Trundle Privacy Policy
Last updated: August 2026
1. Introduction
Trundle Technologies Ltd (“Trundle”, “we”, “our”, or “us”) is committed to protecting your privacy and handling your data transparently and securely. This Privacy Policy explains how we collect, use, store, and protect your information when you use our website, applications, and services.
2. Who We Are & Data Protection Roles
Company: Trundle Technologies Ltd, a company registered in England & Wales.
Data Controller: For the purposes of processing personal data belonging to account holders, administrators, website visitors, and marketing recipients, Trundle acts as a Data Controller.
Data Processor: For proprietary customer content uploaded directly into interactive workspaces (such as code repositories, PRDs, and transcripts containing third-party personal data), Trundle acts as a Data Processor operating strictly under the instructions of our customers (the Data Controllers).
3. Lawful Bases for Processing
Under the UK General Data Protection Regulation (UK GDPR) and EU GDPR, we must establish a valid lawful basis to process your personal data. We rely on the following bases depending on the context of the interaction:
Performance of a Contract: Processing is necessary to fulfill our obligations under our Terms of Service, including managing your account, authenticating your login, and delivering the core functionalities of the Trundle platform.
Legitimate Interests: Processing is necessary for our legitimate business interests, provided they do not override your fundamental privacy rights. This includes monitoring fair usage, tracking system latency, error debugging, tracking aggregate platform usage metrics, and securing our infrastructure.
Legal Obligation: Processing is necessary to comply with financial, accounting, tax laws, or mandatory law enforcement requests.
Consent: Where you explicitly agree to non-essential storage or access (such as operational tracking pixels or behavioral cookies), we process data based on your affirmative consent.
4. Information We Collect
Depending on how you interact with Trundle, we may collect the following categories of information:
Account Information: Name, email address, encrypted password, and authentication details (such as Google OAuth tokens where applicable).
Workspace Information: User-generated content uploaded to the app, including repositories, projects, tasks, tickets, documentation, Knowledge Base assets (PRDs, notes, transcripts), comments, and attachments.
Connected Services Data: Metadata and content authorized by you via third-party integrations (e.g., GitHub repository access, Slack workspace structure, Google user tokens). We only fetch data strictly necessary to execute the features you activate.
Usage Information: Technical log data, including login activity, feature interaction metrics, error/crash reports, device/browser identifiers, and workspace performance tracking.
5. Artificial Intelligence & Data Processing
When you invoke our AI features, relevant snippets of prompts, code, or documentation are sent to our model gateways (Anthropic Claude and Google Gemini via enterprise Google Vertex AI endpoints).
5.1 Quality and Accuracy Disclaimer
AI-generated responses may occasionally be inaccurate, incomplete, or unsuitable for your intended purpose. AI outputs do not constitute professional or technical advice. Users retain full responsibility for reviewing, testing, and validating any AI-generated code or text descriptions before deploying or relying on them.
5.2 Training Restrictions
We enforce a strict zero-training policy. We do not permit our AI infrastructure partners to store, retain, or use your workspace data to train public models.
6. Third-Party Subprocessors
To deliver our platform services, we partner with trusted infrastructure and technical providers. These processors handle data only in accordance with our strict privacy instructions.
Provider
Purpose
Google Cloud Platform
Core hosting, database storage, system compute, and network infrastructure.
Google Vertex AI
Secure enterprise AI model hosting environment.
Anthropic Claude
Powers AI-assisted coding, analysis, and code review engines via Vertex AI.
Google Gemini
Powers conversational assistance and dynamic text generation via Vertex AI.
GitHub
Code repository syncing and developer environment integration.
Stripe
Enterprise-grade billing, invoicing, and subscription payment processing.
Resend
Delivery of transactional system emails and notifications.
Google OAuth
Secure, passwordless user authentication.
Slack
Powers optional conversational workspace workflows and automated ticket logging.
PostHog
Consent-based website and product usage analytics, processed through PostHog’s EU service endpoint.
Rollbar
Real-time application error monitoring and crash debugging.
Laravel Nightwatch
Server and platform performance monitoring.
Langfuse
AI observability, latency tracking, and prompt execution tracing.
Ably
Powers real-time websocket connections for live multi-user collaboration.
7. International Data Transfers & Safeguards
Trundle’s infrastructure is hosted on servers located within the UK and EEA. However, some of our subprocessors (such as Stripe, Slack, and US-based cloud infrastructure gateways) may transfer or access personal data outside the UK or European Economic Area (EEA).
To ensure your data remains protected when crossing borders, we enforce rigorous legal safeguards in compliance with Chapter V of the UK/EU GDPR. These include:
Utilizing countries that have been granted an official Adequacy Decision by the UK Government or European Commission (such as certified participants in the Data Privacy Framework).
Executing the Standard Contractual Clauses (SCCs) approved by the European Commission, alongside the UK International Data Transfer Addendum (IDTA), which contractually bind global recipients to equivalent European data protection standards.
Conducting Transfer Risk Assessments (TRAs) to verify that the destination legal system does not compromise data confidentiality.
8. Data Retention Policy
We maintain rigorous technical protocols to protect your data, including end-to-end encryption for data in transit (TLS 1.3) and encryption at rest.
We retain information only as long as your account remains active. If you request account deletion, your data is wiped from active production systems within a reasonable operational window. Legacy backups are fully overwritten on a standard automated rotation cycle.
9. Cookies and Tracking Technologies
Trundle uses cookies, tracking pixels, and browser local storage to maintain session persistence, secure authentication, and evaluate application performance.
9.1 Cookie Categorization
Under the Privacy and Electronic Communications Regulations (PECR) and the Data (Use and Access) Act, cookies are treated as follows:
Strictly Necessary (Consent Exempt): These cookies are essential to let you log in, access your unique workspace, secure your payment forms, and maintain platform state. They cannot be turned off.
Analytics (Consent Required on Our Public Website): We use PostHog to understand page visits and interactions so we can improve the website. PostHog loads only after you give affirmative Analytics consent. We use PostHog’s EU service endpoint, disable session recording, do not create person profiles, and do not intentionally send names, email addresses, or other directly identifying information through this website integration. Interface preferences that are strictly necessary to provide a feature you request may be stored separately.
Marketing & Tracking (Consent Required): Tracking technologies used to profile user behavior across unrelated networks or attribute marketing campaigns require explicit, affirmative opt-in consent before activation. Trundle does not deploy optional behavioral marketing cookies inside authenticated workspaces.
9.2 Managing Preferences
You can review, modify, or withdraw consent for non-essential cookie processing at any time by selecting “Cookie settings” in the website footer. Withdrawing Analytics consent stops further PostHog capture and clears its browser persistence where supported.
10. Your Rights and Data Subject Requests
Depending on your regional jurisdiction (such as the UK or EU), you possess explicit statutory rights over your personal data. These include:
The Right of Access: To request a complete copy of the personal data we hold about you.
The Right to Rectification: To correct inaccurate or incomplete profile records.
The Right to Erasure (“Right to be Forgotten”): To request permanent deletion of your personal datasets.
The Right to Restrict or Object: To halt or limit specific processing tracks (such as opting out of statistical monitoring).
The Right to Data Portability: To receive your personal data in a machine-readable format.
10.1 Right to Lodge a Complaint
If you believe Trundle has processed your personal data unlawfully or failed to address your privacy rights adequately, we ask that you contact us first so we can rectify the matter.
You hold an absolute statutory right to lodge a formal complaint at any time with the relevant supervisory authority. In the United Kingdom, this is the Information Commissioner’s Office (ICO). You can contact them via their website at https://ico.org.uk.
11. Compliance with Lawful Requests & Disclosures
We may disclose personal data if explicitly required to do so by applicable laws, or in good faith response to lawful subpoenas, warrants, or court orders issued by competent judicial authorities, provided such disclosures are legally mandatory and strictly limited to minimal necessary datasets.
12. Changes to this Policy
We may update this Privacy Policy from time to time to accommodate adjustments in product architecture, subprocessor changes, or evolving global data frameworks. The latest version will always be accessible on our public website with an updated revision date. Significant policy modifications will be highlighted via in-app dashboard alerts or email updates.