Skip to main content
Howly connects to your HubSpot portal through read-only OAuth 2.0. It never writes to your CRM, and you can revoke access from HubSpot in a single click.

Read-only access

Howly connects with read-only OAuth 2.0 and never modifies anything in your, or a client’s, HubSpot portal.

Encrypted in transit

All data between HubSpot, Howly, and your browser is encrypted with TLS 1.2 or higher.

Revocable anytime

Revoke Howly’s access at any time from your HubSpot Connected Apps settings.

Official HubSpot app

Howly is an official HubSpot app and Technology Partner, built on HubSpot’s own OAuth and API standards.

Secure by design

Howly is built around HubSpot’s own OAuth and API standards. It connects with read-only access and never modifies your data, so you get full context on your workflows without any risk to your portal. You can see the listing on the HubSpot Marketplace.

What Howly can access

Howly requests read-only access, and only what it needs to map and audit your automations:
  • Automation — your workflows, the core of what Howly maps.
  • Contacts, companies, deals, and lists (read-only) — needed to resolve how workflows connect to each other, since enrollment and connections run through list membership and property conditions across these objects. Tickets are requested optionally, so portals without Service Hub can still connect.
Howly reads workflow and property structure to build the map. It does not write to any object, and it does not pull your CRM record contents into storage or into its AI audits.

How data is protected in transit

All data transmitted between HubSpot, Howly, and your browser is encrypted with TLS 1.2 or higher.

AI-powered audits

Howly’s AI audit sends workflow structure to Anthropic’s Claude API to generate findings: workflow names, status, trigger types, action types, and action counts, along with portal-wide summary statistics. For very large portals, only the 150 most recently modified workflows are sent in full detail; the aggregate statistics are still based on your entire portal. No contact, deal, or ticket record data is ever included, only workflow structure. Audit results are cached for 24 hours to avoid rerunning the same analysis, then discarded.

What Howly stores

The live structure of your workflows — names, triggers, actions, and connections — is cached in memory for up to two hours to keep the app responsive, then cleared. It is never written to a database table.
Some things are saved deliberately, because that’s the point of the feature:
  • Any note, purpose, or risk level you add to a workflow
  • Any planned workflow you build in the workflow planner
  • Your canvas layout and saved views
  • Your HubSpot connection token, so you’re not reconnecting constantly
  • A hashed version of any MCP access token you create — never the raw token

Sub-processors

Howly uses a small, named set of sub-processors: Supabase for authentication and database hosting, Stripe for billing, Anthropic for AI-powered audits, and Loops for account emails. Howly does not sell or share your data with anyone else.