Privacy Policy
Last updated: August 2026
Allopy ("we," "us," "our") provides software that reads incoming business communications, judges them against rules a business sets, and executes actions on connected systems (such as Stripe and Google Calendar) on that business's behalf. This policy explains what data we collect, how we use it, and the choices you have.
1. What We Collect
Depending on how you use Allopy, we collect:
- Account information — name, email, company details you provide when signing up.
- Gmail data — with your explicit authorization via Google OAuth, we read incoming email content and metadata necessary to classify and act on business requests, and send replies on your behalf when you've enabled that capability.
- Stripe data — with your explicit authorization, we read payment, subscription, and customer records necessary to process refunds, cancellations, and billing-related requests under the rules you configure.
- Calendar data — with your explicit authorization, we read and create calendar events necessary to handle scheduling requests.
- Usage data — how you interact with the Allopy dashboard, for the purpose of improving the product.
2. Google API Services User Data — Limited Use Disclosure
Allopy's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- Data obtained through Gmail or Google Calendar APIs is used solely to provide and improve the specific business-operations features you have enabled — classifying incoming requests, drafting or sending responses, and managing calendar events under your configured rules.
- We do not use Google user data to serve advertisements, and we do not sell Google user data to any third party.
- We do not transfer Google user data to third parties except: (a) with your explicit direction, (b) to our infrastructure sub-processors strictly as necessary to operate the service (see Section 5), or (c) as required by law.
- Human access to Google user data is limited to circumstances necessary for security purposes, to comply with law, with your consent, or for the operation and maintenance of the service, and is logged.
3. How We Use Data
- To classify incoming requests and determine the correct action under your configured rules.
- To execute actions you've authorized — issuing refunds, processing cancellations, booking or rescheduling meetings, replying to requests.
- To maintain an audit trail of decisions and actions taken, visible to you in your dashboard.
- To improve the accuracy and safety of our classification systems, using de-identified or aggregated data wherever possible.
- To communicate with you about your account, product updates, and support.
4. What We Do Not Do
- We do not sell your data or your customers' data to any third party.
- We do not use your Gmail, Calendar, or Stripe data to train models for use by other customers.
- We do not take financial or communication actions outside the rules and limits you configure.
5. Sub-Processors
We use a limited set of infrastructure providers to operate Allopy, each bound by their own data protection obligations: Supabase (database and storage), OpenAI (request classification), Resend (transactional email delivery), Vercel (application hosting), and Stripe (payment processing, for accounts you explicitly connect). We do not add new categories of sub-processors without updating this policy.
6. Data Retention
We retain account and audit-trail data for as long as your account is active, and for a reasonable period afterward to comply with legal obligations and resolve disputes. You may request deletion of your data at any time (see Section 8).
7. Security
We use industry-standard measures to protect data in transit and at rest, including encrypted connections, access-controlled infrastructure, and scoped API credentials. No system is perfectly secure; we will notify affected users promptly in the event of a data breach affecting their information, as required by law.
8. Your Rights and Choices
- You may revoke Allopy's access to your Google or Stripe account at any time via your Google Account permissions or Stripe dashboard.
- You may request a copy of, correction to, or deletion of your data by contacting us at the address below.
- If you are located in the EU/UK or California, you have additional rights under GDPR or CCPA respectively, including the right to access, delete, or restrict processing of your personal data.
9. Children's Privacy
Allopy is a business tool not directed at or intended for use by children. We do not knowingly collect personal information from anyone under 16.
10. Changes to This Policy
We may update this policy as Allopy evolves. Material changes will be communicated to active users by email or in-product notice before they take effect.
11. Contact
Questions about this policy or your data can be sent to privacy@allopy.com.