Back to chat
trustcert.ai

Legal

Privacy
policy.

Last updated: July 12, 2026

01Who we are

trustcert.ai is operated by TrustCert LLC, a Colorado limited liability company (“TrustCert”, “we”, “us”). This policy describes what personal data we collect when you use the trustcert.ai service, how we use it, who we share it with, and the choices you have. It should be read together with our Terms of Service.

02Information we collect

Account data. When you register we collect your email address, display name, and authentication credentials, managed through our identity and authentication provider. If you sign in with a federated provider (such as Google or Microsoft), we receive your name and email from that provider.

Chat content. Your messages, conversation history, and the AI responses generated for you are stored in our database so you can return to past conversations, subject to the retention periods described in “Data retention” below. Paid plans can additionally enable an optional scrubbing setting that redacts personal and product identifiers (such as names, emails, and product or model names) from new messages before they are stored; the AI still processes the original message to generate its answer.

Uploaded files. Documents, images, and audio you upload for analysis are stored with our cloud storage provider and automatically deleted approximately 24 hours after upload.

Billing data. Payments are processed by Stripe. We store your subscription tier, Stripe customer and subscription identifiers, and billing status. We never see or store your full card number — that is handled entirely by Stripe.

Usage and security data. We record daily usage (credits), model and token usage per message, and signals from Google reCAPTCHA Enterprise and Firebase App Check used to protect the Service from abuse. When you sign up or sign in we also collect your IP address, approximate location (country and region), and network (ISP/ASN). We use these to operate analytics and to detect and prevent abuse — for example, the creation of multiple accounts to evade free-tier limits.

Analytics data.We use Google Analytics to understand how visitors find and use the Service — pages viewed, the referring site, approximate location, and device and browser information. Google Analytics sets cookies and processes this data on our behalf in accordance with Google’s terms; in regions that require it, these analytics cookies are set only after you consent (see “Cookies and local storage” below).

03How we use your information

  • to provide, operate, and secure the Service;
  • to generate AI responses grounded in regulatory sources, including classifying queries to retrieve relevant compliance requirements;
  • to manage subscriptions, billing, and usage allowances;
  • to send transactional email — verification, research-completion notices, and account or billing notifications (via Resend);
  • to understand how the Service is found and used (analytics) and to improve it;
  • to prevent fraud, bots, and abuse, including multiple-account creation that evades usage limits;
  • to comply with legal obligations.

We do not sell your personal data, and we do not use your content for advertising.

04AI processing of your content

To generate responses, your messages and uploaded files are processed by one or more trusted third-party AI service providers acting on our behalf as our processors. We may add or change these providers over time. These providers process your content only to provide the service to us; they do not use your content to train or improve their own models, and we do not permit them to use it for advertising. Separately, anonymized and aggregated research derived from queries (for example, which regulations are frequently asked about) may be used to improve our curated regulatory corpus; this corpus contains regulatory information, not your personal data or documents.

05Service providers and sharing

We share data only with the processors needed to run the Service: trusted cloud infrastructure providers (hosting, authentication, database, file storage), third-party AI service providers (AI processing), Microsoft (federated sign-in, if you choose it), Stripe (payments), Resend (transactional email), Google Analytics (usage analytics), and Google reCAPTCHA Enterprise (abuse prevention). We may also disclose data where required by law or to protect our rights, and in connection with a merger or acquisition, subject to this policy.

This site is protected by reCAPTCHA Enterprise and the Google Privacy Policy and Terms of Service apply.

06Data retention

  • Uploaded files: deleted automatically approximately 24 hours after upload.
  • Chat history (Free plan): conversations are deleted automatically 30 days after their last activity, or earlier if you delete them.
  • Chat history (paid plans): you control the retention period in account settings — 30 days, 90 days, or 1 year after last activity, or kept until you delete the conversation or your account (the default).
  • Deleted conversations: deleting a conversation removes it from your history immediately.
  • Ephemeral conversations: Ephemeral conversations are permanently erased the moment you close or refresh the page.
  • Account data: retained while your account is active; deleted when you delete your account, except where we must retain records (for example, billing records) to meet legal obligations.
  • Abuse-prevention IP data: the raw IP address collected at sign-up/sign-in is retained for approximately 90 days, after which only derived, non-identifying signals (approximate location and network) are kept.
  • Analytics data:retained according to Google Analytics’ retention settings (for example, 14 months).

Deleting your account also cancels any active Stripe subscription.

07Security

Data is encrypted in transit (TLS) and at rest by our cloud providers. Access to production systems is restricted through identity-based access controls and service accounts with least privilege. Multi-factor authentication is available for your account and we recommend enabling it in account settings. No system is perfectly secure; notify us immediately if you suspect unauthorized access to your account.

08Your rights and choices

You can view and update your profile, manage multi-factor authentication, choose your conversation-retention period (paid plans), enable identifier scrubbing (paid plans), and delete your account from your account settings. You can delete any conversation at any time from the chat sidebar, which removes its full message history from our database. Depending on where you live, you may also have rights to access, correct, export, or erase your personal data, to object to or restrict processing, and to lodge a complaint with a supervisory authority. To exercise these rights, contact privacy@trustcert.ai, and we will respond as required by the laws that apply to you, including the GDPR/UK GDPR and the CCPA/CPRA where applicable.

09Cookies and local storage

Essential cookies and storage. We use cookies and browser storage for authentication session state, security tokens (Firebase App Check and reCAPTCHA Enterprise), and interface preferences such as your theme choice. These are necessary to operate the Service.

Analytics cookies. Google Analytics sets cookies to measure how the Service is found and used. Where consent is required (for example, in the EU and UK), we ask before any analytics cookies are set: a banner lets you accept or decline, analytics is not initialized until you accept, and your choice is remembered on your device. Declining keeps analytics off. We do not use third-party advertising or cross-site advertising cookies.

10International transfers

The Service is hosted by trusted cloud infrastructure providers, primarily in the United States, and our analytics provider (Google Analytics) also processes data in the United States. If you access the Service from outside the United States, your data is transferred to and processed in the United States. For transfers of personal data from the European Economic Area, the United Kingdom, or Switzerland, we and our providers rely on appropriate safeguards — such as the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum — as set out in those providers’ data processing terms, including Google’s and Stripe’s data processing addenda and Microsoft’s Products and Services Data Protection Addendum.

11Legal bases for processing (EEA/UK)

Where the GDPR or UK GDPR applies, we rely on the following legal bases: performance of a contract to provide the Service and manage your account; legitimate interests to secure the Service and prevent abuse, including processing IP address and network information to detect duplicate-account creation; and consent for analytics cookies, which you may withdraw at any time.

12Children

The Service is intended for business and professional use and is not directed at children under 18. We do not knowingly collect personal data from children.

13Changes to this policy

We may update this policy from time to time. For material changes we will give notice — for example by email or an in-product notice — before the changes take effect. The “Last updated” date above reflects the latest revision.

14Contact

Privacy questions or requests: privacy@trustcert.ai. TrustCert LLC is a limited liability company organized under the laws of the State of Colorado, United States.