Security and privacy

Understand how TruthSpine handles your data

TruthSpine is built to keep project knowledge on your computer by default and to be clear about the limited information used for payments and product operation.

Where is my project data stored?

TruthSpine keeps project truth, project history, and local product records on your computer by default.

What leaves my computer?

TruthSpine sends limited product-journey events such as app opened, project connected, first answer, and checkout started. These events do not include project paths, source content, chat text, machine identity, or license keys.

What does Stripe receive?

Stripe handles checkout and payment collection. TruthSpine keeps the proof needed to activate your purchase, not your card information.

What do connected AI tools receive?

A connected AI tool receives the project information needed for the request you make. The privacy terms and settings of that AI tool still apply.

Can I export or delete my data?

TruthSpine provides local export and deletion controls for its project data.

Are connector files designed to contain secrets?

No. TruthSpine connector configuration is designed to avoid storing passwords, payment details, or service secrets.

Current limitations

Claims we do not make

TruthSpine is not currently SOC 2 certified, HIPAA certified, or independently penetration-test certified. It does not guarantee how a third-party AI provider stores or protects information sent to that provider. Review the privacy settings and terms of every AI tool you connect.

TruthSpine also does not currently claim broad encryption for all project data stored on your computer. Use the security controls and disk encryption available on your operating system when your project requires them.

Questions about your data?

Contact TimeProofLabs before connecting sensitive work if you need help understanding the current boundaries.