Legal · Privacy
Privacy Policy
Last updated September 7, 2026 · Gopherlume LLC · engageramo.com
This policy explains what engageramo collects, why, who we share it with, and what you can ask us to do about it. It covers engageramo.com, the engageramoapp, the chat widget we serve on our customers’ sites, and the help centers we host for them.
The short version: we collect what the product needs to work, we sell nothing, we run no advertising trackers, and Sign in with Google gives us your name, email and profile picture — nothing more.
Who we are
engageramo is a customer engagement platform — a chat widget, a shared inbox, tickets from email, a help center, automation and reports — operated by Gopherlume LLC, a Minnesota limited liability company. Gopherlume LLC is the holding company for engageramo and is the entity responsible for this site and service.
- Postal address: 330 2nd Ave S, Ste 200, Minneapolis, MN 55401, USA
- Privacy contact: privacy@engageramo.com
- Service: engageramo.com
The two roles we play
Which parts of this policy apply to you depends on how your data reached us, and the distinction matters legally.
- We are the controller for the accounts of people who sign up for engageramo — agents, workspace owners, waitlist applicants — and for visitors to engageramo.com itself. We decide what we collect and why, and this policy governs it.
- We are a processorfor the conversations, contacts, tickets and attachments a customer’s own end users send into that customer’s workspace. The workspace decides what to collect, how long to keep it, and who may see it; we process it on their instructions to run the service. If you contacted a company through a chat widget or support address powered by engageramo, that company’s privacy policy governs your data — contact them first, and we will help them respond.
What we collect
Account data. Your name, email address, a hashed password (only if you set one), your Google account identifier if you sign in with Google, your profile picture URL, your role and workspace memberships, and a generated avatar color. We never store your Google password.
Waitlist data. engageramo is invite-only. When you join the waitlist we record your queue number and tier, and — only if you choose to fill in the optional form — your website, support team size, current help desk, what you find painful about support today, and the name you plan to give your workspace. We use it to decide who to let in next.
Workspace content.Conversations and messages across chat and email, tickets, internal notes, contacts and companies, tags, saved replies, help center articles, files and images uploaded as attachments, and the inbound emails that become tickets. This is your customers’ data; see the two roles we play.
Contact and visitor metadata. For people who message a workspace through the widget or email we may store an IP address, a coarse geolocation derived from it (country and city, never a precise location), browser user agent, page URL, and the timestamps of their messages. Agents see this in the contact sidebar so they can recognize and, where necessary, block abusive traffic.
Security and abuse signals. Rate-limit counters, hashed IP addresses used for reputation lookups, and an audit log of sensitive administrative actions (approvals, role changes, deletions) with the acting account and timestamp.
Product analytics. Pageviews and basic session activity, collected first-party from our own domain. We do not run third-party advertising or cross-site tracking pixels, and we do not sell or share this data for behavioral advertising.
Sign in with Google
engageramo offers Sign in with Google as a way to create and access your account. When you use it, Google asks for your permission and then gives us a signed identity token. We request exactly three non-sensitive scopes, and nothing else:
- openid — A stable, pseudonymous Google account identifier for you. Links your Google account to your engageramo agent record so the same person signing in twice is the same account.
- email — Your Google account email address and whether Google has verified it. Identifies your account, matches workspace invitations, and is where we send account and support email.
- profile — Your basic profile: name and profile picture URL. Fills in your display name in the shared inbox so teammates can tell who replied.
What we do with it.We verify Google’s token signature, then create or match an engageramo account with that email address, store your name and profile picture URL for display in the shared inbox, and start a session. If your email matches a pending workspace invitation, we join you to that workspace. New accounts without an invitation join the waitlist.
What we do not do. We do not request access to Gmail, Google Drive, Google Calendar, Contacts or any other Google service, and we hold no Google access token that could reach them. We do not use Google user data for advertising, do not sell it, do not transfer it to others except as needed to run engageramo (see who we share data with) or to comply with law, and do not use it to train generalized AI or machine-learning models.
engageramo’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Revoking access. You can disconnect engageramo at any time at myaccount.google.com/permissions. That stops future sign-ins; to delete the account data we already hold, email privacy@engageramo.com.
How we use data, and our legal basis
- To provide the service— authenticate you, route and deliver conversations, send email on a workspace’s behalf, render the help center, compute reports. Basis: performance of a contract.
- To keep it secure — rate limiting, abuse and fraud detection, audit logging, incident investigation. Basis: legitimate interests.
- To support you — answer your questions and act on your requests. Basis: contract and legitimate interests.
- To improve the product — aggregate, first-party usage analytics. Basis: legitimate interests.
- To communicate — account, waitlist and service email. Marketing email only where you have opted in, with an unsubscribe link in every message. Basis: consent or legitimate interests.
- To comply with law — tax, accounting and lawful requests. Basis: legal obligation.
We do not sell personal information, and we do not share it for cross-context behavioral advertising, as those terms are used under US state privacy laws.
AI features
engageramoincludes optional AI assistance: suggested and automatic replies, conversation summaries and titles, and instant answers drawn from a workspace’s own help center. When a workspace turns these on, the relevant conversation text and help center content is sent to our AI provider (Anthropic) to generate that response, and the generated text is stored with the conversation.
- Conversation content is not used to train generalized AI models.
- Workspaces can leave AI features off entirely, or run them in draft mode so a human approves every reply before it is sent.
- A workspace may instead connect its own AI client over MCP. In that case the client acts with that workspace’s credentials and its own provider’s terms apply to anything it reads.
- AI output can be wrong. Nothing generated by these features is advice from us, and workspaces are responsible for what they send to their customers.
How long we keep it
- Account data — for as long as your account exists, then deleted or anonymized within 30 days of a deletion request.
- Workspace content — for as long as the workspace keeps it. When a workspace is deleted we remove its conversations, contacts, articles and files within 30 days, except where retention is legally required.
- Waitlist entries — until you are admitted or ask us to remove you.
- Security logs and audit records — up to 12 months.
- Backups — encrypted backups roll off within 35 days, so deleted data can persist in a backup for that long before it is overwritten.
How we protect it
- TLS in transit for every request, with HTTPS enforced.
- Passwords stored only as salted hashes; sign-in sessions are opaque tokens in HTTP-only cookies.
- Google sign-in uses the authorization code flow with PKCE and full ID-token signature verification.
- Workspace data is scoped per workspace at the query layer, so one tenant cannot read another’s.
- Rate limiting and abuse detection on authentication and widget endpoints.
- Access to production is restricted to the people who need it.
No system is perfectly secure. If we discover a breach affecting your personal data we will notify you and any required regulator without undue delay.
Your rights
Depending on where you live you may have the right to access, correct, delete, port or restrict your personal data, to object to processing based on legitimate interests, and to withdraw consent. Under US state privacy laws you may also have the right to know what we collect and to opt out of sale or sharing — we do neither.
Email privacy@engageramo.comand we will respond within 30 days. We will not discriminate against you for exercising a right. If your data sits inside a customer’s workspace, we forward the request to that customer, who decides it as controller.
If you are in the EEA or UK you may also complain to your local supervisory authority.
International transfers
engageramois hosted in the United States. If you use it from outside the United States, your data is transferred to and processed there. Where we transfer personal data out of the EEA or UK we rely on the European Commission’s Standard Contractual Clauses, plus the UK Addendum where applicable.
Children
engageramo is a business tool and is not directed to children. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us data, email privacy@engageramo.com and we will delete it.
Changes to this policy
We will update this page when our practices change, and we will move the “last updated” date at the top. If a change materially affects how we handle your personal data we will tell account holders by email at least 30 days before it takes effect. Continuing to use engageramo after that means you accept the updated policy.
Contact us
Privacy questions, requests, or anything that looks wrong:
- privacy@engageramo.com
- Gopherlume LLC, 330 2nd Ave S, Ste 200, Minneapolis, MN 55401, USA
See also our Terms of Service.