When you sign in, Talk asks Google for one thing: your email address (the standard "openid" and "email" scopes). It does not request or receive your name, profile photo, contacts, calendar, Drive files, or any other Google data.
We use that email address to identify you, to check whether you are on the invite list, to create your account the first time you sign in, and to address the reminder emails Talk sends when a message goes unanswered.
It is stored on our own server, in our own database, for as long as your account exists. It is transmitted only over HTTPS.
We never sell, rent, or share it with advertisers, data brokers, or any third party, and we do not use it for advertising or for training any AI model. Talk uses no Google APIs beyond sign-in.
Ask an administrator to delete your account and your email address is removed from our records.
What we collect
Your email address, taken from Google Sign-In. That is the only thing we request from Google — not your name, profile photo, contacts, or anything else.
The messages, photos, videos, voice notes and GIF choices you send, plus who you sent them to and when.
Basic technical data needed to run the service: your browser user-agent string on sign-in, and — if you turn notifications on — a push subscription token from your browser.
What we do not collect
No tracking pixels, no analytics scripts, no advertising identifiers, no third-party cookies.
We do not sell, rent, or share your data with anyone for marketing.
How your messages are protected
Message text, attachment filenames, and uploaded files are encrypted on our server with AES-256-GCM before being written to disk. All traffic runs over HTTPS/WSS.
Important and stated plainly: this is encryption at rest, not end-to-end encryption. The server holds the key, so a server administrator is technically able to read message content. This protects you if the database or disk is stolen; it does not protect you from the operator of this service. If that matters for what you want to discuss, use a tool with end-to-end encryption instead.
Who can see your messages
Only the members of the conversation. Every read of a message or file re-checks that you are a member of that room.
Direct messages are visible to the two of you. Group messages are visible to everyone in the group, including people added later — new members can see the history that came before they joined.
Third parties
Google — used only to verify your identity when you sign in.
Giphy — when you open the GIF picker, your search term is sent to Giphy through our server so your IP is not exposed to them. A GIF you send is stored as a link to Giphy, which means Giphy can see when it is loaded.
Your browser vendor (Google, Apple, Mozilla, Microsoft) — if you enable notifications, delivery goes through their push service.
Email notifications
If a message goes unanswered for a couple of hours, we email you a reminder from chat@trinityegroup.com. It contains a short preview of the waiting message. Mute the conversation in the app to stop these.
How long we keep things
Messages and files are kept until you delete them or an administrator deletes the account. Deleting a message removes its content from the database immediately; a placeholder remains so the conversation still reads correctly.
Sign-in sessions expire after 30 days.
Your choices
Delete any message you sent, at any time.
Turn notifications off in your browser settings at any time.
Ask an administrator to remove your access and delete your account.
Children
This service is not intended for anyone under 13, and access is by invitation only.
Contact
Questions about this policy: chat@trinityegroup.com