your request or performing an agreement. Security, abuse prevention and handling ordinary support enquiries rely on legitimate interests in operating and protecting the service, balanced against your rights. Required legal records rely on the applicable legal obligation.

Optional marketing and non-essential tracking require consent where applicable. Creating an account or accepting terms is not consent to marketing. Consent can be withdrawn without affecting earlier lawful processing. Smerio must assess the legal basis of new uses before introducing them.

5. Cookies, storage and analytics

Authentication uses cookies or equivalent browser storage to maintain requested sessions. Optional Google Analytics and PostHog scripts load only after your corresponding choice in Cookie settings. You can reject both, customize the providers or withdraw permission without losing access to the website or account. PostHog session recording and automatic interaction capture are disabled.

See the Cookie Policy for purposes, storage names, durations and scope. Consent to website analytics is separate from marketing consent. Background account/email analytics exports are disabled pending a separately revocable account consent mechanism. Operational service records and transactional email continue independently.

6. Service providers and disclosures

We use the following providers for the stated functions:

Provider Purpose and information involved
Clerk Account identity, authentication and requested sessions
Render Website and Hub hosting; request handling and operational logs
Supabase/PostgreSQL Account, workspace, device, messaging-preview and service records
Resend Transactional email delivery, recipient addresses and delivery status; optional marketing only under its separate permission
Google Analytics Optional website visit and booking-click measurement, after permission
PostHog Optional browser analytics on the website and Hub, after permission; background account/email exports are disabled
Mintlify Serve the documentation and its requested features; visitor telemetry is disabled
Google Workspace / Calendar and Google sign-in Support correspondence, requested bookings, and identity information when you choose Google sign-in

Hosting and authentication providers necessarily receive technical data to deliver the pages and account functions you request. Rejecting optional analytics does not prevent this essential processing. A browser cookie is not itself sent to every provider: analytics code can read an identifier and send it together with event data, subject to your permission.

Data may be disclosed to providers as needed for these functions, to authorised people handling support or security, or where legally required. A business’s own messaging providers and carriers would need to process relevant message information if real messaging is enabled in the future; they are not implied by a simulated test.

Providers may process information outside your country, including outside the EEA. The final notice must identify the applicable locations and transfer safeguards, such as adequacy decisions or standard contractual clauses. These arrangements have not been fully documented in this provisional version; request current details before submitting data subject to specific residency requirements.

7. Retention and security

Account and workspace records are retained while needed to provide the preview and handle support, security or legal obligations. The detailed periods for messages, logs, inactive accounts and backups are pending definition. No automatic deletion interval for application records is promised by this version. The implemented browser limits are 180 days for the consent choice and Google Analytics cookie lifetime, and a 90-day campaign-attribution window; PostHog browser identifiers use page memory. These browser limits do not specify how long a provider retains events already received. See the Cookie Policy for expiry and withdrawal behavior.

You may request deletion at any time. We will explain any records that must be retained and the applicable reason. Session verification, access controls and workspace separation help protect data, but no system guarantees absolute security. Do not send passwords, API secrets or sensitive message contents to support unnecessarily.

8. Your choices and rights

Contact support@smerio.com with the subject “Privacy request” to ask about your data, correct it, request deletion or close your account. We may request proportionate information to verify that the request is yours.

Depending on applicable law, you may have rights of access, rectification, erasure, restriction, objection and portability, and the right to withdraw consent. You can complain to your local data protection authority, including the Spanish Data Protection Agency where applicable. If a business controls the messaging data concerned, we may direct the request to that business or assist it in responding.

9. Audience and changes

Smerio is intended for adult business and developer users, not children. This policy will be updated at this URL as the preview changes. The date above identifies this version; material changes affecting existing users should be communicated through the service or account contact details.


Questions? Contact support@smerio.com.