Privacy Policy
Effective date: August 11, 2026
Last updated: September 28, 2026
This Privacy Policy describes how Truee ("Truee," "we," "us," or "our"), an independently operated service comprising the Truee application and the website truee.ai (together, the "Service"), collects, uses, discloses, and protects personal information.
Truee is an AI-powered scam and fraud detection service. Because our Service is built to analyze content that you choose to submit - such as screenshots, text messages, emails, links, and phone numbers - we take our responsibility for handling that content seriously. This Policy explains exactly what we collect, why, how long we keep it, and the choices you have.
By using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with it, please do not use the Service.
1. Who We Are and How to Contact Us
Service operator ("data controller"): Truee, an independently operated service ("the operator")
Privacy contact: support@truee.ai
General support: support@truee.ai
If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland and we are required to appoint a local representative or Data Protection Officer, their contact details will be listed here; none is currently appointed.
2. Information We Collect
We collect information in three ways: (a) information you provide directly, (b) information collected automatically, and (c) information from third parties.
2.1 Information You Provide Directly
Account information. When you sign in with Google, we receive your name, email address, and profile picture from your Google account (see Section 2.3). We do not receive or store your Google password.
Content you submit for analysis ("User Content"). The core of the Service is analyzing content you voluntarily submit, which may include:
- Screenshots and images (e.g., of suspicious messages, websites, or advertisements);
- Text messages (SMS) or message content you paste or upload;
- Emails or email content, including headers, sender addresses, and body text;
- URLs and website addresses you ask us to scan;
- Phone numbers you ask us to look up;
- Files or documents you upload for review;
- Free-text descriptions or questions you provide.
Important: User Content may itself contain personal information - yours or a third party's (for example, a scammer's phone number, or an email that mentions a friend). You are responsible for ensuring you have the right to submit such content. We process it solely to provide the analysis you requested and as described in this Policy.
Communications. If you contact support, report a problem, or respond to a survey, we collect the contents of those communications and any contact details you provide.
Payment-related information. Payments are processed by our merchant of record, Paddle (see Section 5.4). We do not collect or store your full card number, CVV, or bank credentials. We receive limited transaction data from the payment processor, such as your subscription plan, transaction status, transaction identifiers, and billing country.
2.2 Information Collected Automatically
When you use the Service, we and our service providers automatically collect:
- Device and technical data: IP address, browser type and version, operating system, device type, screen resolution, language settings, and app version;
- Usage data: pages viewed, features used, scan history metadata (e.g., number and type of scans performed), timestamps, referring URLs, and interaction events;
- Approximate location: inferred from your IP address (country/region level). We do not collect precise GPS location;
- Cookies and similar technologies: as described in Section 12 (Cookies & Similar Technologies) below.
2.3 Information from Third Parties
- Google Sign-In: name, email address, and profile picture, as authorized by you through Google's OAuth consent screen. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
- Payment processor (Paddle): subscription and transaction status, plan type, and billing country.
- Threat intelligence and reputation sources: when you scan a URL or phone number, we may check it against third-party fraud, phishing, and reputation databases and receive results associated with that URL or number.
2.4 Information We Do Not Intentionally Collect
We do not knowingly collect government identification numbers, precise geolocation, biometric identifiers, or health information, and we ask that you do not submit such data unless it is strictly necessary for a scam analysis. If sensitive data appears incidentally in User Content (for example, in a screenshot), we process it only to deliver the analysis you requested.
3. How We Use Your Information
We use personal information for the following purposes:
- To provide the Service. Authenticating you, operating your account, performing AI-powered analysis of your submitted content, returning scam-risk assessments, maintaining your scan history, and delivering subscription features (including facilitating the VPN benefit for eligible yearly plans - see Section 6).
- AI processing. User Content you submit is processed by our AI systems (which may include third-party AI model providers acting as our processors) to detect indicators of scams, phishing, fraud, and social engineering. See Section 4 for details.
- To manage subscriptions and billing. Confirming your subscription status with our payment processors, applying promotional discounts in accordance with each promotion's terms, and handling cancellations.
- To improve the Service. Debugging, analytics, understanding feature usage, and improving detection quality. Where we use User Content for improvement purposes, we do so as described in Section 4.2.
- Safety and security. Detecting, preventing, and responding to fraud against the Service itself, abuse, unauthorized access, and violations of our Terms & Conditions and Acceptable Use Policy.
- Communications. Sending transactional messages (e.g., receipts, renewal reminders, security alerts, service announcements) and, with your consent where required, product updates and marketing. You can opt out of marketing at any time.
- Legal compliance. Complying with applicable laws, responding to lawful requests, and establishing, exercising, or defending legal claims.
Legal Bases (EEA/UK Users)
Where the GDPR or UK GDPR applies, we rely on: contract performance (providing the Service you signed up for); legitimate interests (securing and improving the Service, preventing abuse, limited analytics); consent (marketing communications, non-essential cookies, and any optional uses we specifically ask you about); and legal obligation (tax, accounting, and lawful requests).
4. AI Processing and User Content
4.1 How AI Analysis Works
When you submit content, it is transmitted securely to our systems and analyzed by automated AI models to identify scam indicators (e.g., phishing language, spoofed sender patterns, malicious URLs, known fraud signatures). The output is a risk assessment returned to you. AI analysis is automated; no human reviews your individual submissions in the ordinary course, except as described in Section 4.3.
4.2 Use of User Content to Improve Detection
We may use User Content and scan results to train, fine-tune, and improve our detection models and systems, so that the Service becomes better at identifying scams over time (for example, learning from confirmed phishing messages and adding malicious URLs to our threat database). Wherever feasible, we de-identify or aggregate content before using it for improvement purposes, and we do not use it for advertising or sell it to third parties. If you do not want your submitted content used to improve our models, you can request exclusion or deletion at any time by contacting support@truee.ai or by deleting the relevant scans or your account; deleted content is removed from future training use.
4.3 Limited Human Access
Authorized personnel may access specific User Content only when necessary to: (a) resolve a support request you raised; (b) investigate abuse, security incidents, or suspected violations of our Terms; (c) comply with legal obligations; or (d) verify and correct systematic model errors, under confidentiality obligations.
4.4 AI Limitations
AI-generated risk assessments are informational and probabilistic. They may produce false positives or false negatives and are not a guarantee of safety or a substitute for your own judgment or professional advice. See our Terms & Conditions for the full disclaimer.
5. How We Share Information
We do not sell your personal information.
We do not share your information with third parties for their own advertising purposes, with one exception: advertising measurement (Section 12). Where it is active, the Meta Pixel sends Meta the limited event information described there, and our servers send Meta a purchase report containing a one-way hash of your account email address, and Meta may use both for its own purposes under its own terms. Nothing you type into the Service is ever included. Visitors in the EEA, the UK and Switzerland are asked first, and nothing is sent unless they accept; elsewhere it is on by default and can be turned off at any time, which stops the purchase report too.
We share information only as follows:
5.1 Service Providers (Processors)
We use vetted vendors who process data on our behalf under contractual safeguards, including:
- Supabase - database hosting, authentication infrastructure, and file storage for account data and User Content;
- AI/model providers - automated analysis of submitted content, under confidentiality and no-training restrictions as described in Section 4.2;
- Cloud hosting and infrastructure providers;
- Analytics and error-monitoring providers;
- Email/communication delivery providers.
5.2 Advertising Measurement
Meta Platforms - the Meta Pixel reports page views and subscription events (plan name and list price) so we can tell which advertising works. Separately, when a payment succeeds our servers report that purchase to Meta directly, including a one-way hash of your account email address; Section 12 sets out exactly what that report contains and why it is sent from our servers rather than from your browser. Meta is not acting solely on our behalf for either: it may use the information for its own purposes, including its own advertising systems, under its own policies. In the EEA, the UK and Switzerland both are off until you accept. Elsewhere they are on by default, and both stay off if your browser sends a Global Privacy Control signal. You can turn them on or off at any time from Your privacy choices in the footer, and your answer governs both.
5.3 VPN Partner
The VPN benefit included with eligible yearly plans is operated by our third-party partner ("VPN Partner"). If you choose to activate the VPN benefit, we share the minimum information necessary to provision your access (such as your email address or a redemption identifier). Your use of the VPN itself is governed by the VPN Partner's own terms and privacy policy, and we do not receive, collect, or store your VPN browsing activity or traffic data. See our VPN Terms for details.
5.4 Payment Processors (Merchants of Record)
Purchases are handled by Paddle, who acts as the merchant of record for your transaction. They collect and process your payment details under their own privacy policies. We receive only limited transaction metadata (see Section 2.1).
5.5 Legal, Safety, and Corporate
We may disclose information: to comply with law or valid legal process; to protect the rights, property, or safety of Truee, our users, or the public; to enforce our agreements; or in connection with a merger, acquisition, financing, or sale of assets (in which case this Policy will continue to apply to your data, and we will notify you of any material changes).
6. VPN Benefit - Data Notes
- The VPN benefit is available only on eligible yearly subscription plans, not on monthly plans.
- Activation is optional. If you never activate it, no data is shared with the VPN Partner.
- Truee and the VPN Partner are independent controllers of the data each collects. We are not responsible for the partner's processing, and they are not responsible for ours.
7. Data Retention
We keep personal information only for as long as necessary for the purposes described in this Policy. In general:
- Account data and User Content are retained while your account is active. To delete individual scans or your entire account, contact support@truee.ai; deleted data is removed from our active systems.
- Transaction records are retained as long as required by applicable tax, accounting, and financial regulations.
- Support communications and security logs are retained for a reasonable period to resolve issues, maintain security, and defend legal claims.
- De-identified or aggregated data (which no longer identifies you) and threat-intelligence signatures derived from confirmed malicious content may be retained indefinitely.
Residual copies may persist in encrypted backups for a limited period before being purged on a rolling basis. Where law requires longer retention, we retain only what is required.
8. Data Security
We implement technical and organizational measures appropriate to the risk, including encryption in transit (TLS) and at rest, access controls and least-privilege permissions, authentication via Google OAuth (we never see your password), logging and monitoring, and vendor due diligence. No system is perfectly secure; if we become aware of a breach affecting your personal data, we will notify you and regulators as required by applicable law.
To report a security vulnerability, contact support@truee.ai.
9. International Data Transfers
Your account data and User Content are primarily stored on Supabase infrastructure hosted in Canada (Central region). Canada benefits from a European Commission adequacy decision for data transferred under its commercial privacy law (PIPEDA). Some processing (for example, AI analysis, payments, or email delivery) may occur in other countries where our service providers operate. Where personal data is transferred from the EEA, UK, or Switzerland to countries not deemed adequate, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (and the UK Addendum/IDTA where applicable).
10. Your Rights and Choices
Depending on your location, you may have the right to:
- Access the personal data we hold about you and receive a copy;
- Correct inaccurate data;
- Delete your data ("right to erasure");
- Port your data in a machine-readable format;
- Restrict or object to certain processing, including processing based on legitimate interests;
- Withdraw consent at any time, where processing is based on consent;
- Opt out of marketing via the unsubscribe link in any marketing email;
- Complain to your local data protection authority (EEA/UK) or applicable regulator.
California residents: You have rights under the CCPA/CPRA to know, access, correct, delete, and to opt out of "sale" or "sharing" of personal information. We do not sell personal information. The Meta Pixel and the server-side purchase report described in Sections 5.2 and 12 may count as "sharing" for cross-context behavioral advertising under the CPRA; you can opt out of both at any time using Your privacy choices in the footer, and we treat a Global Privacy Control signal from your browser as a valid opt-out of both. We do not use or disclose sensitive personal information for purposes requiring a right to limit. We will not discriminate against you for exercising your rights.
How to exercise your rights: email support@truee.ai from the email address associated with your account. We may need to verify your identity. We respond within the timeframes required by applicable law (generally 30-45 days). Requests to delete individual scans or your entire account are handled the same way, through support@truee.ai.
11. Children's Privacy
The Service is not directed to anyone under 18 (or the minimum age required in your jurisdiction, if higher), and we do not knowingly collect personal information from them. If you believe a child has provided us personal information, contact support@truee.ai and we will delete it.
12. Cookies & Similar Technologies
We keep our use of cookies and similar technologies (such as browser local storage) minimal:
- Strictly necessary: authentication and session management (keeping you signed in via Google Sign-In and Supabase), security and abuse prevention, and cookies set by Paddle during checkout for payment processing, fraud prevention, and tax calculation. These are required for the Service to function.
- Site event analytics: we collect first-party usage events (such as pages viewed, features used, and errors) to understand how the Service is used and to improve it. This data is used in aggregate.
- Advertising measurement: we load the Meta Pixel so we can measure how our advertising performs. It records that a page was viewed and that a subscription was started or completed, together with the plan name and its list price. It sets cookies belonging to Meta and allows Meta to recognise the same browser across other sites and its own services. In the EEA, the UK and Switzerland it requires your consent; elsewhere it is on by default and you can turn it off.
- Advertising measurement from our servers: when a payment succeeds, our servers report that purchase to Meta directly, rather than relying on your browser. We do this because a browser may be closed, may block the report, or may not be open at all when a subscription renews, and a measurement that only counts some sales is not a measurement. This report contains the amount paid, the currency, the plan, a one-way hash (SHA-256) of your account email address, a one-way hash of your Truee account identifier, and the Meta cookie identifiers already set in your browser if the Pixel was allowed to run. Hashing means Meta receives a fingerprint rather than the address itself, which it compares against fingerprints it already holds; it is not reversible by us, but it can be matched. This report is governed by exactly the same consent as the Pixel. If you declined, or if you are in a region where consent is required and you have not accepted, nothing is sent when you buy. If we hold no record of your choice at all, nothing is sent.
- What we never send to advertising or analytics providers: anything you type into the Service. The email addresses, phone numbers and ZIP codes you enter into a scan, along with scan results, pasted messages and uploaded screenshots, are never included in advertising events, in hashed form or otherwise. The only contact detail that ever reaches an advertising provider is the hashed form of your account email address, and only as part of the purchase report described above. We disable Meta's "Automatic Advanced Matching", which would otherwise read values from forms on the page.
- What we do not do: we do not sell data collected through cookies or events, and in the EEA, the UK and Switzerland we do not use advertising technologies at all unless you have agreed to them.
If you are in the EEA, the UK or Switzerland, the Meta Pixel is not loaded until you accept it: if you decline, or have not answered yet, no request is made to Meta and no Meta cookie is set. Everywhere else it loads by default, unless your browser sends a Global Privacy Control signal or you have turned it off. You can change your answer at any time using Your privacy choices in the footer of any page; turning it off stops any further data being sent, though information already shared cannot be recalled.
The same answer governs the purchase report our servers send. We record your choice against your device and your account so that it can still be honoured at the moment a payment succeeds, which may be long after the visit where you made it. Turning advertising measurement off stops that report as well, including for any renewal that happens afterwards.
You can control or delete cookies through your browser settings; blocking strictly necessary cookies may prevent sign-in and core functionality. Where required by law, non-essential technologies are used only with your consent.
13. Third-Party Links and Services
Scan results may reference or link to third-party websites (for example, the URL you asked us to analyze). We are not responsible for the privacy practices of third parties. This Policy does not apply to the VPN Partner, Paddle, or Google, each of which has its own privacy policy.
14. Changes to This Policy
We may update this Policy from time to time. For material changes, we will notify you by email or in-app notice before the changes take effect. The "Last updated" date at the top reflects the latest revision. Continued use of the Service after the effective date constitutes acceptance of the updated Policy, where permitted by law.
15. Contact
Questions or concerns about this Policy or our data practices:
the operator of Truee
Email: support@truee.ai
Truee