Robin

Privacy Policy

Last updated: July 16, 2026

Privacy Commitment

At Robin, we are committed to protecting the privacy and security of our users' personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our SMS communication platform and optional integrations (including Google Calendar).

Information We Collect

We may collect the following types of information:

  • Phone Numbers:We collect mobile phone numbers when you opt-in to receive SMS messages from Robin or our clients' services.
  • Message Content: We process the content of SMS messages you send to and receive from Robin-powered services to provide automated responses and operate our platform.
  • Opt-in Consent: We record when and how you consent to receive SMS communications.
  • Usage Data: We collect information about how you interact with our services, including message timestamps and response patterns.
  • Google Account Data: If you choose to connect a Google account, we access limited Google user data as described in the Google Workspace API Data section below.
  • Website Analytics: On robin.guide, we may collect usage information via PostHog as described in Website Analytics and Session Replay.

How We Use Your Information

Except as limited in the Google Workspace API Data section, we use information collected through Robin's own services (such as SMS) to:

  • Provide and maintain our SMS communication services
  • Send automated responses to your inquiries
  • Send announcements and updates you've opted into
  • Improve and optimize our AI response system for Robin's SMS and platform features (this does not include using Google user data to train or improve generalized AI models)
  • Comply with legal obligations
  • Protect against fraudulent or unauthorized activity

SMS & Mobile Information Sharing

Mobile information will not be shared with third parties/affiliates for marketing/promotional purposes.

All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.

Information Sharing & Disclosure

We do not sell your personal information. For information collected through Robin's own services (such as SMS), we may share that information only in the following circumstances. Sharing of Google user data is governed exclusively by the Google Workspace API Data section below.

  • With Service Clients: When you interact with a Robin-powered service, the organization operating that service may receive your messages and phone number to provide you with support.
  • Service Providers: We work with third-party service providers (such as Twilio for SMS, Amazon Web Services for infrastructure) and Vercel for hosting who assist us in operating our platform.
  • Legal Requirements: We may disclose information if required by law, court order, or government request.

Google Workspace API Data

Robin's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. The practices in this section apply to raw Google user data and any data aggregated, anonymized, or derived from it. The broader uses described elsewhere in this Privacy Policy (for example, SMS messaging, announcements, or general platform improvement) do not apply to Google user data and do not expand our use of Google user data beyond Limited Use.

What Google user data we access

When you connect Google Calendar to Robin, we request only the OAuth scopes needed for SMS-based scheduling. We do not request access to Gmail, Drive, Contacts, or other Google products. Depending on the scopes you grant, we may access:

  • Your calendar list (so you can choose which calendars Robin may use)
  • Free/busy availability information needed to answer scheduling questions
  • Calendar event details needed to create or list events according to rules you set (such as event times, titles, descriptions, attendees, and related metadata)
  • OAuth tokens used to authenticate Robin's access to your connected Google Calendar data

Google OAuth scopes we request

The scopes we request, and how each one is used:

ScopeData accessedHow used / protected
https://www.googleapis.com/auth/calendar.eventsCalendar events (create and list as authorized)SMS scheduling: create and list events per your rules; Limited Use only
https://www.googleapis.com/auth/calendar.calendarlist.readonlyCalendar list metadataLet you choose which calendars Robin may use
https://www.googleapis.com/auth/calendar.freebusyFree/busy availabilityAnswer availability questions for scheduling

How we use Google user data

We use Google user data solely to provide or improve user-facing features that are prominent in Robin — specifically, SMS-based scheduling and calendar management for the account that connected Google. Examples include checking availability, proposing open times, and creating or listing calendar events according to rules you set.

Robin does not use Google Workspace user data to train, improve, or develop generalized AI/ML models. Any AI processing is limited to personalized, per-user features within the Robin platform (for example, generating a scheduling reply for that user's connected calendar).

We do not use Google user data for:

  • Advertising of any kind, including targeted, personalized, retargeted, or interest-based ads
  • Selling data to data brokers or providing it to information resellers
  • Determining credit-worthiness or for lending purposes
  • Creating databases of Google user data for unrelated purposes, or training, creating, or improving generalized machine learning or artificial intelligence models
  • Any other purpose that is not providing or improving the connected Robin feature

How we share or transfer Google user data

We do not sell Google user data. We do not transfer Google user data to third parties except:

  • To provide the connected feature: with subprocessors that help us operate Robin, solely as needed to provide or improve the Google-connected user-facing feature, and only with your consent to connect the integration
  • For security: when necessary to investigate abuse, unauthorized access, or similar security issues
  • For legal compliance: when required to comply with applicable law, regulation, legal process, or enforceable governmental request
  • In a corporate transaction: as part of a merger, acquisition, or sale of assets, and only after obtaining your explicit prior consent where required by Google policy

Google user data is not shared with Robin service clients, advertising platforms, data brokers, or information resellers. SMS recipients who book through Robin may receive confirmation details for appointments created on a connected calendar, but that is part of providing the scheduling feature — not a transfer of your Google account for unrelated purposes.

Subprocessors

Depending on how you use Robin, the following parties may process Google-derived data or related platform data as needed to provide the connected feature (or for security or legal compliance). They do not receive Google user data for advertising or for Robin to train generalized AI/ML models:

  • AI / LLM providers: OpenAI, Anthropic, Google Gemini, xAI (Grok), and Cohere — may process prompts and tool results (including calendar availability or event details needed for a reply) to generate personalized scheduling responses
  • Amazon Web Services: cloud infrastructure used to host and store Robin systems and data in the United States
  • Twilio: SMS delivery, including appointment confirmations generated by the scheduling feature
  • PostHog: product analytics and AI request tracing; also website analytics on robin.guide as described below

International data transfers

Robin processes personal information, including Google user data used for connected features, in the United States — primarily on Amazon Web Services and via Twilio's US regions. PostHog and LLM providers may process data in the regions they operate (our PostHog configuration uses PostHog's US environment).

How we store and protect Google user data

We store Google user data only as needed to operate the connected feature (for example, OAuth tokens and limited calendar information required to check availability or manage events). We protect Google user data with industry-standard security practices, including:

  • Encryption in transit using modern protocols (such as HTTPS/TLS)
  • Field-level encryption (AES-GCM) for Google OAuth access and refresh tokens stored in our systems
  • Access controls so that Calendar connect and disconnect actions require authenticated team members authorized for that Robin account

Robin personnel are not permitted to read Google user data unless: (a) you give affirmative agreement for us to view specific data (for example, to troubleshoot your account); (b) it is necessary for security purposes (such as investigating abuse); (c) it is necessary to comply with applicable law; or (d) the data is aggregated and used for internal operations in accordance with applicable privacy requirements.

Disconnecting and retention

You can disconnect your Google account from Robin at any time in Robin, or by revoking access at myaccount.google.com/permissions. Disconnecting stops all future calendar access and removes stored Google OAuth tokens so Robin can no longer call Google Calendar APIs on your behalf. Events Robin previously created on your behalf remain on your calendar unless you delete them yourself. Calendar event data Robin already processed (for example, in SMS or conversation history) may be retained in our systems unless you request deletion, subject to legal and operational retention requirements.

You may request deletion of your Google user data stored by Robin by emailing privacy@robin.guide.

Website Analytics and Session Replay

On our public website (robin.guide) we use PostHog to understand how visitors use the site and to fix issues. How we handle analytics cookies depends on your location:

  • EU, EEA, and UK visitors: by default PostHog runs in a cookieless mode that records anonymous, aggregate usage (such as pages viewed and clicks) without setting analytics cookies or identifying you across visits. We set analytics cookies only if you accept our analytics cookie prompt.
  • Visitors elsewhere: we set analytics cookies by default so we can recognize your browser across visits. You can opt out at any time by declining our analytics cookie prompt, which turns off analytics cookies.

If you accept the analytics cookie prompt, we also:

  • Set analytics cookies (if they are not already set) so we can recognize your browser across visits
  • Record session replays of your interactions with the website. Session replay captures a reconstruction of the page including mouse movement, clicks, scroll, and visible text and images. Form input values you type are masked and not recorded. We do not capture audio, video, or microphone input.

Session replay recordings are processed by PostHog and retained for up to 90 days, after which they are deleted. You can withdraw your consent at any time by clearing your browser's site data for this website, which resets the prompt and stops session replay.

Your Choices & Opt-Out

You have control over your SMS communications and connected integrations:

  • Opt-Out: You can opt out of receiving SMS messages at any time by replying STOP to any message.
  • Help: Reply HELP to any message for assistance or contact information.
  • Google connection: You can disconnect Google integrations in Robin or revoke access in your Google Account permissions settings at any time.
  • Data Deletion: You may request deletion of your personal information, including Google user data stored by Robin, by contacting us at privacy@robin.guide.

Your Rights

Depending on where you live (including under GDPR and CCPA/CPRA where applicable), you may have the right to:

  • Access the personal information we hold about you
  • Rectify inaccurate personal information
  • Delete personal information we hold about you, subject to legal exceptions
  • Port your personal information in a structured, commonly used format
  • Object to or opt out of certain processing, including SMS by replying STOP, disconnecting Google integrations, or declining analytics cookies as described above

To exercise these rights, contact us at privacy@robin.guide.

Data Security

We implement appropriate technical and organizational security measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. These measures include encryption of data in transit (HTTPS/TLS) and field-level encryption (AES-GCM) for Google OAuth tokens stored in our systems. However, no method of transmission over the Internet or electronic storage is 100% secure.

Data Retention

We retain your personal information for as long as necessary to provide our services, comply with legal obligations, resolve disputes, and enforce our agreements. SMS message history may be retained for platform operation and support purposes. Retention and disconnection practices for Google user data are described in the Google Workspace API Data section above. Website session replay retention is described in Website Analytics and Session Replay.

Children's Privacy

Our services are not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe we have collected information from a child under 13, please contact us immediately.

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date. If we change how we use Google user data, we will update this policy and obtain any additional consent required before using that data in a new way.

Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us: