Who we are
TruePoint Agents is a sole proprietorship based in Vidalia, Georgia, United States.
You can reach a human at support@truepointagents.com.
What this policy covers
Two things:
- truepointagents.com — our marketing site, including the concierge chat on it.
- Our software products — subscription applications we build and run, each at its own
address, such as Portal Pilot at portal-pilot.truepointagents.com.
It does not cover anything else, because nothing else exists.
The short version
We sell access to software. We do not want your business records, we do not read them to learn anything, we do not sell them, and we do not train anything on them. We hold them because you put them in a product we run for you, and that is the only reason.
What we actually look at is boring: whether the servers are up, whether someone is attacking them, and whether people who sign up end up using the thing.
What we collect
If you only visit truepointagents.com
Standard web server records: your IP address, the pages you requested, the time, your browser and operating system version. We use these to keep the site running and to spot abuse.
The site sits behind Cloudflare, which sees the same request data and runs the anti-bot check you may occasionally see. Cloudflare sets its own cookies to do that.
The site also sets one cookie of our own, and here is exactly what it does.
tpa_vid is a random identifier — a UUID with no meaning outside our own records. It is set on your first visit and lasts a year. It is HttpOnly, so no script can read it, Secure, so it travels only over HTTPS, and SameSite=Lax, so it is not sent from other sites.
We use it for one thing: if you talk to the concierge more than once, or come back later and leave your details, it lets us recognise those as the same visitor rather than treating you as a stranger each time. It also helps us spot abuse. It is not advertising, it is not shared with anyone, and there is no third-party tracking on this site.
If you would rather not have it, block or clear cookies for this site — the site works without it, you will simply look like a new visitor each time.
If you use the concierge chat
The chat on our marketing site is answered by an AI assistant. When you use it we keep:
- what you type and what it replies, so we can answer you and so we know what people ask for;
- what you tell us about yourself — your message, your name and contact details if you give
them, and which tier you were interested in;
- how you arrived — your IP address, your browser's user-agent, the page you landed on, the
site that referred you, any campaign tags in the link, and the tpa_vid above.
Your conversation is sent to Anthropic to generate the reply. A notice of a new enquiry, including what you wrote, is sent to us over Telegram so a person sees it promptly. If we email you back, that email is sent through Cloudflare. All three are listed below.
Do not type anything into the chat you would not want stored and read by a person — it is a sales enquiry channel, not a secure one. The site also loads fonts from Google Fonts, which means Google receives your IP address when a page loads. Both are governed by their own privacy policies, not this one.
If you hold an account in one of our products
- Your email address and a password. We never store the password itself. It is stored as a
PBKDF2-HMAC-SHA256 hash with a salt unique to your account, which means we cannot read it, recover it, or tell you what it is.
- The records you create in the product. These are yours, and they are your responsibility —
see Your data is your responsibility below. Every row is tagged with your account, and the product enforces that separation at the database level.
- A small activity log: when you registered, when you first created a record, when your trial
notice was shown, when you subscribed, when you cancelled, and when you were refunded. Six timestamps. We use them to know whether the product is useful to people. They are not sold, shared, or used to profile you.
- A subscription reference — an identifier issued by Stripe linking your account to your
subscription, so the product knows whether you are paying.
Our products set no cookies of their own — no analytics, no advertising, no tracking. Your login is a token held in your own browser's local storage, which your browser sends only to us and which you clear by logging out. Our products carry no third-party analytics, advertising or tracking of any kind — no Google Analytics, no pixels, no session recording, and fonts are bundled into the application when it is built rather than fetched at page load.
Our products do sit behind Cloudflare, which sees each request and may set its own cookie to run its anti-bot check. That is governed by Cloudflare's privacy policy, not this one. Apart from Cloudflare, loading a product page makes no request to any outside service.
If you pay us
Your card details never reach our servers, and we never store them. Payment happens on Stripe's own hosted page. We receive back only what Stripe tells us: that a subscription exists, its status, and a customer identifier. Card changes and cancellations happen in Stripe's customer portal, which we do not see into.
Stripe is the data controller for your payment information. Their privacy policy governs it.
Your data is your responsibility
This section matters, so it is written plainly.
You decide what goes into the product. We do not choose it, review it, validate it, or correct it. Whatever you type, upload or import is yours — its accuracy, its legality, your right to hold it, and any consent you needed from the people it describes are all your responsibility, not ours.
Do not put regulated data into our products. Our products are general-purpose record-keeping tools. They are not designed, certified or contracted for:
- protected health information under HIPAA, or anything that would make us a business associate;
- payment card numbers or cardholder data under PCI-DSS;
- government identity numbers such as Social Security numbers;
- children's data covered by COPPA;
- classified, export-controlled, or similarly restricted material.
We have signed no Business Associate Agreement with anyone, and we are not a PCI-compliant processor. If you put that kind of data in anyway, you do so on your own responsibility and you accept the consequences of doing so.
We do not read your records. Staff access is limited to what is genuinely needed to keep the service running — investigating a fault you have reported, restoring a system, or responding to a security incident or a lawful order. We do not browse customer records, and we do not mine them for insight, product ideas, or model training. We are telling you this is limited, not impossible: anyone who runs a database can technically reach it, and a policy that claimed otherwise would be untrue.
Backups exist for our benefit, not as a promise to you. We take backups so that we can recover our own systems. They are an operational measure, not a data-protection service, not a guarantee, and not something you should rely on. We do not promise any backup will exist, be current, be complete, or be restorable, and we do not offer per-customer restores. Keep your own copies. Every product exports everything you hold to CSV, at any time, free, for as long as your account is open — see the Terms. That export is your backup. Taking it is your responsibility, and you should not wait: we may close an account or withdraw a product under section 13 of the Terms, which governs what happens then.
What we never do
- We never sell or rent your data. Not to advertisers, not to data brokers, not to anyone
who wants to market to you. We have no advertising business and no data-broker relationships. The one exception is a sale, merger or transfer of the business itself: a buyer would receive your data as part of the business, bound by this policy as it then stands, and we would tell you.
- We never train models on your data. Not ours, not anyone else's.
- We never send you marketing email you did not ask for. No cold outreach, no bought lists,
no "sequences". Marketing email only ever goes to someone who asked for it, and every one carries a working unsubscribe. Separately, while you hold an account we send a small number of service messages you cannot unsubscribe from: a price change, a change to these documents, and a security notice. Those come from us, by email to the address on your account — the products themselves send no email of their own, and every message about a payment comes from Stripe. If you write to us through the concierge chat and leave an address, we may reply to it; that is an answer to you, not marketing.
- We never charge you to get your data out. We will not withhold an export to make you pay.
Your data when you stop paying
Our products run a 30-day trial with no card. When a trial ends, or a subscription lapses, the account becomes read-only: you can still open everything, read everything, and export everything. What stops is creating and changing records. We do not delete your records because you stopped paying, and there is no countdown running against you.
That is how a lapsed subscription works. It is separate from our right, under section 13 of the Terms, to close an account or withdraw a product at any time — where that happens, section 13 sets out the export window you get. Do not treat "it will still be there" as a plan. Export.
If you ask us to delete your account, we delete it — see Your rights.
Who else touches your data
| Who | What they see | Why |
|---|---|---|
| Hetzner Online GmbH | The servers our products run on, and therefore the data at rest on them | Hosting |
| Cloudflare, Inc. | Requests to our sites — IP address, URL, headers | DNS, TLS, and blocking attacks |
| Stripe, Inc. | Your name, email and card details, which you give directly to them | Taking payment |
| Google Fonts | The IP address of visitors to truepointagents.com only | Web fonts on the marketing site |
| Anthropic | What you type into the concierge chat, and its replies | Generating the assistant's answers |
| Telegram | A notice of a new enquiry, including what you wrote and any contact details you gave | Alerting a human that someone is asking |
| Cloudflare Email | Your email address and the message, if we reply to an enquiry | Sending that reply |
That is the complete list of who touches your data while we run the business normally. It does not include a buyer of the business, or the advisers who would review it on a sale — see We never sell or rent your data above. We use no analytics vendor, no advertising network, no CRM, no email marketing platform, and no data enrichment service.
Where your data lives and how long we keep it
Our products run on servers in Nuremberg, Germany, operated by Hetzner Online GmbH. We are based in Georgia, United States, so your records are stored in the European Union and administered from the United States.
- Your records: kept for as long as your account exists. Deleted when you ask us to delete
the account.
- Server and security logs: 30 days, then discarded.
- Concierge conversations and enquiries: kept while we deal with your enquiry, and as our own record of what people ask for. We have not set a fixed deletion period for these yet. Ask us and we will delete yours.
- Payment records: kept as long as tax and accounting law requires, which is longer than your
account may last. Stripe holds the payment data itself.
Your rights
These rights are for people who hold an account with us, and they cover the data we hold about you as an account holder — your email address, your activity log and your subscription reference. They do not cover records a customer put into their own account about someone else: those belong to that customer, who decides what they contain, and you should contact them rather than us. If you cannot identify the customer, write to us and we will pass your request on.
Whatever country you are in, we will:
- tell you what we hold about you;
- give you a copy — though you can already export everything yourself, at any time;
- correct it;
- delete it, along with your account — with two exceptions we cannot avoid: payment records tax
and accounting law requires us to keep (see Where your data lives and how long we keep it), and anything we need to defend a legal claim already made or threatened. We delete those when the obligation ends.
Write to support@truepointagents.com and we will answer within 30 days. We will not charge you, and we will not make you jump through hoops.
We honour these for everyone rather than only where a statute compels it, because operating one standard is simpler than gating rights by geography. Doing so is our own choice, not an admission that any particular country's privacy law applies to us, and it does not change the governing law and courts named in section 14 of the Terms.
Security
Passwords are hashed, never stored. Traffic is encrypted in transit. Each customer's records are separated at the database level and the product enforces it on every request. Payment card data never reaches us.
This section describes how we have built the products, so that you can judge them. It is a description, not a warranty or a guarantee, and it does not change the No warranties and Limits on liability sections of the Terms, which govern.
We are a small business running real software on a small number of servers. We do not claim, and you should not assume, that our systems are immune to compromise. No system is. If a breach affects your data, we will tell you what happened, what we know, and when — without waiting to have a comfortable version of the story.
Children
Our products are for business use. They are not directed at anyone under 18, and we do not knowingly collect data from children. If you believe a child has given us data, write to us and we will delete it.
Changes to this policy
If we change this policy in a way that materially affects you, we will email account holders at least 30 days before it takes effect, and the date at the top will change.
Language
This policy is written in English. We may publish translations, including a Spanish translation, to help you read it. A translation is provided for convenience only. If a translation and the English version conflict, the English version governs.
Contact
support@truepointagents.com