Personalisation has an uncomfortable property: the techniques that increase response rates in a test can also be the ones that make a recipient decide you are not to be trusted. Both effects are real, and they do not show up in the same metric.
After running a lot of these tests, the boundary turns out to be reasonably predictable.
The working rule
Referencing a page someone read on your site is fine — they were there, and it is obviously your data. Referencing something they did elsewhere, or an inference about their circumstances they never disclosed, reads as surveillance even when it is technically public.
What works
- Segment-level relevance — a message shaped for their industry or company size, without implying you have been watching them individually.
- Their own stated words — repeating back the problem they described in the form, which shows you read it.
- Behaviour on your own site — the pricing page they visited, the guide they downloaded.
- Timing based on their signals — following up shortly after they returned to a key page.
- Adapting the offer to the stage they are actually at, rather than pushing everyone toward a call.
What backfires
- Fake familiarity — AI-generated "personal" openers about their recent post, at a scale that is obviously automated.
- Inferences about their situation they never shared, particularly about budget, headcount or difficulty.
- Aggregated third-party data used in a way that reveals you bought a profile of them.
- Personalisation applied to a message with nothing worth reading. It highlights the mismatch rather than hiding it.
The last one deserves emphasis. Personalisation amplifies whatever the message already is. A relevant message becomes more relevant; an irrelevant one becomes intrusive as well as irrelevant.
How to test it honestly
Open rate and reply rate will tell you the message worked. They will not tell you what it cost you with people who found it unsettling and simply moved on.
- Track unsubscribes and spam complaints as primary metrics, not as footnotes.
- Read the negative replies rather than filtering them. The wording tells you which specific element crossed the line.
- Ask a handful of recent customers to read the sequence and say how it lands.
- Apply the disclosure test: if you had to explain in the message exactly how you knew each fact, would any line become awkward? Rewrite that line.
Helpful personalisation makes someone feel understood. Creepy personalisation makes them feel observed. The data is often identical; the difference is whether they can see how you got it.
A note on scale
AI makes it possible to personalise every message individually, which mostly means it is now possible to be unsettling at a scale that used to be impractical. The constraint that made old marketing tolerable was effort, and that constraint is gone.
So the judgement has to be deliberate. Decide what you will not use before you build the system, and write it down, because in the moment the incremental data point always looks harmless.
Bikash Gurung
AI Digital Marketing Consultant
I help businesses use AI, automation and modern marketing systems to grow in ways they can measure and repeat. Based in Pokhara, working worldwide.