Security and privacy · Effective September 5, 2026

Understand how TruthSpine handles your data

TruthSpine is built by TimeProofLabs LLC to keep project knowledge on your computer by default and to be clear about the limited information used for payments and product operation. We do not sell customer data or use project content to train shared models.

Where is my project data stored?

TruthSpine keeps project truth, project history, and local product records on your computer by default.

What leaves my computer?

Entitlement verification needed to start, restore, and protect a trial or purchase is separate from optional usage analytics. Optional analytics are off until you grant consent, and licensing works either way. Consented events describe app sessions, project attachment counts, connector and agent choices, updates, and feature use. They do not include project names or paths, source content, chat text, prompts, email addresses, raw machine identity, or license keys.

Are usage records anonymous?

No. Pseudonymous journey and entitlement identifiers and locally salted project and repository hashes can group activity over time and link it to a verified entitlement. They are not used for cross-company advertising tracking. Marketplace listing and download totals are aggregate reports, not a universal person-level identity.

Can I change my analytics choice?

Yes. The app offers an optional first-run choice and a Settings control. Declined and not-yet-chosen consent remain local. Consented events may wait locally for retry for up to 30 days, with a target limit of 500 pending events. Turning analytics off clears pending events and stops further optional delivery, but cannot retract a request already in flight or erase previously received events. Settings shows local delivery status.

How long are usage records kept?

Raw product events are retained for up to 400 days; pseudonymous daily aggregates may be retained for historical reporting. Contact support@timeprooflabs.com to request deletion. Essential entitlement and transaction evidence follows licensing, refund, fraud-prevention, and legal retention needs.

What do payment services receive?

Apple StoreKit and Microsoft Store process purchases under their own policies. TruthSpine verifies Store ownership and retains pseudonymous entitlement evidence, not raw marketplace tokens or project content. Stripe remains a legacy entitlement channel. TruthSpine does not collect your card information.

What do connected AI tools receive?

A connected AI tool receives the project information needed for the request you make. The privacy terms and settings of that AI tool still apply.

Can I export or delete my data?

TruthSpine provides local export and deletion controls for its project data.

Are connector files designed to contain secrets?

No. TruthSpine connector configuration is designed to avoid storing passwords, payment details, or service secrets.

Current limitations

Claims we do not make

TruthSpine is not currently SOC 2 certified, HIPAA certified, or independently penetration-test certified. It does not guarantee how a third-party AI provider stores or protects information sent to that provider. Review the privacy settings and terms of every AI tool you connect.

TruthSpine also does not currently claim broad encryption for all project data stored on your computer. Use the security controls and disk encryption available on your operating system when your project requires them.

Questions about your data?

Contact TimeProofLabs before connecting sensitive work if you need help understanding the current boundaries.