Privacy policy
Last updated 7 September 2026
Who we are and what this covers
Please Meet is operated by Please Meet, LLC (we, us), and runs a referral service at pleasemeet.app. A company hires us to help it get warm introductions. One of that company's customers — the introducer — connects their Google account, reviews a list of people they know, and sends introductions from their own Gmail account to the person being introduced, the introducee.
This policy covers all three, plus anyone who simply visits this website. It explains which Google permissions we ask for, what we do with the data behind them, who else sees it, how long we keep it, and how to have it deleted.
The Google permissions we request
Two kinds of people connect a Google account, and they grant different permissions. These lists are the complete set — this page is generated from the same constants our sign-in code uses, so it cannot describe more or less access than we actually request.
The client’s representative — the person who will take the meetings
- gmail.send“Send email on your behalf”
- Sends the specific messages you approved, from your own Gmail account, so they arrive as ordinary mail from you. This permission carries no ability to read, search, list or open anything in your mailbox.
- calendar.events.readonly“View events on your calendars”
- Reads events on your primary calendar to see who you meet with. We use only the attendee email addresses and the event start times; we do not use or store event titles, descriptions, attachments or guests’ other details.
The introducer — the customer making the introductions
- contacts.other.readonly“See and download contact info automatically saved in your ‘Other contacts’”
- Reads the addresses Google files under “Other contacts” — people you have corresponded with but never saved — for the same suggestions. Reading this list is not the same as reading your mail: it returns names and email addresses only, never message content.
- contacts.readonly“See your contacts”
- Reads the contacts you have saved in Google Contacts, so we can suggest which of them might be worth introducing to the company that asked you.
- calendar.events.readonly“View events on your calendars”
- Reads events on your primary calendar to see who you meet with. We use only the attendee email addresses and the event start times; we do not use or store event titles, descriptions, attachments or guests’ other details.
- gmail.send“Send email on your behalf”
- Sends the specific messages you approved, from your own Gmail account, so they arrive as ordinary mail from you. This permission carries no ability to read, search, list or open anything in your mailbox.
We never read the introducer’s mailbox — or anyone else’s
We do not request gmail.readonly, gmail.metadata, gmail.modify, gmail.compose, or any other Gmail permission that can open, search or list mail. The single Gmail permission we ask for, gmail.send, can only send a message. This is not something you have to take on trust: an application holding only gmail.send is technically incapable of reading a mailbox, and Google is the one enforcing that.
Limited Use
Please Meet's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In practice that means we use Google user data only to provide the feature the person granted it for, we do not transfer it except as described on this page, we do not use it for advertising, we do not sell it, and no human reads it except with the account holder's explicit permission, to resolve a support problem they raised, for a narrow security investigation, or where the law requires it.
What we do with an introducer’s data, and what we do not
An introducer grants access for one purpose: making the introductions for the campaign whose link they opened. Any other use of their contacts or calendar is a separate purpose that needs their separate, explicit consent — asked for on screen, in plain language, next to the button that gives it.
Concretely: we do not analyse an introducer's network to sell them something, to build a product for somebody else, or to work out what a campaign of their own might be worth, unless and until they have clicked to agree to exactly that. Recording that somebody expressed interest is not the same as computing something from their data, and we do not do the second one first.
From the introducer's Google account we store:
- Their own name and email address.
- For each person we suggest: name, email address, and the company domain from that email address — taken from their contacts.
- For each of those people: how many events they and the introducer both attended in the last two years, and the date of the most recent one. Event titles, descriptions, locations, attachments and other guests’ details are not stored or used.
- A relationship score computed from those counts, used only to order the suggestions.
The client never sees a contact the introducer did not approve, and never sees the scores. The introducer is never shown who declined an introduction, or any ranking of their own relationships.
What we do with the client representative’s data
We store the representative's name and email address, the introductions sent on their campaigns, and — from their calendar — whether an introducee's email address appears as an attendee on an event created after the introduction went out. That is how a booked meeting is counted, and it is the only thing we look for. We do not store the contents of their calendar.
If you were introduced to someone
If you received an introduction, your name, email address and employer's domain came from the contacts of the person who introduced you — somebody who had your address already. We keep those details, and a record of the introduction, so that we never send you a second one by accident and so the client can be billed if you book a meeting.
Email hello@pleasemeet.app and we will add you to a do-not-contact list that applies across every client and campaign we run, and delete your details if you ask us to.
Who else your data reaches
These are all of them. We will update this page before adding another.
- Gmail, Google Contacts and Google Calendar are where the data comes from, and Gmail is how introductions are sent. Sending an introduction means handing Google the message, exactly as any mail app does.
- Postmark
- Sends our own system email — the note telling a client representative that an introduction went out, and alerts about a broken account connection. These go to our clients’ own staff, never to an introducee. Postmark sees the recipient’s address and the message.
- Anthropic
- Identifies what a company does, from its public website. We send the company’s internet domain and the text of its public homepage. We never send a person’s name, email address, contact list or calendar data to Anthropic.
- Railway
- Hosts the application and the database it stores everything in.
We do not sell personal data, we do not share it with advertisers, and we do not use it to train machine-learning models.
How your data is protected
Google access and refresh tokens are encrypted before they are written to our database, using AES-256-GCM with a key held outside it. Tokens are never shown in our own admin screens, never returned by our API, and never written to a log or an error message.
Access to the production database is limited to the people who operate the service.
How long we keep it, and how to have it deleted
What happens today, stated plainly
We do not currently delete data on a schedule. Google tokens and campaign records stay in our database until the account holder revokes access or asks us to delete them. We are building automatic deletion of Google tokens 30 days after a campaign ends; it is not running yet, and this page will say so when it is. We would rather tell you what is true than describe a schedule we do not keep.
You can act on your own data at any time, in two ways:
- Revoke our access to your Google account directly, at myaccount.google.com/permissions. That takes effect immediately and stops us reading or sending anything further. Revoking does not by itself erase what we already stored.
- Email hello@pleasemeet.app and ask us to delete your data. We will delete your Google tokens and the contact and calendar-derived data associated with you, and confirm when it is done. We aim to do that within 30 days.
Two things we keep after a deletion request, and why: a record that an introduction was sent to a particular address, so nobody sends that person another one, and the invoice records a business is required to retain. If you would rather we did not keep the do-not-contact record either, say so and we will remove it — but then we have no way to recognise the address again.
Cookies
These public pages set no cookies and run no analytics or advertising trackers. The approval page an introducer uses, and the admin area our own staff sign into, set a session cookie needed to keep you signed in and the page working. There is no third-party tracking anywhere on this site.
Children
Please Meet is a business tool, not intended for anyone under 18, and we do not knowingly collect data from children.
Changes to this policy
If we change how we handle Google user data, we will update this page and the date at the top of it before the change takes effect.
Contact
Questions, deletion requests, and anything else: hello@pleasemeet.app. A person reads that address.
See also our terms of service.