Privacy Policy

Last updated: January 5, 2026

1. Introduction

Trill Sapp LLC, doing business as TRISP Studio ("we," "us," or "our"), operates Inquifly (the "Service"). This Privacy Policy explains how we collect, use, and protect your information when you use our Service.

2. Information We Collect

We collect the following types of information:

  • Account Information: Email address, name, and authentication credentials via Supabase.
  • Business Information: Business name, website, Instagram handle, and address that you provide.
  • Calendar Data: Read-only access to your Google Calendar to check availability (if you connect it).
  • Email Content: Inbound inquiry emails forwarded to your Inquifly address for AI processing.
  • Payment Information: Billing details processed securely by Stripe (we do not store card numbers).
  • Usage Data: How you interact with the Service, including inquiry counts and feature usage.

3. How We Use Your Information

  • To provide the Service, including AI-generated email draft responses.
  • To check your calendar availability when generating responses.
  • To process payments and manage your subscription.
  • To send you service-related notifications.
  • To improve and optimize the Service.

4. Third-Party Services

We use the following third-party services to operate Inquifly:

  • Supabase: Authentication and database hosting.
  • Stripe: Payment processing and subscription management.
  • Postmark: Inbound email processing.
  • Google Gemini: AI processing of email content to generate draft replies.
  • Google Calendar API: Read-only calendar access for availability checking.
  • Vercel: Application hosting.

Each service has its own privacy policy governing their use of data.

5. Google User Data and Limited Use Requirements

Inquifly uses the Google Calendar API to provide calendar availability checking functionality. This section describes how we access, use, store, and share Google user data in compliance with Google's API Services User Data Policy and Limited Use requirements.

5.1. Google Data We Access

When you connect your Google Calendar, we request read-only access to your calendar events (https://www.googleapis.com/auth/calendar.readonly scope). We do not request access to your email, contacts, or any other Google data.

5.2. How We Use Google Calendar Data

We use your Google Calendar data solely to:

  • Check your calendar availability when processing inquiry emails that contain a preferred date
  • Display availability status in AI-generated draft email responses
  • Provide this availability information to you within the Inquifly interface

Calendar data is accessed in real-time only when processing an inquiry email. We do not store your calendar events, event details, or any calendar content in our database. We only store encrypted OAuth tokens (refresh token and access token) necessary to authenticate API requests.

5.3. Data Storage

We store only the OAuth authentication tokens (refresh token and access token) required to access the Google Calendar API. These tokens are encrypted and stored securely in our database. We do not store, cache, or retain any calendar event data, event details, or calendar content.

5.4. Data Sharing and Transfers

We do not share, sell, or transfer your Google Calendar data to any third parties. Calendar data is used exclusively within Inquifly to provide the availability checking feature. The only exception is when required by law or for security purposes (e.g., investigating abuse).

5.5. Compliance with Google's Limited Use Requirements

Our use of Google Calendar data is limited to providing user-facing features that are prominent in the Inquifly interface. Specifically:

  • No Advertising: We do not use Google Calendar data for advertising, retargeting, or interest-based advertising purposes.
  • No Data Brokering: We do not transfer, sell, or share your calendar data with data brokers, advertising platforms, or information resellers.
  • No Credit/Lending: We do not use calendar data to determine credit-worthiness or for lending purposes.
  • No Human Reading: Our employees do not read your calendar data. Access is programmatic and automated for availability checking only.
  • No AI Training: We do not use your calendar data to train AI models or for any purpose other than providing the availability checking feature.

5.6. User Control

You can disconnect your Google Calendar integration at any time through your account settings. Upon disconnection, we immediately revoke access and delete stored OAuth tokens. Since we do not store calendar event data, disconnecting immediately stops all access to your calendar.

5.7. Google API Services User Data Policy

Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

6. Data Retention

We retain your data for as long as your account is active or as needed to provide services. You may request deletion of your data at any time by contacting us. Upon account deletion, we will remove your personal data within 30 days, except where required by law.

7. Data Security

We implement industry-standard security measures to protect your data, including encryption in transit (HTTPS) and at rest. However, no method of transmission over the Internet is 100% secure.

8. Your Rights

You have the right to:

  • Access the personal data we hold about you.
  • Request correction of inaccurate data.
  • Request deletion of your data.
  • Disconnect third-party integrations (like Google Calendar) at any time.

9. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last updated" date.

10. Contact Us

If you have any questions about this Privacy Policy, please contact us at: sapp@trispstudio.com