Your data stays yours. Always.
Overview
This Privacy Policy is Trueleveler's explanation of how it collects, uses and protects information when you use its services.
Short version: Documents you submit for one-off analysis are processed in memory and the files aren't stored. AI results are kept for up to 7 days to speed up repeat runs, then deleted automatically. Engine runs inside a project are saved in that project's Engine History, most of them with their results, until you delete the project. Files you choose to save into your project workspace (the Documents area, Drawings, or engine PDFs you save) are kept in your private, encrypted, access-controlled storage so you can use them again. We retain document text for cross-document search only if an organization owner turns that setting on — it is off by default. We never use your procurement documents to train AI models, and we collect only what's needed to run the service and communicate results.
Trueleveler ("we", "our", "us") operates the AI procurement analysis platform available at trueleveler.com and its subdomains. This Privacy Policy explains how we collect, use, and protect information when you use our services.
By using Trueleveler, you agree to the collection and use of information as described in this policy. If you do not agree, please do not use the service.
What We Collect
Account information
When you create an account, we collect your email address and a password (stored as a one-way hash). You may optionally provide your name and company. We do not collect payment card details directly — all billing is handled by Stripe, which is PCI-DSS Level 1 certified.
Usage data
We collect anonymised usage telemetry: which analysis engines you use, how many analyses you run, general session duration, and error rates. This data does not include the contents of your documents. It is used to improve product reliability and prioritise features.
Communications
If you contact us by email or submit a free analysis request, we store the email address and message content to respond to your enquiry and deliver your results. Free analysis result emails are sent via our transactional email provider (Resend) and are retained for 30 days for deliverability purposes.
When you create an account you choose whether to receive our weekly product email. If you do, we keep a record of that choice with your subscription: the wording next to the box, when you made the choice, whether you ticked the box yourself or left it ticked as shown, and the country we used to decide how to show it. That country is worked out from your IP address by our hosting provider (Vercel), and we keep it only as part of this record. The box starts ticked only for visitors in the United States. Every one of these emails has a one-click unsubscribe link.
Technical data
We collect standard server logs including IP address, browser type, referring URL, and timestamps. These are retained for up to 90 days for security and abuse prevention purposes.
Public notices and permit records
The Opportunities list is filled with public information that we bring in from government sources: federal construction notices published by SAM.gov, building-permit records that cities and counties publish as open data, and public construction bids and awards that cities publish the same way. Our servers read these sources once a night, what they read is the same for every customer, and nothing about you or your organization is sent to them. The sources we read today are listed under Public lookup services in our Data Processing Agreement. This information is about projects, not about the people who use Trueleveler.
We keep what a source publishes about a project, such as its title, the agency or city behind it, the address or place of the work, its dates, its value and size where given, and its description where it has one. We do not keep the contact fields that these sources publish (for example a government contact’s name, email address and phone number, or a vendor’s phone number and email address): we ask the portals only for the fields we use, and our program skips the contact columns of the federal file as it reads it. We also remove the email addresses and phone numbers that we find in a description before we store it. A federal lead links to the notice’s own page for anyone who needs a contact.
We do not read the name of the owner or of the applicant from a permit record. Where a permit or a city’s award list names a contractor or a winner, we keep the name only when it is clearly a company’s, for example one with an ending such as LLC or Inc, and not a person’s own name. A federal award notice names its winner, and we keep that name as the notice gives it.
We compare this information with the trade and the Pursuit profile (for example where you work, project types, and value and size ranges) that your organization sets in Settings, and show what fits in your organization’s Opportunities list. What you do with a lead (save it, dismiss it, add a note, edit it) is your organization’s own data and stays in your workspace like your other records.
Your Documents
One-off analysis is processed in memory. When you submit a document just to run an analysis — a bid, contract, invoice, PO, or RFQ — it is transmitted over TLS 1.2 or higher, processed entirely in server memory, and discarded immediately after the analysis response is returned. That analysis path does not write the source file to any database, object storage, or log file. The AI results are kept for up to 7 days to speed up repeat runs, then deleted automatically. Engine runs inside a project are saved in that project's Engine History, most of them with their results, until you delete the project.
Files you choose to save are stored in your private workspace. When you upload a file to the Documents area, add a drawing set, or save an engine PDF to a project, you are deliberately filing it for later use, so we keep it. Saved files live in private, organization-scoped object storage (a shared bucket gated by row-level access controls) protected by encryption in transit and at rest, so only members of your organization can reach them. You can delete them at any time, and they are removed when you delete the project or close your account.
Cross-document search retention is opt-in. An organization owner or admin can turn on "Store my documents for cross-document search" in Settings. It is off by default. When off, we do not retain document text for search. When on, the text of saved documents is retained so search and cross-document questions can reference it; turning it back off stops retaining text from new documents but does not retroactively delete text already indexed — to remove that, delete the document or contact support.
Document content is transmitted to an AI processing API for analysis. This transmission is covered by the provider's API data processing terms, which prohibit the provider from using API-submitted data to train its models.
We never use your procurement documents, bid data, or contract contents to train our own models or any third-party model.
Desktop Meeting Recorder
The Trueleveler desktop app (Windows/macOS) can record and transcribe a meeting when you start a recording, and reminds you before each recording to let everyone on the call know it's happening — recording without consent may be unlawful in some places, and that is your responsibility as the person recording.
Presentation slide capture is off by default. If you turn it on in the app's settings, it periodically screenshots a screen you choose while a recording is in progress, saving still images of slide changes alongside the recording (not a continuous video or every frame — only when the captured screen visibly changes). It never captures a screen you have not explicitly selected.
Recorded audio, transcripts, and any captured slides are saved to your project like other files you deliberately save (see "Your Documents" above), and are subject to the same retention: kept until you delete them, delete the project, or close your account.
How We Use Your Data
We use the data we collect for the following purposes:
- Service delivery — to run analyses, deliver results by email, and maintain your account history
- Opportunities — to match public federal notices, city and county building permits, and public bids and awards to the trade and Pursuit profile your organization sets in Settings, and to show the matches in your Opportunities list
- Product improvement — anonymised usage patterns to fix bugs, improve accuracy, and prioritise features
- Security — to detect and prevent abuse, fraud, and unauthorised access
- Communications — to send you your analysis results, account notices, and (with your consent) product updates
- Legal compliance — to comply with applicable law, regulations, and lawful requests from authorities
We do not use your documents or project data for advertising. The one advertising tool on our site is the LinkedIn Insight Tag on our public pages, which loads only if you accept marketing cookies (see Cookies & Tracking below). We do not sell your data to any third party. We do not use your documents or analysis results for any purpose other than delivering the service to you.
Data Sharing
We share data only with the following categories of service providers, under contractual obligations that restrict their use of the data:
- Supabase — database, authentication and file storage (account data, project data, saved files). Hosted in the European Union (AWS eu-central-1, Frankfurt).
- AI inference providers: Google (Gemini) and Anthropic (Claude) — AI analysis. Gemini runs most engines and transcribes meeting audio; Claude runs Contract Review and a few others; each takes over when the other is unavailable. Document text (and, for Gemini, meeting audio) is sent for analysis. It is not used to train their models, and each provider keeps it only for a limited period under its API terms.
- Vercel — hosting and compute infrastructure. Our application servers (serverless functions) run in the European Union (Frankfurt); static files and request routing use Vercel’s global edge network. Vercel is a United States company.
- Stripe — payment processing (billing data only; we never see raw card numbers)
- Resend — transactional email delivery (email address and analysis result content, 30-day retention)
- Sentry — error monitoring (stack traces, browser metadata, anonymised IPs)
- Microsoft Clarity — session-replay and heatmap analytics for product usability, consent-gated (see Cookies & Tracking below)
- LinkedIn Insight Tag — conversion analytics for our LinkedIn advertising, consent-gated (see Cookies & Tracking below)
- Google Analytics 4 — aggregate traffic measurement on our public marketing pages, IP-anonymised and consent-gated (see Cookies & Tracking below)
- HeyCatch — website visitor analytics on our public marketing pages (page views and clicks), consent-gated (see Cookies & Tracking below). HeyCatch, Inc. is a United States company and stores this data in the United States. It may also pass the data to AI model providers, through OpenRouter, Inc. (United States), to power its analytics features, under policies that prohibit training on it; those providers may keep prompts for a limited period for abuse prevention.
- Google Maps Platform — address autocomplete and business search when you type an address or look up a vendor (the text you type)
- Firebase Cloud Messaging (Google) — push notifications to the Trueleveler mobile app (device push token and notification text)
Public lookup services. The app also calls three services for public information: ipapi.co (Kloudend, Inc., USA), once and directly from your browser, to learn which country you are in; open.er-api.com (ExchangeRate-API, South Africa), directly from your browser, for currency exchange rates; and Open-Meteo (OpenMeteo GmbH, Switzerland), from our servers, for weather and place lookups on a project’s location. The first two receive your IP address and browser details; Open-Meteo receives the project’s address or city name.
Integrations you connect. If you connect your own DocuSign account, documents you send for signature go to DocuSign with the signers’ names and email addresses. If you connect your own Microsoft Outlook mailbox, we get read-only access to it; today we read its profile (name and email address). Your own agreement with each provider governs what it does with that data.
If you connect your own company in QuickBooks Online (Intuit), we do not contact QuickBooks until someone in your organization who is allowed to post to the ledger chooses Connect under Settings → Integrations and approves access on Intuit’s own sign-in page; we never see your QuickBooks password. Once connected, we read your company’s name, its chart of accounts and its vendor list, so you can map them to your own accounts and vendors. Nothing is written to your books until someone with the same permission also switches on posting, which is off by default, and chooses Sync now. We then send your posted general-ledger journal entries: date, reference, descriptions, the QuickBooks accounts you mapped, and amounts. Open purchase orders are shown as QuickBooks bills inside Trueleveler as a preview only; we do not create bills, vendors or bill payments in QuickBooks. If you never connect QuickBooks, nothing goes to it.
We keep your QuickBooks company name and ID, the access tokens Intuit gives us, the account and vendor mapping you save, and a record of which entries were sent. The tokens are stored in our database and used only by our servers; your browser cannot read them. To disconnect, choose Disconnect on the same Settings → Integrations card: we ask Intuit to revoke our access and delete the stored tokens, company name and ID. You can also remove Trueleveler from inside QuickBooks Online. Entries already sent stay in your QuickBooks until you delete them there. Intuit Inc. and its group companies handle what reaches QuickBooks under their own terms and Privacy Statement, which also says where they store and process data.
The full list, with each service’s location and the data it receives, is in our Data Processing Agreement.
We do not share your data with advertisers, data brokers, or analytics resellers. We do not sell personal data under any circumstances.
In the event of a merger, acquisition, or sale of assets, user data may be transferred to the acquiring entity, subject to the same privacy protections described here. We will notify affected users by email prior to any such transfer.
Data Retention
- One-off analysis documents: Files you upload for an analysis aren't stored. AI results are kept for up to 7 days to speed up repeat runs, then deleted automatically.
- Engine runs in a project: Engine runs inside a project are saved in that project's Engine History, most of them with their results, until you delete the project.
- Saved files (Documents, Drawings, saved engine PDFs): Files you deliberately save to a project are stored in your private, encrypted, organization-scoped storage and retained until you delete them, delete the project, or close your account
- Cross-document search text: Off by default. Retained only while an organization owner has enabled "Store my documents for cross-document search"; turning it off stops retaining text from new documents but does not retroactively delete already-indexed text (delete the document to remove it)
- Analysis results (saved sessions): Retained until you delete them or close your account
- Procurement Tracker data: Items you add to the Procurement Tracker (descriptions, PO numbers, vendor details, amounts, dates) are stored persistently in your account database and retained until you delete them or close your account
- Submittal Tracker data: Submittals, revision history, and extracted spec text are stored persistently in your account database and retained until you delete them or close your account
- Vendor Database: Vendor names, contact details, ratings, and notes are stored persistently in your account database and retained until you delete them or close your account
- Opportunities (leads, notes and activity): Leads in your organization’s Opportunities list, whether the nightly feed added them or a person typed or imported them, and the notes and activity on them, are stored in your account database and retained until you close your account. A lead you delete leaves your list, but its record stays in your account database until you close your account; the nightly feed relies on it so that a lead you deleted is not added again. When you close your account, your organization’s leads are deleted, with their notes and activity. The public notices, permit records, bids and awards themselves are kept in a shared pool that is the same for every customer and holds none of the contact fields described under What We Collect; an item that its source stops listing is marked closed, and we delete it 180 days after it closed.
- Desktop meeting recordings, transcripts, and slide captures: Presentation slide capture is off by default and, like recordings and transcripts, is stored in your project and retained until you delete it, delete the project, or close your account
- Account data: Retained until you request deletion, plus 30 days for processing
- Free trial data: Retained for 90 days, then automatically deleted unless you create an account
- Email analytics: Retained for 12 months
- Server logs: 90 days
- Billing records: 7 years (legal requirement)
Security
We take the security of construction procurement data seriously. Our security measures include:
- Encryption for all data in transit (TLS 1.2 or higher)
- In-memory processing for one-off analysis — those source files are not written to persistent storage; files you save to your workspace are stored with encryption in transit and at rest, and row-level access control
- Supabase row-level security — users can only access their own data
- Server-side API key management — your AI analysis requests are proxied server-side; API keys are never exposed to the browser
- SOC 2 is on our roadmap
No system is perfectly secure. If you discover a security vulnerability, please report it to security@trueleveler.com. We aim to respond to security reports within 24 hours.
GDPR Rights (EEA & UK Users)
If you are located in the European Economic Area or the United Kingdom, you have the following rights under the General Data Protection Regulation (GDPR) and UK GDPR:
- Access — you can request a copy of the personal data we hold about you
- Rectification — you can correct inaccurate data via your account settings or by contacting us
- Erasure — delete your account and data by emailing support@trueleveler.com with subject "Erasure Request." We will confirm deletion within 14 days. Billing records required by law may be retained per our retention schedule.
- Portability — request your data in JSON format by emailing support@trueleveler.com with subject "Data Portability Request." We will provide your account profile, saved analysis metadata, and activity log within 30 days. Note: files you saved to your workspace remain downloadable directly in the app; documents submitted only for one-off analysis are processed in memory and are not retained.
- Restriction — you can ask us to restrict processing of your data in certain circumstances
- Objection — you can object to processing based on legitimate interests
- Withdraw consent — where processing is based on consent, you may withdraw it at any time
Our lawful basis for processing is: contract performance (to deliver the service you signed up for), legitimate interests (security, fraud prevention, product improvement), and consent (marketing communications).
How to Exercise Your Rights
- Email support@trueleveler.com with your request
- We will verify your identity and respond within 30 days
- For erasure requests: we will delete your account, all saved analyses, vendor data, and project data within 14 days of confirmation. Billing records required by law may be retained per our retention schedule.
- For data portability: we will provide a JSON export of your data — including your account profile, saved analysis metadata, vendor records, and activity log — within 14 days. Note: files you saved to your workspace remain downloadable directly in the app; documents submitted only for one-off analysis are processed in memory and are not retained.
You also have the right to lodge a complaint with your national data protection authority.
Data Protection Officer: Trueleveler is not required to designate a Data Protection Officer under GDPR Article 37. For all privacy matters, contact support@trueleveler.com.
CCPA Rights (California Residents)
Under the California Consumer Privacy Act (CCPA), California residents have the right to:
- Know what personal information we collect and how it is used
- Request deletion of personal information
- Request a copy of your personal information in a portable, commonly used format
- Opt out of the sale or sharing of personal information (we do not sell personal information; see below for sharing)
- Non-discrimination for exercising CCPA rights
How to Exercise Your CCPA Rights
- Email support@trueleveler.com with the subject line "CCPA Request"
- We will verify your identity and respond within 45 days
- For deletion requests: we will delete your account, all saved analyses, vendor data, and project data within 14 days of identity verification. Billing records required by law may be retained per our retention schedule.
- For data access requests: we will provide a copy of all personal information collected, including your account profile, saved analysis metadata, and activity log, within 45 days
- For data portability requests: we will provide your data in JSON format — including your account profile, saved analysis metadata, vendor records, and activity log — within 45 days. Note: files you saved to your workspace remain downloadable directly in the app; documents submitted only for one-off analysis are processed in memory and are not retained.
We do not sell personal information. If you accept marketing cookies, the LinkedIn Insight Tag sends LinkedIn the pages you visit on our public site for ad measurement, which California law may treat as “sharing”. You can switch it off at any time from Cookie Preferences; our Do Not Sell or Share page explains how. We don’t yet act on the Global Privacy Control signal automatically. We will not discriminate against you for exercising any CCPA rights.
Data Erasure & Data Portability
Regardless of where you are located, you can request deletion of your data or a portable copy of your data at any time. Here is a summary of the process:
To request data erasure or a data export, email support@trueleveler.com. Use the subject line "Erasure Request" or "Data Export Request." We will verify your identity and process your request within the applicable timeframe.
Data Erasure (Right to Deletion)
- What is deleted: Your account, all saved analyses, vendor records, project data, and activity logs
- What may be retained: Billing records required by law (up to 7 years per our retention schedule) and anonymised, aggregated usage data that cannot identify you
- Timeline: We will verify your identity and complete the deletion within 14 days of confirmation. Under GDPR, we respond within 30 days; under CCPA, within 45 days.
- Confirmation: You will receive an email confirming that your data has been deleted
Data Portability (Right to Export)
- Format: Your data will be provided in machine-readable JSON format
- What is included: Account profile, saved analysis metadata, vendor records, project data, and activity log
- What is not included: Documents submitted only for one-off analysis (processed in memory and not retained). Files you saved to your workspace are not part of the JSON export, but remain downloadable directly in the app for as long as you keep them.
- Timeline: We will deliver the export within 14 days. Under GDPR, the maximum response time is 30 days; under CCPA, 45 days.
- Delivery: The export file will be sent to your verified account email address via a secure, time-limited download link
If you have questions about either process, contact support@trueleveler.com.
Cookies & Tracking
We use a minimal set of cookies necessary to operate the service, plus four optional tools that only load once you've made a cookie choice:
- Session cookies — to keep you logged in (Supabase authentication token, first-party, session-scoped)
- Preference cookies — to remember your UI preferences such as currency selection (first-party, 1-year expiry)
- Microsoft Clarity (analytics) — session-replay and heatmap analytics (clicks, scrolls, navigation) so we can see how the product is used and fix usability problems. On our mobile app, financial and document content is masked from recordings. Only loads after you accept analytics cookies below.
- LinkedIn Insight Tag (marketing) — conversion tracking for our LinkedIn advertising. Only loads after you accept marketing cookies below.
- Google Analytics 4 (analytics) — aggregate traffic measurement on our public marketing pages (which pages are visited, and which referrer or campaign brought you). IP addresses are anonymised, and it runs under Google Consent Mode with analytics storage denied by default. It is not loaded inside the product itself, only on the public site. Only loads after you accept analytics cookies below.
- HeyCatch (analytics) — counts page views and clicks on our public website pages (which pages are visited, what is clicked, and which referrer or campaign brought you) so we can see how the site is used. It receives the page address, the page you came from, the text and link of what you click (not what you type into a form), your IP address and your browser and device details, and it keeps a random visitor identifier in a first-party cookie for up to one year and in your browser’s local storage. It does not make recordings of your visit. It is not loaded inside the product itself, only on the public site. Only loads after you accept analytics cookies below.
Outside of these four, we do not use other advertising cookies or tracking pixels — no Facebook Pixel, and no advertising-network trackers beyond the LinkedIn Insight Tag named above. All four are opt-in — nothing loads until you choose to accept, and you can change your choice at any time from Cookie Preferences (see Local Storage below). Clarity, HeyCatch and Google Analytics are gated on your analytics choice; the LinkedIn Insight Tag is gated on your marketing choice.
Local Storage
We use browser localStorage to persist your preferences locally on your device. Most of it never leaves your browser. The one exception is the first-touch attribution record described below: once you have accepted analytics cookies, what it holds is included with the product-analytics events we record. Nothing else in this list is transmitted. Items stored include:
- Language and currency preferences
- UI settings (dark mode, reviewer name)
- Cookie consent choice
- Email notification preference
- Company logo (if uploaded, stored as image data on your device only)
- First-touch attribution (
tl_first_touch) — recorded the first time you arrive through a campaign or referral link, and kept for 90 days: the campaign source, medium, name and content (theutm_tags on the link), any partner referral code, and, if you arrived by clicking a Google ad, Google’s ad-click identifier (gclid,wbraidorgbraid). A plain visit records nothing, and nothing is recorded if your browser sends Do Not Track. It is written in your browser when you arrive, but none of it is sent until you accept analytics cookies. After that, the source, medium, name, content and referral code travel with product-analytics events, and the whole record — ad-click identifier included — travels with the events that mark a sign-up, a first engine run or a purchase. Nothing else in this list is sent. - An anonymous visitor identifier (
tl_anon) — a random id stored in a cookie for one year so repeat visits can be counted as one visitor rather than several. It is not linked to your name or email, and it is only set once you have accepted analytics cookies.
You can clear localStorage at any time through your browser settings.
Children's Privacy
Trueleveler is a business-to-business software service. It is not directed at children under the age of 16. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us with personal information, please contact us and we will delete it promptly.
Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify registered users by email at least 14 days before the changes take effect. The "Last updated" date at the top of this page will always reflect the most recent revision. Continued use of the service after a policy update constitutes acceptance of the revised terms.
Contact Us
For privacy-related questions, data requests, or to exercise your rights:
- Email: support@trueleveler.com
- Security issues: security@trueleveler.com
- General: hello@trueleveler.com
Trueleveler · trueleveler.com · Privacy Policy · Effective March 1, 2026