Privacy Policy

Last Updated: July 10, 2026

This privacy policy ("Privacy Policy") discloses what information Trussi.AI ("Trussi.AI," "we," "us," or "our") gathers about you through our website at trussi.ai and any services provided through our website (collectively, the "Website") and when you use our applications and any services provided through our applications (collectively the "App"), however accessed, and discloses how that information is used. Trussi.AI owns and operates the Website and App, and we use the information we receive from them as described below. We do not sell your personal information, and we do not use your data - including data received from Google APIs or any other third-party integration - to train generalized artificial intelligence or machine learning models.

BY USING THE WEBSITE AND/OR APP AND SHARING YOUR INFORMATION WITH US, YOU CONSENT TO AND ACCEPT THE PRIVACY PRACTICES DESCRIBED IN THIS PRIVACY POLICY.

ONLINE AND MOBILE INFORMATION PRACTICES

We are committed to protecting your personal privacy as you visit our Website and/or App. Accordingly, this Privacy Policy informs you how we collect and use your information on our Website and through our App. If we make material changes to this Privacy Policy, we will indicate that by changing the "Last Updated" date at the top of this page.

INFORMATION WE MAY COLLECT

The information we collect varies depending on the type of activity you are performing on our Website or App and helps us personalize and continually improve your experience. Much of the Website and App can be accessed without providing any personal information. In all instances where we collect personal, financial, or other information through the Website and/or App, we specifically indicate that that information is being collected in order to provide you with the product or service you have requested.

ONLINE OR MOBILE ACCOUNT SERVICES

When you access our Website or App for products or services, we may need to collect personal, financial, and/or other information in order to complete your request. The information we collect varies depending upon the product or service you are using. Examples of information we may collect for our products or services include information such as your name, company name, address, employment and financial information, e-mail address, credit card or payment information (processed via our payment processors and not stored on our servers), client and project information, photos and documents you upload, and call, message, and email content you send or receive through the App.

BROWSING

When you visit our Website, we gather information including page requests (URL requests), time of your visit, your IP address, operating system, web browser software, and any cookies which were set during a previous visit to our site. IP address information is not distributed to third parties. We use this information to improve your overall experience. We use cookies to help with navigation through our web pages; they are not used to gather any personal information about users.

MOBILE LOCATION SERVICES

The App may utilize location services on your mobile device to collect and use location data, including the real-time geographic location of your device. If you consent to the App's utilization of location services, we may use GPS, Bluetooth, your device's unique identifier, and/or your IP address, along with Wi-Fi and cell tower locations, and other technologies to determine your device's geolocation. This location data is utilized to deliver services requested by you, including driving directions to job sites, attaching a location to photos, and live route tracking for production crews. We do not maintain a history of the location of a device, only where your device is at any given moment, except where you have explicitly enabled features that record location history (such as crew tracking). You may disable location services through our App settings or your mobile device settings at any time.

HOW WE USE YOUR INFORMATION

The information you provide to us is primarily used to deliver requested products and/or services and help us improve our products and services. We also use that information to deliver to you or contact you about the requested products/services or information. We may also use your personal information to provide important information about products or services that you have or are using, including security risks and updates. If you elect, we may send you information relating to our company, products, or services. If you do not want to receive such marketing communications from us, you may opt out by emailing support@trussi.ai.

WHO WE SHARE YOUR INFORMATION WITH

We limit the release of information and we require privacy protections in our business relationships. We do not sell customer information. We may share your information with:

  • Service providers and sub-processors that perform functions on our behalf - such as cloud hosting (Amazon Web Services), database management (MongoDB Atlas), error monitoring (Sentry), uptime monitoring (Better Stack), and content delivery (Cloudflare) - under contractual obligations of confidentiality and data protection.
  • Third-party integrations you connect (such as Google, DocuSign, QuickBooks, Twilio, ABC Supply, Beacon, RoofScope, EagleView, Meta Ads, and others), strictly in the manner you authorize.
  • Legal authorities when required by applicable law, subpoena, court order, or other legal process.
  • A successor entity in connection with a merger, acquisition, financing, reorganization, bankruptcy, or sale of company assets.

We never share, sell, or rent your data - including data received from any third-party integration - to advertisers, data brokers, or credit reporting agencies.

MOBILE DATA SHARING

We take your privacy seriously, especially when it comes to your mobile data. We want to be explicitly clear that we do not share any mobile data with third-party marketers. Your mobile information, including phone numbers and SMS preferences, is used solely for the purpose of providing you with our services and communicating with you about your account. No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. All categories above exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.

SMS MESSAGING AND OPT-OUT

By providing your mobile phone number and opting in to receive SMS messages, you consent to receive text messages from Trussi.AI sent through our SMS provider (Twilio). Message and data rates may apply. The frequency of messages will vary based on your interaction with our services. SMS is used for transactional purposes such as appointment reminders, one-time passcodes for the customer portal, project updates, and two-way conversations between roofing contractors and homeowners initiated through the App.

To opt out of receiving SMS messages at any time:

  • Reply "STOP" to any message you receive from us
  • Contact us at support@trussi.ai
  • Update your preferences in your account settings

After you opt out, you will receive one final message confirming your opt-out status. If you opt out and later decide to receive messages again, you can opt back in through your account settings or by contacting us.

COOKIES

A cookie is an element of data that a website can send to your browser, which is then stored on your system. A cookie is useful for having the browser remember specific information across several pages or between visits to a website. Our website makes use of cookies for the following purposes:

  • Website administration and personalization
  • Authentication and session management
  • Completing your request
  • Analysis of page and website information that does not identify specific individuals

You can set your browser to notify you when you receive a cookie or to refuse cookies entirely. Some portions of our website may not function properly if cookies are disabled.

CROSS-CONTEXT AND CROSS-DEVICE COLLECTION, IDENTIFICATION, AND PERSONALIZATION

We merge data collected from our Website and our Apps. That data could include cookie IDs, device advertising IDs and/or device IDs, transactions and browsing history, email address, and/or any other information you have entered on our Website or App. This combination of data helps us identify you, improve your experience, and create a more personalized setting. We may also link your various devices so that the content you see on one device is the same as that seen on another one of your devices.

GOOGLE ANALYTICS ON OUR WEBSITE (VISITOR ANALYTICS)

We use a tool called "Google Analytics" to collect information about use of this site across devices. Visitors can opt out of Google Analytics for Display Advertising and customize Google Display Network ads using the Ad Settings. You can opt out of Google Analytics without affecting how you visit the Website. For more information on opting out of being tracked by Google Analytics, visit this Google page.

GOOGLE API SERVICES - DATA ACCESS, USE, AND SHARING

When you choose to connect a Google Account to Trussi.AI, we request only the minimum OAuth scopes necessary to provide the features you have enabled. The scopes Trussi.AI requests, the data we receive, the purpose for which we use it, where it is stored, and how long we retain it are described below. You may revoke Trussi.AI's access to your Google Account at any time by visiting https://myaccount.google.com/permissions.

OAuth Scopes Requested

ScopeWhy we request itopenid, email, profileTo verify your identity, sign you in to Trussi.AI, and link your Google Account to your Trussi.AI user record. We do not access the contents of your Gmail mailbox.https://www.googleapis.com/auth/calendar.readonlyTo read events from the Google Calendars associated with your authorized Google Account so that they can be displayed inside Trussi.AI alongside your projects, appointments, and production schedules. This enables the Google → Trussi.AI direction of two-way sync - any event added to your Google Calendar (typically a work-email calendar) appears in Trussi.AI for the calendar owner.https://www.googleapis.com/auth/calendar.eventsTo create, update, and (with your action) delete calendar events on your authorized Google Calendar. This enables the Trussi.AI → Google direction of two-way sync, so that scheduled inspections, installs, meetings, and other events you create in Trussi.AI are written to your Google Calendar.https://www.googleapis.com/auth/adwordsTo retrieve read-only advertising performance data from your Google Ads and Google Local Services Ads accounts (campaigns, ad groups, spend, impressions, clicks, cost-per-lead, lead categories, and lead status) so that it can be displayed in your Trussi.AI executive dashboard. We do not create, modify, or delete campaigns, ad groups, or ads.https://www.googleapis.com/auth/analytics.readonlyTo list the Google Analytics 4 properties your Google Account can access so you can choose one, and to read aggregate reporting data for the property you select (sessions, users, engagement, key events, and traffic by default channel). We do not modify your Google Analytics configuration.https://www.googleapis.com/auth/webmasters.readonlyTo list the Search Console sites your Google Account has verified so you can choose one, and to read aggregate organic-search performance data for the site you select (clicks, impressions, click-through rate, average position, and top queries and pages). We do not submit, modify, or remove anything in Search Console.

Google Analytics 4 Integration (Your Analytics Data)

If you connect a Google Analytics account, Trussi.AI uses the Google Analytics Admin API to list the GA4 properties your Google Account can access, and the Google Analytics Data API to retrieve aggregate reporting data for the single property you select: sessions, total and new users, engaged sessions, page views, key events (conversions), and sessions grouped by default channel (organic search, paid search, direct, referral, social, and email). This data is displayed only in your Trussi.AI marketing dashboard. Trussi.AI does not modify your Google Analytics configuration and does not retrieve individual visitor identities from your property. This integration is separate from the Google Analytics tag we use to measure traffic on our own marketing website, described above.

Google Search Console Integration

If you connect a Google Search Console account, Trussi.AI uses the Search Console API to list the sites your Google Account has verified, and to retrieve aggregate organic-search performance data for the single site you select: clicks, impressions, click-through rate, average position, and your top search queries and landing pages. This data is displayed only in your Trussi.AI marketing dashboard. Trussi.AI does not submit, modify, or remove sitemaps, URLs, or any other resource in your Search Console property.

How Google User Data Is Stored

Data that Trussi.AI retrieves from Google APIs is stored in our primary database (MongoDB Atlas) hosted on Amazon Web Services in the United States. OAuth tokens are encrypted at rest. All data is transmitted over TLS 1.2 or higher. Access to production data is restricted to a small number of authorized Trussi.AI engineers, audit-logged, and available only for break-fix support and security investigation.

How Google User Data Is Retained and Deleted

  • Calendar events read from your authorized Google Calendar (typically a work-email calendar) are stored in our database so they can be displayed inside Trussi.AI as part of two-way sync. Stored events are refreshed periodically. When you disconnect your Google Account from Trussi.AI, all calendar event data we have synced from your Google Calendar is purged from our systems within 30 days. Disconnecting from Trussi.AI does not delete events from your underlying Google Calendar.
  • Google Ads performance metrics are stored as aggregated daily snapshots and refreshed periodically. When you disconnect your Google Ads account, all previously synced metrics are deleted from our systems within 30 days.
  • Google Analytics metrics are stored as aggregated daily snapshots by traffic channel and refreshed periodically. When you disconnect your Google Analytics property from Trussi.AI, the synced analytics data is deleted from our systems within 30 days.
  • Search Console metrics are stored as aggregated daily totals plus a periodic snapshot of your top search queries and pages. When you disconnect your Search Console site from Trussi.AI, the synced organic-search data is deleted from our systems within 30 days.
  • OAuth tokens are deleted immediately when you disconnect a Google Account from Trussi.AI or revoke access from your Google Account permissions page.
  • You may also request full deletion of all Google-derived data associated with your account by emailing support@trussi.ai. We will complete the request within 30 days.

Limited Use of Google User Data

Trussi.AI's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, Trussi.AI affirms that:

  1. We use Google user data only to provide or improve user-facing features of Trussi.AI that are prominent in the requesting app's user interface (the calendar view, the executive dashboard, and the data-source settings page).
  2. We do not transfer Google user data to others except as necessary to provide or improve those user-facing features, to comply with applicable law, or as part of a merger, acquisition, or sale of assets with notice to users.
  3. We do not use Google user data to serve advertisements, including retargeting, personalized, or interest-based advertising.
  4. We do not allow humans to read Google user data unless (a) we have obtained your affirmative agreement to view specific messages or data, (b) it is necessary for security purposes (such as investigating abuse), (c) it is required to comply with applicable law, or (d) the data has been aggregated and is used for internal operations in accordance with applicable privacy and other jurisdictional legal requirements.
  5. We do not use Google user data - including data obtained through the Google Calendar, Google Ads, Google Local Services Ads, Google Analytics, or Google Search Console APIs - to develop, improve, or train generalized or non-personalized artificial intelligence or machine learning models. Trussi.AI's AI features (described below) operate only on data you explicitly provide within the App, and do not ingest data received from Google APIs as training material.

GOOGLE MAPS PLATFORM

Trussi.AI uses the Google Maps Platform (including Maps JavaScript API and Places API) to display maps, geocode addresses, and provide address autocomplete. Your use of Google Maps within Trussi.AI is also governed by the Google Privacy Policy.

ARTIFICIAL INTELLIGENCE FEATURES

Trussi.AI offers artificial intelligence features that use large language models from Anthropic, PBC ("Anthropic") to assist with tasks such as conversational assistance, optical character recognition on uploaded documents, image analysis, voice note transcription, automatic file categorization, and quality checks on uploaded media.

When you use these features, the specific content you submit (for example, a chat message, a photograph, or a voice recording) is transmitted to Anthropic's API solely to generate a response and is not retained by Anthropic for model training. Anthropic processes this data as a sub-processor on our behalf under their commercial terms.

Trussi.AI does not use any customer data, project data, uploaded photos, documents, voice notes, calendar data, advertising data, or data obtained from any third-party integration (including Google APIs) to train, fine-tune, or otherwise develop generalized artificial intelligence or machine learning models. Inference performed for an individual customer is restricted to that customer's own tenant.

OTHER THIRD-PARTY INTEGRATIONS

Trussi.AI offers optional integrations that you can enable to connect external services to your Trussi.AI account. Each integration is initiated by you and authenticated via the third party's secure OAuth flow, API key, or equivalent. We do not receive or store the login credentials of these third-party services.

DocuSign

When you connect a DocuSign account ("Bring Your Own Account") to Trussi.AI, we use DocuSign's eSignature REST API to send envelopes for electronic signature on your behalf, to position signature, initial, date, and text fields on documents you upload, to track envelope status (sent, delivered, completed, voided), and to retrieve signed documents for storage in your Trussi.AI project. We request the minimum DocuSign scopes required for these features (signature, impersonation where applicable for service integrations, and account information). DocuSign access tokens are encrypted at rest. You may disconnect DocuSign at any time from your Trussi.AI account settings, which will revoke our refresh token and stop all future API access.

QuickBooks Online (Intuit)

When you connect a QuickBooks Online company to Trussi.AI, we request the com.intuit.quickbooks.accounting and openid scopes via Intuit's OAuth 2.0 flow. We use this access to read and write invoices, customers, items, and payment records associated with the projects and worksheets you create in Trussi.AI, and to display profit-and-loss and accounts-payable information on your executive dashboard. QuickBooks tokens are encrypted at rest, refreshed automatically, and revoked when you disconnect QuickBooks from Trussi.AI.

Twilio (SMS, Voice, and OTP)

Twilio Inc. is our communications service provider. Trussi.AI uses Twilio to send and receive SMS messages between roofing contractors and homeowners, to deliver one-time passcodes for the Trussi customer portal, to handle SMS opt-in / opt-out compliance under A2P 10DLC requirements, and to deliver delivery-status webhooks back to the App. The phone numbers, message content, and delivery metadata you exchange through these features are processed by Twilio under their privacy policy. Mobile phone numbers and opt-in consent collected for SMS will not be shared with third parties or affiliates for marketing or promotional purposes.

Email (IMAP / SMTP)

Trussi.AI allows you to connect your business email mailbox via IMAP and SMTP so that the App can send and receive project-related emails on your behalf and associate them with the correct customer and project. We store mailbox credentials encrypted at rest and use them only to deliver the email features you have enabled. You may disconnect the mailbox at any time from your account settings.

Push Notifications (Firebase Cloud Messaging and Apple Push Notification Service)

Trussi.AI sends push notifications to your mobile device through Google's Firebase Cloud Messaging (Android) and Apple's Push Notification Service (iOS). We register your device token with these services solely to deliver notifications you have opted into (such as project updates, mentions, and reactions). You may disable push notifications at any time from your device settings.

Meta (Facebook / Instagram) Ads

Trussi.AI integrates with Meta's Marketing API to retrieve advertising performance data from your connected Facebook and Instagram ad accounts. When you authorize this integration, Trussi.AI requests read-only access to your ad account data. We do not create, modify, or delete your campaigns, ad sets, or ads. Data retrieved from Meta is stored in our database and refreshed periodically. You may disconnect your Meta ad account at any time through your Trussi.AI account settings; previously synced advertising data will be deleted from our systems within 30 days.

ABC Supply Partner API

When you connect an ABC Supply account, Trussi.AI uses ABC Supply's partner API (via OAuth 2.0) to look up product catalogs, pricing, branch availability, place purchase orders, and receive order-status webhooks. The data exchanged is limited to the supplier information necessary to support quoting and material ordering for your roofing projects.

Roof Measurement Providers (RoofScope, EagleView)

Trussi.AI integrates with RoofScope and EagleView so that you can order roof measurement reports from within the App. The property address you specify and any associated project identifier are sent to the chosen provider in order to fulfill the report. The completed report is returned to Trussi.AI via webhook and stored on the corresponding project.

Beacon Building Products

Trussi.AI integrates with Beacon's pricing and catalog APIs to allow you to look up materials and branch pricing while building quotes. Only the search terms and product identifiers necessary to fulfill the lookup are sent to Beacon.

Five9 (Call Center)

For customers using Trussi.AI's call-center features, we receive call event webhooks from Five9 (caller phone number, call duration, call recording references, and disposition) so that calls can be associated with the correct project. Recordings and transcripts are stored against the corresponding project record.

Cloud Hosting and Data Infrastructure

Trussi.AI is hosted on Amazon Web Services (AWS) in the United States. We use AWS S3 for file storage, AWS SQS for asynchronous job queues, MongoDB Atlas for our primary database, and Cloudflare for DNS and content delivery. These providers act as sub-processors and process customer data only to the extent necessary to operate the service.

Error Monitoring and Observability

We use Sentry for application error monitoring and OpenTelemetry-based services for performance and uptime telemetry. These services may collect technical information about errors and requests (such as stack traces, request paths, and anonymized identifiers). Sensitive fields are scrubbed before being sent. We use Better Stack for public uptime monitoring at status.trussi.ai.

DATA SECURITY

We protect your information using administrative, technical, and physical safeguards appropriate to the sensitivity of the data, including TLS 1.2+ in transit, encryption at rest for OAuth tokens and sensitive credentials, role-based access controls, audit logging, and least-privilege provisioning of production access. No security control is perfect; if you believe your account has been compromised, please contact us immediately at support@trussi.ai.

ACCOUNT AND DATA DELETION

You may request deletion of your account and the personal data associated with it at any time by emailing support@trussi.ai from the email address on file. We will verify your request, complete the deletion within 30 days, and notify you when it is complete. Some information may be retained where required by law (for example, financial records that we are obligated to keep for tax or accounting purposes) or in anonymized, aggregated form.

You can independently revoke any third-party integration's access to Trussi.AI at any time:

  • Google: myaccount.google.com/permissions
  • QuickBooks: Intuit account → Settings → Apps
  • DocuSign: DocuSign account → Apps and Keys
  • Meta: Facebook/Instagram account → Settings & Privacy → Business Integrations

LEAVING OUR WEBSITE AND/OR LINKING TO THIRD PARTIES

When you are logged into our Website or App, it is secure. Your browser URL will indicate if you are leaving a secured portion of the Website. We strive to ensure that any information you send us is safe. When you leave this Website and go to another linked site, we are not responsible for the content or availability of the linked site. The privacy and security policies of the linked site may differ from those practiced by us.

CONTROL OVER AND ACCESS TO YOUR INFORMATION

We enable you to have control over the accuracy of your personal information. You can delete or change your personal information with us at any time by contacting us via a method described under "Contact Us" below.

DO NOT TRACK

Third parties may collect information about you across different websites, including our website. We do not currently respond to web browser "Do Not Track" signals.

CHILDREN'S PRIVACY

Trussi.AI is intended for use by businesses and adults aged 18 and over. We do not knowingly collect personal information from children under the age of 13. If you believe a child has provided us with personal information, please contact us at support@trussi.ai and we will delete it promptly.

INTERNATIONAL USERS

Trussi.AI is operated from, and your data is stored in, the United States. By using the Website or App from outside the United States, you acknowledge that your information will be transferred to and processed in the United States, which may have different data protection rules than those of your country.

YOUR PRIVACY RIGHTS (CCPA / CPRA / GDPR)

Depending on where you live, you may have the right to access, correct, delete, restrict or object to processing of, or receive a portable copy of your personal information; the right to withdraw consent; and the right not to be discriminated against for exercising your rights. To exercise any of these rights, contact us at support@trussi.ai. We will respond within the timeframes required by applicable law.

HOW TO OPT-OUT, CORRECT PERSONAL INFORMATION, OR REQUEST ADDITIONAL INFORMATION

We want our customers and Users to choose how their information may be used. You can delete or change your personal information with us at any time. If, at any time after registering for information or ordering the service, you change your mind about receiving information from us, send us a request specifying your new choice. Simply send your request to support@trussi.ai. Questions regarding this Privacy Policy or the practices of this Site should be directed to support@trussi.ai or by regular mail addressed to Trussi.AI, Attn: Product Support, 7899 Frontage Rd, Overland Park, KS 66204.

AI Assistant Connector (Claude & ChatGPT)

This section explains how the Trussi connector for AI assistants handles data when you connect your Trussi account to an AI assistant - such as Claude (operated by Anthropic) or ChatGPT (operated by OpenAI). The connector is offered to Trussi customers and their authorized users; it is not intended for consumers or children. Where this section is silent, the rest of this Privacy Policy applies.

What data the connector accesses

The connector only accesses data your Trussi user is already permitted to see, and only within the permission scopes you approve when connecting. Depending on those scopes, this can include:

  • Projects, leads, and pipeline status; customer (homeowner) contact records
  • Quotes/estimates, profit analysis, calendar events, and roof-measurement reports and status
  • Team-member directory and sales-dashboard / reporting metrics for your account

Every request runs through the same permission checks as the Trussi web and mobile apps. The assistant cannot access anything your role could not access directly, and cannot reach other Trussi customers' data.

What we collect and store for the connector

  • Authorization records: the OAuth client registration, short-lived authorization codes, and access/refresh tokens that let the assistant act on your behalf. Tokens and codes are stored only as one-way hashes - never in plaintext - and are bound to your user and account.
  • Connector activity logs: for security and troubleshooting we log the time, the acting user and account, the connected client, and the name and outcome of each tool the connector runs. We do not store the content of your prompts, the arguments you pass, or the CRM data returned to the assistant.

How the connector uses and shares data

  • To fulfill your requests: when you ask the assistant to do something, the connector retrieves or updates the relevant Trussi data and returns the result so the assistant can answer you. That information is sent to the AI provider you connected - Anthropic for Claude, OpenAI for ChatGPT - to process your request. Your use of that assistant is governed by the provider's own privacy policy and terms.
  • To act on your behalf: if you grant write or communicate scopes and instruct the assistant accordingly, the connector may create or update records, or send emails/text messages to your customers through Trussi's existing email and SMS providers - exactly as those actions work in the Trussi app.
  • No sale of data and no other sharing: we do not sell your data or share it for advertising. Aside from sending data to the AI provider you connected to fulfill the requests you initiate, the connector does not disclose your data to third parties.

Connector storage and security

  • All connector traffic is encrypted in transit over HTTPS.
  • Authentication uses OAuth 2.0 with PKCE; the assistant never receives your password. Access is limited to the scopes you approve and isolated to your account.
  • Tokens and authorization codes are stored as hashes and are individually revocable.

Connector data retention

  • Authorization codes expire within minutes and are single-use.
  • Access tokens are short-lived (about one hour); refresh tokens last up to 90 days and rotate on each use. Revoking access invalidates them immediately.
  • Connector activity logs are retained in line with Trussi's standard operational-log retention and then deleted.

Your connector choices and controls

  • Choose which permission scopes to grant when you connect, and decline any you don't want.
  • Disconnect the connector at any time in the assistant's connector settings, or ask Trussi to revoke access server-side. Revoking stops all further access immediately.