1. Two roles
For account data (who you are, how to reach you, how you pay), we are the controller and this policy governs.
For customer content (the AI responses you submit for verification, the questions, the evidence retrieved from your connectors, the standing records and attestations produced), you are the controller and we are your processor. We process it only to provide the service, under your instructions and our Data Processing Addendum. On a dedicated stack, that content lives in an AWS account under your control and we have no standing path to read it.
2. What we collect and why
From visitors to this website
- Contact form. Name, work email, company, what your AI answers, and volume. Used to reply to you and to prepare a proposed configuration. Sent by email; we do not store it in a marketing database.
- Server logs. Our hosting provider (Amazon CloudFront) records IP address, user agent, requested page, and time, retained for 30 days for security and capacity. We do not run analytics scripts, advertising pixels, or third-party trackers on this site.
- Fonts. Pages load typefaces from Google Fonts, which receives your IP address and user agent to serve the files. See Google's privacy policy for how it handles that request.
From customers and users of the service
- Account and sign-in. Name, email, password hash, optional authenticator secret, session records, sign-in attempts and failures, roles, teams, and organizations. Used to authenticate you and enforce access.
- Company profile. Legal name, tax id, addresses, phone, website, billing and support contacts, industry, time zone. Used for invoices, notices, and support.
- Billing. Plan, usage meters, invoices, and receipts. Card details are entered directly into Stripe and never touch our servers. We hold Stripe's customer and payment-method identifiers.
- Audit log. Who did what and when in the admin app: invites, role and team changes, key and connector changes, policy edits, adjudications. Kept for the life of the account because the audit log is part of the product.
- Support. Emails and any material you send us to diagnose a problem.
Customer content, processed on your behalf
- Submissions. AI responses, questions, and citations you send to the verify endpoint. These may contain personal data about your users or third parties. You decide what to send and how long we keep it; retention is set per organization and redaction hooks run before storage when you configure them.
- Evidence snapshots. Text retrieved from your connectors at grading time, hashed and stored in the object bucket of your stack.
- Connector credentials. Held encrypted in AWS Secrets Manager, used only to query your stores. External connectors never copy your corpus.
- Model provider keys. If you bring your own, they are stored encrypted, shown masked, validated with a minimal call, and never returned after entry.
- Standing records and attestations. The output of the service, retained as long as you keep the account or stack, exportable at any time.
3. Who else processes data
We use these subprocessors. Each is bound by a contract that restricts use to providing its service to us.
- Amazon Web Services, us-east-1 by default, or the region of your dedicated stack. Compute, database, object storage, key management, email delivery, and this website.
- Stripe for payments, invoices, and receipts.
- Model providers chosen per organization: Anthropic, OpenAI, Google, xAI, or Amazon Bedrock. When you use platform keys, submissions and evidence are sent to the provider under our agreement with it. When you bring your own keys, they are sent under your agreement, and any zero-retention terms you hold with that provider apply.
- Exa for live web search when an organization enables the website connector, limited to the domains you declare.
We do not sell personal data, we do not share it for advertising, and we do not train models on customer content.
4. Where data lives
Pooled accounts run in AWS us-east-1. Dedicated stacks run in the region and account you choose. Customer content on a dedicated stack does not leave that account except when your configured model provider or connector is called. Transfers from the EEA or UK rely on standard contractual clauses; ask us for the DPA.
5. How long we keep it
- Account and company data: while the account is open, then 90 days, except records we must keep for tax or legal reasons.
- Billing records: seven years.
- Customer content: per the retention you set for each organization, or until you delete the organization or stack.
- Website logs: 30 days.
- Backups: rolled off within 35 days of deletion.
6. Security
Encryption in transit and at rest, KMS-managed keys, argon2id password hashing, optional multi-factor authentication, throttled sign-in attempts, role-based access with a single authority table for screens and API routes, per-company row scoping with row-level security on pooled deployments, and an audit log. Signed attestations mean a record cannot be altered without detection. The security page has the detail.
7. Your rights
Depending on where you live you may have the right to access, correct, delete, export, or restrict processing of your personal data, to object to processing, and to complain to a supervisory authority. Account holders can do most of this in the Account and Company pages. For anything else, email privacy@truthlock.io and we will respond within 30 days. If your data reached us as customer content, we will refer you to the customer, who controls it, and help them respond.
California residents: we do not sell or share personal information as those terms are defined in the CCPA, and we do not use it for cross-context behavioral advertising.
8. Children
The service is for businesses and is not directed to anyone under 16. We do not knowingly collect their data.
9. Changes
When this policy changes, the effective date at the top changes and account owners are emailed if the change affects them. Older versions are available on request.
10. Contact
Iron Rod Systems · privacy@truthlock.io