01Who we are
Talisk ("Talisk", "we", "us") is an AI-assisted email and bookkeeping service for small businesses, operated by:
Talisk Technologies Inc.
British Columbia, Canada
Email: privacy@talisk.ai
Talisk Technologies Inc. is the organization responsible for the personal information processed through the Talisk service at talisk.ai and the Talisk applications (the "Service"). This policy explains what information we collect, why we collect it, who we share it with, and the rights you have over it.
We comply with the Canadian federal Personal Information Protection and Electronic Documents Act (PIPEDA), the British Columbia Personal Information Protection Act (PIPA), and, for Quebec residents, the Act respecting the protection of personal information in the private sector as amended by Law 25.
We do not sell personal information, and we do not use your data for advertising.
02Privacy Officer
The person in charge of the protection of personal information at Talisk is:
Mark Haimes
Talisk Technologies Inc.
privacy@talisk.ai
Contact the Privacy Officer for any question about this policy, to exercise your rights (section 11), or to make a complaint about how your information is handled.
03Information we collect
Account information
When you create an account: your name, email address, and a password (stored only as a salted hash — we cannot read it). If you enable two-factor authentication, we store the secrets needed to verify your codes. Purpose: creating and securing your account.
Connected mailbox — email content and metadata
Talisk is an email client. When you connect a mailbox (Google, Microsoft, or a generic IMAP/SMTP account), we sync and store the contents of that mailbox: messages, subjects, senders and recipients, attachments, labels/folders, and drafts. We also store the OAuth tokens (or, for IMAP, the credentials you provide) needed to keep the connection alive; these are encrypted at rest. Purpose: providing the mail features you signed up for — inbox, search, compose, triage, drafts, scheduled send.
Contacts
With your permission, we sync your provider address book (e.g. Google Contacts and Gmail's auto-curated "Other contacts") and maintain contact profiles built from your mail. Contact email addresses and display names are also kept in a fast lookup index so the compose autocomplete responds instantly. Purpose: address autocomplete, contact management, and two-way contact sync with your provider.
Financial and bookkeeping data
If you use the bookkeeping side of Talisk, we store the business records you create or connect: bills, receipts and their images, invoices, quotes, jobs and time entries, clients and vendors, chart of accounts and journal entries, bank statements you upload, bank account and transaction data retrieved through Plaid when you connect a bank, and sales/payout data retrieved from ecommerce and payment platforms you connect (Shopify, WooCommerce, Square, PayPal, Stripe). If you connect Shopify, we can also create a customer record in your store from contact details you have received, but only when you ask us to and only after you confirm the details. If you connect an accounting platform (QuickBooks Online or Xero), we also read your chart of accounts and related records from it, and send it the bills and transactions you choose to push. Purpose: bookkeeping — capturing transactions, reconciliation, reports, and handover to your accountant.
Payment and billing information
Subscription payments are processed by Stripe. Talisk does not store your full card number or card verification code — those go directly to Stripe. We store your subscription tier, billing status, and Stripe's reference identifiers. Purpose: billing for the Service.
Identity documents, if you ask us to restore your account
If you turn on two-factor authentication and then lose both your authenticator app and your recovery codes, the only way back into your account is for a person here to confirm who you are. That check asks you for a photograph of your government photo ID and a selfie holding up a number we give you. You are never asked for these at any other time, and never as a condition of using the Service. Both photographs are encrypted at rest with a key derived for your account, are seen only by a reviewing administrator, and are destroyed 90 days after the decision — we keep the record that you asked and what was decided, not the photographs. Purpose: confirming your identity before restoring access to your account.
Usage and technical data
Standard server logs (IP address, browser type, request timestamps), security events (sign-ins, failed attempts), and operational metrics such as AI feature usage counts. Purpose: keeping the Service secure, reliable, and within plan limits.
Cookies and local storage
We use only essential cookies (sign-in session, security tokens) and local browser storage for interface preferences. We run no third-party analytics or advertising trackers. See the Cookie & Tracking Notice. Purpose: keeping you signed in and remembering your settings.
04How we use your information
- To provide the Service — syncing and displaying your mail, storing your books, generating reports, sending the email you tell us to send.
- To provide AI features you invoke or enable — inbox triage, drafting assistance, document extraction (e.g. reading a receipt), and the bookkeeping assistant. See section 6.
- To operate your account — verification emails, password resets, security notices, billing.
- To secure the Service — detecting abuse, enforcing isolation between accounts, auditing data integrity.
- To comply with law — where we are legally required to retain or disclose information.
We do not use your information for advertising, we do not sell or rent it, and we do not use your content to train AI models (ours or anyone else's — see sections 5 and 6).
05Google & Microsoft account data
When you connect a Google or Microsoft mailbox, Talisk requests only the permissions it needs to act as your email client and contact manager. What each permission is used for:
Google permissions
| Permission | What Talisk uses it for |
|---|---|
| Read, compose, send and manage your email (gmail.modify) | Syncing your inbox into Talisk; showing, searching and organizing messages (labels, archive, trash); saving drafts; sending mail you write or approve. Talisk never permanently deletes messages behind your back — deletions go to your Gmail trash. |
| Basic account info (userinfo.email, userinfo.profile, openid) | Identifying which Google account is connected and showing it in the interface. |
| Your contacts (contacts) | Reading your saved Google Contacts to power the compose "To:" autocomplete, and writing back contacts you save in Talisk so both address books stay aligned. |
| Other contacts (contacts.other.readonly) | Reading Gmail's auto-curated "Other contacts" list so autocomplete suggests people you actually correspond with. |
Microsoft permissions
| Permission | What Talisk uses it for |
|---|---|
| Mail.Read, Mail.ReadWrite, Mail.Send | Syncing, organizing, drafting, and sending mail in your Outlook mailbox — the same email-client functions as above. |
| User.Read | Identifying which Microsoft account is connected. |
| Contacts.ReadWrite, People.Read | Contact sync and autocomplete, including write-back of contacts you save. |
| offline_access | A refresh token so your mailbox keeps syncing when you are not in the app. |
Google API Services — Limited Use disclosure
Talisk's use and transfer to any other application of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In particular, for all data obtained through Google APIs:
- We use it only to provide and improve the user-facing features of Talisk that you see and interact with — mail, contacts, triage, drafting, and bookkeeping capture. We do not use it for any other purpose.
- We do not transfer it to anyone else, except as necessary to provide those features (see sections 6 and 7), to comply with applicable law, or with your explicit consent.
- Humans do not read this data, except with your explicit consent for specific messages, where necessary for security purposes (such as investigating abuse), to comply with applicable law, or where the data has been aggregated and anonymized for internal operations.
- We do not use it for serving advertisements, and we never sell it.
- We do not use it to train generalized artificial-intelligence or machine-learning models. Our AI provider is contractually prohibited from training its models on it (section 6).
06AI processing
Talisk's AI features — inbox triage, reply drafting, receipt and bill extraction, and the bookkeeping assistant — are powered by Anthropic's Claude models via Anthropic's API. When you use these features, the relevant content (for example, the email being triaged, the receipt being read, or the ledger figures the assistant is asked about) is sent to Anthropic PBC (United States) to generate the result, then returned to you.
- No training: under Anthropic's commercial terms, Anthropic does not use content submitted through its API to train its models.
- Limited retention: Anthropic does not retain API conversation content by default; narrow exceptions exist (for example, content flagged by Anthropic's automated trust-and-safety systems, or where retention is required by law).
- Output is assistance, not judgment: AI output can be wrong. Talisk's money-affecting AI suggestions are drafts that you review and approve.
07Service providers and connected services
We use a small number of service providers ("sub-processors") to run Talisk — hosting, AI, payments, and transactional email. Separately, when you connect a third-party service (your mailbox, your bank via Plaid, your store), data flows between Talisk and that service at your direction, under that service's own terms.
The current list, what each one does, and where it is located is published at talisk.ai/subprocessors. We update that page when the list changes.
08Where your data is stored
Talisk's servers are hosted with DigitalOcean in the United States (Santa Clara, California). Documents you upload — receipts, bills, invoices and email attachments — are stored encrypted in DigitalOcean's object storage, in a United States region (San Francisco), as are our encrypted backups. Some service providers listed at talisk.ai/subprocessors also process data in the United States.
Communication of information outside Quebec and outside Canada: if you are in Quebec (or elsewhere in Canada), your personal information is communicated to, stored in, and processed in the United States as described above. Before choosing these providers we assessed the sensitivity of the information, the purposes of the processing, and the protections applied (encryption at rest and in transit, contractual commitments, and the isolation measures described on our Security page), and concluded the information receives adequate protection. While in the United States, information may be subject to lawful access requests by U.S. authorities.
09Security
Security measures are described in detail on our Security page. In short: every account's data lives in its own isolated database schema with row-level security enforced by the database engine itself; personal content is encrypted at rest with a per-account key; connections are encrypted in transit (TLS); nightly database backups are GPG-encrypted before leaving the server; and payment card data is handled by Stripe, never stored by Talisk.
10Retention and deletion
- While your account is active, we retain your account data, mailbox data, and books so the Service can function. Bookkeeping records are retained for as long as you keep them in your books — they are your business records.
- Mailbox disconnection: disconnecting a mailbox stops syncing; revoking Talisk's access from your Google or Microsoft account settings cuts off Talisk's access immediately.
- Account deletion: to close your account and have your data deleted, contact privacy@talisk.ai. Deletion removes your account's database schema — mail, contacts, books, and documents — from the live system, normally within 30 days of the request.
- Account-recovery photographs: the government ID and selfie described in section 03 are destroyed 90 days after the decision on your request. The record that a request was made and what was decided is kept as part of your account's security history.
- Backups: encrypted database backups age out on a rolling 30-day schedule, after which deleted records are gone from them too. Uploaded documents are separately mirrored to encrypted off-site storage, and that mirror is additive: it has no scheduled expiry. Closing your account now removes your documents from that mirror as well as from the live service, as part of the deletion procedure above. Two limits, stated rather than glossed over. Deleting a single document while your account stays open removes it from the live service only; the encrypted copy in the mirror remains until the account itself is closed. And a small number of documents stored before August 2026 are filed under storage locations that do not identify an individual account, so they cannot be removed that way. We would rather tell you the current position than describe the intended one.
- What we may keep: records we are legally required to keep (for example, billing and tax records of our own), kept only as long as the law requires.
11Your rights
Subject to the exceptions in applicable law, you have the right to:
- Access the personal information we hold about you and be told how it is used and to whom it has been communicated.
- Correct information that is inaccurate, incomplete, or out of date.
- Delete your information (see section 10).
- Portability: receive computerized personal information you provided to us in a structured, commonly used technological format. Talisk's export tools (CSV and accountant handover exports) cover most of this directly.
- Withdraw consent at any time — for example by disconnecting a mailbox or integration, or closing your account. Withdrawal does not affect processing that happened before it.
To exercise any of these rights, contact the Privacy Officer at privacy@talisk.ai. We respond within 30 days. We may need to verify your identity before acting on a request.
If you are not satisfied with our response, you may complain to the Office of the Privacy Commissioner of Canada, the Office of the Information and Privacy Commissioner for British Columbia, or — in Quebec — the Commission d'accès à l'information du Québec.
12Breach notification
If a confidentiality incident involving your personal information creates a real risk of significant harm (or, for Quebec residents, a risk of serious injury), we will notify you and the applicable regulator (the Privacy Commissioner of Canada and/or the Commission d'accès à l'information du Québec) as required by law, keep a register of the incident, and take reasonable measures to reduce the risk of harm.
13Children
Talisk is a business tool. It is not directed at minors, and you must be at least 19 to use it. We do not knowingly collect personal information from anyone under that age; if you believe a minor has provided us information, contact privacy@talisk.ai and we will delete it.
14Marketing communications
We send transactional email that the Service requires — verification, password resets, security and billing notices. If we send commercial electronic messages (product news, offers), we do so in compliance with Canada's Anti-Spam Legislation (CASL): only with your consent, identifying ourselves, and with a working unsubscribe that we honour promptly. Unsubscribing from marketing never affects transactional email.
15Changes to this policy
When we change this policy, we will update the "Last updated" date above; for material changes we will notify you in the app or by email before the change takes effect. The current version always lives at talisk.ai/privacy.
16Contact
Privacy questions and requests: privacy@talisk.ai
General support: support@talisk.ai
Talisk Technologies Inc., British Columbia, Canada. A postal address for
formal notices is available on request from
legal@talisk.ai.