Data processed
TrustFill stores account and workspace records, uploaded security evidence, uploaded XLSX questionnaires, generated drafts, citations, human edits and approvals, exports, usage records, and security audit metadata needed to provide the service.
Purpose and access
Data is used to parse approved evidence, retrieve relevant excerpts, draft and independently verify questionnaire answers, support human review, and create approved-only workbook copies. Workspace membership is checked server-side. Production operators may access infrastructure only for support, security, recovery, and service operation.
AI processing boundary
When real generation is enabled, selected question text and selected evidence excerpts—not an automatic full-document transfer—may be sent to the configured Maimaiya OpenAI-compatible gateway. Local semantic embeddings remain inside TrustFill infrastructure. The gateway has not published an enabled privacy policy or user agreement that establishes retention, training, residency, deletion, DPA, or subprocessor terms; real customer documents therefore remain prohibited.
Storage, retention, and deletion
The current production deployment is approved only for isolated synthetic data until a private, encrypted, versioned S3 bucket passes the release gate. User-requested document, questionnaire, and workspace deletion removes database-derived data and all object versions. PostgreSQL operational backups are retained for 14 days; deletion from backups follows backup expiry unless a security or legal preservation requirement applies.
Your choices
Workspace owners can delete documents, questionnaires, and the workspace through the product. Do not upload personal data or customer security material until the beta operator confirms that the customer-data gate is open. Access, correction, export, or deletion questions must currently be directed through the operator who issued the beta invitation.