Privacy Policy
Effective date: July 17, 2026 Last updated: August 7, 2026
This Privacy Policy describes how TrueHuman LLC ("TrueHuman", "we", "us"), 5830 E 2nd St, Ste 7000 #30633, Casper, WY 82609, USA, collects, uses, and shares personal data when you use our websites and applications at www.mytruehuman.com, app.mytruehuman.com, and dashboard.mytruehuman.com (together, the "Services").
For privacy questions or to exercise your rights, contact us at help@mytruehuman.com.
1. Our roles
TrueHuman provides an AI-powered sales assistant and CRM workspace for business users. Depending on the data, we act in two different roles:
- Data controller. For the personal data of people who register and use the Services (account data, billing data, usage data), we decide how and why data is processed and act as controller.
- Data processor. For the content our customers upload or sync into the Services — such as contact lists, deal records, notes, files, and call recordings ("Customer Content") — we process it only on the customer's behalf and instructions. The customer (typically your employer or company) is the controller of that data. Our Data Processing Agreement governs this processing.
If your data appears in the Services because a TrueHuman customer uploaded or synced it (for example, you are a sales prospect in a customer's contact list), please direct privacy requests to that customer. We will assist them in responding, and where required by law we will also respond directly.
2. Data we collect
Account and profile data. Name or nickname, username, email address, company name, password (handled by our authentication provider; where collected at registration it is stored encrypted and only until account creation completes), role, timezone, preferred language and currency, and optional profile details you choose to provide, such as onboarding interview answers, working days, sales targets, and assistant personalization settings (e.g., coach name).
Billing data. Subscription plan, seats, billing interval, credit and wallet balances and transactions. Payments are processed by Stripe; we do not store full card numbers.
Customer Content. Data you or your company upload, create, or sync into the Services: contacts (names, emails, phone numbers, job titles, companies, LinkedIn URLs, notes, custom fields), deals and pipelines, files and attachments, chat messages with the AI assistant, saved notes, objectives, and daily check-ins.
Call recordings and transcripts. Audio files you upload, calls you place from within the Services (see Section 4a), their transcripts, and AI-generated analyses and scores. You are responsible for obtaining any legally required consent from call participants before recording or uploading (see our Terms of Service).
CRM data. If you connect a CRM (e.g., Salesforce or Attio), we access and sync contacts, deals, and related records as authorized by you, and store connection credentials (OAuth tokens) securely.
Connected email. If you connect a business email account (e.g., Microsoft Outlook), we store the connection credentials (OAuth tokens) securely and process the content and metadata of the emails you send through the Services and of the replies we detect on those conversations. See Section 4b.
Connected calendar. If you connect a Google account for scheduling, we store the connection credentials (OAuth tokens) securely, together with the account's email address and the identifiers of the calendar events we create. See Section 4d.
Enrichment data. We may retrieve additional business information about contacts from third-party data providers (e.g., Apollo) and public web sources, such as job titles, company details, and fit scores.
Prospecting and lead-discovery data. When a User uses our lead-discovery features ("find clients" / suggested contacts), we retrieve and may store business-contact information about individuals who are not yet in your CRM — such as name, job title, seniority, employer, location, and LinkedIn URL — from third-party providers (e.g., Apollo), so the User can decide whether to add them as contacts. See Section 3 for the legal basis.
Derived AI data. To power search and the AI assistant's memory, we generate and store data derived from Customer Content, including vector embeddings of chat, contacts, and uploaded documents, summarized long-term memory, and versioned AI profiles ("dossiers") of contacts. These are retained for as long as the account is active.
Usage and technical data. Log data, device and browser information, IP address, feature usage, AI usage metrics (model used, token counts), and error diagnostics.
Cookies. See our Cookie Policy.
3. How we use data
| Purpose | Examples | Legal basis (GDPR) |
|---|---|---|
| Provide the Services | Accounts, sync, AI assistant, recordings analysis, support | Contract (Art. 6(1)(b)) |
| Billing | Subscriptions, credits, invoices, fraud prevention | Contract; legal obligation |
| Personalization | Assistant tone, language, working schedule, coaching | Contract; consent for optional fields |
| Prospecting and lead discovery | Surfacing potential business contacts for B2B outreach | Legitimate interests (Art. 6(1)(f)) |
| Product improvement and security | Aggregated usage analytics, debugging, abuse prevention | Legitimate interests (Art. 6(1)(f)) |
| Communications | Service emails, proactive assistant messages (you can opt out), important notices | Contract; legitimate interests |
| Legal compliance | Tax, accounting, responding to lawful requests | Legal obligation |
We do not sell personal data, and we do not use it for third-party advertising.
Where we or a customer obtain personal data about an individual from a third-party source (e.g., prospecting or enrichment) rather than from the individual directly, the customer, as controller of that Customer Content, is responsible for any source-of-data notice required by Art. 14 GDPR; we assist as described in our Data Processing Agreement.
4. AI processing
The Services use large language models and AI services from third-party providers, currently including Anthropic, Google, and OpenAI, plus specialized services for transcription (AssemblyAI) and web/contact research (Apollo, Bright Data, Firecrawl, Serper). Content you submit to AI features (chat messages, recordings, contact context, and the content of connected-email conversations you started through the Services) is sent to these providers to generate responses, including suggested email drafts and replies.
Under our agreements with these providers, content submitted through their business APIs is not used to train their general-purpose models. AI outputs are generated automatically and may be inaccurate; do not rely on them without review.
Data obtained from a connected Google account (Section 4d) is not sent to these AI providers.
4a. Call recording and transcription
The Services let a User place a phone call to a business contact directly from the app ("in-app calls"). When a User starts an in-app call, the call is connected through our telephony provider (Twilio), and the call is recorded and transcribed so that the Services can generate a recap, transcript, AI analysis, and coaching insights — the same outputs produced when a User uploads a recording. The audio is processed for transcription and analysis only; it is not used for biometric identification or to create a voiceprint.
In-call notice. At the start of each in-app call, the Services play an automated audio recording announcement on the calling User's line. Depending on how the call is connected, the contact may not hear this announcement, and the User remains responsible for giving any notice and obtaining any consent the law requires (see Legal basis below).
Purposes. Recap and note-taking, AI analysis and scoring, sales coaching, and quality and training of the User's own performance.
Legal basis. For business-to-business calls, we and our customers rely on legitimate interests (Art. 6(1)(f) GDPR) in documenting and improving sales conversations, balanced against participants' interests, supported by the in-call recording notice. Where applicable law requires the consent of all participants — for example, "two-party" / "all-party consent" US states (such as California, Florida, Illinois, Pennsylvania, Washington) and various non-US jurisdictions — the customer and its Users are responsible for ensuring such consent is obtained; the in-call announcement is provided as a tool to support this but does not by itself guarantee compliance in every jurisdiction.
Audio retention is the User's choice, per call. Before each in-app call the User chooses whether to keep the audio recording:
- Keep audio off (default). The audio file is sent to our transcription provider (AssemblyAI) to produce the transcript, then promptly deleted (best-effort) from our storage and from our telephony provider after transcription.
- Keep audio on. The audio file is retained until the User deletes it. The User can delete the audio at any time from the call record in the app.
In both cases, the transcript and AI analysis are retained as part of Customer Content for as long as the account is active (see Section 8) and are not deleted when the audio is deleted.
Subprocessors. In-app calls involve Twilio (telephony, call connection, and recording), AssemblyAI (transcription), and Anthropic (AI analysis). See our Subprocessors list.
Your rights. Call participants may exercise their data subject rights (including access and erasure / "right to be forgotten") as described in Section 10. Where the recording is Customer Content controlled by a TrueHuman customer, we will refer the request to that customer and assist them in responding.
4b. Connected email accounts
The Services let a User connect their own business email account (currently Microsoft Outlook, via Microsoft Graph) to send outreach and follow-up emails from within the app and to keep the User's follow-up plan up to date automatically ("connected email").
What we access. Connecting Outlook grants TrueHuman Microsoft's Mail.ReadWrite permission (send, plus read/write access to the mailbox). We use it to (i) send the emails the User approves, from the User's own mailbox, and (ii) keep the follow-up plan current: our periodic sync enumerates inbox message headers to identify replies and delivery failures relating to the conversations the User started through the Services, and reads the full content only of (a) replies on those tracked conversations and (b) delivery-failure / bounce notices. We do not build a copy of the mailbox, and we do not use tracking pixels or read receipts. The broad Microsoft permission is used because Microsoft does not offer a narrower per-conversation scope.
What we store. The content of emails sent through the Services and of the replies we detect on tracked conversations, together with message and conversation identifiers, recipients, subjects, timestamps, and status (sent, replied, bounced), and a per-contact do-not-contact list used to suppress follow-up emails. This is Customer Content. The content of emails you send through the Services is also written to your connected CRM (if any) as a contact note. Connection credentials (OAuth tokens) are stored encrypted.
Purposes. Sending approved outreach and follow-ups; detecting replies and bounces; generating suggested reply and follow-up drafts with AI (Section 4); updating the contact's status and activity timeline; scheduling reminders.
Legal basis. Providing the Services (Art. 6(1)(b)). For the underlying business-to-business outreach, the customer and its Users rely on legitimate interests and are responsible for compliance with anti-spam and e-privacy laws, including honoring opt-out requests (see our Terms of Service).
Disconnection. The User can disconnect the email account at any time in settings. On disconnection we stop accessing the mailbox, delete the stored connection, and remove the tracked email conversations captured for that connection.
Subprocessors. The User's own email provider (e.g., Microsoft) acts under its own agreement with the User, like a connected CRM; AI drafting uses the providers listed in Section 4. See our Subprocessors list.
4c. Connected meeting accounts (Zoom)
The Services let a User connect their own Zoom account (via Zoom OAuth) so that TrueHuman can bring the User's own meeting recordings in for transcription and coaching, and can schedule meetings on the User's behalf ("connected meetings"). Connection credentials (OAuth tokens) are stored encrypted.
What we access.
- User profile (
GET /users/me): the connected user's Zoom user id, name, and email, used to identify the account and route the User's own recordings to their TrueHuman account. - Cloud recordings of the User's own meetings: when a meeting the User cloud-records on Zoom completes, Zoom notifies TrueHuman, which retrieves the audio to produce a transcript, AI analysis, and coaching insights — the same outputs produced for uploaded recordings and in-app calls (Section 4a).
- Meeting participants (
GET /past_meetings/{meetingUUID}/participants): the participant list of the User's own meetings, used to match a recorded call to the User's existing contacts. Recordings that do not match a contact are still imported and simply left unassigned. - Meeting creation (
POST /users/me/meetings): when the User schedules a call from within the Services, TrueHuman creates a scheduled Zoom meeting on the User's account and a matching calendar invite.
What we store. The recording audio (in access-controlled storage), its transcript and AI analysis (Customer Content), the identifiers of created meetings, and the encrypted OAuth connection. We access only the connected User's own Zoom data.
Purposes. Transcription, AI analysis and scoring, sales coaching, matching calls to contacts, and scheduling meetings.
Consent / legal basis. The recording is made by the User on their own Zoom account, subject to Zoom's own controls; the User is responsible for the in-meeting recording notice and for obtaining any consent the law requires, including in "all-party consent" jurisdictions, on the same basis described in Section 4a. TrueHuman relies on providing the Services (Art. 6(1)(b)) and, for the underlying B2B activity, on legitimate interests (Art. 6(1)(f)).
Disconnection and Zoom app removal. The User can disconnect Zoom at any time in settings, and can remove ("deauthorize") the app from Zoom. On disconnection or deauthorization, TrueHuman stops accessing the account, deletes the stored connection, and deletes the associated recordings, transcripts, and derived data, including deleting the recording from the User's Zoom cloud.
Subprocessors. Zoom acts as the User's own meeting provider under its agreement with the User (like a connected CRM or email provider); transcription uses AssemblyAI and AI analysis uses Anthropic. See our Subprocessors list.
4d. Connected calendar accounts (Google Calendar)
The Services let a User connect their own Google account (via Google OAuth) so that TrueHuman can schedule meetings on the User's behalf and propose available time slots ("connected calendar"). Connection credentials (OAuth tokens) are stored encrypted.
What we access.
- Account identity (
openid,email): the connected account's email address, used only to identify which account is connected and to display it in settings. - Calendar events (
https://www.googleapis.com/auth/calendar.events): we create and update calendar events for the meetings a User schedules from within the Services, and we read free/busy intervals on the User's calendar to propose available time slots.
What we store. The encrypted OAuth connection, the connected account's email address, and the identifiers of the events we create. We do not copy or index the User's calendar, and we do not read the content of events we did not create.
Purposes. Scheduling meetings and proposing available time slots.
AI processing. Data obtained from the connected Google account is not sent to the AI providers listed in Section 4.
Legal basis. Providing the Services (Art. 6(1)(b)). Where a meeting invitation includes other participants, the User and the customer are responsible for the lawfulness of inviting them, on the same basis as the outreach described in Section 4b.
Disconnection. The User can disconnect Google at any time in settings. On disconnection we revoke the OAuth token with Google, stop all access to the account, and delete the stored connection. Events already created remain in the User's own Google Calendar, under the User's control.
Google API Services disclosure. TrueHuman's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not transfer, sell, or use data obtained from Google APIs to create, train, or improve machine learning or artificial intelligence models, and we limit human access to that data to the cases the policy permits: with your affirmative agreement, where the data is aggregated and anonymized for internal operations, as necessary for security purposes, or to comply with applicable law.
Subprocessors. Google acts as the User's own calendar provider under its agreement with the User, like a connected CRM or email provider, and is not a TrueHuman subprocessor for this purpose. See our Subprocessors list.
5. Workspace visibility
If your account is part of a company workspace, your company's administrators may see information about your use of the Services, including activity summaries, performance reports, objectives, and coaching insights generated by the Services. Check with your employer for its policies.
6. Sharing
We share personal data only with:
- Service providers (subprocessors) that host and operate the Services — see our current Subprocessors list. Key providers include Supabase (database hosting, USA), Vercel and Render (application hosting), Okta/Auth0 (authentication), Stripe (payments), Twilio (telephony and call recording for in-app calls), Ably (realtime delivery of AI-assistant messages, UK), Sentry (error monitoring), and the AI providers listed above.
- Your company/workspace as described in Section 5.
- Authorized TrueHuman personnel, on a limited, least-privilege basis, to provide support, resolve technical issues, and maintain the Services, subject to confidentiality obligations and access logging.
- Third parties you connect (e.g., your CRM provider, your email provider such as Microsoft, your meeting provider Zoom, or your calendar provider Google) at your direction. When you connect one of these accounts, you interact with your own provider under its terms; we access it only as you authorize and only as described in Sections 4b, 4c, and 4d.
- Authorities or other parties where required by law, to protect rights and safety, or in connection with a merger, acquisition, or sale of assets (with notice where required).
7. International transfers
We are based in the United States and our Services are hosted there. If you use the Services from the EEA, UK, or Switzerland, your data is transferred to the US and other countries. Where required, we rely on the European Commission's Standard Contractual Clauses (SCCs), the UK Addendum/IDTA, and, for providers certified under it, the EU-U.S. Data Privacy Framework.
8. Retention
We keep personal data for as long as your account is active and as needed for the purposes above. Audio of in-app calls is retained according to the per-call choice described in Section 4a; call transcripts and analyses are retained as Customer Content. After account closure, we delete or anonymize personal data within 90 days, except where longer retention is required (e.g., invoices and tax records, typically up to 10 years) or needed to resolve disputes. Customer Content is deleted or returned in accordance with our DPA. If you disconnect a connected email account, we stop accessing your mailbox, delete the stored connection, and remove the tracked email conversations we captured for it. If you disconnect a connected calendar account, we revoke the token with the provider and delete the stored connection. Backups are purged on a rolling basis.
9. Security
We use technical and organizational measures appropriate to the risk, including encryption in transit (TLS) and at rest, row-level access controls in our database, role-based access, encrypted credential storage, and audit logging. No system is perfectly secure; notify us immediately at help@mytruehuman.com if you suspect unauthorized access.
10. Your rights
EEA, UK, Switzerland. You have the right to access, rectify, erase, restrict, or object to processing of your personal data, the right to data portability, and the right to withdraw consent at any time (without affecting prior processing). You may lodge a complaint with your local supervisory authority.
US states (e.g., California, Colorado, Virginia). Depending on your state, you may have rights to know, access, correct, delete, and obtain a portable copy of your personal information, and to opt out of "sales", "sharing", or targeted advertising. We do not sell or share personal information for advertising purposes. We do not discriminate against you for exercising your rights.
Everyone. You can access and update most account data in your settings, or contact help@mytruehuman.com. We respond within the timeframe required by applicable law (one month under GDPR, extendable; 45 days under most US state laws). We may need to verify your identity. If your request concerns Customer Content controlled by a TrueHuman customer, we will refer it to that customer.
11. Children
The Services are intended for business users aged 18 or older. We do not knowingly collect data from children under 16. If you believe a child has provided us data, contact us and we will delete it.
12. Changes
We may update this Policy. We will post the new version here and update the date above; for material changes we will notify you via the Services or email. Continued use after the effective date constitutes acceptance.
13. Contact
TrueHuman LLC 5830 E 2nd St, Ste 7000 #30633 Casper, WY 82609, USA help@mytruehuman.com