Privacy Policy
Last updated September 29, 2026.
Who this covers
This policy says what personal information Truss Legal Inc., a Delaware corporation (“Truss”), collects from the people who meet its service, and what it does with it. It covers visitors to trusslegal.com, people who book a demo or write to Truss, the attorneys and staff of the organizations that use the service (the “customer”), and the witnesses who join a session from a link a customer sent them.
What a customer and its witnesses put into the service is customer content. The customer owns it, and the Terms of Service govern how Truss handles it. The Witness Terms are the witness's agreement. This policy says what personal information is in the service and where it goes; the Security page says how it is protected.
Visitors
The public pages set no cookies, run no analytics, and carry no advertising trackers. Each page reports its load timing and any error to Sentry, without the visitor's address. Truss's hosts, Vercel and Railway, keep their own request logs, which include the address a request came from, for their own short windows.
Booking a demo happens on Cal.com, which passes the name, email address, and time to Truss. Truss posts them to its own Slack and keeps them in its reminder queue, which is cleared within 30 days of the demo. Writing to Truss gives it the email address and whatever the message says.
Customer accounts
An account is an email address, the organization it belongs to, and a role in it. An organization also has a name and a billing email address. Signing in is a link emailed to that address; the service sets cookies only to sign in and to hold the signed-in session. Inviting a colleague stores their email address until the invitation is accepted or expires.
Payment cards go to Stripe and never to Truss. Stripe sees the billing email address and each invoice line, which names the witness, the matter, and the person who created the session link.
Witnesses
A witness has no account, and Truss does not email them; the customer sends the session link. What the service holds about a witness is what the customer entered, the witness's name and role and the customer's notes, and what the session produced: the recording, with audio and video; the transcript; the report; and, only if the witness ticked the camera box on the session page, measurements taken from the geometry of their face and body and the observations made from them. Truss does not use those measurements to identify anyone.
The session page reports timing, connection trouble, and the outcome of its microphone and camera checks, and never what was said. Truss keeps a record of each witness's acceptance of the witness terms: the session, the time, the version and language accepted, and the answer to camera analysis. The record holds no name.
Operational data
Truss's own logs hold ids, timings, counts, and status codes, never testimony, prompts, or document text. Error reports go to Sentry with addresses and tokens scrubbed and with no request bodies; the browser sends no address, and the session page is never replayed. The record of each call to an AI model holds counts and lengths, and its output is cleared after 7 days.
How Truss uses it
Truss uses personal information to run the service, bill for it, secure it, support the people using it, and answer them. Truss does not use customer content, including recordings and transcripts, to train AI models, and does not sell personal information or share it for advertising.
Who receives it
Truss runs on service providers, which process personal information under their agreements with Truss and for no purpose of their own. Supabase holds the database, the documents, and sign-in; Amazon S3 holds the recordings; Vercel and Railway host the web app and the api and store no customer content. OpenAI receives the transcript and the case materials, and Tavus, with its recording service Daily, receives the witness's audio and video; the witness's browser connects to them directly, so they see its address. The Security page says what each sees and that neither keeps it. Stripe handles payment, Resend sends the emails, Sentry holds error reports, Slack carries Truss's own alerts and demo bookings, and Cal.com takes demo bookings.
A witness's recording, transcript, report, and camera observations go to the customer that arranged the session, which decides who sees them. Truss may disclose personal information when it believes in good faith that the law requires it, and where the law allows and it is practicable, will try to tell the customer first. If Truss is sold or merged, personal information goes with the business, under this policy.
How long it stays
A session recording is deleted on its deletion date: 30 days after it lands by default, up to 365 by the matter's setting, or a date the customer moves or clears. Camera measurements and the observations made from them are destroyed, backups included, no later than 90 days after the session, or sooner when the session is deleted. Transcripts, reports, documents, and notes stay until the customer deletes them or its agreement ends. Account information stays while the account does. The session page's telemetry and the record of AI calls are deleted after 90 days. The record of a witness's acceptance of the witness terms stays after the session is deleted. Once deleted, content is gone from every copy Truss controls within 7 days, which is how long the database's backups are kept, and service providers remove their copies under their own agreements.
Your choices
A witness who wants to see, correct, or delete their information can ask the organization that arranged the session, which holds it, or write to Truss at privacy@trusslegal.com. Truss may need to consult that organization before acting. A witness declines camera analysis by leaving its box unchecked on the session page.
A customer deletes sessions, witnesses, matters, and documents from the service itself, and can ask Truss to delete an account or an organization. Anyone can ask what personal information Truss holds about them, ask for it to be corrected or deleted, and ask questions about this policy, at the same address. Truss answers within 45 days, does not sell personal information, and does not treat anyone differently for asking. Where a state privacy law gives more rights, Truss honors them; for customer content, Truss acts as the customer's service provider and refers a request to the customer.
Security
The Security page says where personal information lives, how it is encrypted, and who at Truss can reach it. If Truss learns of an incident affecting a customer's content, it notifies the customer within 72 hours.
Children and location
The service is for adults in the United States. Truss does not knowingly collect information from anyone under 18; a witness confirms they are 18 or older before a session starts. Personal information is stored and processed in the United States.
Changes
When this policy changes, the date at the top changes with it. Truss tells each organization by email, at its billing address, about a change that affects how its information is handled.
Contact
Questions and requests about privacy go to privacy@trusslegal.com. Everything else goes to max@trusslegal.com.