Privacy Policy, VRM

Last updated: July 13, 2026

This Privacy Policy explains how Truegility Inc., a Delaware corporation ("Truegility," "we," "us"), collects, uses, and protects personal information in connection with the VRM application (the "Service"). By using the Service you agree to this Policy and our Terms of Service. We designed VRM to collect as little as possible.

This Policy governs the VRM application specifically. In the event of any conflict between this Policy and Truegility's general Privacy Statement, this Policy controls with respect to the Service.

1. Our Privacy-First Design

The business data you analyze in VRM is processed entirely within your web browser. Your datasets, the files you open, and the analyses and files you save stay on your own device, they are never uploaded to, transmitted to, or stored by Truegility. The only personal information we hold is the minimal account data needed to sign you in and to know who our users are.

2. Information We Collect

WhatWhen / HowWhy
Email addressYou enter it to sign inTo send your one-time sign-in code and identify your account
One-time sign-in codeGenerated when you request sign-inStored only as a one-way cryptographic hash, never the actual code, and deleted the moment it is used or after 10 minutes
Sign-in timestamps & login countEach sign-inAccount activity and security
IP addressRecorded in our security/audit log on authentication requestsRate limiting, abuse prevention, and audit; auto-deleted after ~90 days
Rate-limit counters (send times/counts)When you request codesTo prevent email flooding and abuse
Consent record (timestamp + policy version)When you accept our Terms & this PolicyProof that you agreed
Usage analytics (telemetry)As you use the appUnderstand how the product is used and improve it (see Section 4a)

3. What We Do NOT Collect

4. How We Use Your Information

Solely to authenticate you, operate and secure the Service, prevent abuse, maintain a security audit trail, record your consent, understand and improve how the product is used, and communicate with you about your account. We do not sell your personal information and do not use it for advertising or profiling.

Legal basis (GDPR): We process this information under the following legal bases: Contractual Necessity (authenticating you and operating the Service you signed up for); Legitimate Interest (security audit logging, abuse prevention, and product-usage telemetry); and Consent (recording your acceptance of our Terms and this Policy). Where we rely on legitimate interest, we have considered that this processing is proportionate to its narrow security and product-improvement purposes and does not override your rights and freedoms.

4a. Usage Analytics (Telemetry)

To understand how VRM is used and to improve it, we record product-usage telemetry associated with your account. This includes: sign-in sessions and how long you use the app, which tabs and features you use, and operational metrics such as how long an analysis takes to run and how many rows are in the dataset you are analyzing. This telemetry never includes the contents of your data, only counts, timings, feature names, and similar metadata. Unlike our security logs (deleted after ~90 days), usage telemetry may be retained indefinitely in aggregate to inform product decisions; however, if you ask us to delete your account, we will delete the telemetry associated with your account as well (see Section 8).

5. Cookies

We use a single, strictly-necessary session cookie to keep you signed in after you enter your code. It is HttpOnly, Secure, and SameSite=Strict, and contains only a signed session token. We use no analytics, advertising, or third-party tracking cookies.

6. Where Your Data Is Stored & Who Processes It

Your account information is stored and processed on Microsoft Azure cloud infrastructure located in the United States. Our systems authenticate to these resources using managed identities, so no access credentials are stored in our code, and your data is encrypted in transit (TLS) and at rest. Microsoft is our sole sub-processor.

Your browser also loads visual assets (web fonts and icons) from the Google Fonts and jsDelivr content-delivery networks; as part of normal web delivery these networks receive your IP address. We do not share any account information with them. Where these or other providers process data outside the EEA or UK, we rely on the providers' Standard Contractual Clauses, applicable adequacy decisions, or equivalent safeguards for that transfer.

7. Data Retention

8. Your Rights

Depending on your location (including under the EU GDPR and the California Consumer Privacy Act), you may have the right to access, correct, delete, or export your personal information, and to object to or restrict certain processing. Because we store so little, honoring a deletion request typically means removing your account record and associated audit entries. To make a request, contact info@truegility.com; we will respond within the time required by applicable law. We do not sell personal information.

Right to lodge a complaint: If you believe your data protection rights have been violated, you have the right to lodge a complaint with a supervisory authority. For EEA residents, this is your local Data Protection Authority. For UK residents, this is the Information Commissioner's Office (ICO). For California residents, you may contact the California Attorney General's office.

9. Data Breach Notification

In the event of a personal data breach affecting your account information that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by GDPR Article 33. Where the breach is likely to result in a high risk to you, we will also notify you without undue delay in accordance with GDPR Article 34 and applicable US state data breach notification laws.

10. Security

We use encryption in transit and at rest, managed-identity access to backend resources (no stored credentials), one-time hashed sign-in codes, rate limiting, strict security headers, and access controls. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

11. Children

The Service is intended for business users and is not directed to children under 18; we do not knowingly collect their information.

12. Changes

We may update this Policy from time to time. Material changes will be reflected in the "Last updated" date, and we may ask you to re-acknowledge.

13. Contact

Truegility Inc., info@truegility.com

← Back to sign in

© 2026 Truegility Inc. All rights reserved.