PennaWorks legal

Privacy Policy

Effective date: July 15, 2026

This policy explains what data PennaWorks collects when you use QuippyAI, why we collect it, how we protect it, and how to delete it. The short version: your data is used only to power the features you see, it is never sold or used for advertising, and PennaWorks does not use it to train generalized AI models.

Who we are

QuippyAI is operated by PennaWorks ("we", "us") and available at pennaworks.com. For any privacy question or request, email kyle@pennaworks.com.

When a customer organization provides workspace data, PennaWorks generally processes that information on the organization's behalf to provide QuippyAI, and the organization controls which users, mailboxes, and integrations it authorizes. PennaWorks determines how it uses account, billing, security, support, and website information for its own legitimate business operations.

Information we collect

Account information. When you sign in with Google we receive your name, email address, and profile photo. Signing in does not give QuippyAI access to your email.

Gmail data (only if you connect a mailbox).Connecting Gmail is a separate, explicit authorization using Google's read-only Gmail scope (gmail.readonly). With it, QuippyAI syncs messages from approximately the last 30 days and new messages on an ongoing basis: sender and recipient addresses, subject lines, message content, dates, thread structure, and read/unread state. The read-only scope makes it technically impossible for QuippyAI to send, delete, or modify your email.

Google Calendar and meeting data (optional). If you enable deadline sync, QuippyAI uses Calendar access to create, update, and clean up dedicated deadline events. Meeting features may also read a bounded window of event metadata from your primary calendar—including titles, times, attendees, recurrence details, attachments, and meeting links—to identify client meetings, prepare briefs, and record completed Google Meet activity. If you separately authorize the narrower Google Drive and Meet permissions, QuippyAI may also discover supported Meet transcripts, conference records, and Meet-created files that your Google account can access. It does not request broad access to arbitrary Drive files.

Meeting material you import. You may paste meeting notes or a transcript, upload a supported text file, or save a source link. Imported content is encrypted and is used to propose decisions, commitments, follow-ups, risks, blockers, scope changes, and questions for human review. A proposal does not become a confirmed fact or task unless a person approves it.

Writing-style profile (opt-in only). If — and only if — you explicitly enable suggested replies, QuippyAI analyzes a sample of messages you have sent to build a profile of your writing style (tone, greetings, sign-offs). You can disable this and delete the profile at any time in Settings.

Learn My Business data (opt-in only). A learning run starts only after you choose the inboxes, labels, date range, source categories, visibility, retention preference, and analysis types, then give explicit consent. Source content is transient by default. We store the selected scope, fingerprints, minimal provenance, reviewable proposals, your answers and edits, and any business profile you confirm. Optional retained excerpts are encrypted, time-limited, and deletable.

Connected service and time data (optional).If an administrator enables and you connect ClickUp, Canva, or Toggl, QuippyAI stores encrypted credentials plus the identifiers, mappings, status metadata, links, and time-entry details needed for the features you use. This can include task titles and status, design titles and thumbnails, tracked time, billable status, project or client mappings, and user-entered estimates or cost settings. Provider content remains subject to that provider's permissions.

Information you provide. Client records, tasks, notification settings, meeting notes and files, business-learning answers and corrections, time estimates and allocations, your Discord webhook URL if you configure one, and anything you send us in support conversations.

Billing information. Payments are processed by Stripe. We store your subscription status and plan; we never see or store full card numbers.

Technical data. Essential sign-in, security, and preference cookies; push-notification subscription tokens for devices where you enable notifications; and standard server logs such as IP address, browser or device information, timestamps, and request or error details.

Where information comes from

We collect information from:

  • You, when you create an account, configure a workspace, import material, contact support, or choose a feature.
  • Your customer organization and its authorized workspace administrators or teammates.
  • Google and any optional service you connect, within the permissions and settings you authorize.
  • Stripe, for subscription and payment status, and our systems automatically when you use the service.

How we use your information

  • Organize your email by client and surface conversations that need a response.
  • Identify requests, commitments, and deadlines in your mail and turn them into tasks and calendar entries.
  • Prepare a focused Daily Brief and answer grounded Ask Quippy questions about the work available to you.
  • Prepare meeting briefs, maintain confirmed client timelines, and explain relationship or delivery risks.
  • Learn reviewable business context from the historical sources you explicitly select and approve.
  • Show connected ClickUp, Canva, and Toggl context, including time intelligence, where those features are enabled and connected.
  • Alert you (via the channels you configure — web push and/or your own Discord webhook) when an important email is at risk of going unanswered.
  • Generate suggested reply drafts in your writing style, if you opt in. Drafts are suggestions only; QuippyAI has no ability to send email.
  • Operate, secure, and support the service, including billing and abuse prevention.

We do not sell your data, share it for cross-context behavioral advertising, share it with data brokers, or use it for advertising. Email and workspace content may include sensitive information; we use it only for the service, security, and legal-compliance purposes described here, not to infer unrelated characteristics about you.

Google user data and Limited Use

QuippyAI's use and transfer to any other application of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In plain terms, that means:

  • Google user data is used only to provide the user-facing features described above.
  • It is never sold, never used for advertising, and never used to determine creditworthiness or for lending.
  • It is never used by PennaWorks to develop, improve, or train generalized artificial-intelligence or machine-learning models. Authorized content and derived context are processed by Anthropic's commercial API only when needed to generate the Quippy features you request. Anthropic states that commercial API inputs and outputs are not used for model training by default unless the commercial customer explicitly opts in; PennaWorks does not opt QuippyAI customer data into that training.
  • No human reads your Google user content except: with your explicit permission (for example, a support request); as necessary for security or abuse investigation; to comply with applicable law; or where the data has been aggregated and anonymized for internal operations.

Optional integrations and connected services

ClickUp connections can create or link a task only through a user-confirmed workflow and can read the task metadata needed to refresh its status. Canva connections read metadata for designs you choose to attach; QuippyAI does not copy the design contents. Toggl connections read the workspace, project, user, and time-entry information needed for time intelligence and may perform the timer or time-entry action you explicitly request. QuippyAI does not send your email content to these providers except for the concise task details you choose to create in a connected work system.

Disconnecting a service stops future access, removes or disables the stored credential, and leaves the source records in that provider untouched. Previously normalized QuippyAI history may remain so your prior reports and client context continue to make sense, as described under Retention and deletion.

Sharing and service providers

Your data is disclosed only as needed to run QuippyAI: Railway (application hosting), Neon (database hosting), Anthropic (AI processing), Stripe (payment processing), Google (the APIs you authorize), and Resend (transactional email delivery). These providers process information under their applicable agreements and privacy terms. If you configure a Discord webhook, alert notifications are delivered to the Discord channel you chose. If you connect ClickUp, Canva, or Toggl, data is exchanged with that provider only as needed for the connected feature.

Within a shared workspace, your connected mailbox is private by default. Teammates cannot see your email or email-derived tasks unless you explicitly share the mailbox with them in Settings.

We may disclose information if required by law, or as part of a merger or acquisition (in which case this policy would continue to apply to previously collected data).

Security

  • All data is encrypted in transit with TLS.
  • Google OAuth tokens, connected-service credentials, retained meeting content, optional learning excerpts, and Discord webhook URLs are additionally encrypted at the application layer with AES-256-GCM before being stored.
  • Databases are hosted with encryption at rest.
  • Every workspace is isolated: all data access is scoped to your organization and enforced server-side on every query.

Retention and deletion

Disconnect a mailbox:in Settings at any time. This immediately deletes the synced Gmail messages and email-derived tasks for that mailbox from our database, attempts to clean up Quippy-created deadline events, and revokes QuippyAI's access token with Google so future access ends. Workspace records you created or confirmed—such as imported meeting material, confirmed business profiles, or normalized history from a separately connected service—may remain until you delete them using the relevant control or request account deletion.

Delete learning data: Learn My Business lets an authorized user delete retained excerpts at any time or delete a learning run and its sources, proposals, and draft profile. A business profile already reviewed and confirmed is preserved unless you request its deletion or delete the account.

Revoke from Google's side:you can also remove QuippyAI's access at myaccount.google.com/permissions, which stops all syncing immediately.

Delete your account: email kyle@pennaworks.com from your account address and we will delete your account and associated data from active systems within 30 days, except records we must retain for legal, tax, fraud-prevention, security, or dispute-resolution purposes. Residual copies may remain in restricted backups until they are overwritten under our providers' normal backup schedules and are not used for ordinary product operations.

Our retention period depends on the category and why it is needed: connected source and derived workspace data is kept while the relevant account, workspace, or feature remains active; optional learning excerpts follow the retention setting you select; security and server logs are kept only as reasonably needed to operate, secure, and troubleshoot the service; and account, subscription, transaction, support, and legal records are kept for the applicable business, tax, accounting, limitations, and compliance periods. We delete or de-identify information when those purposes end, subject to the exceptions above.

Your privacy rights and choices

Depending on where you live and subject to applicable law, you may ask to know or access the personal information we hold about you, obtain a portable copy, correct it, delete it, or restrict or object to certain processing. You may also have the right to opt out of a sale or sharing for cross-context behavioral advertising, limit certain uses of sensitive personal information, appeal a denied request, and receive equal service and pricing when exercising a privacy right. PennaWorks does not sell or share personal information for cross-context behavioral advertising and did not do so during the preceding 12 months.

Submit a request to kyle@pennaworks.com from your account address. We may verify your identity or authority before acting and may deny or limit a request where applicable law permits. An authorized agent may submit a request where the agent provides proof of authority. We will respond within the period required by applicable law.

You can also control product data directly by disconnecting integrations, changing workspace sharing and notification settings, deleting learning data, or requesting account deletion. If your organization provides your workspace account, it may be the appropriate party to handle a request concerning organization-controlled data; we will support it as required by our agreement and applicable law.

Cookies and tracking signals

QuippyAI uses only essential cookies needed for sign-in, security, OAuth connection flows, and your theme preference. We do not use advertising cookies or permit third parties to track your activity across unrelated websites through QuippyAI.

Because QuippyAI does not engage in cross-site behavioral tracking, it does not change its practices in response to legacy browser "Do Not Track" signals. A Global Privacy Control signal likewise does not change our current practices because there is no sale or sharing for cross-context behavioral advertising to stop.

Children

QuippyAI is a business service for adults and is not directed to anyone under 18. We do not knowingly collect personal information from children. If you believe a child has provided us data, contact us and we will delete it.

Changes to this policy

If we make material changes, we will update the effective date above and notify active users in the app or by email before the changes take effect.

Contact

Questions, concerns, or requests: kyle@pennaworks.com. See also our Terms of Service.