TruePaper AI Privacy Policy
Effective date: 22 September 2026
This Privacy Policy explains how TruePaper AI Inc. (TruePaper, we, us or our) collects, holds, uses and discloses Personal Data in connection with our website, platform, demonstrations and related products and services (collectively, the Offerings).
This Policy is a privacy notice, not a contract. A Client Agreement or data processing agreement may contain additional or stricter commitments. Nothing in this Policy limits rights that cannot lawfully be limited.
1. Definitions
- Authorised User means an individual whom a Client permits to access or use the Platform.
- Client means an accounting firm, professional-services firm or other organisation that evaluates, subscribes to or otherwise obtains the Offerings.
- Client Agreement means an order form, master services agreement, subscription agreement, data processing agreement or other written agreement between TruePaper and a Client governing the Offerings.
- Client Data means information, documents, files, records, prompts, corrections and other materials submitted to or connected with the Platform by or for a Client or Authorised User.
- Output means a draft, workpaper, extraction, classification, reconciliation, recommendation, request, report or other result generated by the Platform.
- Personal Data, also called Personal Information in some laws, means information or an opinion about an identified individual or an individual who is reasonably identifiable, or other information protected as personal information or personal data under applicable law.
- Platform means TruePaper's artificial intelligence-enabled platform and related features, applications and services.
- process means to collect, hold, access, organise, use, analyse, disclose, transfer, store or delete information.
- Website means our websites at https://truepaper.ai and https://portal.truepaperai.com, including their pages and subdomains.
2. Scope and our role
This Policy applies to Personal Data we handle about Website visitors, prospective and current Clients, Authorised Users, business contacts and people who communicate with us. It also describes our handling of Personal Data contained in Client Data, which may concern a Client's customers, employees, contractors and other individuals.
For account, Website, business-contact and similar information, TruePaper generally decides why and how the information is processed. For Client Data, the Client generally decides why the information is processed and instructs TruePaper how to process it. The Client is responsible for its own privacy practices and for providing required notices and obtaining any rights, permissions or consents needed for Client Data. TruePaper remains responsible for its own obligations under applicable law.
This Policy does not govern a Client's own privacy practices or a third-party website, service or integration that has its own privacy notice.
3. Personal Data we collect
What we collect depends on how a person interacts with us and what a Client chooses to submit or connect.
- Account and business-contact data. Name, work contact details, organisation, role, account preferences and related information a person provides.
- Sign-in data. When a person uses Sign in with Google or Sign in with Microsoft, we receive basic profile and authentication information made available by that provider, such as name, email address and account identifiers.
- Communications and support data. The content of enquiries, Demonstration requests, support requests, feedback and other communications, together with information needed to investigate or resolve an issue.
- Commercial and billing data. Billing contacts, subscription or plan information, invoices, payment status and transaction references.
- Device, usage and security data. IP address, browser and device type, operating system, referring pages, features used, timestamps, diagnostic information, authentication events, and application and security logs.
- Cookies and similar data. Information stored or read through cookies, local storage, pixels and similar technologies used for authentication, security, preferences, functionality, analytics and error diagnosis.
- Client Data and Outputs. Client Data may contain personal, accounting, financial, tax, identity, trust, superannuation and other regulated information that Clients choose to submit. Outputs may contain or be derived from that information.
- Integration and third-party data. Information received from identity providers, Client-authorised integrations and service providers acting for us.
Clients must only submit tax file number information where they are authorised to do so. We handle tax file number information in accordance with applicable law.
4. How we collect Personal Data
We collect Personal Data:
- directly from a person when they create or use an account, request a Demonstration, communicate with us or otherwise use an Offering;
- from Clients and Authorised Users that submit, connect, correct or generate information through the Platform;
- automatically from browsers, devices and systems that interact with the Offerings;
- from Google, Microsoft and other identity or integration providers a user chooses to connect;
- from service providers that support our business.
Some information is optional. If required account, authentication, contact or Client Data is not provided, we may be unable to create or secure an account, respond to a request, enter into a Client relationship or provide the relevant feature.
5. How we use Personal Data
Except for the de-identified and aggregated uses described in Section 6, we may use account, contact, commercial, communications, device and usage data, but not raw Client Data, to:
- create, authenticate, administer and secure accounts;
- provide, operate and support the Offerings;
- manage Demonstrations, subscriptions, billing and Client relationships;
- respond to enquiries, support requests and feedback;
- send service, security, account and transactional communications;
- send marketing communications as permitted by law and a person's preferences;
- monitor reliability, diagnose errors, prevent fraud or misuse, and protect the Offerings, our users and others;
- understand use of the Website and Platform and improve their functionality, usability and performance;
- conduct internal administration, reporting, quality assurance, auditing, risk management and business planning;
- comply with applicable law and binding legal process, and establish, exercise or defend legal claims; and
- carry out another purpose disclosed when the information is collected, authorised by the relevant person or Client, or otherwise permitted by law.
We use raw Client Data only as reasonably necessary to:
- provide, operate, configure, secure, support and administer the Offerings for the Client;
- follow the Client's and its Authorised Users' permitted instructions;
- comply with applicable law and binding legal process; and
- exercise and enforce rights under the applicable Terms of Service and Client Agreement.
We do not sell Personal Data or Client Data. We do not share Personal Data for cross-context behavioural advertising, use Client Data for third-party advertising or provide Client Data to data brokers.
6. Artificial intelligence and de-identified information
The Platform uses artificial intelligence and machine-learning systems to process Client Data and provide requested features and Outputs.
We use approved artificial intelligence providers to process the Client Data, prompts and Outputs needed to provide Platform features. Raw Client Data is not used to train general-purpose models. Provider retention varies by service and configuration.
Subject to applicable law and any stricter Client Agreement, we may use information derived from Client Data, Outputs and Platform use only after it has been robustly de-identified or aggregated so that no individual, Client or end-client is reasonably identifiable. We may use that information to analyse, evaluate, secure, develop, train and improve TruePaper products, models and systems. It does not include raw Client Data, customer documents or Google or Microsoft sign-in data, and we will not attempt to re-identify it.
7. How we disclose Personal Data
We may disclose Personal Data to the following categories of recipients when reasonably necessary for the purposes described in this Policy:
- Clients and Authorised Users. The relevant Client and people it authorises, according to their roles and permissions.
- Affiliates and personnel. Our affiliates and personnel may access information where reasonably necessary to provide, support, secure and administer the Offerings.
- Service providers. Providers of cloud infrastructure, hosting, databases, storage, content delivery, authentication, communications, monitoring, analytics, customer support, billing, security, and artificial intelligence or machine-learning services.
- Client-authorised integrations. Third-party applications, platforms and APIs that a Client or Authorised User chooses to connect. The third party's terms and privacy practices apply to its handling of information.
- Professional advisers. Lawyers, accountants, auditors, insurers and other advisers subject to appropriate duties of confidentiality.
- Corporate-transaction participants. Actual or prospective investors, lenders, buyers, successors and advisers involved in a financing, merger, acquisition, reorganisation, insolvency or sale of all or part of our business or assets, subject to appropriate confidentiality protections where practicable.
- Authorities and other parties for legal or safety reasons. Courts, regulators, law-enforcement bodies, government authorities and other parties where we reasonably believe disclosure is required or permitted by law, needed to protect rights or safety, or appropriate to investigate misuse and enforce an agreement.
- Recipients a person or Client directs. Other recipients where the relevant person or Client directs or authorises the disclosure.
Not every recipient receives every category of information. Additional provider information may be made available through a Client Agreement, data processing agreement or procurement process.
8. Google and Microsoft sign-in
When a person chooses Sign in with Google or Sign in with Microsoft, we use basic profile and authentication data received from that provider to authenticate the person, create or link their TruePaper account, display basic account information and protect account security.
We do not use social sign-in to access Gmail, Google Drive, Outlook, OneDrive, calendars, contacts or other mailbox or file content. We do not sell sign-in data, use it for advertising, or use it to train artificial intelligence models.
Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. A user may disconnect TruePaper through their Google or Microsoft account settings. We may retain account information already received where reasonably necessary for the purposes in this Policy, a Client Agreement or applicable law.
9. International handling
Our application databases and customer document storage are hosted in Australia. We work with affiliates and service providers in the United States and India, and Personal Data may be disclosed to, accessed from or processed in those countries.
Where applicable law requires it, we take reasonable steps and use contractual, organisational or technical safeguards designed to protect Personal Data disclosed overseas. A Client Agreement may include additional location or transfer commitments.
10. Cookies, analytics and browser signals
We and our providers use cookies, local storage and similar technologies for authentication, security, preferences, analytics, and error and performance monitoring. Our public Website may use traffic analytics. We do not use information collected through the Offerings for third-party or cross-context behavioural advertising.
Most browsers allow users to manage cookies and local storage, although blocking essential technologies may prevent some features from working. Where required, we provide additional choices through a cookie notice or settings control.
We do not currently respond to browser “Do Not Track” signals and honour other browser-based opt-out signals where required by law.
11. Retention and deletion
We retain Personal Data for as long as reasonably necessary to provide the Offerings, follow Client instructions, maintain security and business records, resolve disputes, enforce agreements and comply with law. Client Data retention, return and deletion are governed by the relevant Client Agreement and Client instructions.
When information is no longer required, we take reasonable steps to delete or de-identify it. Information may remain in backups or logs for operational, security or legal reasons, and de-identified or aggregated information may be retained as described in Section 6.
12. Security and data incidents
We use reasonable technical and organisational safeguards designed to protect Personal Data, including access controls, encryption and monitoring. Our safeguards evolve with the Offerings and the risks we identify.
We investigate suspected privacy incidents and provide notifications where required by law or contract.
13. Choices, access, correction and complaints
Depending on applicable law, a person may ask to access, correct or delete Personal Data or exercise other available privacy rights. Exceptions may apply.
A person may opt out of promotional email by using the unsubscribe method in the message or contacting us. An opt-out does not stop service, security, account or transactional communications.
Where practical and lawful, a person may make a general enquiry without identifying themselves or may use a pseudonym. Identification is normally required to create and secure an account, provide the Platform, administer a Client relationship, process an account-specific request or verify a privacy request.
To make a request or complaint, email privacy@truepaper.ai. Please describe the request and provide enough information for us to identify the relevant records. We may ask for information needed to verify identity and authority before acting. We will investigate complaints, respond within a reasonable period and explain available review options.
If the Personal Data is controlled by a Client, the request should usually be directed to that Client. We will assist the Client as required by applicable law and the Client Agreement.
If a person in Australia is dissatisfied with our response to a privacy complaint, they may contact the Office of the Australian Information Commissioner. Other regulators or remedies may be available depending on the person's location.
14. Children
The Offerings are designed for businesses and professional users and are not directed to children. A person under 18 must not create an account or use the Platform. If we learn that we collected a child's Personal Data directly in circumstances not permitted by law, we will take reasonable steps to delete it.
15. Changes to this Policy
We may update this Policy as the Offerings, our practices or applicable law change. We will post the updated Policy with a new effective date and provide any additional notice or obtain any consent required by law. A Client Agreement remains governed by its own terms.
16. Contact
TruePaper AI Inc.
8 The Green, Ste A
Dover, Delaware 19901
United States
