Privacy Policy

LAST UPDATED: 2026-06-22

Co-Shopper ("we", "the service", run by TasteGraph Inc.) provides personalized shopping recommendations by analyzing signals from your connected services (Gmail, Google Calendar, etc.). This policy explains what we collect, why, how we protect it, and your rights. Co-Shopper is operated from and intended for users in the United States.

What we collect

When you sign up:

  • Email address, display name, and profile picture from your Google account, so we can identify you and personalize the UI.

When you connect Gmail:

  • Read-only access to your Gmail messages (full body, subject, headers, attachment metadata). We do NOT send mail on your behalf.

When you connect Google Calendar:

  • Read-only access to your calendar events (titles, dates, attendees, descriptions, locations). We do NOT modify calendars.

Information about others. Gmail and Calendar inherently contain information about other people. When you connect them, we necessarily process information about those you communicate with — names, email addresses, and details within your messages and events — solely to build your graph and provide Co-Shopper to you. Please connect only accounts you are authorized to connect, and do not share others' details with us without their permission.

Information we collect automatically

When you use Co-Shopper, we and our analytics provider automatically log:

  • Device data — operating system and version, browser type and version, device type, screen size, language settings, IP address, and unique device/browser identifiers.
  • Online activity data — pages and screens you view, the links and features you interact with, navigation paths and searches within the app, access times, how long you spend, and the page you came from.
  • Approximate location — a coarse location (city or region) inferred from your IP address. We do not collect precise GPS location.
  • Email interaction data — if we send you emails, we may use pixel tags to detect whether you opened them or clicked a link.
  • Cookies & similar technologies — session cookies (random IDs that recognize you across page loads; they expire after 30 days of inactivity) and similar browser-storage technologies used to keep you signed in and measure usage.

This automatically-collected data never includes the content of your emails, and our behavioral analytics use only opaque identifiers and category labels — never email content, names, or addresses. We do not use session-replay or interest-based advertising technologies.

What we derive

We use AI models to extract structured information from your emails and calendar events:

  • Purchases — what you bought, when, from where, for whom
  • People — family members, friends, colleagues mentioned in your communications
  • Life events — birthdays, weddings, anniversaries, moves
  • Trips — past and upcoming travel
  • Residences — addresses you've lived at or visited
  • Style preferences — inferred taste from purchase history and explicit feedback

This derived data powers the recommendations you see in the app.

Google user data — Limited Use

Co-Shopper's use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Specifically:

  • we access and use Google user data only to provide and improve Co-Shopper's features for you;
  • we do not use Google user data to train generalized AI / machine-learning models;
  • we do not use Google user data to serve advertisements;
  • we do not share Google user data with third parties except as necessary to provide the service you requested (for example, AI processing under zero-retention contracts), for security purposes, to comply with applicable law, or with your explicit consent; and
  • we do not allow humans to read your Google user data unless you give affirmative consent for specific messages, it is necessary for security or to comply with law, or the data has been aggregated / de-identified for internal operations.

How we store and retain it

Your data is encrypted both at rest and in transit (including backups) and stored on reputable cloud infrastructure in an environment dedicated to Co-Shopper. We keep each type of data only as long as we need it:

DataRetention
OAuth tokens (Google access + refresh)Until you disconnect
Raw email contentUp to 6 months, then permanently deleted
Derived data (purchases, people, etc.)Until you delete your account
Behavioral analyticsPer our analytics provider's terms
Session cookies30 days

How we protect it

  • Encryption everywhere: your data is encrypted at rest, in transit, and on backups.
  • Isolated environment: we run on reputable cloud infrastructure in an environment dedicated to Co-Shopper, separate from any other product.
  • No public database: the databases holding your data are private and not directly reachable from the internet.
  • Limited access: only a small number of engineers can access your data, and only for incident response. No support staff or contractors have standing access.
  • Access logging: we log access to your data; you can request your access log (see "Your data access log" below).
  • Security review: we are completing Google's CASA security assessment for Gmail restricted scopes.

Who we share with

We do not sell, rent, or share your personal data with anyone for advertising or marketing purposes.

We rely on a small number of third-party processors and partners to operate the service:

CategoryWhat they handle
Cloud infrastructureHosting and storage of your (encrypted) data
AI providersClassifying and extracting information from your emails and calendar events, under zero-retention contracts — your data is not used to train their models
Product analyticsAnonymous usage events only (never email content, names, or addresses)
Affiliate networkYour Co-Shopper user ID (a pseudonymous identifier) — to attribute purchases you make through partner / affiliate links so commissions can be tracked and reconciled. No email content, names, or addresses are shared.

Your connected Google account (Gmail / Calendar) is the source of the data you choose to share with us. A detailed, up-to-date list of our subprocessors is available on request at privacy@tastegraph.ai.

Compliance and protection

We may use or disclose your information where we believe it is necessary to:

  • comply with applicable laws, lawful requests, and legal process — such as responding to subpoenas, court orders, or requests from government authorities;
  • protect the rights, privacy, safety, and property of you, us, and others — including making and defending legal claims;
  • audit our internal processes for compliance with legal and contractual requirements;
  • enforce the terms that govern Co-Shopper; and
  • prevent, identify, investigate, and deter fraudulent, harmful, unauthorized, or illegal activity, including cyberattacks and identity theft.

Your rights

You can at any time:

  • Access all data we hold about you — request via account settings or by emailing privacy@tastegraph.ai
  • Correct any data we've derived incorrectly (e.g. wrong person attribution) — through the UI or by request
  • Delete your account — Settings → Delete account. We soft-delete immediately (revoking Gmail access, stopping processing); hard-delete after 30 days unless you reverse it.
  • Export your data in a machine-readable format — request via privacy@tastegraph.ai; we provide a JSON dump within 30 days
  • Disconnect a specific integration (Gmail / Calendar) at any time, independently — this stops further processing of that source

We do not sell or share your personal information, and we will never discriminate against you for exercising any of these rights.

Your data access log

You can request a record of how your personal data has been accessed by emailing privacy@tastegraph.ai. We will provide the information available to us, which may include:

  • when the data was accessed;
  • who or what accessed it (you via the app, an automated extraction job, etc.);
  • what was accessed (e.g. "purchases", "persons"); and
  • why (e.g. "user request", "scheduled enrichment").

Breach notification

If we discover a breach affecting your personal data, we will:

  • Notify you by email promptly after we confirm it
  • Disclose what was accessed, what we did to contain it, and what you should do
  • Report it to the relevant authorities and to Google as required by law

Users outside the United States

Co-Shopper is intended for users located in the United States. We do not market or offer the service to individuals outside the US. If you choose to access Co-Shopper from outside the United States, you do so on your own initiative and are responsible for compliance with your local laws.

International data transfers. We are a U.S.-based company, and we and many of our service providers operate in the United States. If you access the service from outside the US, your information will necessarily be transferred to, processed, and stored in the United States, where privacy laws may not be as protective as those in your country.

Children

Co-Shopper is not intended for users under 18. We do not knowingly collect data from minors. If you believe we have, email privacy@tastegraph.ai and we will delete it.

Changes to this policy

Material changes (new scopes, new processors, expanded retention) will be communicated by email at least 30 days before they take effect. You can decline by deleting your account.

Minor clarifications will be noted in the "Last updated" date with a changelog at the bottom of this page.

Contact

  • Privacy / data questions: privacy@tastegraph.ai
  • General support: support@tastegraph.ai
  • Legal: legal@tastegraph.ai
  • Postal: TasteGraph Inc., 770 Jackson St #835, Hoboken, NJ 07030, USA

Changelog

DateChange
2026-06-22Published.
2026-05-28Initial version drafted.