Privacy Policy
Last updated September 22, 2026
This Privacy Policy explains how Guestify (“Guestify,” “we,” or “us”) collects, uses, and protects information when you use our website and the Interview Authority System platform (the “Service”). By using the Service, you agree to the practices described here.
Information we collect
We collect only what we need to run the Service and support you:
- Account information — your name, email address, and the details you provide when you create an account or book a demo.
- Content you create — the podcasts, pitches, contacts, and other material you add to or generate within the platform.
- Usage data — basic technical information such as your browser, device, and how you interact with the Service, used to keep it working and improve it.
- Payment information — handled by our payment processor; we do not store full card numbers on our servers.
- Information from people without an account — what you enter into one of our free tools, and any message you send through the contact form on a Guestify customer’s media kit. Each is described in its own section below.
How we use your information
- To provide, maintain, and improve the Service.
- To communicate with you about your account, support requests, and updates.
- To process payments and manage subscriptions.
- To keep the Service secure and prevent abuse.
- To send you marketing and product email where you have given us your address, on the basis described under Email from our free tools below — you can unsubscribe at any time.
What we don’t do
We don’t sell your data, and we don’t share your contact information with third parties for their own marketing. We do not trade, rent, or auction your personal information.
One thing that deserves naming rather than burying: we do load advertising pixels on our public pages, which tell an ad platform that a browser visited one of our pages. No contact information is involved — we never upload your email address to an ad platform — but some privacy laws treat this kind of ad targeting as “sharing” even though no money changes hands and no list is handed over. See Advertising and retargeting below for exactly what those pixels do, who they are, and where they fire.
Service providers
We work with a small number of vendors that process data on our behalf — for example, hosting, analytics, email delivery, AI processing, and payments. These providers are permitted to use your information only to perform services for us, and are bound by confidentiality obligations.
Our marketing and lifecycle email is delivered through HighLevel(LeadConnector), which acts as a processor on our behalf. What we pass it depends on how we know you. If you gave us your address at a free tool and have no account, we send your email address and tags recording that you used a tool and which one. If you have a Guestify account, we also send your name and a small set of fields describing that account — for example your plan, your stated goal, and where you are in setting things up — so that the email is relevant to you. In both cases HighLevel sends the email described above and records whether you unsubscribed, processes this only under our instructions, and does not use it for its own marketing.
Google user data
Some Guestify features work by connecting your Google account, and each one is something you turn on yourself. Signing in with Google tells us your name, email address and profile picture. Connecting your calendar lets us read your events and the people invited to them, so we can show you who you already have a relationship with and put your interviews on your calendar. Connecting your contacts lets us read your address book to find those same relationships. Connecting Gmail lets us send outreach from your own address, at your request: the permission we ask Google for is send-only, and we do not use Google’s APIs to read your mail.
Separately from that, you can turn on reply detection for a connected mailbox. It is off unless you switch it on, and it does not use Google’s APIs: it connects to your mailbox over IMAP with an app password you create yourself, so that we can match incoming replies to outreach you sent. While it is on, it reads new messages arriving in that inbox in order to find those replies, and stores the content of the ones that match. You can turn it off at any time.
We use this only to provide those features to you. We do not sell it, we do not use it for advertising, and we do not use it to train generalized AI or machine-learning models. You can disconnect your calendar, your contacts or a connected mailbox at any time from inside Guestify, which stops all further access. The Google sign-in itself is how you get into your account, so it has no disconnect of its own — you can revoke Guestify’s access from your Google Account’s security settings, and you can ask us to delete what we already hold at the address below.
Guestify’s use and transfer to any other app of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements.
Free tools, results, and result links
Some of our tools are open to anyone, with no account. When you run one, we store our own record of what the tool produced so that we can show it back to you at a private link and, if you ask us to, email you that link. What you type into a tool — for example a topic, a bio, or a person’s name — is processed to produce that result and is stored with it.
- The link is unguessable and short-lived — a result page carries a random identifier, is not indexed by search engines, and stops being readable 14 days after it is created. Expiry is enforced when the page is read, so a result is unreachable at the end of that window whether or not our clean-up job has already deleted the row; a scheduled job then removes the stored record itself.
- We email the link, not the content — a result email from us contains no text supplied by whoever asked for it. Any one result can be emailed to at most three different addresses, and only from the same device and network the result was generated from.
- Why the 14 days matter, stated plainly — a tool result may describe a person who never visited our site, and we do not learn who that person is: a stored result holds no email address, account, or other identifier for them, so we cannot look up results by the person they are about. For those records the retention window is the deletion mechanism, which is why it is short. Where we do hold a key — you claimed a result into a Guestify account, or you gave us the email address we sent it to — we can find and delete the record on request; see Your rights below.
The free media-kit builder works differently, and on a longer clock. When you build a media kit from a LinkedIn profile, we save it as a draft page every time you generate one — not only when you ask to keep it — so that you can edit it and share its link. A draft is not a tool result, and the 14-day window above does not apply to it.
- What a draft holds — the name, headline, photo and bio from the profile it was built from, the sections we wrote from them, any edits you make, and the address of that LinkedIn profile. Like a result page, its link is unguessable and not indexed by search engines, and anyone holding the link can read it.
- How long it lasts — a draft that nobody has claimed into an account is deleted by a scheduled job 90 days after it was last edited, or 180 days after it was created, whichever comes first. Editing a draft keeps it alive for a while, but not indefinitely. If you create a Guestify account from a draft, it becomes part of that account and is kept on the same terms as the rest of your account data.
- The profile details are kept separately — to build from a LinkedIn profile we fetch its public details once and keep that copy, filed under the profile’s address, so that a later build from the same address does not fetch it again. That copy is not on the draft’s clock: deleting a draft does not delete it.
- Unlike a tool result, we can find it by the person it is about — both the draft and our copy of the profile record the LinkedIn address they came from. If a media kit here is about you, your LinkedIn profile address is enough for us to find and delete both; see Your rights below.
Messages sent through a media kit’s contact form
Guestify customers can publish a media kit with a contact form on it. If you use one of those forms, you do not need an account, and we store what you send — your name, your email address, the phone number and subject if you give them, and your message — so that we can show it to the owner of that media kit in their Guestify inbox and they can reply to you.
- Who sees it — the owner of the media kit you wrote to, and the other members of their Guestify workspace. We tell them a message has arrived without putting your name or your message in that notice; they read it in their inbox. We do not add you to our marketing email because you sent one.
- What else we keep with it — a scrambled (hashed) copy of your email address, which is what lets us still find your message if you ask us to erase your data after the address itself has been removed elsewhere, and a technical fingerprint of your browser and network, used only to deal with abuse of the form.
- How long it lasts — there is no fixed expiry. A message stays in the owner’s inbox until it is deleted on request or the media kit itself is deleted. To have a message you sent removed, write to the privacy address below and include the email address you sent it from.
- What happens after they read it — once the owner has your message, what they do with it outside Guestify, such as replying from their own email, is between you and them.
Email from our free tools
When you give us your email address at a free tool, we use it to send you the result you asked for and to send you occasional tips and product email about getting booked on podcasts. We tell you this beside the button before you submit, and submitting the form is what enrolls you — we do not use a pre-ticked consent box, and we do not treat a declined opt-in as agreement.
- Unsubscribing is the control. Every marketing email carries an unsubscribe link, and it takes effect for all of this email. You can also write to the privacy address below and we will remove you.
- We record which basis applied to you. For each capture we store whether you were enrolled on the strength of the notice beside the button or of an explicit opt-in checkbox, so that we can honour the terms you were actually shown.
- It is separate from your account email. Service and account messages — sign-in, password reset, receipts — are not marketing and continue whether or not you are subscribed.
Browser extension
The Guestify browser extension helps you capture contacts, draft outreach, and autofill forms while you work. It is an optional companion to your Guestify account and follows the same principles as the rest of the Service.
- What it accesses — when you are viewing a LinkedIn page and you click an action in the extension, it reads the profile details visible on that page (such as name, headline, role, company, and the profile URL) so it can match or create a contact and draft messages in your Guestify account. On pages where you ask it to autofill, it reads the form fields in order to fill them.
- It acts only when you ask it to — the extension does not run in the background and does not browse or collect pages on its own. When you ask it to find a path to a show's host, it asks LinkedIn — from your own logged-in browser, on that click — which of your own connections also know that person, and keeps only the ones already in your imported network. LinkedIn may treat that lookup as automated activity on your account. It never sends connection requests or messages on your behalf: LinkedIn invites and messages are prepared for you to review and send yourself.
- What it sends to Guestify — only the information you choose to save, together with a secure token that signs you in. This is transmitted over an encrypted connection to Guestify’s servers and handled exactly like the rest of your account data described above. We don’t sell it or share it for others’ marketing.
- What it stores on your device — a sign-in token and your local preferences, kept in the browser’s extension storage so you stay signed in. Signing out or removing the extension clears this.
The extension requests access to LinkedIn and to Guestify only — the sites it needs to do its job. You can disconnect it at any time by signing out or removing it from your browser.
Cookies and analytics
We use cookies and similar technologies to keep you signed in, remember preferences, and understand how the Service is used. You can control cookies through your browser settings, though some features may not work without them.
Advertising and retargeting
On our public pages — our marketing pages, our free tools, and the result pages those tools produce — we load advertising pixels from Meta, Google, and LinkedIn. These tell the platform that a browser visited a particular page of ours, so that we can show later ads to people who have already been here. That is the only thing we use them for.
We only show these ads to people who have already visited us — visitors to our tools and result pages, and people who registered for one of our webinars. We do not build advertising audiences from cold lists, and we never upload email addresses to an ad platform, including addresses you gave us at a free tool. Audiences are built only from the pixel on your visit.
These pixels fire for visitors in the United States only. If you are outside the US they do not load, and no advertising data about your visit reaches these platforms from us.
You can limit this from your side too: browser tracking-protection settings and the ad platforms’ own ad-preference controls both apply here, and blocking third-party cookies stops most of it.
Data retention
We keep your information for as long as your account is active or as needed to provide the Service. You can request deletion of your account and associated data at any time.
Some records are not tied to an account, and each has its own rule, as described in the sections above:
- Free-tool results become unreadable 14 days after they are created and are then deleted.
- Media-kit drafts that nobody has claimed into an account are deleted 90 days after they were last edited, or 180 days after they were created, whichever comes first. Our copy of the LinkedIn profile a draft was built from is kept separately and is not deleted with the draft.
- Messages sent through a media kit’s contact form have no fixed expiry; they are kept until deleted on request or until the media kit is deleted.
- Marketing contact details are kept until you unsubscribe or ask us to remove them.
Security
We use reasonable technical and organizational measures to protect your information. No method of transmission or storage is completely secure, but we work to safeguard your data and respond promptly to any issues.
Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal information, and to object to certain processing. To exercise any of these rights, contact us at the address below.
Some of what we hold can only be found with a particular key, so please include the one that fits:
- A free-tool result — the result link, or the email address it was sent to. A stored result holds no identifier for the person it describes, so without one of those we have no way to find it — and in any case it stops being readable 14 days after it was created.
- A media kit built from your LinkedIn profile — your LinkedIn profile address. That is enough for us to find the draft and our copy of your profile, even if someone else built it.
- A message you sent through a media kit’s contact form — the email address you sent it from.
Children
The Service is not directed to children under 16, and we do not knowingly collect personal information from them.
Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date above, and significant changes will be communicated through the Service.
Contact us
Questions about this policy or your data? Email us at [email protected].
