Typrio Privacy Policy
Last updated: August 13, 2026
This Privacy Policy describes how Typrio (“Company”, “we”, “us”, or “our”) collects, uses, processes, and protects personal data when you use our services, including the Typrio mobile application, web dashboard, and related services (collectively, the “Services”).
By using Typrio, you agree to the practices described in this policy. If you do not agree, please discontinue use of the Services.
1. Scope of Services
Typrio provides:
- A mobile AI assistant application
- A web assistant for operating connected services
- Infrastructure that executes user-requested actions and automations
2. Data Controller and Processor Roles
Depending on the context:
Typrio acts as a Data Controller for:
- Account data
- Billing data
- Platform usage analytics
Typrio acts as a Data Processor for:
- Connected-service task and automation execution
- User-defined integrations
- External API interactions
Users remain responsible for the data they process through connected-service tasks and automations, including ensuring they have a lawful basis for doing so.
3. Information We Collect
3.1 Account Information
- Email address
- Authentication credentials (OAuth tokens, session tokens)
- Profile metadata
3.2 Billing Information
- Subscription status
- Transaction identifiers
- Payment provider references
Note: Payment processing is handled by third-party providers (e.g., Stripe). Typrio does not store full payment card details. Stripe's privacy policy is available athttps://stripe.com/privacy.
3.3 Usage Data
- Feature usage patterns
- Execution counts
- System diagnostics (non-sensitive)
3.4 Assistant and Automation Data
- Task and action configurations
- Automation definitions
- Metadata associated with actions
3.5 Credentials
- API keys, tokens, and secrets provided by users
- Stored encrypted at rest; never logged in plain text
3.6 Cookies and Tracking Technologies
The marketing site (typrio.com) and the dashboard (app.typrio.com) use different storage, so they are listed separately:
| Where | Storage | Purpose | Consent |
|---|---|---|---|
| Marketing site | Consent record (browser storage) | Remembers your cookie choice | Strictly necessary |
| Marketing site | Analytics script | Aggregate page statistics via a self-hosted, cookie-free tool | Loads only if you accept via the banner |
| Both | Session and security cookies | Sign-in and request protection | Strictly necessary |
| Dashboard | Device id cookie (2 years) | Fraud prevention and payment dispute evidence | Strictly necessary |
| Dashboard | Interface preferences | Theme and layout choices you make | Set when you use the feature |
| Dashboard | Push subscription id | Delivers notifications you turned on | Set when you enable push |
| Dashboard | Google sign-in script | Lets you sign in with Google; Google may set its own cookies | Loads as part of sign-in |
A consent banner appears on your first visit to the marketing site. To change your choice later, clear the Typrio cookie-preferences entry in your browser storage. The dashboard shows no banner because it runs no analytics and sets only the storage needed to operate.
We do not use advertising cookies or third-party analytics and tracking vendors.
4. Legal Basis for Processing (GDPR)
We process personal data under the following legal bases as defined in Article 6 of the GDPR:
| Processing activity | Legal basis |
|---|---|
| Providing and operating the Services | Contractual necessity (Art. 6(1)(b)) |
| Billing and fraud prevention | Contractual necessity / Legal obligation (Art. 6(1)(b)(c)) |
| Service improvement and security monitoring | Legitimate interests (Art. 6(1)(f)) |
| Optional AI integrations and analytics | Consent (Art. 6(1)(a)) |
| Compliance with legal obligations | Legal obligation (Art. 6(1)(c)) |
Where processing is based on consent, you may withdraw consent at any time without affecting the lawfulness of processing carried out prior to withdrawal.
5. Assistant Memory and Chat History
The assistant keeps a memory of things worth remembering between chats: preferences, profile details, goals, open tasks, facts, summaries, and rules you have set. Each item is a short note saved during a chat, kept with your account. Memory is on by default.
Chat transcripts are also stored with your account, including the results of actions the assistant ran for you. Those results can contain content from your connected services, such as email text or calendar events. To answer a new question, the assistant may reuse saved memory items and short excerpts from your other chats.
Your controls:
- Forget removes an item from the assistant's recall and keeps a suppression record so the fact is not relearned.
- Erase does the same and also replaces matching text in your stored chat history with a redaction marker.
- Deleting a chat session deletes its messages. Closing your account deletes memory and history.
Memory items and chat history do not expire on their own; they stay until you remove them or your account closes. In-product erase replaces exact text matches. For complete deletion of your data, use the rights described in Section 15.
6. Connected-Service Tasks and Automations
Users may ask Typrio to execute actions and configure automations on their behalf.
When a task or automation is executed:
- Requests may be sent to external services as configured by the user
- Data is processed strictly to fulfill user instructions
- Typrio does not independently use, analyse, or monetise this data
- Users are responsible for ensuring they have appropriate rights and consents for any data processed through their tasks and automations
7. Third-Party Services and Subprocessors
We use a small set of third-party processors to run the Services:
- Payments: Stripe processes card payments (stripe.com/privacy); a cryptocurrency payment processor handles crypto checkouts. We never store full card details.
- AI model providers: we send AI requests to third-party model providers. The providers may change as we balance quality and cost, so this policy names none; the current list is available on request. What they receive is described in Section 8.
- Error monitoring: an error monitoring service receives failure reports (see Section 11).
- Hosting: cloud infrastructure providers run our servers.
Separately, the external services you connect (for example your email or calendar provider) receive requests when the assistant acts on your instructions. Their own privacy policies apply to what they do with those requests.
We maintain a list of infrastructure subprocessors (e.g., cloud hosting providers) used in delivering the Services. You may request the current subprocessor list by contacting[email protected].
We will notify users of any material changes to our subprocessors with at least 10 days' notice before such changes take effect, providing an opportunity to object.
8. AI-Assisted Features
To interpret and carry out your requests, we send data to the active AI model provider. Depending on the request, this can include:
- Your message and recent messages from the same chat
- Content fetched from your connected services while carrying out the request, such as email text, calendar events, or documents
- Saved memory items and short excerpts from your other chats (see Section 5)
- Your regional preferences, such as language, currency, and timezone
Credential-shaped values are stripped from text before sending, and the assistant is built to keep secrets in workspace credentials rather than in chat. The home screen's suggestions feature sends the names and labels of your connected services and skills, not their contents.
We do not train AI models on your data. Model providers process your data to generate responses and may cache repeated request prefixes to speed up later responses. Providers may change over time; the current list is available on request (Section 7), and providers may be located outside the EEA (Section 13).
Google user data
Typrio's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
- We access Google data (such as Gmail, Calendar, Docs, Sheets, and Drive content) only to provide features you ask for.
- Google data is shared with AI model providers only as needed to carry out your request, and is never used to train AI models.
- We do not use Google data for advertising, and we do not sell it.
- Humans do not read your Google data except with your consent, for security or abuse investigation, or where the law requires it.
9. Data Security
We implement appropriate technical and organisational safeguards, including:
- Encryption of data at rest and in transit (TLS 1.2+)
- Role-based access controls and least-privilege principles
- Multi-tenant isolation to prevent cross-user data access
- Secure credential handling (see Section 10)
- Regular security reviews
No system can guarantee absolute security. In the event of a data breach affecting your rights and freedoms, we will notify you and the relevant supervisory authority as required by applicable law.
10. Credentials Handling
- User-provided credentials (API keys, tokens, secrets) are encrypted at rest using industry-standard encryption
- Credentials are never logged in plain text
- Credentials are used exclusively during execution of user-defined actions
- Credentials are never shared with third parties beyond what is necessary to execute user-defined integrations
Users are responsible for revoking and rotating credentials if they believe they have been compromised.
11. Logging and Monitoring
We keep operational records to run and debug the Services, including:
- Execution status, timing, and performance metadata
- Request and result payloads of executed actions, with credential fields masked
- System-level diagnostics
Credential fields in structured payloads (keys, tokens, passwords, authorization headers) are masked before storage. Action results themselves, which can include content from your connected services, are stored with your account's execution history so you can review what ran.
When something fails, an error report goes to our error monitoring service. A report can include a short excerpt of the failing provider's response.
Webhook and audit logs are deleted after 30 days. Execution history is kept until you delete it or your account closes.
12. Data Retention
We retain personal data only as long as necessary for the stated purpose:
| Data type | Retention period |
|---|---|
| Account data | For the duration of your account, plus 30 days after deletion |
| Billing records | 7 years (legal/tax obligation) |
| Usage analytics | 12 months, then aggregated/anonymised |
| Webhook and audit logs | 30 days |
| Execution history and chat transcripts | Until deleted by user or account closure |
| Assistant memory | Until forgotten or erased by user, or account closure |
| Assistant and Automation configurations | Until deleted by user or account closure |
| Credentials | Until deleted by user or account closure |
You may request early deletion of your data at any time (see Section 15).
13. International Data Transfers
Typrio may process personal data in jurisdictions outside your country of residence, including countries that may not offer the same level of data protection as your home country.
Where such transfers occur, we implement appropriate safeguards such as:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Adequacy decisions where applicable
Our AI model providers may be located outside the EEA, including in the United States and in other jurisdictions without an EU adequacy decision. The current provider list is available on request (see Section 7).
You may request information about the specific safeguards applicable to a transfer by contacting[email protected].
14. Data Processing Agreements (DPA)
Where Typrio acts as a Data Processor on behalf of business users (e.g., when executing automations that process end-user personal data), a Data Processing Agreement is available upon request. Please contact[email protected] to obtain a DPA.
15. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
| Right | Description |
|---|---|
| Access | Request a copy of the personal data we hold about you |
| Rectification | Request correction of inaccurate or incomplete data |
| Erasure | Request deletion of your data (“right to be forgotten”) |
| Restriction | Request that we limit how we process your data |
| Portability | Receive your data in a structured, machine-readable format |
| Objection | Object to processing based on legitimate interests |
| Withdraw consent | Withdraw consent at any time where processing is consent-based |
To exercise any of these rights, contact us at[email protected]. We will respond within 30 days. We may need to verify your identity before processing a request.
Supervisory Authority
If you are located in the European Economic Area, you have the right to lodge a complaint with your local data protection authority (DPA). A list of EU data protection authorities is available athttps://edpb.europa.eu/about-edpb/about-edpb/members_en.
If you are based in Portugal, the relevant authority is theComissão Nacional de Proteção de Dados (CNPD):https://www.cnpd.pt
16. Data Protection Officer
Based on our current scale and the nature of data we process, we are not required to appoint a Data Protection Officer under Article 37 of the GDPR. Privacy-related enquiries can be directed to[email protected].
17. Children's Privacy
The Services are not directed at or intended for use by children under the age of 13 (or the applicable minimum age in your jurisdiction, which may be higher). We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a minor, please contact us immediately at [email protected] and we will take steps to delete it.
18. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will:
- Notify you by email (to the address associated with your account) at least 14 daysbefore the changes take effect
- Display a prominent notice within the Services
- Update the “Last updated” date at the top of this policy
Your continued use of the Services after the effective date of the revised policy constitutes acceptance of the changes. If you do not agree to the updated policy, you should discontinue use and may request deletion of your account.
19. Contact
For privacy-related enquiries, requests, or complaints:
Email: [email protected]
We aim to respond to all requests within 30 days.
Summary
Typrio is designed to:
- Minimise data collection and retain data only as long as necessary
- Give users meaningful control and transparency over their data
- Enable powerful integrations responsibly, with clear subprocessor disclosure
- Comply with applicable data protection laws, including the GDPR