Privacy Policy
Effective July 19, 2026
This policy explains what Trelleon ("we", "us") collects when you use trelleon.com, how it is used, and the choices you have.
1. What we collect
Account information. Your name, email address, and authentication details when you sign up (directly or via Google sign-in).
Workspace content. The tasks, documents, chats, records, and deliverables you and your agents create in your workspace.
Connection credentials. Tokens and keys for services you choose to connect (Google, Slack, Notion, Shopify, WordPress, GitHub, QuickBooks, and others). These are stored encrypted in a secrets vault and used only to operate the integrations you configure.
Usage and billing data. Feature usage, AI token consumption and cost, and subscription state. Payments are processed by Stripe; we never see or store full card numbers.
2. How we use it
To provide and improve the Service: running your agents, syncing the integrations you set up, metering plan allowances, billing, support, and product security. We do not sell your personal information, and we do not use your workspace content to train foundation models.
3. AI processing
When an agent runs, relevant workspace content is sent to our AI provider (Anthropic) to generate the response or perform the work. These requests are made under commercial API terms that do not permit training on your data. If you supply your own AI API key, requests run under your key and your agreement with that provider.
4. Google user data
If you connect a Google account, we access only the scopes you approve (for example Calendar, Analytics, or Search Console data) and use them solely to power the features you configure — building reports, syncing meetings, and similar workspace functions. Google user data is never sold, never used for advertising, and never used to train AI models. Trelleon's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. You can revoke access at any time in Settings or at myaccount.google.com.
5. Who processes data for us
We use a small set of subprocessors to run the Service: Supabase (database, auth, file storage), Vercel (application hosting), Fly.io (background workers), Upstash (job queue), E2B (sandboxed agent execution), Anthropic (AI processing), Stripe (payments), and Resend (transactional email). Each processes data only as needed to provide their function.
6. Retention and deletion
Workspace data is retained while your account is active. When a workspace is deleted, or on request after cancellation, we delete its content from production systems within 30 days, with encrypted backups aging out on their normal cycle. You can export your content before deleting.
7. Security
Data is encrypted in transit and at rest, tenant data is isolated with row-level security, and connector credentials live in an encrypted vault. Access to production systems is limited and audited. No method of storage is 100% secure; report suspected issues to the address below.
8. Your rights
You can access, correct, export, or delete your personal information — most of it directly in the product, or by contacting us. Depending on where you live (for example the EEA, UK, or California) you may have additional statutory rights, which we honor.
9. Changes and contact
We will post any changes to this policy here and, for material changes, give notice in the product or by email. Questions or requests: support@wedoworldwide.com.