Legal
Privacy notice
Last updated 31 July 2026
Draft, pending legal review. This page describes our intended practice in plain language so you can evaluate the service. It is not the executed agreement. For a signable DPA or the current terms, write to security@triguna.ai.
Who this covers
Two different sets of people, with different relationships to us. Keeping them separate is the only way this page is useful.
- Account holders. The engineers and organizations who hold API keys. We are the controller for this data.
- Record subjects. The people and companies described by records retrieved through the API. Our customer decides why a record is retrieved; we process it on their instruction.
Account holder data
Name, work email, organization, authentication metadata, billing details handled by our payment processor, and request logs tied to your API keys. We use it to run your account, bill for usage, and investigate errors. We do not sell it, and we do not use it to train models.
Record data
A record is assembled at request time from independent sources and returned to the caller who asked for it. We retain the assembled record and its provenance so that repeat requests can be served and audited, and so that a caller can reconcile a past decision against what was actually returned.
Every record carries source and fetched_at. Those fields exist partly
for your engineering and partly for this: they are what makes a retrieval auditable rather than
anonymous.
Retention
- Account and billing data: for the life of the account, then as tax law requires.
- Request logs: 90 days, then aggregated.
- Assembled records: retained until deleted on request, or superseded by a fresh assembly.
Requests from record subjects
If you are described by a record we hold and want to know what that is, correct it, or have it deleted, write to security@triguna.ai. We will respond within 30 days. Where the record was retrieved on a customer's instruction, we will tell you so and route the request appropriately rather than acting unilaterally on their data.
Sub-processors
We use third parties for hosting, error monitoring, payments, and email. A current list is available on request and forms part of the data processing terms. We give notice before adding one.
Security
Keys are scoped per project and per environment, transport is TLS-only, and keys can be revoked with immediate effect. If you believe a key has leaked, rotate it (create a second key, move traffic, revoke the first) and tell us at security@triguna.ai.
Contact
Privacy questions: security@triguna.ai. General enquiries: contact page.