Legal

Privacy Policy

Plain-language summary of what TruLayer collects, why we collect it, and the controls you have over your data.

Last updated: April 29, 2026

1. Who we are

TruLayer is a reliability platform for production AI agents, operated by OmniModa LLC (“TruLayer”, “we”, “us”). This policy describes the personal and operational data we process when you use our website, dashboard, and SDKs.

2. What we collect

We collect only what we need to run the service:

  • Trace and span data — the LLM call records, prompts, completions, tool calls, and metadata your application sends to our ingestion API via the TruLayer SDK or OpenTelemetry. You configure what is sent. The SDK redacts secrets and configurable PII fields client-side before they leave your process.
  • Account information — name, email, workspace name, and authentication identifiers from our identity provider (Clerk).
  • Billing information — handled by Stripe. We store the customer ID and subscription state; we do not store card numbers.
  • Product usage data — page views, feature interactions, and aggregate dashboard activity, captured at the workspace level for analytics. We do not capture personally identifiable user content in analytics events.
  • Operational logs — request logs, error traces, and platform telemetry needed to keep the service running and to investigate incidents.

3. How we use it

  • To provide the service — ingest traces, run evaluations, surface alerts, and serve the dashboard.
  • To bill you accurately and answer support questions.
  • To monitor reliability, security, and abuse of the platform.
  • To improve the product based on aggregate usage signals.

We do not sell your data. We do not share customer trace content with third parties for advertising, model training, or any purpose other than operating the service you signed up for.

4. Data retention

Trace and span retention is set by your subscription tier. After the retention window, raw spans are deleted; aggregated metrics may be retained for billing and capacity planning.

  • Free / Hobby — 30 days
  • Starter — 90 days
  • Growth — 180 days
  • Scale / Enterprise — 365 days (or longer by contract)

Account and billing records are retained for as long as your workspace is active and for a reasonable period afterwards to satisfy tax, accounting, and legal obligations.

5. Sub-processors

We use a small number of vetted infrastructure providers to deliver the service — hosting, authentication, payments, email, and analytics. The full list, with the region and purpose for each, lives on our Trust Center. We notify customers in advance of material sub-processor changes per GDPR Art. 28(2).

6. Your rights

You can exercise the following rights for any personal data we hold about you, regardless of where you live:

  • Access — request a copy of the data tied to your account.
  • Export — workspace owners can export trace, eval, and configuration data from the dashboard at any time.
  • Correction — update profile and workspace fields directly, or email us for anything you cannot self-serve.
  • Deletion — delete a workspace from the dashboard, or email us to delete your account. We honour deletion requests within 30 days unless retention is required by law.
  • Objection / restriction — write to us if you want to limit specific processing activities.

7. Security

All customer traffic is served over TLS 1.2 or newer. Trace payloads, eval records, and metadata are encrypted at rest with AES-GCM. API keys are stored as HMAC digests. SOC 2 Type I audit is in progress; Type II will follow. See our Security page for the full posture.

8. International transfers

TruLayer is operated from the United States. If you access the service from outside the US, your data may be transferred to and processed in the US. Where required, we rely on Standard Contractual Clauses with sub-processors handling data subject to EU/UK transfer restrictions.

9. Children

TruLayer is not intended for use by anyone under 16. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.

10. Changes to this policy

When we make material changes, we will update the “Last updated” date and — for active customers — send notice by email or in-product banner before the change takes effect.

11. Contact

For privacy questions, data subject requests, or anything that does not have an obvious home, reach our privacy team directly. We aim to respond within 5 business days.

privacy@trulayer.ai