---
title: "Privacy Policy - Trooth"
description: "How Trooth collects, uses, discloses, and protects personal information."
canonical_url: "https://trooth.co/privacy"
markdown_url: "https://trooth.co/privacy.md"
generated_from: "the rendered page, converted to Markdown when this was requested"
agent_index: "https://trooth.co/llms.txt"
---

# Privacy Policy

Last Updated September 27, 2026

Questions: [legal@trooth.co](mailto:legal@trooth.co)

This Privacy Policy explains how Trooth, LLC ("Trooth," "we," "us") collects, uses, discloses, and protects personal information when you use our websites, applications, and services (the "Service"). If you use Trooth on behalf of an organization that is our customer, that customer controls the data you process through the Service, and our [Data Processing Addendum](https://trooth.co/dpa) governs that processing.

**Contents** 1. Information we collect2. How we use information3. Legal bases (EEA/UK)4. How we share information5. Sub-processors and service providers6. Data retention7. Security8. International transfers9. Your privacy rights10. Cookies11. Children12. Changes and contact

## 1. Information we collect

- **Account information:** name, work email, company name, and credentials you create.
- **Connected-integration data:** when you connect a tool, we process the configuration and operational signals we are authorized to read, and we store the access tokens or keys you provide (encrypted at rest). We retrieve only what is needed to witness and map evidence.
- **Content you provide:** documents, policies, and other material you upload or link.
- **Usage and device data:** log data, IP address, and browser/device information.
- **Cookie choices:** the choice you make in the cookie panel, kept in your browser with a random receipt id, and a copy of that choice we keep so we can show it was made. The copy holds no IP address, email or account (Section 10).
- **Web analytics, where allowed:** page visits counted in aggregate by Vercel Web Analytics and a sample of page-load timings, as the Cookie Policy describes. In the European Economic Area, the United Kingdom and Switzerland they run only with your consent.

**Where it comes from.** Most of this information comes from you or from your use of the Service. Evidence from a tool comes from the tool you connect. Listings of companies that have not claimed a profile are built from public sources, such as a company's own website, public DNS and certificate records and public filings, as the Trust Profile & Network Terms describe.

**What is required.** Your name, work email and a credential are needed to create an account; without them we cannot provide one. Everything else you give us is optional, and the Service works without it, with the features that depend on it unavailable.

Trooth does not charge for the service today and collects no payment information. If that changes, this policy and the subprocessor register will be updated first.

## 2. How we use information

We use information to provide, secure, and improve the Service; to witness and map evidence; to manage accounts, watchlists and alert subscriptions; to send transactional and service messages and alerts; to provide support; to detect, prevent, and address fraud, abuse, and security issues; and to comply with law. We do not sell personal information, and we do not use the content of your connected data for advertising.

**We do not train AI models on your data.** We do not use your content, your connected-integration data, or your account information to train foundation models, and we do not sell or share it so that others can train on it. Where AI features run inside the Service, they run on your data to produce your result and for no other purpose. The full commitment, including how we handle model providers, is in our [AI Policy](https://trooth.co/ai-policy).

## 3. Legal bases (EEA/UK)

Where the GDPR or UK GDPR applies, we rely on: performance of a contract (to provide the Service); our legitimate interests (to secure and improve the Service and prevent abuse); consent (where required, e.g., certain cookies or communications); and compliance with legal obligations.

For web analytics, we rely on your consent in the European Economic Area, the United Kingdom and Switzerland, and on our legitimate interest in understanding how the Website is used elsewhere; you can turn analytics off at any time from Cookie preferences in the Website's footer. We keep a copy of each cookie choice because the law asks us to be able to show that consent was given (GDPR Article 7(1)).

**Automated decisions.** We do not make decisions about you that produce legal or similarly significant effects based solely on automated processing. The AI features in the Service draft and explain; a person decides what to do with the result.

We also rely on legitimate interests to publish limited, factual listings for companies in the Trooth Network that have not yet claimed a profile. The interest we are pursuing, the balancing test we carried out, and the free correction and removal routes that go with it are set out in Sections 4, 6, and 7 of the [Trust Profile & Network Terms](https://trooth.co/network-trust-profile-terms). You can object to that processing at any time.

## 4. How we share information

We share personal information with: service providers and sub-processors that help us operate the Service (Section 5); third-party services you choose to connect, at your direction; and authorities or others where required by law or to protect rights, safety, and security. In a merger, acquisition, or sale of assets, information may be transferred subject to this Policy. We do not sell or "share" personal information for cross-context behavioral advertising as defined under U.S. state privacy laws.

## 5. Sub-processors and service providers

We use the following sub-processors to deliver the Service:

| Sub-processor | Purpose | Data residency |
| --- | --- | --- |
| Cloudflare, Inc. | Edge compute and network security services, form bot checks (Turnstile), and AI inference (Workers AI) for the Kyrie assistant and questionnaire drafting | Global edge |
| WorkOS, Inc. | Authentication, single sign-on (SSO), and OAuth | United States |
| Amazon Web Services, Inc. | Cloud storage and key management | United States and European Union |
| Anthropic, PBC | Internal-use generative AI for productivity | United States |
| Google LLC | Business email and document storage | Multi-region |
| Neon, Inc. | Managed PostgreSQL database for company profiles, buyer requests, and Trust Center access requests | United States (AWS us-east-1) |
| Nango (only when a customer connects an integration via OAuth) | OAuth authorization broker for customer-initiated integrations | United States |
| Vercel, Inc. | Web hosting, and web analytics where allowed (see the Cookie Policy) | Multi-region edge |
| Sentry (Functional Software, Inc.) | Application error tracking | United States, EU region available |
| Resend, Inc. | Transactional email | United States |
| UptimeRobot | Availability monitoring | Multi-region |
| Third-party tools you connect | Processed at your direction to witness evidence | Determined by the tool you connect |
| GitHub, Inc. | Source control, continuous integration, and storage of the nightly database backup | United States |

We require sub-processors to protect personal information consistent with this Policy. The current, complete list of our sub-processors, including the purpose and data location of each, is published at [trooth.co/subprocessors](https://trooth.co/subprocessors) and updated whenever it changes.

## 6. Data retention

We retain personal information for as long as your account is active and as needed to provide the Service, then for a reasonable period to comply with legal, tax, accounting, and security obligations, after which we delete or de-identify it. You may request deletion as described below, and you can export your data at any time from your account settings.

The schedule below states the **maximum** period we keep each category. We often delete sooner, and deleting sooner is always consistent with this schedule.

| Category | Kept no longer than |
| --- | --- |
| Account and profile records | The life of the account, then 30 days after you ask us to delete it |
| Connected-integration credentials, tokens, and keys | 24 hours after you disconnect the integration or delete the account |
| Witnessed evidence and control snapshots | The life of the account, then 30 days |
| Security and authentication logs (sign-ins, sessions, administrative actions) | 12 months |
| Records of who opened a document a company shared | 24 months, and they cannot be altered before then |
| Application and error logs | 90 days |
| Email delivery and notification records | 12 months |
| Support and correspondence records | 24 months from the last message |
| Unclaimed Network listings | Until claimed or removed on request |
| Backups | 35 days, after which deleted data ages out of every backup copy |
| Copies of cookie choices (receipts) | As long as we may need to show that a choice was made. A receipt identifies a browser's choice, not a person, and holds no IP address, email or account |
| Web analytics | Vercel discards the visit hash after 24 hours; what remains is aggregate counts that identify no one |

Where we must keep something longer, for example because of a legal hold, a tax obligation, or an open dispute, we keep only what that obligation requires and delete the rest on the schedule above.

## 7. Security

We use technical and organizational measures designed to protect personal information, including encryption in transit (TLS) and encryption of sensitive stored fields and credentials at rest (AES-256-GCM), least-privilege access, edge isolation, and regular backups. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

**Breach notification.** If we confirm a personal-data breach affecting your information, we will notify affected users without undue delay after confirming the breach, and we will notify the relevant supervisory authorities where the law requires it.

## 8. International transfers

We may process and store information in the United States and other countries. Where we transfer personal data from the EEA, UK, or Switzerland, we use appropriate safeguards such as the European Commission's Standard Contractual Clauses.

## 9. Your privacy rights

Depending on where you live, you may have rights to access, correct, delete, port, restrict, or object to the processing of your personal information, and to withdraw consent at any time, without affecting processing that took place before. EEA/UK residents may lodge a complaint with a supervisory authority. U.S. state residents (for example, in California, Colorado, Connecticut, Virginia or Texas) may have rights to know, access, delete and correct personal information, to obtain a copy in a portable form, and to opt out of sale, sharing, targeted advertising and profiling; we do none of those things, so there is nothing to opt out of. Where you are our customer's user, we may direct your request to that customer.

**How to make a request.** Email [privacy@trooth.co](mailto:privacy@trooth.co?subject=Data%20Request) with the subject line "Data Request"; a request sent to [hello@trooth.co](mailto:hello@trooth.co?subject=Data%20Request) is accepted too. We will verify your identity before acting on the request, using information we already hold, and respond within the time the law allows: one month under the GDPR and UK GDPR, and 45 days under U.S. state laws, extended only where the law permits and with notice. You may use an authorized agent; we will ask for proof of the agent's authority and may ask you to confirm your identity directly. There is no charge for a request.

**Appeals.** If we decline your request, you may appeal by replying with the subject line "Appeal". We will answer within 45 days and explain our decision in writing. If your appeal is denied, you may contact your state attorney general.

**No discrimination.** We will not deny you the Service, charge you a different price or give you a different quality of service because you exercised a privacy right.

**Sensitive information.** The only sensitive personal information we handle is the credential you use to sign in, and we use it only to authenticate you and keep your account secure. We do not use or disclose sensitive personal information to infer characteristics about you.

**Privacy officer.** Trooth's Founder is responsible for privacy and for answering requests, including as the person in charge of the protection of personal information under Quebec law and as the contact for data protection under Brazil's LGPD. Contact: [privacy@trooth.co](mailto:privacy@trooth.co).

## 10. Cookies

We use strictly necessary cookies to operate the Service, such as keeping you signed in. Web analytics runs only where allowed: in the European Economic Area, the United Kingdom and Switzerland only after you agree in the cookie panel, and elsewhere by default, with a switch to turn it off in Cookie preferences in the Website's footer. Trooth sets no advertising cookies and does no cross-site tracking. Every cookie we set, what it does and how long it is kept is listed in our [Cookie Policy](https://trooth.co/cookies).

**Global Privacy Control and Do Not Track.** If your browser sends a Global Privacy Control signal, we treat it as a choice to reject all optional cookies and analytics for that browser. Browsers' older "Do Not Track" setting has no agreed meaning, so we do not act on it separately; the Global Privacy Control signal and Cookie preferences give you the same control.

## 11. Children

The Service is intended for businesses and is not directed to children under 18. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.

## 12. Changes and contact

We may update this Policy; material changes will be posted here with a new "Last updated" date. Questions or requests: [privacy@trooth.co](mailto:privacy@trooth.co), Trooth, LLC, 777 Brickell Ave, Suite 500, PMB 1174, Miami, FL 33131, United States.

© 2026 Trooth, LLC. All rights reserved.

## Document workflows

Three different things are called sharing a document, and Trooth stores different things for each.

| Workflow | What Trooth stores | What Trooth never stores |
| --- | --- | --- |
| A buyer requests an NDA-gated document from a company's profile | The request: the requester's name, work address, company and message, and when it was relayed. Kept as the retention schedule says for requests | The document. The company sends it to the buyer directly, under its own NDA, outside Trooth |
| A company publishes a document on its profile | What the company puts on the profile: a link to the document, or the file if the company uploads one. It is public | Nothing beyond what the company published |
| A buyer shares a review or pack by link | The link's token (as a hash), and a record of each time it was opened, kept 24 months | The link's token in readable form |

## Tools that need no account

The public API, the MCP server, the command line and the badge need no account, and that is not the same as sending nothing. Each request sends what you ask about, and your connection sends your IP address and a user agent, as with any web request.

| Tool | What reaches Trooth | What Trooth keeps |
| --- | --- | --- |
| trooth check (command line) | The domain you look up, in the request URL | Standard server request logs (application logs, 90 days) |
| trooth lint (command line) | Nothing. It runs on your machine and opens no network connection | Nothing |
| MCP tools | The company, domain, token or question you pass | A daily count of calls by tool, the company or domain looked up, outcome and a client label from the user agent; for a token, its id only when it matched. No IP address, no question text, no unmatched token |
| Badge on a company's site | The company's slug, the page address as the Referer, and one view count unless the site turns it off | A count of views by profile. The referring page and the time are also delivered to the company as a profile.viewed event if it subscribes to one; repeat views from one address within ten minutes count once |

The MCP server uses the IP address to rate-limit tool calls, in memory for about a minute, and writes it nowhere.

*Revision note. Revised September 3, 2026. The billing-information entry previously described a subscription plan and payment records. Trooth takes no payment for access, so the entry now says so. No other collection, use or disclosure was changed, and the correction is recorded under our [publication and correction policy](https://trooth.co/corrections).*

*Revised September 4, 2026: descriptions of retired features (composite figure, plan tiers, TruePass badge, Verified Inquiries) removed; the document now describes the witness record as published. The usage-data entry no longer names push-notification tokens from a mobile app, because Trooth distributes no mobile app and collects none. No collection, use or disclosure was widened.*

*Revised September 4, 2026: the billing-information category, the billing purpose in Section 2, the payment-processor disclosure in Section 4, the Stripe, Inc. row in Section 5 and the billing-records row in Section 6 were removed. Trooth takes no payment and processes no card data, so none of them described anything that happens. One sentence in Section 1 now records that, and what will happen first if it changes. The Expo (650 Industries, Inc.) row in Section 5 was also removed, because Trooth distributes no mobile application and sends no push notifications. No collection, use or disclosure was widened.*

*Revision note. Revised September 23, 2026. Dates are written month first. No right or obligation was narrowed, and the correction is recorded under our [publication and correction policy](https://trooth.co/corrections).*

*Revision note. Revised September 26, 2026. The retention table listed "security, authentication, and access logs" at 12 months while the [retention schedule](https://trooth.co/retention) keeps records of who opened a shared document for 24 months. They are two kinds of record, and the table now lists them separately, with the 24 months the schedule has always applied. The retention schedule is the controlling statement of how long each kind of data is kept and what each deletion action does; this table summarizes it. No right or obligation was narrowed, and the correction is recorded under our [publication and correction policy](https://trooth.co/corrections).*

*Revision note. Revised September 26, 2026. A section, Tools that need no account, now says what the command line, the MCP server and the badge send to Trooth and what Trooth keeps. A no-account tool was described elsewhere as sending nothing about you; the command line's check sends the domain you look up. A second new section, Document workflows, says what Trooth stores when a buyer requests a gated document, when a company publishes one, and when a buyer shares a review by link; a statement elsewhere that Trooth never stores documents applies to the first of those only. No right or obligation was narrowed, and the correction is recorded under our [publication and correction policy](https://trooth.co/corrections).*

*Revision note. Revised September 27, 2026. This policy now says where the information we hold comes from, which information is required to open an account, how web analytics is governed by region and by consent, that we keep a copy of each cookie choice and for how long, that we make no solely automated decisions with legal effect, how Global Privacy Control and Do Not Track signals are handled, how to appeal a declined request, that authorized agents may make requests, that exercising a right never changes the Service you receive, how sensitive information is used, who the privacy officer is, and the response times the law sets. It names both addresses that accept a data request, which the policy previously gave differently in two places, and the sub-processor table now says that Cloudflare also runs form bot checks and the AI inference behind Kyrie, and that Vercel also provides web analytics where allowed. No right or obligation of yours was narrowed, and the change is recorded under our [publication and correction policy](https://trooth.co/corrections).*

On this page

1. 1. Information we collect
2. 2. How we use information
3. 3. Legal bases (EEA/UK)
4. 4. How we share information
5. 5. Sub-processors and service providers
6. 6. Data retention
7. 7. Security
8. 8. International transfers
9. 9. Your privacy rights
10. 10. Cookies
11. 11. Children
12. 12. Changes and contact
13. Document workflows
14. Tools that need no account

## Structured data

```json
{
  "@context": "https://schema.org",
  "@graph": [
    {
      "@type": "Organization",
      "@id": "https://trooth.co/#org",
      "name": "Trooth",
      "legalName": "Trooth, LLC",
      "alternateName": [
        "Trooth, LLC",
        "Trooth Network",
        "trooth.co"
      ],
      "url": "https://trooth.co",
      "logo": {
        "@type": "ImageObject",
        "@id": "https://trooth.co/#logo",
        "url": "https://trooth.co/brand/trooth-mark_black-on-white_1024.png",
        "contentUrl": "https://trooth.co/brand/trooth-mark_black-on-white_1024.png",
        "width": 1024,
        "height": 1024,
        "caption": "Trooth"
      },
      "image": {
        "@id": "https://trooth.co/#logo"
      },
      "description": "Trooth is an infrastructure and cybersecurity company providing Machine-Readable Trust. The Trooth Network keeps one current, evidence-backed Machine-Readable Trust Profile per company, rechecked on a schedule and signed so it can be replayed.",
      "foundingDate": "2025-12-16",
      "address": {
        "@type": "PostalAddress",
        "streetAddress": "777 Brickell Ave, Suite 500, PMB 1174",
        "addressLocality": "Miami",
        "addressRegion": "FL",
        "postalCode": "33131",
        "addressCountry": "US"
      },
      "contactPoint": {
        "@type": "ContactPoint",
        "contactType": "customer support",
        "email": "hello@trooth.co",
        "url": "https://trooth.co/contact"
      },
      "sameAs": [
        "https://x.com/Troothllc",
        "https://github.com/troothllc",
        "https://www.crunchbase.com/organization/trooth",
        "https://www.wikidata.org/wiki/Q141292994",
        "https://www.youtube.com/@Troothllc",
        "https://www.trustpilot.com/review/trooth.co"
      ]
    },
    {
      "@type": "WebSite",
      "@id": "https://trooth.co/#website",
      "url": "https://trooth.co",
      "name": "Trooth",
      "alternateName": "Trooth Network",
      "inLanguage": "en",
      "publisher": {
        "@id": "https://trooth.co/#org"
      },
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://trooth.co/network?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    },
    {
      "@type": "ItemList",
      "@id": "https://trooth.co/#sitelinks",
      "name": "Trooth sitelinks",
      "itemListElement": [
        {
          "@type": "SiteNavigationElement",
          "position": 1,
          "name": "Join Trooth now - it's free!",
          "url": "https://trooth.co/signup"
        },
        {
          "@type": "SiteNavigationElement",
          "position": 2,
          "name": "Company, Trooth",
          "url": "https://trooth.co/network/company/trooth"
        },
        {
          "@type": "SiteNavigationElement",
          "position": 3,
          "name": "Trooth Network",
          "url": "https://trooth.co/network"
        }
      ]
    }
  ]
}
```
