TricorneBook a demo

Privacy Policy

Tricorne Privacy Policy

Effective date: 31 August 2026 Last updated: 31 August 2026


1. Who we are

Tricorne is operated by Tricorne Labs LLC ("Tricorne", "we", "us"), 440 Burroughs St, Suite 667, Detroit, MI 48202, USA.

For privacy questions, data requests, or to exercise any right described in this policy, contact us at privacy@tricornelabs.com.

Tricorne is a business tool sold to organisations. When you use Tricorne as a member of a workspace, the organisation that owns that workspace is the controller of the data in it and we act as a processor on its behalf. This policy describes what we do with data in both roles. If your organisation has signed a separate data processing agreement with us, that agreement governs where it conflicts with this policy.

2. What Tricorne does, in one paragraph

Tricorne connects to the systems a business already runs — email, calendar, intake forms, accounting — and builds a single working record of each client from them. It sorts incoming mail by priority, writes a daily briefing, drafts replies for a human to review, and extracts structured fields from documents. Doing this requires reading the correspondence you connect. This policy explains what that means in practice.

3. Information we collect

3.1 Information you give us

What Why we have it
Name, email address, profile picture Sign-in, via Google OAuth
Workspace and business configuration Tenant setup, tone and business context for drafting
Team member email addresses Invitations
Billing name, email, address Subscription billing (collected by Stripe — see §6)
Feedback you submit in-app Product support

3.2 Information from services you connect

You choose which services to connect, and you can disconnect any of them at any time.

Service What we access
Gmail Message content, subjects, addresses, headers, attachments, and thread structure for the connected mailbox; the ability to send mail on your behalf
Google Calendar Event titles, times, locations, and attendees (read-only)
Microsoft Outlook / Graph Mailbox content and calendar, equivalent to the above
QuickBooks Financial reports (profit & loss, balance sheet, cash flow)
Typeform Answers submitted to your intake forms
HubSpot / EZLynx Contact and applicant records you push to or pull from

3.3 Information we generate

  • AI-derived data: priority and category labels, thread summaries, daily briefings, draft replies, extracted document fields, and client overviews.
  • Operational records: audit events, credit-ledger entries, usage counts (model, token count, latency — never prompt or completion text), and error telemetry.

3.4 What we deliberately do not collect

  • Card numbers. Payment details are entered on Stripe-hosted pages. Card data never transits or rests in our systems; we store only opaque Stripe identifiers and subscription status.
  • Credit and insurance scores. These are filtered out of document extraction before anything is written, as a code-level control rather than a model instruction.
  • Full request URLs, query strings, and unlisted headers are dropped by our logging serializer, so authorization codes and webhook tokens cannot land in logs.
  • Only a five-header allowlist of SMTP headers is retained from each message.

4. Google user data — Limited Use

Tricorne's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically, and without qualification:

  1. We use Google user data only to provide and improve the user-facing features described in §2 — triage, briefings, drafting, sending, calendar context, and document extraction. These features are prominent in the interface; there is no secondary use.
  2. We do not transfer Google user data except to the subprocessors listed in §6 that are necessary to operate those features, for security purposes, or where compelled by law.
  3. We do not allow humans to read your Google user data except (a) where you have given us affirmative consent for specific messages — for example, when you ask us to investigate a support issue; (b) where necessary for security purposes, such as investigating abuse; (c) where required by law; or (d) where the data has been aggregated and de-identified for internal operations such as capacity planning. Our internal operational metrics are content-free by construction — they carry model names and token counts, never message text.
  4. We do not sell Google user data, and we do not transfer it to advertising platforms, data brokers, or credit-assessment services. We do not use it for personalised advertising. We do not use it to train generalised AI or machine-learning models — see §5.

Our use of the following restricted and sensitive Google scopes:

Scope Why we need it
gmail.readonly Read the messages, threads, and attachments Tricorne triages, summarises, and drafts replies to
gmail.send Send the replies you approve, and autonomous replies only where you have explicitly enabled that (see §5)
calendar.readonly Show the week's commitments alongside the correspondence they relate to
openid, email, profile Sign you in and identify your account

We request the narrowest scopes that support these features. We do not request permission to modify your mailbox, and Tricorne never deletes, archives, relabels, or otherwise alters the messages in it — the only thing it writes to your mailbox is a reply you asked it to send.

5. How we use information, including AI

We use the information above to operate the service: to sort and prioritise correspondence, to generate briefings and drafts, to extract fields from documents you upload, to assemble client records, to bill you, to support you, and to keep the service secure and reliable.

AI processing. Tricorne sends message content, document contents, and business context to Anthropic to generate classifications, summaries, drafts, and extractions. Under Anthropic's commercial API terms, inputs and outputs are not used to train their models. We do not train any model on your data, and we do not use your data to build features for other customers.

AI output is a draft, not an action. Replies Tricorne writes are held for a human to review and send. The one exception is autonomous sending, which is off by default and must be switched on deliberately per workspace. Where it is on, every autonomous send passes confidence and sentiment checks and a daily cap, is delayed by a configurable window during which any member can stop it, and writes an audit record when it is armed, stopped, or sent.

We do not use your correspondence for advertising, profiling, or sale. We have no advertising business.

Legal bases (UK/EU)

Where GDPR applies and we act as a controller, we rely on: contract (providing the service you signed up for), legitimate interests (securing the service, preventing abuse, improving features — balanced against your rights), consent (for optional integrations you choose to connect), and legal obligation (tax and accounting records).

6. Who we share information with

We do not sell personal information. We share it with the subprocessors below, each of which processes it only to deliver the function named.

Processor Function What it touches
Railway Hosting: application compute, Postgres, Redis All database and queue data. SOC 2 Type II and SOC 3 certified; GDPR DPA available
Amazon Web Services (S3) Object storage Attachment and document bytes, encrypted at rest
Anthropic AI model calls Message content, document contents, and business context, per call. Not used for model training
Google Sign-in; Gmail and Calendar APIs Mailbox and calendar content at ingestion
Microsoft Outlook / Graph connector Mailbox and calendar content at ingestion
Intuit QuickBooks connector Financial reports
Typeform Intake forms Answers submitted to your forms
HubSpot CRM connector Client contact records you sync
EZLynx Insurance applicant connector Applicant records you push
Stripe Billing and payments Payer name, email, address, and card data, entered on Stripe-hosted pages. PCI DSS Level 1
Resend Transactional email Invitee email addresses
Sentry Error telemetry Error events with workspace and user identifiers
Discord In-app feedback routing Feedback text you submit
Cloudflare DNS and static hosting Marketing site delivery. Application traffic records are DNS-only and not proxied

We may also disclose information where required by law, to enforce our terms, to protect the rights and safety of users or the public, or in connection with a merger or acquisition — in which case we will give notice before your information becomes subject to a different privacy policy.

International transfers. Our infrastructure and several subprocessors are located in the United States. Where we transfer personal data out of the UK or EEA, we rely on the European Commission's Standard Contractual Clauses, together with the UK International Data Transfer Addendum where the transfer is from the UK.

7. How we protect information

A fuller technical account is available on request. In summary:

  • Tenant isolation is enforced in the database itself through PostgreSQL row-level security, forced on every workspace-scoped table, with the application's database role holding no bypass. Isolation is verified by automated tests and periodic live probes.
  • Correspondence content is encrypted at rest with AES-256-GCM under keys we hold, in addition to the platform's own encryption. This covers email bodies, AI drafts, client intake answers, client notes, phone numbers, and team notes. Each encrypted value is cryptographically bound to the workspace and row it belongs to, so a value copied elsewhere cannot be decrypted.
  • OAuth tokens and integration credentials are encrypted at rest under the same scheme.
  • Files are stored in Amazon S3 with server-side AES-256 encryption verified on every object, all public access blocked, and non-TLS requests denied. Access from a browser is only ever through signed URLs that expire in five minutes.
  • All traffic is encrypted in transit. Public traffic terminates TLS with HSTS; internal service-to-database traffic rides an encrypted private network with no public endpoints.
  • Sessions are held server-side with httpOnly, Secure cookie references — no tokens in browser storage.
  • Bearer tokens and invitation tokens are stored as hashes only, so a database reader holds nothing redeemable.

No system is perfectly secure, and we do not claim otherwise. If we become aware of a breach affecting your personal data, we will notify you and any applicable regulator as required by law.

8. How long we keep information

We keep information for as long as your workspace is active and you have the relevant service connected.

  • Files and documents are subject to an automatically enforced maximum lifetime of seven years, after which they are deleted from object storage.
  • Correspondence and derived records are retained while the workspace is active.
  • Content-free operational records — audit events, usage counts, billing history — are kept for as long as we need them for security, accounting, and legal purposes.

If you disconnect a mailbox or delete your workspace, contact us at privacy@tricornelabs.com and we will delete the associated content.

9. Your rights

Depending on where you live, you may have the right to access, correct, delete, port, or restrict processing of your personal information, to object to processing, and to withdraw consent. You will never be discriminated against for exercising these rights.

If your data is in a workspace owned by your employer or client, we will generally direct your request to them as the controller, and support them in answering it.

To make a request, contact privacy@tricornelabs.com. We will respond within the period required by applicable law. If you are in the UK or EEA you also have the right to complain to your supervisory authority; if you are in California, you may designate an authorised agent to act for you.

Revoking Google access. You can revoke Tricorne's access to your Google account at any time at myaccount.google.com/permissions, independently of any request to us.

10. Children

Tricorne is a business tool and is not directed to children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us information, contact us and we will delete it.

11. Changes to this policy

We will post any changes here and update the "last updated" date. If a change materially reduces your rights or materially expands how we use your information, we will give notice in the application or by email before it takes effect.

12. Contact

Tricorne Labs LLC 440 Burroughs St, Suite 667 Detroit, MI 48202, USA

Email: privacy@tricornelabs.com