Privacy at a Glance
- We do NOT sell your personal data
- We do NOT use your content to train AI models
- Voice data is NOT classified as biometric data
- You can request deletion of your data at any time
- Data is stored securely in the United States
1. Introduction
TrueTone AI, LLC ("TrueTone AI," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform, website, applications, and services (collectively, the "Service").
Scope: This Privacy Policy applies to all users of the Service, including visitors to our website, registered users, and customers.
Who We Are: TrueTone AI, LLC is a Virginia limited liability company that provides AI-powered content generation, voice cloning, website hosting, and marketing tools for professionals.
By using the Service, you consent to the data practices described in this Privacy Policy. If you do not agree with these practices, please do not use the Service.
2. Information We Collect
2.1 Information You Provide Directly
- Account Information: Full name, email address, phone number, and password (managed by Kinde)
- Profile Information: Job title, company name, website URL, avatar image, bio, timezone, and language preferences
- Organization Data: Company name, logo, business address, brand colors, and compliance information
- Voice Data: Voice recordings from interviews and voice samples for cloning
- Content Data: Blog drafts, social media posts, emails, and other content you create or edit
- Contact/CRM Data: Customer and lead information you input, including names, emails, and phone numbers
- Review Data: Customer reviews you manually enter or sync from external platforms
- Payment Information: Processed by Stripe; we do not store complete credit card numbers
- Communications: Support tickets, feedback, and inquiries you send us
2.2 Information Collected Automatically
- Device Information: Browser type, operating system, device type
- Log Data: IP addresses, access times, pages viewed, referrer URLs
- Usage Data: Features used, content generated, actions taken within the Service
- Analytics Data: Session duration, page views, bounce rates, engagement metrics
- Cookie Data: Authentication tokens, session identifiers, preferences
- Location Data: Approximate location based on IP address
2.3 Information from Third Parties
- Kinde Auth: Authentication status, login events, user verification
- Stripe: Subscription status, payment success/failure (not full card details)
- Google Business/Places: Business reviews when you connect your account
- FireCrawl: Website analysis data (only with your explicit consent)
- Bundle Social: Post scheduling status and social account connections
2.4 Voice & AI Processing Data
- Voice recordings submitted for voice cloning
- Voice analysis characteristics (tone, formality, humor, emotional expression)
- Content generation prompts and parameters
- TrueTone Profile personality assessments
3. How We Use Your Information
3.1 Service Provision
- Create and manage your account
- Authenticate your identity
- Generate AI content based on your inputs
- Create and manage voice models
- Host and manage your websites
- Process your CRM and contact data
- Aggregate and display reviews
- Schedule and publish content
- Provide analytics and reporting
3.2 Service Improvement
- Analyze usage patterns to improve features
- Fix bugs and resolve technical issues
- Develop new features and capabilities
- Optimize platform performance
Important: We do NOT use your personal content, voice recordings, or generated content to train our AI models. Your data remains your own.
3.3 Communications
- Send transactional emails (receipts, confirmations, account updates)
- Provide product updates and announcements
- Send marketing communications (with your consent)
- Respond to support inquiries
- Alert you to security issues
3.4 Legal & Compliance
- Prevent fraud and abuse
- Comply with legal obligations
- Resolve disputes
- Enforce our Terms of Service
- Comply with industry regulations (CFPB, etc.)
5. Data Retention
We retain your information for as long as necessary to provide the Service and fulfill the purposes described in this Privacy Policy:
| Data Type | Retention Period |
|---|---|
| Account data | Until account deletion + 30 days |
| Generated content | Until you delete it |
| Voice recordings | Until you delete them |
| Payment records | 7 years (tax/legal requirements) |
| Log data | 90 days |
| Analytics data | 26 months |
| Support tickets | 3 years |
| Backup data | 90 days after deletion request |
After account deletion, we retain your data for thirty (30) days to allow for account recovery, after which it is permanently deleted from our systems.
6. Your Rights & Choices
6.1 Access & Portability
You have the right to request a copy of the personal information we hold about you. You can export your generated content, voice recordings, and other data through the Service's export features.
6.2 Correction
You can update your profile information directly in the Service. If you believe any information we hold is inaccurate, contact us to request correction.
6.3 Deletion
You can delete individual content items within the Service. To request complete account deletion, contact us at privacy@truetone.ai. Upon deletion:
- Your account and profile will be deactivated
- Your data will be retained for 30 days for recovery purposes
- After 30 days, your data will be permanently deleted
- Some information may be retained for legal compliance
6.4 Communication Preferences
- Marketing emails: Unsubscribe via the link in any marketing email or update preferences in your account settings
- Transactional emails: Cannot be opted out while you have an active account
- Push notifications: Manage through your device or browser settings
8. Data Security
8.1 Technical Measures
- TLS/SSL encryption for all data in transit
- Encryption at rest for stored data
- Row Level Security (RLS) for multi-tenant data isolation
- OAuth 2.0 authentication protocols
- JWT token security with regular rotation
- Regular security audits and vulnerability assessments
8.2 Organizational Measures
- Employee security training and awareness
- Access controls and principle of least privilege
- Incident response procedures
- Vendor security reviews
8.3 Breach Notification
In the event of a data breach affecting your personal information, we will notify you via email within 72 hours of discovery and provide information about the breach, affected data, and remediation steps.
9. Data Storage & Transfers
Your data is primarily stored in the United States through our infrastructure providers (Supabase, Vercel, AWS). Some third-party service providers may process data in other locations:
- ElevenLabs: Voice processing
- OpenAI/Anthropic: AI content generation
- Google: Analytics and APIs
All service providers are bound by data processing agreements that require them to protect your data and process it only as instructed.
10. Children's Privacy
The Service is not directed to children under the age of 13, and we do not knowingly collect personal information from children under 13. If we learn that we have collected personal information from a child under 13, we will promptly delete that information.
If you are a parent or guardian and believe your child has provided us with personal information, please contact us at privacy@truetone.ai.
11. California Privacy Rights (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
11.1 Categories of Information Collected
- Identifiers: Name, email, phone number, IP address
- Commercial information: Subscription history, payment records
- Internet activity: Browsing history, usage data
- Audio information: Voice recordings
- Professional information: Job title, company name
- Inferences: AI-generated personality profiles
11.2 Your California Rights
- Right to Know: Request disclosure of personal information collected, used, and shared
- Right to Delete: Request deletion of your personal information
- Right to Opt-Out: We do NOT sell personal information
- Right to Non-Discrimination: Exercise your rights without discriminatory treatment
- Right to Correct: Request correction of inaccurate information
11.3 Submitting Requests
To exercise your California privacy rights, contact us at privacy@truetone.ai. We will verify your identity before processing your request. You may also designate an authorized agent to submit requests on your behalf.
11.4 "Shine the Light" Disclosure
We do not share personal information with third parties for their direct marketing purposes.
12. Voice Data Provisions
We take special care with voice data due to its personal nature:
12.1 Collection & Use
Voice recordings are collected when you participate in voice interviews or upload voice samples for cloning. This data is used solely to create and operate your personalized voice model.
12.2 Processing
Voice data is processed by ElevenLabs, our voice synthesis partner, under a data processing agreement. ElevenLabs processes voice data only to provide voice cloning and text-to-speech services.
12.3 Not Biometric Data
Your voice data is used solely for voice synthesis purposes, not for identification or authentication. We do not classify voice recordings as biometric data because they are not used to identify individuals.
12.4 Deletion
You may request deletion of your voice recordings and voice models at any time by contacting us at privacy@truetone.ai. Upon deletion, your voice data will be removed from our systems and our service providers' systems.
13. AI-Generated Content
13.1 No Training on Your Data
We do NOT use your content, voice recordings, or generated outputs to train our AI models. Your data is used solely to provide the Service to you.
13.2 AI Processing
When you generate content, your prompts are sent to AI providers (OpenAI, Anthropic) for processing. These prompts are designed to exclude personally identifiable information where possible.
13.3 Human Review
We do not routinely review AI-generated content unless flagged for potential policy violations or reported by users.
14. Third-Party Links & Integrations
The Service may contain links to third-party websites and integrations with third-party services. We are not responsible for the privacy practices of these third parties. We encourage you to read the privacy policies of any third-party services you connect.
When you authorize OAuth connections (such as Google Business Profile), you consent to the data sharing required for those integrations. You can revoke these authorizations at any time through your account settings or the third-party service.
15. Changes to This Policy
We may update this Privacy Policy from time to time. For material changes, we will provide at least thirty (30) days' notice via email or through the Service before the changes take effect.
The "Last Updated" date at the top of this policy indicates when it was last revised. Your continued use of the Service after any changes constitutes acceptance of the updated policy.
If you do not agree to the changes, you should stop using the Service and may request deletion of your account.
16. Contact Us
If you have questions about this Privacy Policy or our privacy practices, please contact us:
TrueTone AI, LLC
Privacy inquiries: privacy@truetone.ai
General support: support@truetone.ai
We will respond to privacy inquiries within thirty (30) days.
Ready to Get Started?
Join thousands of mortgage professionals using TrueTone AI to create authentic, compliant marketing content.