Privacy Policy
This Privacy Policy explains how Trooth, LLC ("Trooth," "we," "us") collects, uses, discloses, and protects personal information when you use our websites, applications, and services (the "Service"). If you use Trooth on behalf of an organization that is our customer, that customer controls the data you process through the Service, and our Data Processing Addendum governs that processing.
1. Information we collect
- Account information: name, work email, company name, and credentials you create.
- Connected-integration data: when you connect a tool, we process the configuration and operational signals we are authorized to read, and we store the access tokens or keys you provide (encrypted at rest). We retrieve only what is needed to witness and map evidence.
- Content you provide: documents, policies, and other material you upload or link.
- Usage and device data: log data, IP address, and browser/device information.
Trooth does not charge for the service today and collects no payment information. If that changes, this policy and the subprocessor register will be updated first.
2. How we use information
We use information to provide, secure, and improve the Service; to witness and map evidence; to manage accounts, watchlists and alert subscriptions; to send transactional and service messages and alerts; to provide support; to detect, prevent, and address fraud, abuse, and security issues; and to comply with law. We do not sell personal information, and we do not use the content of your connected data for advertising.
We do not train AI models on your data. We do not use your content, your connected-integration data, or your account information to train foundation models, and we do not sell or share it so that others can train on it. Where AI features run inside the Service, they run on your data to produce your result and for no other purpose. The full commitment, including how we handle model providers, is in our AI Policy.
3. Legal bases (EEA/UK)
Where the GDPR or UK GDPR applies, we rely on: performance of a contract (to provide the Service); our legitimate interests (to secure and improve the Service and prevent abuse); consent (where required, e.g., certain cookies or communications); and compliance with legal obligations.
We also rely on legitimate interests to publish limited, factual listings for companies in the Trooth Network that have not yet claimed a profile. The interest we are pursuing, the balancing test we carried out, and the free correction and removal routes that go with it are set out in Sections 4, 6, and 7 of the Trust Profile & Network Terms. You can object to that processing at any time.
4. How we share information
We share personal information with: service providers and sub-processors that help us operate the Service (Section 5); third-party services you choose to connect, at your direction; and authorities or others where required by law or to protect rights, safety, and security. In a merger, acquisition, or sale of assets, information may be transferred subject to this Policy. We do not sell or "share" personal information for cross-context behavioral advertising as defined under U.S. state privacy laws.
5. Sub-processors and service providers
We use the following sub-processors to deliver the Service:
| Sub-processor | Purpose | Data residency |
|---|---|---|
| Cloudflare, Inc. | Edge compute and network security services | Global edge |
| WorkOS, Inc. | Authentication, single sign-on (SSO), and OAuth | United States |
| Amazon Web Services, Inc. | Cloud storage and key management | United States and European Union |
| Anthropic, PBC | Internal-use generative AI for productivity | United States |
| Google LLC | Business email and document storage | Multi-region |
| Neon, Inc. | Managed PostgreSQL database for company profiles, buyer requests, and Trust Center access requests | United States (AWS us-east-1) |
| Nango (only when a customer connects an integration via OAuth) | OAuth authorization broker for customer-initiated integrations | United States |
| Vercel, Inc. | Web hosting | Multi-region edge |
| Sentry (Functional Software, Inc.) | Application error tracking | United States, EU region available |
| Resend, Inc. | Transactional email | United States |
| UptimeRobot | Availability monitoring | Multi-region |
| Third-party tools you connect | Processed at your direction to witness evidence | Determined by the tool you connect |
| GitHub, Inc. | Source control, continuous integration, and storage of the nightly database backup | United States |
We require sub-processors to protect personal information consistent with this Policy. The current, complete list of our sub-processors, including the purpose and data location of each, is published at trooth.co/subprocessors and updated whenever it changes.
6. Data retention
We retain personal information for as long as your account is active and as needed to provide the Service, then for a reasonable period to comply with legal, tax, accounting, and security obligations, after which we delete or de-identify it. You may request deletion as described below, and you can export your data at any time from your account settings.
The schedule below states the maximum period we keep each category. We often delete sooner, and deleting sooner is always consistent with this schedule.
| Category | Kept no longer than |
|---|---|
| Account and profile records | The life of the account, then 30 days after you ask us to delete it |
| Connected-integration credentials, tokens, and keys | 24 hours after you disconnect the integration or delete the account |
| Witnessed evidence and control snapshots | The life of the account, then 30 days |
| Security, authentication, and access logs | 12 months |
| Application and error logs | 90 days |
| Email delivery and notification records | 12 months |
| Support and correspondence records | 24 months from the last message |
| Unclaimed Network listings | Until claimed or removed on request |
| Backups | 35 days, after which deleted data ages out of every backup copy |
Where we must keep something longer, for example because of a legal hold, a tax obligation, or an open dispute, we keep only what that obligation requires and delete the rest on the schedule above.
7. Security
We use technical and organizational measures designed to protect personal information, including encryption in transit (TLS) and encryption of sensitive stored fields and credentials at rest (AES-256-GCM), least-privilege access, edge isolation, and regular backups. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
Breach notification. If we confirm a personal-data breach affecting your information, we will notify affected users without undue delay after confirming the breach, and we will notify the relevant supervisory authorities where the law requires it.
8. International transfers
We may process and store information in the United States and other countries. Where we transfer personal data from the EEA, UK, or Switzerland, we use appropriate safeguards such as the European Commission's Standard Contractual Clauses.
9. Your privacy rights
Depending on where you live, you may have rights to access, correct, delete, port, restrict, or object to the processing of your personal information, and to withdraw consent. EEA/UK residents may lodge a complaint with a supervisory authority. U.S. state residents (e.g., California) may have rights to know, delete, and correct personal information, and to opt out of sale or sharing (we do not sell or share). To exercise rights, contact privacy@trooth.co. Where you are our customer's user, we may direct your request to that customer.
Data-subject request route. To submit a data-subject request (to access, correct, delete, or port your personal information), email hello@trooth.co with the subject line "Data Request". We will verify your identity before acting on the request and respond within the timeframe the applicable law requires.
10. Cookies
We use strictly necessary cookies to operate the Service (such as authentication) and, where applicable, limited analytics. Where consent is required, we request it and honor your choices. You can control cookies through your browser settings.
11. Children
The Service is intended for businesses and is not directed to children under 18. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.
12. Changes and contact
We may update this Policy; material changes will be posted here with a new "Last updated" date. Questions or requests: privacy@trooth.co, Trooth, LLC, 777 Brickell Ave, Suite 500, PMB 1174, Miami, FL 33131, United States.
Revision note. Revised 3 September 2026. The billing-information entry previously described a subscription plan and payment records. Trooth takes no payment for access, so the entry now says so. No other collection, use or disclosure was changed, and the correction is recorded under our publication and correction policy.
Revised September 4, 2026: descriptions of retired features (composite figure, plan tiers, TruePass badge, Verified Inquiries) removed; the document now describes the witness record as published. The usage-data entry no longer names push-notification tokens from a mobile app, because Trooth distributes no mobile app and collects none. No collection, use or disclosure was widened.
Revised September 4, 2026: the billing-information category, the billing purpose in Section 2, the payment-processor disclosure in Section 4, the Stripe, Inc. row in Section 5 and the billing-records row in Section 6 were removed. Trooth takes no payment and processes no card data, so none of them described anything that happens. One sentence in Section 1 now records that, and what will happen first if it changes. The Expo (650 Industries, Inc.) row in Section 5 was also removed, because Trooth distributes no mobile application and sends no push notifications. No collection, use or disclosure was widened.