Troppus
Privacy Policy
This policy explains what Troppus collects, why we collect it, and how it is handled. The short version: we store what a team needs to run a shared support inbox, we use infrastructure providers only to operate the product, we do not sell your data, and we do not train AI on your mail.
Troppus is operated from Canada. The service is offered to companies in Canada and the United States, whether they sell to other businesses or to consumers.
1. Who this covers
Our customer is the workspace, meaning your company. That includes B2B teams and B2C teams (for example an app on the App Store whose users email support). People you invite are workspace members. People who write in (customers, users, anyone on the other side of support) have their messages land in your workspace so you can reply. We process that mail on your behalf. You decide who is on the workspace and what stays in it.
2. What we collect
- Account data: name, email address, password hash, email verification status, and profile details you add (alias, avatar, signature).
- Workspace data: workspace names, membership and roles, invites, domain and sender configuration, statuses, views, and billing status.
- Inbox content: emails the workspace sends and receives, including message bodies, attachments, internal notes, tags, and the name and email of people who write in.
- Email metadata: message IDs, thread references, sender and recipient addresses, and timestamps needed for threading and deduplication.
- Billing data: handled by Stripe (customer and subscription identifiers, plan, and payment status). We do not store full card numbers.
3. How we use it
- Operating the shared inbox: receiving, storing, and sending support email.
- Authentication, sessions, and email verification.
- Showing your team conversation history, assignments, and customer profiles.
- Billing the workspace owner through Stripe.
- Protecting the service: abuse prevention and deliverability monitoring.
We do not sell personal data. We do not use inbox content for advertising.
4. Assist and AI
Troppus does not train AI models on your mail or workspace content.
Assist is optional. When someone on the workspace uses it, the current thread may be sent to the AI provider you configured (your own OpenAI key) so a draft can be written. If a conversation is sensitive, do not use Assist on that thread.
5. Infrastructure providers
We use a small set of providers solely to run the product:
- Database and authentication: Neon (Postgres / Neon Auth).
- Email send and receive: Amazon SES. Attachments: Amazon S3.
- Workspace invites: Resend.
- Payments: Stripe.
- Live inbox updates: Ably.
- Error monitoring: Sentry.
- Bot protection on auth: Cloudflare Turnstile.
- Application hosting for the web app and APIs.
- Optional Assist: OpenAI, only when a member uses Assist, via the workspace's own API key.
6. Retention and deletion
- Inbox content is kept while the workspace is active so the team has history.
- Deleting a conversation removes that conversation and its messages.
- Deleting a workspace removes its conversations, messages, members, invites, and domain configuration right away. That is the way to delete workspace data. If you need confirmation after that, email us.
- Deleting your account removes your profile. Workspace content belongs to the workspace, not to a single login.
- If billing is cancelled and the workspace is not deleted, we will delete the workspace later (about 30 days after the subscription ends), unless you restore billing or delete it yourself first.
People who wrote in and want their mail removed should ask the workspace admin. We do not treat those requests as coming from our customer unless the workspace owner asks us to help.
7. Access control
Workspace admins control who can access their organization. Members only see workspaces they belong to. The workspace owner is the billing contact.
8. Security
Data is encrypted in transit. Access to production systems is limited and credential-gated. No system is perfectly secure. If we learn of a breach affecting your data, we will notify affected workspace owners without undue delay.
9. Cookies and analytics
We use cookies for authentication sessions and basic preferences (such as appearance). We also use Google Analytics and Microsoft Clarity, plus a first-party attribution cookie (troppus_attribution) that stores campaign UTMs, landing page path, and referrer hostname, without emails, names, or tokenized URLs. Same-visit UTM parameters may be kept in session storage so signup links keep attribution during that browser session. We do not use third-party advertising cookies.
10. Changes to this policy
We may update this policy as the product evolves. Material changes will be reflected on this page with an updated date, and we will make reasonable efforts to notify workspace owners.
11. Contact
Questions about privacy or a deletion confirmation? Email support@troppus.app, see our Contact page, or read the Terms of Service.
Last updated: August 14, 2026