1. The data we collect
From Customers (tenant administrators)
- Account data: email address, company name, tenant configuration.
- Billing data: processed by our payment processor (Stripe). We store billing identifiers, not card numbers.
- Usage telemetry: request counts, error rates, disposition counts. Used for billing and capacity planning.
From end-users of Customer's deployments
- Chat content: the message the end-user sends and the agent's reply. Stored as part of the conversation transcript in the Customer's tenant.
- Conversation metadata: conversation ID, agent type, channel, outcome, CSAT (if provided).
- Citations consumed: which articles the agent cited, used for the feedback flywheel.
End-user data is the Customer's data — Truvyo is a data processor for it. Customer determines what end-user PII (if any) is allowed to enter the chat surface.
From visitors to truvyo.ai
- Standard server logs: IP address, user agent, page requested, timestamp. Retained for 30 days.
- Cookies: see the Cookie Policy. We do not run third-party advertising trackers.
2. How we use it
- To operate the Service: serve API requests, render answers, retain conversation history per Customer configuration.
- To bill: count dispositions and seats, generate invoices.
- To improve the Shared Library: aggregated retrieval gaps inform what content the Truvyo team curates next. Aggregated and de-identified; no Customer Content is exposed across tenants.
- To investigate security incidents: server logs and request samples may be reviewed during an active incident.
- To comply with law: only when required by a valid legal process.
3. What we don't do
- We do not train AI models on Customer Content.
- We do not sell or rent personal information.
- We do not export Customer Content in bulk. No extract endpoint exists. (See data sovereignty.)
- We do not share data across tenants. Multi-tenant isolation at D1 row and Vectorize metadata levels prevents cross-tenant queries.
- We do not run ad-tech trackers on truvyo.ai.
4. Where data lives
Customer's tenant data resides in Cloudflare D1 + Vectorize + R2 in the region designated for that tenant. Default is the United States; Enterprise customers can request EU or APAC. Anthropic API calls route through Anthropic's infrastructure per the Anthropic Privacy Policy.
5. Retention
| Category | Retention |
| Active tenant data (KB articles, conversations) | Retained for the life of the tenant |
| After tenant deletion | Purged within 30 days |
| Server logs (truvyo.ai + api.truvyo.ai) | 30 days |
| Billing records | 7 years (tax compliance) |
| Aggregated, de-identified usage metrics | Indefinite |
6. Your rights
Depending on your jurisdiction, you may have rights to access, correct, delete, or port the personal data we hold about you. To exercise these:
- If you're a Tenant Administrator: most controls are self-serve. Email support@truvyo.ai for items not exposed in the admin tools.
- If you're an end-user of a Customer's deployment: contact that Customer directly. Truvyo is a data processor for end-user content; the Customer is the data controller.
- EEA/UK/CA residents: additional rights under GDPR/UK-GDPR/CCPA apply. Contact privacy@truvyo.ai for a structured request.
7. Children
The Service is not directed at children under 13 (or under 16 in the EEA). Customers deploying Truvyo on surfaces that may collect data from minors must do so under their own COPPA/GDPR-compliant procedures.
8. International transfers
Truvyo is a Delaware company. Data may be transferred to and processed in the United States. EEA/UK Customers can request EU data residency on the Enterprise tier; for those customers, transfers outside the EEA happen only under the EU Standard Contractual Clauses, included by reference in the DPA.
9. Changes to this Policy
We'll post material changes here with at least 30 days' notice to Customer's primary email. The "Effective date" at the top tracks the current revision.
10. Contact
Privacy enquiries: privacy@truvyo.ai
Security disclosures: security@truvyo.ai
General legal: legal@truvyo.ai