Privacy Policy
Requestify · Effective 2026-06-02
Requestify ("Requestify", "we", "our", "us") is operated by Elm Studios AI Inc. This Privacy Policy explains what personal data we collect when you use the Requestify app, why we collect it, and how we handle it.
1. Information we collect
When you connect Requestify to your Jobber account, we access and store:
- Jobber account identifier and OAuth tokens — used to authenticate API requests on your behalf.
- Jobber business data — clients, properties, requests, and related fields visible to your Jobber user, accessed via Jobber's public GraphQL API. We use this to deduplicate clients and properties when creating new requests.
- Team membership — for each user on your Jobber account, we cache their Jobber user ID, name, email address, role (admin / non-admin), and Jobber-side activation status. This is the team list used to authorize sign-ins.
- Sign-in email — when you sign in with Google, we receive the verified email address from your Google account and store it as your Requestify sign-in identifier. We request only the standard
openid email profilescopes; we do not access your Gmail, Drive, contacts, or any other Google data. If you sign in with a magic-code email instead, we store only the email address and the verification metadata. - Inbound call data — call summaries, transcripts, recording URLs, caller phone numbers, and call metadata received from your connected Quo (OpenPhone) account via webhook.
- Inbound email data — forwarded emails routed to your custom Requestify address, including sender, recipients, subject, body, and attachments.
- AI-extracted fields — the structured fields (client name, address, phone, email, job details) that Requestify extracts from calls and emails using AI, plus the classification (new request / follow-up / spam / ignore).
- Geocoded addresses — we send address strings to Google's Geocoding API to validate and normalize them.
- Operational metadata — request IDs, processing timestamps, error codes, and aggregate per-account cost/usage counters.
- Authentication cookie — a signed session cookie that identifies your browser as signed in.
- Device and usage analytics — when you sign in to the Requestify dashboard, we record your IP address, an approximate location (city) derived from that IP, your device type (mobile or desktop), browser user-agent, and visit timestamps and counts. We use this to understand engagement and to monitor for unusual access.
We do not write personally identifiable information (client names, emails, phone numbers, addresses) to our application logs. Logs contain only IDs, counts, and operational metadata.
2. How we use information
- To classify incoming calls and emails and extract the structured fields used to create Jobber service requests on your behalf.
- To deduplicate clients and properties by matching against your existing Jobber records before creating new ones.
- To validate and normalize extracted addresses via Google's Geocoding API.
- To present a triage dashboard so your team can review extractions, correct mistakes, and manually create requests in test mode.
- To maintain reliability (logging, error tracking, and operational metrics).
- To understand aggregate usage patterns and improve the app.
- To understand how your team engages with the dashboard and to monitor for unusual or unauthorized access, using the device and usage analytics described above.
We do not sell your data. We do not use your data for advertising. We do not share your data with third parties except as described in the next section. We do not use your data to train AI models — your transcripts and emails are processed at inference time only and are not retained by our AI provider for training purposes.
3. Third parties
- Jobber (Octopus Research Inc.) — we exchange data with Jobber on your behalf via its public API. Jobber's own privacy policy applies to data held on Jobber's side.
- Anthropic — we send call transcripts, call summaries, and email contents to Anthropic's Claude API to classify and extract structured fields. Anthropic's API processes data at inference time and does not retain it for training. Anthropic's privacy policy applies.
- Google Maps Platform — we use Google's Geocoding API to validate and normalize addresses. Google's privacy policy applies to data Google receives.
- ip-api.com — we send your IP address to ip-api.com to resolve an approximate location (city) for the device and usage analytics described above. ip-api.com's privacy policy applies to data it receives.
- Google Identity Services — we use Google's identity service to verify your sign-in email if you choose Sign in with Google. We receive only the verified email address; we do not access any other Google data.
- Quo (formerly OpenPhone) — your Quo phone provider sends call data to Requestify via webhook. Quo's privacy policy applies to data held on Quo's side.
- Resend — used to route inbound forwarded emails and to send authentication codes. Resend processes email data on our behalf as a service provider.
- Hosting and infrastructure — our servers and database run on Railway. Railway processes data on our behalf as a service provider.
- Cloud infrastructure — our Service is hosted on servers located in the United States and/or Canada. By using the Service, you consent to the transfer and storage of your information in these jurisdictions. Our providers maintain industry-standard security certifications (e.g. SOC2 or ISO 27001).
4. Data retention
- While your Jobber account is connected, your data persists in our database so the app functions.
- When you disconnect Requestify — either from the in-app Disconnect button or from Jobber's Manage Apps page — we delete your account row, OAuth tokens, cached Jobber data, team membership records, and per-source configuration shortly after receiving the disconnect event.
- Server logs may retain technical event data (without business content) for up to 30 days for debugging and security.
5. Your rights
You may:
- Disconnect the app at any time from the in-app settings screen or from Jobber's Manage Apps page.
- Request a copy of the data we hold about you.
- Request deletion of your data.
Contact us at the email below to exercise these rights. Depending on where you live, you may have additional rights under local data-protection law (GDPR, CCPA, PIPEDA, etc.).
6. Security
We use industry-standard measures to protect your data. This includes TLS/SSL encryption for all data in transit, and disk-level encryption at rest provided by our cloud infrastructure (Railway). Access to production systems is restricted to authorized Elm Studios personnel. In the event of a security breach that poses a real risk of significant harm to you, we will notify you and the relevant regulatory authorities without unreasonable delay, in accordance with applicable law (including Alberta's Personal Information Protection Act).
7. Children
Requestify is a business tool not directed at children and is not intended for use by anyone under the age of 16.
8. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be communicated through the app or by email to the account owner.
9. Contact
Elm Studios AI Inc.
Email: dev@elmstudios.ai