At Robin, we are committed to protecting the privacy and security of our users' personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our SMS communication platform and optional integrations (including Google Calendar).
We may collect the following types of information:
Except as limited in the Google Workspace API Data section, we use information collected through Robin's own services (such as SMS) to:
Mobile information will not be shared with third parties/affiliates for marketing/promotional purposes.
All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.
We do not sell your personal information. For information collected through Robin's own services (such as SMS), we may share that information only in the following circumstances. Sharing of Google user data is governed exclusively by the Google Workspace API Data section below.
Robin's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. The practices in this section apply to raw Google user data and any data aggregated, anonymized, or derived from it. The broader uses described elsewhere in this Privacy Policy (for example, SMS messaging, announcements, or general platform improvement) do not apply to Google user data and do not expand our use of Google user data beyond Limited Use.
When you connect Google Calendar to Robin, we request only the OAuth scopes needed for SMS-based scheduling. We do not request access to Gmail, Drive, Contacts, or other Google products. Depending on the scopes you grant, we may access:
The scopes we request, and how each one is used:
| Scope | Data accessed | How used / protected |
|---|---|---|
| https://www.googleapis.com/auth/calendar.events | Calendar events (create and list as authorized) | SMS scheduling: create and list events per your rules; Limited Use only |
| https://www.googleapis.com/auth/calendar.calendarlist.readonly | Calendar list metadata | Let you choose which calendars Robin may use |
| https://www.googleapis.com/auth/calendar.freebusy | Free/busy availability | Answer availability questions for scheduling |
We use Google user data solely to provide or improve user-facing features that are prominent in Robin — specifically, SMS-based scheduling and calendar management for the account that connected Google. Examples include checking availability, proposing open times, and creating or listing calendar events according to rules you set.
Robin does not use Google Workspace user data to train, improve, or develop generalized AI/ML models. Any AI processing is limited to personalized, per-user features within the Robin platform (for example, generating a scheduling reply for that user's connected calendar).
We do not use Google user data for:
We do not sell Google user data. We do not transfer Google user data to third parties except:
Google user data is not shared with Robin service clients, advertising platforms, data brokers, or information resellers. SMS recipients who book through Robin may receive confirmation details for appointments created on a connected calendar, but that is part of providing the scheduling feature — not a transfer of your Google account for unrelated purposes.
Depending on how you use Robin, the following parties may process Google-derived data or related platform data as needed to provide the connected feature (or for security or legal compliance). They do not receive Google user data for advertising or for Robin to train generalized AI/ML models:
Robin processes personal information, including Google user data used for connected features, in the United States — primarily on Amazon Web Services and via Twilio's US regions. PostHog and LLM providers may process data in the regions they operate (our PostHog configuration uses PostHog's US environment).
We store Google user data only as needed to operate the connected feature (for example, OAuth tokens and limited calendar information required to check availability or manage events). We protect Google user data with industry-standard security practices, including:
Robin personnel are not permitted to read Google user data unless: (a) you give affirmative agreement for us to view specific data (for example, to troubleshoot your account); (b) it is necessary for security purposes (such as investigating abuse); (c) it is necessary to comply with applicable law; or (d) the data is aggregated and used for internal operations in accordance with applicable privacy requirements.
You can disconnect your Google account from Robin at any time in Robin, or by revoking access at myaccount.google.com/permissions. Disconnecting stops all future calendar access and removes stored Google OAuth tokens so Robin can no longer call Google Calendar APIs on your behalf. Events Robin previously created on your behalf remain on your calendar unless you delete them yourself. Calendar event data Robin already processed (for example, in SMS or conversation history) may be retained in our systems unless you request deletion, subject to legal and operational retention requirements.
You may request deletion of your Google user data stored by Robin by emailing privacy@robin.guide.
On our public website (robin.guide) we use PostHog to understand how visitors use the site and to fix issues. How we handle analytics cookies depends on your location:
If you accept the analytics cookie prompt, we also:
Session replay recordings are processed by PostHog and retained for up to 90 days, after which they are deleted. You can withdraw your consent at any time by clearing your browser's site data for this website, which resets the prompt and stops session replay.
You have control over your SMS communications and connected integrations:
Depending on where you live (including under GDPR and CCPA/CPRA where applicable), you may have the right to:
To exercise these rights, contact us at privacy@robin.guide.
We implement appropriate technical and organizational security measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. These measures include encryption of data in transit (HTTPS/TLS) and field-level encryption (AES-GCM) for Google OAuth tokens stored in our systems. However, no method of transmission over the Internet or electronic storage is 100% secure.
We retain your personal information for as long as necessary to provide our services, comply with legal obligations, resolve disputes, and enforce our agreements. SMS message history may be retained for platform operation and support purposes. Retention and disconnection practices for Google user data are described in the Google Workspace API Data section above. Website session replay retention is described in Website Analytics and Session Replay.
Our services are not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe we have collected information from a child under 13, please contact us immediately.
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date. If we change how we use Google user data, we will update this policy and obtain any additional consent required before using that data in a new way.
If you have any questions about this Privacy Policy or our data practices, please contact us:
Email: privacy@robin.guide
Website: robin.guide