Skip to main content
trussnote

Privacy Policy

Last updated: April 2026

1. Information we collect

We collect information you provide directly to us when you create an account, fill out a form, or contact us. This includes your name, email address, company name, and any content you upload or create within the platform.

We also collect usage data automatically, such as IP address, browser type, pages visited, and referring URLs. This helps us improve the product and diagnose issues.

2. How we use your information

We use the information we collect to provide, maintain, and improve trussnote; to communicate with you about your account and our services; to send transactional and product update emails; and to comply with legal obligations.

We do not sell your personal information to third parties.

3. Data sharing and disclosure

We may share your information with third-party service providers who perform services on our behalf. These currently include:

Supabase: cloud database and authentication hosting

Resend: transactional email delivery

PostHog: product analytics (anonymized usage data)

Sentry: error monitoring and crash reporting (device and usage data)

Stripe: payment processing

OpenAI / Anthropic: AI model inference (your tool inputs are processed by these providers)

All service providers are contractually required to handle your data securely and only for the purposes we specify.

We may disclose your information if required by law or to protect the rights and safety of our users.

4. Data retention

We retain your account data for as long as your account is active. If you delete your account, we will delete your personal data within 30 days, subject to any legal retention obligations.

5. Security

We implement industry-standard security measures including encryption in transit (TLS) and at rest. Access to customer data is restricted to authorized personnel on a need-to-know basis.

6. Your rights

Depending on your location, you may have rights to access, correct, delete, or export your personal data. To exercise these rights, contact us at info@trussnote.com. You can also export your data directly from your account Settings page.

GDPR (European users): If you are located in the European Economic Area, you have the right to access, rectify, erase, restrict, or object to the processing of your personal data, and the right to data portability. You also have the right to lodge a complaint with your local data protection authority.

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, and affected individuals without undue delay where the breach is likely to result in a high risk.

CCPA / CPRA (California residents): If you are a California resident, you have the right to know what personal information we collect about you and how it is used; the right to delete your personal information; the right to correct inaccurate personal information; and the right to opt out of the sale or sharing of your personal information. We do not sell your personal information to third parties. To exercise your California privacy rights, contact us at info@trussnote.com. We will not discriminate against you for exercising these rights.

7. AI features and model improvement

TrussNote uses AI to power its tools. To improve the quality and relevance of AI responses over time, we process tool outputs in the following ways:

Firm-specific memory: Outputs from your tool usage may be used to build a memory of your firm's preferences, project types, and typical requirements. This memory is used exclusively to personalise future responses for your organisation and is never shared with or accessible to other organisations.

Aggregated insights: Anonymised and aggregated patterns across all users may be used to surface industry-wide insights within the platform. No firm-specific or identifiable data is included in these aggregations. Patterns are only surfaced when they appear across at least three independent organisations in the same jurisdiction.

Model improvement: High-rated tool outputs may be used to fine-tune AI models that power TrussNote. Before any output is used for this purpose, it is de-identified to remove personally identifiable information and project-specific details.

Opt-out: You can disable both aggregated insights and model improvement for your organisation at any time by toggling "Exclude us from AI training" in Settings → AI Memory. Once enabled, your reports are immediately excluded from future aggregation and from the fine-tuning queue. The setting can be changed by any organisation admin and takes effect immediately.

8. Changes to this policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or by posting a notice on our website at least 14 days before the change takes effect.

9. Contact

If you have questions about this Privacy Policy, please contact us at info@trussnote.com.