Legal
Last updated: July 12, 2026
trustcert.ai is operated by TrustCert LLC, a Colorado limited liability company (“TrustCert”, “we”, “us”). This policy describes what personal data we collect when you use the trustcert.ai service, how we use it, who we share it with, and the choices you have. It should be read together with our Terms of Service.
Account data. When you register we collect your email address, display name, and authentication credentials, managed through our identity and authentication provider. If you sign in with a federated provider (such as Google or Microsoft), we receive your name and email from that provider.
Chat content. Your messages, conversation history, and the AI responses generated for you are stored in our database so you can return to past conversations, subject to the retention periods described in “Data retention” below. Paid plans can additionally enable an optional scrubbing setting that redacts personal and product identifiers (such as names, emails, and product or model names) from new messages before they are stored; the AI still processes the original message to generate its answer.
Uploaded files. Documents, images, and audio you upload for analysis are stored with our cloud storage provider and automatically deleted approximately 24 hours after upload.
Billing data. Payments are processed by Stripe. We store your subscription tier, Stripe customer and subscription identifiers, and billing status. We never see or store your full card number — that is handled entirely by Stripe.
Usage and security data. We record daily usage (credits), model and token usage per message, and signals from Google reCAPTCHA Enterprise and Firebase App Check used to protect the Service from abuse. When you sign up or sign in we also collect your IP address, approximate location (country and region), and network (ISP/ASN). We use these to operate analytics and to detect and prevent abuse — for example, the creation of multiple accounts to evade free-tier limits.
Analytics data.We use Google Analytics to understand how visitors find and use the Service — pages viewed, the referring site, approximate location, and device and browser information. Google Analytics sets cookies and processes this data on our behalf in accordance with Google’s terms; in regions that require it, these analytics cookies are set only after you consent (see “Cookies and local storage” below).
We do not sell your personal data, and we do not use your content for advertising.
To generate responses, your messages and uploaded files are processed by one or more trusted third-party AI service providers acting on our behalf as our processors. We may add or change these providers over time. These providers process your content only to provide the service to us; they do not use your content to train or improve their own models, and we do not permit them to use it for advertising. Separately, anonymized and aggregated research derived from queries (for example, which regulations are frequently asked about) may be used to improve our curated regulatory corpus; this corpus contains regulatory information, not your personal data or documents.
We share data only with the processors needed to run the Service: trusted cloud infrastructure providers (hosting, authentication, database, file storage), third-party AI service providers (AI processing), Microsoft (federated sign-in, if you choose it), Stripe (payments), Resend (transactional email), Google Analytics (usage analytics), and Google reCAPTCHA Enterprise (abuse prevention). We may also disclose data where required by law or to protect our rights, and in connection with a merger or acquisition, subject to this policy.
This site is protected by reCAPTCHA Enterprise and the Google Privacy Policy and Terms of Service apply.
Deleting your account also cancels any active Stripe subscription.
Data is encrypted in transit (TLS) and at rest by our cloud providers. Access to production systems is restricted through identity-based access controls and service accounts with least privilege. Multi-factor authentication is available for your account and we recommend enabling it in account settings. No system is perfectly secure; notify us immediately if you suspect unauthorized access to your account.
You can view and update your profile, manage multi-factor authentication, choose your conversation-retention period (paid plans), enable identifier scrubbing (paid plans), and delete your account from your account settings. You can delete any conversation at any time from the chat sidebar, which removes its full message history from our database. Depending on where you live, you may also have rights to access, correct, export, or erase your personal data, to object to or restrict processing, and to lodge a complaint with a supervisory authority. To exercise these rights, contact privacy@trustcert.ai, and we will respond as required by the laws that apply to you, including the GDPR/UK GDPR and the CCPA/CPRA where applicable.
Essential cookies and storage. We use cookies and browser storage for authentication session state, security tokens (Firebase App Check and reCAPTCHA Enterprise), and interface preferences such as your theme choice. These are necessary to operate the Service.
Analytics cookies. Google Analytics sets cookies to measure how the Service is found and used. Where consent is required (for example, in the EU and UK), we ask before any analytics cookies are set: a banner lets you accept or decline, analytics is not initialized until you accept, and your choice is remembered on your device. Declining keeps analytics off. We do not use third-party advertising or cross-site advertising cookies.
The Service is hosted by trusted cloud infrastructure providers, primarily in the United States, and our analytics provider (Google Analytics) also processes data in the United States. If you access the Service from outside the United States, your data is transferred to and processed in the United States. For transfers of personal data from the European Economic Area, the United Kingdom, or Switzerland, we and our providers rely on appropriate safeguards — such as the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum — as set out in those providers’ data processing terms, including Google’s and Stripe’s data processing addenda and Microsoft’s Products and Services Data Protection Addendum.
Where the GDPR or UK GDPR applies, we rely on the following legal bases: performance of a contract to provide the Service and manage your account; legitimate interests to secure the Service and prevent abuse, including processing IP address and network information to detect duplicate-account creation; and consent for analytics cookies, which you may withdraw at any time.
The Service is intended for business and professional use and is not directed at children under 18. We do not knowingly collect personal data from children.
We may update this policy from time to time. For material changes we will give notice — for example by email or an in-product notice — before the changes take effect. The “Last updated” date above reflects the latest revision.
Privacy questions or requests: privacy@trustcert.ai. TrustCert LLC is a limited liability company organized under the laws of the State of Colorado, United States.