Privacy Policy
This policy describes what data Truquire collects, how we use it, and how you can revoke our access. It applies to the Truquire web application at truquire.com and to any integrations you authorize from within it.
Who we are
Truquire is a senior-care facility acquisition intelligence platform used by deal teams to track facilities, owners, and outreach. It is operated by Radiant HCG.
What data we collect
From you, directly
- Account information (name, email, role) you provide when you sign in via Google or magic link.
- Notes, tags, dispositions, and other deal data you create inside the application.
- Files you upload (e.g. underwriting source documents).
From integrations you authorize
-
Google / Gmail. If you connect a Gmail account, we
receive an OAuth refresh token and use it to read, send, and modify
mail in that account on your behalf. We request these scopes:
gmail.readonly— read message metadata and bodies so we can attach correspondence to the right deal recordgmail.send— send messages you compose from inside Truquiregmail.modify— apply labels and adjust read state so threads stay in sync between Gmail and Truquireuserinfo.email— confirm which mailbox you just connected
- Other integrations (e.g. Pipedrive, Twilio) that you explicitly authorize. We only access what you grant.
How we use Gmail data
- To attach inbound and outbound emails to the matching deal, person, or facility record so your team has a complete timeline.
- To send replies you compose from inside the deal drawer.
- To extract structured fields (e.g. broker name, facility name) from messages so you don't have to copy them by hand.
- To keep label and read-state consistent between Gmail and Truquire.
Specifically, Truquire does not:
- Use Gmail data to serve advertising.
- Sell, license, or transfer Gmail data to data brokers or any third parties for unrelated purposes.
- Allow humans to read your Gmail data except (a) with your explicit consent, (b) for security purposes such as investigating abuse, (c) to comply with applicable law, or (d) in an aggregated, anonymized form used internally to improve user-facing features.
- Use Gmail data to train generalized or large language models.
How we store data
- Email metadata and bodies are stored in our Postgres database (Supabase) and accessed only by Truquire's application servers.
- OAuth refresh tokens are encrypted at rest with AES-256-GCM using a key held only by the application runtime; tokens are never logged and are never returned in API responses.
- Application traffic is served over HTTPS only.
- Hosting is provided by Railway (United States) and Supabase (United States).
How we share data
We do not sell your data. We share data only with the following sub-processors, each strictly to operate the service you signed up for:
- Supabase — primary database hosting
- Railway — application hosting
- Google Cloud — Gmail API, Pub/Sub notifications (only for accounts you connect)
- Anthropic, OpenAI — language-model inference for AI-assisted features. Mailbox content is sent only when you invoke an AI feature, is not retained by these providers for training, and is governed by their respective enterprise / API data-handling terms.
- Twilio — voice and SMS, only when you initiate a call or message
- Sentry — error monitoring (no message bodies are sent)
Text messaging and mobile information
Where we send text messages, message and data rates may apply and message
frequency varies. Reply STOP to any message to opt out, or
HELP for assistance. Our full
Messaging Terms describe each messaging program,
how consent is obtained, and how to revoke it.
We disclose data to law enforcement only when compelled by a valid legal process or when we believe in good faith that disclosure is necessary to prevent imminent harm.
Retention and deletion
- Emails captured via the Gmail integration remain in Truquire until you disconnect the mailbox or delete the records.
- When you disconnect a mailbox from Settings → Connected Services, Truquire's stored OAuth tokens are revoked at Google and zeroed in our database within seconds. Historical messages we already captured are retained on the associated deal records unless you delete them; if you want them removed, email us (below) and we will purge them within 30 days.
- When you delete your Truquire account, we remove your user record and all associated tokens. Records linked to your account that other team members rely on (deal notes, attached emails) are anonymized rather than deleted so the team's deal history stays intact; we can fully purge on request.
Your choices and how to revoke access
- Revoke Gmail access via Google. Open myaccount.google.com/permissions, find "Truquire", and click Remove access. Truquire will immediately stop syncing the mailbox; the next time our renewal job runs we detect the revoked grant and mark the mailbox expired.
- Revoke from within Truquire. Go to Settings → Connected Services and click Disconnect on the mailbox. We revoke the token at Google and clear it from our database.
- Request deletion of stored emails. Email privacy@truquire.com with the mailbox address and we will purge captured messages within 30 days.
Cookies and tracking
Truquire uses essential cookies for authentication (a session JWT in an httpOnly cookie). We do not use third-party advertising cookies. We use Sentry for error monitoring; Sentry does not set advertising cookies.
Children
Truquire is a business tool not directed to children under 13 and does not knowingly collect data from them.
International transfers
Our infrastructure is located in the United States. If you connect from outside the U.S., your data is transferred to and processed in the U.S.
Changes to this policy
We may update this policy. When we do, we will update the "Last updated" date at the top. Material changes will also be announced in-app or by email.
Contact
Privacy questions, data-deletion requests, or anything else covered by
this policy:
privacy@truquire.com