Legal

What we collect, and what we do with it.

Written for a person who wants a straight answer. What we hold, which vendors touch it, how long it stays, and how to ask us to hand it over or delete it.

Last updated 2026-09-17.

TruLata LLC is a New Mexico limited liability company with its principal place of business at

712 H St NE, Suite 696, Washington, DC 20002. In this document, "we" and "TruLata" mean that company,

and "you" means you, whether you are visiting our website or your company holds a TruLata platform account

account.

---

Who this is for

This notice covers two things, and you can tell which part applies to you.

An ordinary visit to trulata.com. Reading the site, filling in a form on it, or writing to us

through it. The section "Visiting trulata.com" below is for you, and so are the sections on text

messages, children, changes and contact.

The TruLata platform. The dashboard your team signs into, and the sign in page. Everything from

"What do we collect?" onward is for you, and it explains what we collect, why, who else touches it,

and how long we keep it.

It does not cover your own website, your own CRM or your own advertising accounts. Those are yours

and your own privacy notice covers them.

How we handle personal information, in general

These commitments apply to everything in this notice, a website visit and the product alike.

  • We collect and use personal information solely to fulfil the purposes we have stated, and for

other compatible purposes, unless we have the consent of the person concerned or the law requires

otherwise.

  • We only keep personal information as long as we need it for those purposes.
  • We collect personal information by lawful and fair means and, where appropriate, with the

knowledge or consent of the person concerned.

  • Personal data should be relevant to the purposes it is used for, and, so far as those purposes

need it, accurate, complete and up to date.

  • We protect personal information with reasonable security safeguards against loss or theft, and

against unauthorised access, disclosure, copying, use or modification.

  • We make information about our policies and practices for managing personal information readily

available to customers. This page is that information.

Visiting trulata.com

You can read trulata.com without telling us who you are.

If you fill in a form or write to us, we collect what you type. Depending on the form, that is

your name, your email address, and sometimes your company, your website, your phone number or a

message. We use it to answer you, to arrange the session or the demo you asked for, and to follow up

about our own services. Our forms are protected by Google reCAPTCHA, which checks that a submission

came from a person.

The public site carries advertising and analytics tags, because it is how we market ourselves.

It loads Google Analytics, a Meta pixel, PostHog product analytics, an OpenAI advertising

measurement pixel, and the Apollo website visitor tracker. These tell us which pages get read, which

adverts brought someone, and which forms get completed. Our public demo at demo.trulata.com carries

them too.

Client dashboards are different. There is no advertising tag and no advertising pixel on your

dashboard. The only analytics there is PostHog, and the section below says exactly what it records.

Text messages and mobile information

If you give us a mobile number, whether on a form on our website or inside the dashboard, this is

how we treat it.

No mobile information will be shared with third parties/affiliates for marketing/promotional purposes. All other categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties

---

The TruLata platform

The rest of this notice is about the dashboard your team signs into and the sign in page.

What do we collect?

1. Your sign in email address. That is all the sign in page asks for. There are no passwords in

the product at all.

2. Activity records. Every time someone changes something in the dashboard we write one row:

which company, the signed in email address, what was requested, whether it succeeded, the IP address

and the browser user agent. We also write one row for each step of signing in: a link requested, a

link refused for hitting a rate limit, a successful sign in, and a link someone tried to reuse. The

email address on these rows is always the verified one from the session, never one a page supplied.

Reading a page is not written to that log. It is a record of changes, not of browsing.

3. How people move through the dashboard, including a masked session replay. This has its own

section below, because it deserves one.

4. Your business data, pulled from accounts you connected. Web analytics, search performance,

advertising spend and results, leads, contacts, social posts, jobs, revenue, email campaign figures

and similar, depending on which sources you connected. This comes from your own accounts, on your

instruction.

5. What your team writes in the dashboard. Notes on a lead, comments on a scheduled post, support

tickets and their replies, and files or videos you upload.

6. Support messages. What you write to us in a ticket or by email, and our replies.

Why do we collect it?

  • The email address, to know who you are and whether you hold a seat. There is nothing else to

identify you by.

  • The activity records, for security. They are how we answer who changed what, and how we investigate

if something goes wrong. They are also how the sign in rate limit is counted.

  • The usage records and replay, to find faults and to see which views are actually used.
  • The business data, to build the dashboard you are paying for and to do the marketing work in your

services agreement.

  • What your team writes, to carry out the action you asked for.
  • Support messages, to answer you.

We do not sell any of it. We do not use your business data or your customers' data to advertise to

anyone.

Do we record how you use the dashboard?

Yes, and here is exactly what that means.

We use PostHog, a product analytics service, on every client dashboard. It records which views are

opened, what is clicked, how far a page is scrolled, and where someone stalls. **It also records a

replay of the session.**

Every text value and every form input in that replay is masked. The dashboard sets PostHog to

mask all inputs and to treat every element on the page as text to be masked. What the replay shows is

the shape of the page: the layout, the buttons, the menus, which view was open and where the cursor

went. Every figure, name, email address, lead record and typed character is rendered as a block. The

replay does not show your revenue, your leads, your customers' details, or anything anyone types into

the page. We checked this setting on the dashboards themselves before writing this paragraph, and it

is set the same way on all of them.

PostHog is also told the email address of the person signed in and which company they belong to, so

that a fault can be traced back to a real session. Our own staff addresses are opted out of this

recording entirely. PostHog holds this data in the United States.

**If you would rather your dashboard was not recorded at all, write to [email protected] and we

will turn it off for your company.**

One more thing, stated so there is no surprise. Our public demo at demo.trulata.com, which is not

your dashboard, also loads a Google tag and a Meta pixel for our own advertising.

Client dashboards load neither. There is no advertising tag and no advertising pixel on your

dashboard.

Who decides what happens to the data?

You do. For the business data and the personal information inside it, you decide why and how it

is used, and we process it on your instruction to provide the service. We act as your service

provider, not as an independent user of your data.

There is one narrow exception, which we state rather than blur: for our own security records, the

activity and sign in logs, we set the retention period and we keep them even if you ask us to delete

everything. The reason is in the deletion section below.

Who else touches your data?

Two different things get confused here, so they are split.

Vendors that hold or process your data for us. These are the companies our service runs on. Every

client's data touches all of these.

VendorWhat it does with your data
CloudflareServes every dashboard, holds each company's dashboard files, runs the sign in pages, and applies the rate limits.
RenderRuns the service every dashboard reads from, and the database that holds seats, dashboard payloads, activity logs, support tickets and encrypted connection tokens. Hosted in Ohio, United States.
GoogleThe sign in link is sent through Google's mail service from our own address. Google also runs the consent screen when you connect one of your own Google accounts.
PostHogProduct analytics and the masked session replay described above, including the signed in email address. Held in the United States.
AnthropicPowers the ask and generate features inside the dashboard. It receives the question and the figures needed to answer it, and anything a person types into that box.
ChargebeeSelf serve checkout and subscription billing, where you signed up that way. Card details are entered on their hosted page and never reach our systems.

Your own connected accounts that we read from. These are yours. We read them because you

connected them or gave us access. Which ones apply depends on what you use.

Google Analytics, Google Search Console, Google Ads, Google Sheets, GoHighLevel, your job management software, Stripe,

Meta (Facebook and Instagram), ActiveCampaign, Apollo, Smartlead, Google reCAPTCHA on your forms, and

your own website, including WordPress form submissions read as leads.

This list may change as the product changes. When it does, we update this page. We do not commit to

telling you in advance.

Google user data

This part applies when you connect a Google account to the TruLata platform through Google's own consent screen. It describes exactly what we do with the data Google gives us access to.

What we access. Only what you grant on that screen, and only for the accounts you then choose in the dashboard:

Google serviceWhat we read
Google AnalyticsReports for the properties you choose: visits, where visitors came from, pages viewed and conversions.
Google Search ConsoleSearch performance for the sites you choose: the searches you appear for, which pages appear, clicks, impressions and average position.
Google AdsAccount and campaign performance for the accounts you choose: spend, clicks, conversions and cost per conversion.

Analytics and Search Console access is read only. Google grants Ads access through one permission that would also allow changes, but the TruLata platform only reads it: it never creates, edits, pauses or removes anything in your Ads account. We do not access your email, contacts, calendar, files or any other Google data, and we never see your Google password. We keep an encrypted access token so the dashboard can update itself.

How we use it. Only to provide the TruLata platform to you: to show those figures in your company's dashboard to the people you have given a seat, to work out the comparisons and summaries shown there, and to answer questions your team asks the assistant about your own figures. We do not use Google user data for advertising, we do not sell it, and we do not use it to develop, improve or train general artificial intelligence or machine learning models. Our staff look at your dashboard only when you ask us for help, to investigate a fault or a security issue, or when the law requires it.

Who we share it with. The people at your company you give a seat to, and the service providers the TruLata platform runs on, only as far as they need it to run it for us: Render, which hosts the database and the service that reads your Google accounts; Cloudflare, which serves your dashboard and stores its files; and Anthropic, which receives the figures needed to answer a question your team asks the assistant. We do not share, sell or transfer Google user data to anyone else, including advertisers and data brokers, unless the law requires us to.

Stopping access. You can disconnect Google at any time from the Integrations tab, or from your Google Account under third-party connections, which ends our access. When your subscription ends we delete our copy of the access token. To have figures we already hold deleted, write to [email protected].

TruLata's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

How long do we keep it?

WhatHow long
Activity log and sign in log12 months, then exported and removed. A job runs daily to enforce it.
Spent sign in link tokens1 day, cleaned as each link is used
Seat records, including removed seatsKept, as the record of who had access and who was removed
Dashboard payloadsLatest per company, plus 30 days of history
Lead data inside those payloads90 days. Your own CRM stays the system of record.
Support tickets and replies24 months after the ticket is resolved
Your dashboard files and uploaded video30 days after your last paid day
BackupsDaily copies for 30 days, weekly copies for 12 weeks
Database point in time recovery7 days

PostHog holds its usage records and replays for the period set in our PostHog account, and a replay

that has aged out there is gone.

How do we protect it?

Stated as facts, not as a claim about any standard. **We hold no security certification and we have

not been audited.** We do not claim to be compliant with any framework.

  • Signing in is a link sent to your email address, good for fifteen minutes and burned when it is

used, so a second use is refused and recorded.

  • The session is a signed cookie, marked HttpOnly and Secure, checked on every single request.
  • Every request to a dashboard is checked against the seat table before any file is served. A company

with no seat records is refused.

  • Removing someone takes effect within thirty seconds. The decision is cached for thirty seconds and

is keyed to the company and the email address together.

  • Your company's data is separated from every other company's. Before any of your dashboard's code

runs, every other company's storage and every master key is deleted from its environment, and it

gets a key derived for your company alone.

  • Automated checks run before every release, including one that signs in as a customer of one company

and tries to read every other company's pages, data and files. Anything but a refusal stops the

release.

  • Connection tokens to your accounts are stored encrypted in the database.
  • Every response carries HTTPS enforcement and anti framing headers.
  • The sign in page answers identically whether an address is known or unknown, so it cannot be used

to find out who works at one of our clients.

  • Activity and sign in logs are append only. Nothing in the service updates or deletes a row.
  • Who did what is not readable by another company. It takes an administrative credential that only

our own service holds.

  • The database has point in time recovery enabled, and a restore was rehearsed on 2026-09-17.

Two things we are open about rather than dressing up: we are a small team with no on call rotation,

and we have open items on our own access review, including narrowing which networks may reach the

database.

If we confirm someone reached your data who should not have, we write to your named contact within

seventy two hours of confirming it, and within twenty four hours if it is still happening.

Your customers' personal information

Your leads, contacts, form submitters, subscribers and customers appear in the dashboard, including

names, email addresses and phone numbers. That information is yours and it is your responsibility.

  • You decide what is collected on your own forms and in your own CRM, and your own privacy notice has

to cover it.

  • We hold it to show it to you and to do the work you asked for.
  • Lead records are read from your own system when a page asks for them. They are never written into a

published web file or into our source code. A copy can sit in the saved dashboard payload.

  • If one of your customers asks you to delete their information, delete it in your own system, which

is the system of record. Tell us and we remove any copy we hold.

How do I ask for access or deletion?

Write to [email protected] and tell us who you are and what you want. **We answer within thirty

days.** We offer this to anyone who asks, wherever they live. We are not going to make you prove

which state or country you are in first.

Access. We give you what we hold about a named person, or your company's data, in a readable

form.

Deletion. If you ask us to delete your company's data, we revoke seats the same day, remove your

dashboard files and payloads, and send you written confirmation naming what was removed and what was

kept.

What we will not delete: the activity log and the sign in log. These say who opened the account

and when. They are the security record of access rather than your business content, and deleting them

on request would destroy the evidence that protects both of us if access is ever questioned. They are

kept for twelve months and then removed on their own schedule.

Backups are not edited one record at a time. A copy inside a backup ages out on the rotation above.

Cookies and browser storage

NameWhat it doesHow long
tl_sessionProves you signed in. Holds your email address, an expiry and the companies you could open when you signed in. Signed, HttpOnly, Secure, SameSite Lax, set across trulata.com.30 days
A cookie whose name starts with ph_Set by PostHog, so the usage records and the replay above can tell one visit from the next.Set by PostHog

Signing out at the sign in site clears the session cookie on every dashboard at once.

There are no advertising cookies on the dashboard.

---

The site builder

This part is about the TruLata site builder, where you make and edit a website, and about the sites it serves.

What do we collect when you build a site?

1. Your sign in email address, the same way as the TruLata platform: a link to your inbox, no password. A site you make belongs to the address that made it.

2. What you tell us about your business. Your answers to the setup questions, every one of which is optional: your business name, the contact details you choose to show, what you offer, where you work, your hours and anything else you add. We keep them to write your first version and to show where each sentence came from.

3. What you point us at. If you give us your current website, we read its public pages. If you ask us to import a Google Business Profile listing that we manage, we read its hours, photos, reviews and rating.

4. What you upload. Photos, your logo and documents. When we save a photo we re-save the image itself, which drops the camera details a phone stores inside it, including its location.

5. Your site. The words, settings and every published version, so you can undo a change or bring back an earlier version.

6. Billing, if you take a site live. Your plan and the billing records Chargebee returns to us. Card details are entered on Chargebee's hosted page and never reach our systems.

People who visit a site made with the builder

If a visitor sends a message through the site's own contact form, we receive what they typed: their name, email address, phone number, the service they chose and their message, plus the time and the page they sent it from. We keep it so the site's owner can read and answer it. That message belongs to the site's owner, and the owner's own privacy notice has to cover it. The builder adds no advertising tags or advertising cookies to your site. Cloudflare, which serves the pages, may count page views with its own analytics, which sets no cookies.

Who else touches it?

VendorWhat it does with your data
CloudflareServes your site and stores its files, your uploads and form messages until we collect them.
RenderRuns the builder and the database that holds your sites, answers and form messages. Hosted in Ohio, United States.
AnthropicWrites the first version and makes the changes you ask for in plain words. It receives your answers, the text of your current site and what you type to the assistant.
PexelsSupplies licensed stock photos. It receives the words you search for.
GoogleSupplies your Business Profile listing when you ask us to import it, and sends the sign in link from our own address.
ChargebeeCheckout and subscription billing for a site you take live.

How long do we keep it, and how do I delete a site?

We keep a site, its versions and its uploads for as long as you have it. Write to [email protected] to delete a site: we take it off the air, then remove its files, its versions, your uploads and its records, and confirm in writing. Form messages the owner has already received stay with the owner.

---

Applies to both

Children

Our website and the TruLata platform are for businesses. Neither is directed to anyone under 18, and

we do not knowingly collect information from anyone under 18. If you believe a child's information

has been given to us, write to [email protected] and we will remove it.

Changes to this notice

When we change this notice, we post the updated version with a new date at the top of this page. For

a change that materially affects a TruLata platform customer, we email the account owner. Continuing

to use the site or the dashboard after that is acceptance of the new version.

Contact us

TruLata LLC

712 H St NE, Suite 696

Washington, DC 20002

[email protected]

FAQ

Questions, answered.

Let's build your
growth machine.

Tell us where you want to grow and we will map exactly where your next wave of growth comes from, in writing, within one business day.

Get in touch See TruLata