Tricorne Privacy Policy
Effective date: 31 August 2026 Last updated: 31 August 2026
1. Who we are
Tricorne is operated by Tricorne Labs LLC ("Tricorne", "we", "us"), 440 Burroughs St, Suite 667, Detroit, MI 48202, USA.
For privacy questions, data requests, or to exercise any right described in this policy, contact us at privacy@tricornelabs.com.
Tricorne is a business tool sold to organisations. When you use Tricorne as a member of a workspace, the organisation that owns that workspace is the controller of the data in it and we act as a processor on its behalf. This policy describes what we do with data in both roles. If your organisation has signed a separate data processing agreement with us, that agreement governs where it conflicts with this policy.
2. What Tricorne does, in one paragraph
Tricorne connects to the systems a business already runs — email, calendar, intake forms, accounting — and builds a single working record of each client from them. It sorts incoming mail by priority, writes a daily briefing, drafts replies for a human to review, and extracts structured fields from documents. Doing this requires reading the correspondence you connect. This policy explains what that means in practice.
3. Information we collect
3.1 Information you give us
| What | Why we have it |
|---|---|
| Name, email address, profile picture | Sign-in, via Google OAuth |
| Workspace and business configuration | Tenant setup, tone and business context for drafting |
| Team member email addresses | Invitations |
| Billing name, email, address | Subscription billing (collected by Stripe — see §6) |
| Feedback you submit in-app | Product support |
3.2 Information from services you connect
You choose which services to connect, and you can disconnect any of them at any time.
| Service | What we access |
|---|---|
| Gmail | Message content, subjects, addresses, headers, attachments, and thread structure for the connected mailbox; the ability to send mail on your behalf |
| Google Calendar | Event titles, times, locations, and attendees (read-only) |
| Microsoft Outlook / Graph | Mailbox content and calendar, equivalent to the above |
| QuickBooks | Financial reports (profit & loss, balance sheet, cash flow) |
| Typeform | Answers submitted to your intake forms |
| HubSpot / EZLynx | Contact and applicant records you push to or pull from |
3.3 Information we generate
- AI-derived data: priority and category labels, thread summaries, daily briefings, draft replies, extracted document fields, and client overviews.
- Operational records: audit events, credit-ledger entries, usage counts (model, token count, latency — never prompt or completion text), and error telemetry.
3.4 What we deliberately do not collect
- Card numbers. Payment details are entered on Stripe-hosted pages. Card data never transits or rests in our systems; we store only opaque Stripe identifiers and subscription status.
- Credit and insurance scores. These are filtered out of document extraction before anything is written, as a code-level control rather than a model instruction.
- Full request URLs, query strings, and unlisted headers are dropped by our logging serializer, so authorization codes and webhook tokens cannot land in logs.
- Only a five-header allowlist of SMTP headers is retained from each message.
4. Google user data — Limited Use
Tricorne's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, and without qualification:
- We use Google user data only to provide and improve the user-facing features described in §2 — triage, briefings, drafting, sending, calendar context, and document extraction. These features are prominent in the interface; there is no secondary use.
- We do not transfer Google user data except to the subprocessors listed in §6 that are necessary to operate those features, for security purposes, or where compelled by law.
- We do not allow humans to read your Google user data except (a) where you have given us affirmative consent for specific messages — for example, when you ask us to investigate a support issue; (b) where necessary for security purposes, such as investigating abuse; (c) where required by law; or (d) where the data has been aggregated and de-identified for internal operations such as capacity planning. Our internal operational metrics are content-free by construction — they carry model names and token counts, never message text.
- We do not sell Google user data, and we do not transfer it to advertising platforms, data brokers, or credit-assessment services. We do not use it for personalised advertising. We do not use it to train generalised AI or machine-learning models — see §5.
Our use of the following restricted and sensitive Google scopes:
| Scope | Why we need it |
|---|---|
gmail.readonly |
Read the messages, threads, and attachments Tricorne triages, summarises, and drafts replies to |
gmail.send |
Send the replies you approve, and autonomous replies only where you have explicitly enabled that (see §5) |
calendar.readonly |
Show the week's commitments alongside the correspondence they relate to |
openid, email, profile |
Sign you in and identify your account |
We request the narrowest scopes that support these features. We do not request permission to modify your mailbox, and Tricorne never deletes, archives, relabels, or otherwise alters the messages in it — the only thing it writes to your mailbox is a reply you asked it to send.
5. How we use information, including AI
We use the information above to operate the service: to sort and prioritise correspondence, to generate briefings and drafts, to extract fields from documents you upload, to assemble client records, to bill you, to support you, and to keep the service secure and reliable.
AI processing. Tricorne sends message content, document contents, and business context to Anthropic to generate classifications, summaries, drafts, and extractions. Under Anthropic's commercial API terms, inputs and outputs are not used to train their models. We do not train any model on your data, and we do not use your data to build features for other customers.
AI output is a draft, not an action. Replies Tricorne writes are held for a human to review and send. The one exception is autonomous sending, which is off by default and must be switched on deliberately per workspace. Where it is on, every autonomous send passes confidence and sentiment checks and a daily cap, is delayed by a configurable window during which any member can stop it, and writes an audit record when it is armed, stopped, or sent.
We do not use your correspondence for advertising, profiling, or sale. We have no advertising business.
Legal bases (UK/EU)
Where GDPR applies and we act as a controller, we rely on: contract (providing the service you signed up for), legitimate interests (securing the service, preventing abuse, improving features — balanced against your rights), consent (for optional integrations you choose to connect), and legal obligation (tax and accounting records).
6. Who we share information with
We do not sell personal information. We share it with the subprocessors below, each of which processes it only to deliver the function named.
| Processor | Function | What it touches |
|---|---|---|
| Railway | Hosting: application compute, Postgres, Redis | All database and queue data. SOC 2 Type II and SOC 3 certified; GDPR DPA available |
| Amazon Web Services (S3) | Object storage | Attachment and document bytes, encrypted at rest |
| Anthropic | AI model calls | Message content, document contents, and business context, per call. Not used for model training |
| Sign-in; Gmail and Calendar APIs | Mailbox and calendar content at ingestion | |
| Microsoft | Outlook / Graph connector | Mailbox and calendar content at ingestion |
| Intuit | QuickBooks connector | Financial reports |
| Typeform | Intake forms | Answers submitted to your forms |
| HubSpot | CRM connector | Client contact records you sync |
| EZLynx | Insurance applicant connector | Applicant records you push |
| Stripe | Billing and payments | Payer name, email, address, and card data, entered on Stripe-hosted pages. PCI DSS Level 1 |
| Resend | Transactional email | Invitee email addresses |
| Sentry | Error telemetry | Error events with workspace and user identifiers |
| Discord | In-app feedback routing | Feedback text you submit |
| Cloudflare | DNS and static hosting | Marketing site delivery. Application traffic records are DNS-only and not proxied |
We may also disclose information where required by law, to enforce our terms, to protect the rights and safety of users or the public, or in connection with a merger or acquisition — in which case we will give notice before your information becomes subject to a different privacy policy.
International transfers. Our infrastructure and several subprocessors are located in the United States. Where we transfer personal data out of the UK or EEA, we rely on the European Commission's Standard Contractual Clauses, together with the UK International Data Transfer Addendum where the transfer is from the UK.
7. How we protect information
A fuller technical account is available on request. In summary:
- Tenant isolation is enforced in the database itself through PostgreSQL row-level security, forced on every workspace-scoped table, with the application's database role holding no bypass. Isolation is verified by automated tests and periodic live probes.
- Correspondence content is encrypted at rest with AES-256-GCM under keys we hold, in addition to the platform's own encryption. This covers email bodies, AI drafts, client intake answers, client notes, phone numbers, and team notes. Each encrypted value is cryptographically bound to the workspace and row it belongs to, so a value copied elsewhere cannot be decrypted.
- OAuth tokens and integration credentials are encrypted at rest under the same scheme.
- Files are stored in Amazon S3 with server-side AES-256 encryption verified on every object, all public access blocked, and non-TLS requests denied. Access from a browser is only ever through signed URLs that expire in five minutes.
- All traffic is encrypted in transit. Public traffic terminates TLS with HSTS; internal service-to-database traffic rides an encrypted private network with no public endpoints.
- Sessions are held server-side with
httpOnly,Securecookie references — no tokens in browser storage. - Bearer tokens and invitation tokens are stored as hashes only, so a database reader holds nothing redeemable.
No system is perfectly secure, and we do not claim otherwise. If we become aware of a breach affecting your personal data, we will notify you and any applicable regulator as required by law.
8. How long we keep information
We keep information for as long as your workspace is active and you have the relevant service connected.
- Files and documents are subject to an automatically enforced maximum lifetime of seven years, after which they are deleted from object storage.
- Correspondence and derived records are retained while the workspace is active.
- Content-free operational records — audit events, usage counts, billing history — are kept for as long as we need them for security, accounting, and legal purposes.
If you disconnect a mailbox or delete your workspace, contact us at privacy@tricornelabs.com and we will delete the associated content.
9. Your rights
Depending on where you live, you may have the right to access, correct, delete, port, or restrict processing of your personal information, to object to processing, and to withdraw consent. You will never be discriminated against for exercising these rights.
If your data is in a workspace owned by your employer or client, we will generally direct your request to them as the controller, and support them in answering it.
To make a request, contact privacy@tricornelabs.com. We will respond within the period required by applicable law. If you are in the UK or EEA you also have the right to complain to your supervisory authority; if you are in California, you may designate an authorised agent to act for you.
Revoking Google access. You can revoke Tricorne's access to your Google account at any time at myaccount.google.com/permissions, independently of any request to us.
10. Children
Tricorne is a business tool and is not directed to children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us information, contact us and we will delete it.
11. Changes to this policy
We will post any changes here and update the "last updated" date. If a change materially reduces your rights or materially expands how we use your information, we will give notice in the application or by email before it takes effect.
12. Contact
Tricorne Labs LLC 440 Burroughs St, Suite 667 Detroit, MI 48202, USA
Email: privacy@tricornelabs.com