Privacy Policy
LAST UPDATED: 2026-09-14
Co-Shopper ("we", "the service", run by TasteGraph Inc.) provides personalized shopping recommendations by analyzing signals from your connected services (Gmail, Google Calendar, etc.). This policy explains what we collect, why, how we protect it, and your rights. Co-Shopper is operated from and intended for users in the United States.
What we collect
When you sign up:
- Email address, display name, and profile picture from your Google account, so we can identify you and personalize the UI.
When you connect Gmail:
- Read-only access to your Gmail messages (full body, subject, headers, attachment metadata). We do NOT send mail on your behalf.
When you connect Google Calendar:
- Read-only access to your calendar events (titles, dates, attendees, descriptions, locations). We do NOT modify calendars.
Information about others. Gmail and Calendar inherently contain information about other people. When you connect them, we necessarily process information about those you communicate with — names, email addresses, and details within your messages and events — solely to build your graph and provide Co-Shopper to you. Please connect only accounts you are authorized to connect, and do not share others' details with us without their permission.
Browser extension (Co-Shopper for Chrome)
Co-Shopper offers an optional Chrome browser extension. It is a separate, opt-in product from the web app above, and it only does anything after you sign in and explicitly agree to data collection inside the extension. If you never install the extension, none of this section applies to you.
What the extension captures. For each online store you explicitly turn on, the extension reads:
- Your shopping cart on that store — item names, brands/designers, prices, sizes and colors, quantities, and product images/links.
- Your order history on that store — order numbers, order dates, the items in each order, prices, order totals, and order status (e.g. shipped, delivered, refunded).
What it never captures. The extension never reads or stores your store passwords, your payment card numbers, CVV codes, bank or financial account details, or any site you have not explicitly turned on. It captures shopping data on only the specific stores you enable — never your general web browsing.
How it works, and the permissions it uses. Capture runs in the extension's background service worker using your existing signed-in session on the store. It uses these Chrome permissions:
- Host access to specific stores — requested one store at a time, only when you turn that store on, and only for the retailers Co-Shopper supports. The extension does not hold blanket "all sites" access.
- Cookies — on an enabled store's own site only, the extension reads that store's existing session cookie so its request to the store is recognized as you. Cookie values are used in the moment to authenticate the read and are not stored or sent anywhere as raw cookies. On enabled stores we also check whether you have any cookies at all (a sign you've shopped there) and whether you're currently signed in, so the dashboard can show connection status and surface the stores you actually use — this is limited to stores you enabled and never reads your general browsing history.
- Storage, scripting, and alarms — to save what was captured locally, run the per-store reader only on the stores you enabled, and schedule the periodic background capture.
Consent and your controls. The extension shows you a plain-language disclosure and requires your affirmative agreement before it captures anything. At any time from the extension's dashboard you can turn any store off (which stops capture for that store) or use "Delete my data", which permanently deletes your captured carts and orders from both your device and the Co-Shopper server, and signs you out.
Where the data goes and how long we keep it. Captured carts and orders are sent over an encrypted connection to the Co-Shopper backend and added to your shopping profile to power your recommendations. We retain them until you delete them (via "Delete my data") or delete your account, whichever comes first. We do not sell this data, share it with data brokers, or use it for personalized or interest-based advertising.
Our use of data obtained through the extension adheres to the Chrome Web Store User Data Policy, including its Limited Use requirements.
Information we collect automatically
When you use Co-Shopper, we and our analytics provider automatically log:
- Device data — operating system and version, browser type and version, device type, screen size, language settings, IP address, and unique device/browser identifiers.
- Online activity data — pages and screens you view, the links and features you interact with, navigation paths and searches within the app, access times, how long you spend, and the page you came from.
- Approximate location — a coarse location (city or region) inferred from your IP address. We do not collect precise GPS location.
- Email interaction data — if we send you emails, we may use pixel tags to detect whether you opened them or clicked a link.
- Cookies & similar technologies — session cookies (random IDs that recognize you across page loads; they expire after 30 days of inactivity) and similar browser-storage technologies used to keep you signed in and measure usage.
This automatically-collected data never includes the content of your emails, and our behavioral analytics use only opaque identifiers and category labels — never email content, names, or addresses. We do not use session-replay or interest-based advertising technologies.
What we derive
We use AI models to extract structured information from your emails and calendar events:
- Purchases — what you bought, when, from where, for whom
- People — family members, friends, colleagues mentioned in your communications
- Life events — birthdays, weddings, anniversaries, moves
- Trips — past and upcoming travel
- Residences — addresses you've lived at or visited
- Style preferences — inferred taste from purchase history and explicit feedback
This derived data powers the recommendations you see in the app.
Google user data — Limited Use
Co-Shopper's use of information received from Google Workspace APIs (Gmail and Google Calendar) — whether raw, aggregated, or derived — adheres to the Google API Services User Data Policy, including its Limited Use requirements. Specifically:
- we access and use Google user data only to provide and improve Co-Shopper's features for you;
- we do not use Google user data — raw, aggregated, or derived — to train, and we do not transfer it to any third party to train, generalized or foundational AI / machine-learning models;
- we do not use Google user data to serve advertisements;
- we do not share Google user data with third parties except as necessary to provide the service you requested (for example, AI processing under zero-retention contracts), for security purposes, to comply with applicable law, or with your explicit consent; and
- we do not allow humans to read your Google user data unless you give affirmative consent for specific messages, it is necessary for security or to comply with law, or the data has been aggregated / de-identified for internal operations.
The AI processing described above runs on Amazon Bedrock (Amazon Web Services), using Anthropic Claude models. Per those providers' terms, your prompts and the resulting outputs are not retained for training and are not used to train or improve any generalized or foundational model, and Google user data is not shared with the model provider.
How we store and retain it
Your data is encrypted both at rest and in transit (including backups) and stored on reputable cloud infrastructure in an environment dedicated to Co-Shopper. We keep each type of data only as long as we need it:
| Data | Retention |
|---|---|
| OAuth tokens (Google access + refresh) | Until you disconnect Gmail and Calendar (deleted immediately) or we delete your account |
| Raw email content | Up to 6 months, then permanently deleted |
| Derived data (purchases, people, etc.) | Until you delete your account or ask us to delete it |
| Behavioral analytics | Per our analytics provider's terms |
| Session cookies | 30 days |
How we protect it
- Encryption everywhere: your data is encrypted at rest, in transit, and on backups.
- Isolated environment: we run on reputable cloud infrastructure in an environment dedicated to Co-Shopper, separate from any other product.
- No public database: the databases holding your data are private and not directly reachable from the internet.
- Limited access: only a small number of engineers can access your data, and only for incident response. No support staff or contractors have standing access.
- Access logging: we log access to your data; you can request your access log (see "Your data access log" below).
- Security review: we are completing Google's CASA security assessment for Gmail restricted scopes.
Who we share with
We do not sell, rent, or share your personal data with anyone for advertising or marketing purposes.
We rely on a small number of third-party processors and partners to operate the service:
| Category | What they handle |
|---|---|
| Cloud infrastructure | Hosting and storage of your (encrypted) data |
| AI processing (Amazon Bedrock / Anthropic Claude) | Classifying and extracting information from your emails and calendar events. Inputs and outputs are not retained for training and are not used to train or improve any model. |
| Product analytics | Anonymous usage events only (never email content, names, or addresses) |
| Affiliate network | Your Co-Shopper user ID (a pseudonymous identifier) — to attribute purchases you make through partner / affiliate links so commissions can be tracked and reconciled. No email content, names, or addresses are shared. |
Your connected Google account (Gmail / Calendar) is the source of the data you choose to share with us. A detailed, up-to-date list of our subprocessors is available on request at privacy@tastegraph.ai.
Compliance and protection
We may use or disclose your information where we believe it is necessary to:
- comply with applicable laws, lawful requests, and legal process — such as responding to subpoenas, court orders, or requests from government authorities;
- protect the rights, privacy, safety, and property of you, us, and others — including making and defending legal claims;
- audit our internal processes for compliance with legal and contractual requirements;
- enforce the terms that govern Co-Shopper; and
- prevent, identify, investigate, and deter fraudulent, harmful, unauthorized, or illegal activity, including cyberattacks and identity theft.
Your rights
You can at any time:
- Access all data we hold about you — request by emailing privacy@tastegraph.ai
- Correct any data we've derived incorrectly (e.g. wrong person attribution) — through the UI or by request
- Delete your account — email privacy@tastegraph.ai from the address you sign in with. When we receive your request we revoke Gmail and Calendar access and stop processing, and we permanently delete your account and data within 30 days.
- Export your data in a machine-readable format — request via privacy@tastegraph.ai; we provide a JSON dump within 30 days
- Disconnect Gmail and Google Calendar at any time — Connectors (in your account menu) → Disconnect. They share one Google permission, so they disconnect together. We revoke our access at Google, delete our access tokens immediately, and stop processing both. What we already derived stays in your account until you delete your account or ask us to delete it (privacy@tastegraph.ai). You can also remove Co-Shopper's access from your Google Account at any time.
We do not sell or share your personal information, and we will never discriminate against you for exercising any of these rights.
Your data access log
You can request a record of how your personal data has been accessed by emailing privacy@tastegraph.ai. We will provide the information available to us, which may include:
- when the data was accessed;
- who or what accessed it (you via the app, an automated extraction job, etc.);
- what was accessed (e.g. "purchases", "persons"); and
- why (e.g. "user request", "scheduled enrichment").
Breach notification
If we discover a breach affecting your personal data, we will:
- Notify you by email promptly after we confirm it
- Disclose what was accessed, what we did to contain it, and what you should do
- Report it to the relevant authorities and to Google as required by law
Users outside the United States
Co-Shopper is intended for users located in the United States. We do not market or offer the service to individuals outside the US. If you choose to access Co-Shopper from outside the United States, you do so on your own initiative and are responsible for compliance with your local laws.
International data transfers. We are a U.S.-based company, and we and many of our service providers operate in the United States. If you access the service from outside the US, your information will necessarily be transferred to, processed, and stored in the United States, where privacy laws may not be as protective as those in your country.
Children
Co-Shopper is not intended for users under 18. We do not knowingly collect data from minors. If you believe we have, email privacy@tastegraph.ai and we will delete it.
Changes to this policy
Material changes (new scopes, new processors, expanded retention) will be communicated by email at least 30 days before they take effect. You can decline by deleting your account.
Minor clarifications will be noted in the "Last updated" date with a changelog at the bottom of this page.
Contact
- Privacy / data questions: privacy@tastegraph.ai
- General support: support@tastegraph.ai
- Legal: legal@tastegraph.ai
- Postal: TasteGraph Inc., 770 Jackson St #835, Hoboken, NJ 07030, USA
Changelog
| Date | Change |
|---|---|
| 2026-09-14 | Clarified the Limited Use / AI-training statement (raw, aggregated, and derived data) and named the AI processor (Amazon Bedrock / Anthropic Claude). |
| 2026-09-11 | Your rights: Disconnect is on the Connectors page and removes Gmail and Calendar together (they are one Google permission): it revokes access and deletes our tokens at once, and what we derived stays until you ask us to delete it. Account deletion and data access are by email request. Retention table updated to match. |
| 2026-06-22 | Published. |
| 2026-05-28 | Initial version drafted. |