PRIVACY & DATA HANDLING
Your evidence.
Your workspace.
Effective September 29, 2026. This notice describes the TruInspector website and TruInspector mobile application.
What TruInspector processes
TruInspector uses your signed-in identity and email address to control access. Account setup collects your name, company, email, optional phone number, job, state, industry and reporting needs. Passwords and recovery codes are stored as hashes. Email ownership is not currently verified. Assessment records contain the assessor details, routes, notes, classifications, findings, revisions and photos you choose to save. Location data may be included when you supply it or when readable GPS information is present in evidence.
How it is used
This information provides assessment analysis, evidence storage, reports, revision history and account access. TruInspector administrators can review access requests and approve or revoke users. Assessment APIs limit workspace records and original photos to their owner. Exporting an Excel report creates individual picture links: anyone with a link can view that picture and its selected report details, without an account. Deleting the owner’s TruInspector data removes those hosted picture pages. Site operators and hosting providers may have administrative access to stored data for operation and support.
AI and service providers
Photos or sampled video frames submitted for AI analysis are sent to the OpenAI API, along with assessment instructions and any attached customer requirements documents. All industry assessments can store uploaded PDF and Excel requirements in private workspace storage and send their contents to OpenAI for comparison with submitted evidence. These original documents are not included in public picture links; document names and relevant criteria may appear in reports you export or share. Removing an attachment from a draft does not delete it from earlier saved records. TruInspector sends these requests with storage disabled. Provider security and abuse-monitoring retention may still apply under the provider’s policies. Cloudflare-backed hosting, database and object storage support the website and saved assessments. Customer accounts use email and a password. Developer sign-in is provided through ChatGPT. Industry, job, reporting needs and state may be sent to OpenAI to suggest a workspace; contact fields are excluded from this tailoring request. Invited accounts use a generated password with only its hash stored by TruInspector; session cookies provide time-limited access. Do not include material your organization has not authorized you to upload.
Plan payments
When you purchase through Stripe checkout, Stripe processes your contact, billing and payment information. TruInspector receives the customer, purchase or subscription details needed to manage billing and arrange approved access. Card details are entered on Stripe’s hosted page, not stored in the TruInspector assessment database. Stripe’s privacy policy applies to its payment services. Deleting TruInspector assessment data does not cancel a monthly subscription or remove records retained for billing; visit billing management for billing requests.
Phone permissions and sessions
The mobile app asks for camera access to take photos or record silent videos and uses the system picker for files you select. With optional foreground location permission, live GPS is displayed in the camera and attached to photos or matched video frames; unavailable or stale fixes are omitted. It does not need background location or microphone access. A phone session is stored using the device’s secure credential storage, expires after 30 days, and can be revoked from your account page. Only a hash of the phone session credential is stored on the server. The app keeps the current assessment draft on your device so it can be restored after closing the app. Signing out removes that device draft.
Retention and deletion
Saved assessment records, evidence, uploaded requirements documents and revision history remain until you delete your TruInspector data. On the account page, choose “Delete TruInspector account and data” to delete these records, your access request and phone sessions from TruInspector’s active application storage. You can also delete your TruInspector data in the mobile app. This does not delete your ChatGPT account, files you exported or copies shared with others. Temporary rate-limit and session records support abuse prevention. Hosting backups and security logs follow the providers’ retention processes.
Cookies, sharing and choices
Sign-in uses session cookies. TruInspector uses first-party traffic measurement to count visits, pages, campaign arrivals and account creation. Random browser identifiers expire after 90 days; a visit cookie supports attribution for up to 30 days. Traffic events are retained for 90 days and contain approximate network country and region, not raw IP addresses, precise GPS or email addresses. Do Not Track and Global Privacy Control are respected. Browser blocking and automated traffic can affect the counts. These statistics are available only to the TruInspector administrator. Exported reports are shared only when you choose to download or share them. You can decline camera permission and select existing photos instead. You can stop using AI and enter findings manually in the website workspace.
Help
Visit TruInspector help for access, session and deletion instructions. For privacy or account questions, email support@truinspector.com.