Privacy Policy
Ultimo aggiornamento: 17 agosto 2026
Troupia is a workspace where an AI assistant does real work on your behalf across the tools your business already uses. This policy explains what we collect, why, who processes it, and how you get it removed.
1. Who we are
Troupia ("Troupia", "we", "us") provides an AI workspace at www.troupia.com. This policy covers that service and every connector you choose to authorize through it.
If anything here is unclear, or you want a copy of your data or its deletion, write to hello@troupia.com. A person answers.
2. Information we collect
We collect three kinds of information, and no more than we need to run the service:
- Account information — your name, email address, workspace name, and authentication details. If you sign in with Google, we receive your email address, name and profile picture from Google for the sole purpose of creating and identifying your account.
- Content you put into the workspace — messages you send to the assistant, files you upload, automations you build, and the settings you configure.
- Data from services you connect — when you authorize a connector (for example Google Calendar), we access data from that service on your behalf, strictly within the permissions you granted. See section 3.
- Technical and usage information — IP address, browser type, pages viewed and feature usage, collected so we can keep the service working and understand which parts are used.
3. Google user data
This section applies when you connect a Google service to Troupia. It is deliberately specific.
What we request. We ask only for the narrowest permissions that let the assistant do the job you asked for. For Google Calendar that means the ability to read, create and update calendar events, to check free/busy availability, and to list which calendars you have — nothing that would let us change your calendar sharing settings or delete a calendar.
What we do with it. Google data is used exclusively to deliver the features you requested inside your workspace — showing your schedule, finding an open slot, booking or updating a meeting, and reacting to changes. Nothing else.
What we never do. We do not sell Google user data. We do not use it for advertising. We do not use it to train generalized AI or machine-learning models. We do not let humans read it, except with your explicit permission, for security purposes, to comply with applicable law, or where the data is aggregated and anonymized.
How it is stored. We do not keep a copy of your calendar. We hold the OAuth access and refresh tokens that let us act on your behalf; those are stored encrypted at rest on infrastructure we operate, and are used only to make requests to Google.
How you revoke it. Disconnect the connector inside Troupia and we delete the stored tokens. You can also revoke access at any time from your Google Account permissions page, which takes effect immediately.
Troupia's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements: https://developers.google.com/terms/api-services-user-data-policy
4. How we use information
We use the information above to:
- Provide the service — run the assistant, execute the automations you build, and act on the connectors you authorized.
- Keep accounts secure — authenticate you, detect abuse, and investigate security incidents.
- Communicate with you — service notices, security alerts, and support replies.
- Improve the product — understand which features are used and where the service fails, using aggregated and usage-level data.
- Meet legal obligations.
5. AI processing
The assistant is powered by large language models. To answer you, the relevant part of your conversation and the context it needs are sent to established third-party model providers through a routing gateway.
These providers process the content only to generate a response, under contracts that bind them to that purpose. We do not permit your content to be used to train their models.
We record traces of assistant runs (prompts, responses, timings, errors) so we can debug failures and measure quality. These traces are retained for a limited period and are accessible only to Troupia staff who need them.
6. Who else processes your data
We rely on a small number of service providers to run Troupia. Each is bound by contract to protect the data and may use it only to provide their service to us — never for their own purposes. They fall into these categories:
- Cloud hosting and application infrastructure.
- Language model providers, reached through a routing gateway, for the assistant’s responses.
- Database and storage.
- Background job execution for scheduled automations.
- Connector authorization and encrypted credential storage, on infrastructure we operate in the European Union.
- Transactional email delivery.
- Product analytics and service monitoring.
7. Our subprocessors, by name
We keep an up-to-date list of the individual providers behind the categories above, including where each one operates and what it processes. Request it at hello@troupia.com and we will send it, together with our data processing agreement.
We will tell you before we add a subprocessor that materially changes how your data is handled.
8. Storage, security and location
Data is encrypted in transit. Credentials for connected services are additionally encrypted at rest, and are never exposed to the browser or included in a prompt sent to a model.
Access inside Troupia is scoped per workspace, and staff access to production data is limited to what operating the service requires.
Our infrastructure and subprocessors operate in the European Union and the United States, so your data may be transferred to and processed in those regions.
No system is perfectly secure. If a breach affects your data, we will notify you as required by law.
9. Retention and deletion
We keep account and workspace data for as long as your account is active.
Disconnecting a connector deletes the stored credentials for it. Deleting your workspace removes its content; backups are purged on our ordinary backup cycle.
To request deletion of your account and data, write to hello@troupia.com.
10. Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal data, to object to or restrict certain processing, and to withdraw consent.
Exercise any of these by writing to hello@troupia.com. We will not charge you for it or make the service worse because you asked.
11. Cookies
We use cookies that are necessary to keep you signed in and to keep the service secure, plus analytics cookies that tell us how the product is used. You can clear or block cookies in your browser, but the service will not work signed out.
12. Children
Troupia is a business product and is not directed at children under 16. We do not knowingly collect their data.
13. Changes to this policy
If we change this policy we will update the date at the top of this page, and for material changes we will notify you in the product or by email before they take effect.
14. Contact
Questions, requests, or complaints: hello@troupia.com.