TrusetaPrivacy Policy

Privacy Policy

Effective June 9, 2026 · Last updated September 17, 2026

Truseta is a wealth tracking platform. We are not a financial institution, investment adviser, or broker-dealer, and nothing in the product — including anything produced by Quinn, our AI assistant — is financial advice. Speak to a licensed financial adviser before acting on any figure you see here. We never sell your data, run ads, or monetize your information. We earn revenue from subscription fees only.

Contents
  1. Who we are
  2. Data we collect
  3. How we use your data
  4. Third-party services
  5. Data sharing and disclosure
  6. Data security
  7. Data retention
  8. Your rights
  9. California residents (CCPA/CPRA)
  10. Children's privacy
  11. Changes to this policy
  12. Contact us

1Who we are

Truseta is a private wealth operating system for high-net-worth individuals, family offices, and their advisors. The platform is operated by Truseta Corporation, a Florida corporation (“Truseta,” “we,” “our,” or “us”).

Access to Truseta is by invitation or approved application only. We do not offer open public registration.

Questions about this Privacy Policy can be directed to privacy@truseta.com.

2Data we collect

2.1 Account and identity data

When you create an account, we collect your name, email address, and authentication credentials. We use Supabase Auth for identity management and session handling. If you enable multi-factor authentication (required for password sign-in and advisor portals; Google and Microsoft sign-ins rely on the provider's own second factor), your MFA enrollment data is stored securely.

2.2 Financial account data (via Plaid)

When you connect a bank, brokerage, retirement, or credit account using Plaid, Truseta receives and stores the following from Plaid on your behalf:

  • Account names, numbers (masked), types, and institution details
  • Current and available balances
  • Investment holdings: securities, quantities, prices, and cost basis where available
  • Liability balances (mortgages, credit cards, loans)
  • Transaction history used for performance and cash flow analysis

Truseta does not receive or store your banking credentials. Credential entry and authentication with financial institutions is handled exclusively by Plaid. Plaid's own privacy policy applies to your interaction with Plaid's Link interface.

2.3 Manually entered financial data

Truseta is also used to track assets that cannot be connected automatically. This includes private equity investments, real estate properties, entity structures (LLCs, trusts, holding companies), capital call schedules, ownership percentages, cash flow records, and custom valuations. All of this data is entered or imported by you.

2.4 Documents

You may upload or link financial documents including K-1s, 1099s, partnership agreements, closing statements, and other records. Documents are processed by our AI features to extract structured data (see Section 3). Documents you link from Google Drive are accessed with the encrypted OAuth tokens you granted (not your Google password) and are not copied to Truseta servers unless you explicitly import them.

2.5 Google user data and Limited Use

Truseta's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

When you connect Google, we store encrypted OAuth access and refresh tokens so the product can call Gmail and Drive on your behalf. We do not keep a copy of your mailbox: searches run against Gmail at the moment you ask, and the results are not retained. Where a feature draws a specific finding out of your mail — the private-investment intelligence scan is the one that does — the sender, subject, date and a short excerpt of the source message are stored alongside that investment, so a figure can be traced back to where it came from. Drive folder IDs you configure are stored as pointers; file bytes stay in Google Drive unless you explicitly import a document.

We use Google Drive to read the financial documents you point us at and to write files you ask us to save. We use Gmail to let Quinn search and read correspondence you direct it to, and to leave draft replies in your own mailbox. We do not use Google user data for advertising, we do not sell it, and we do not use it to train generalised AI models. Human access to Google user data is limited to what you explicitly authorise, what is necessary for security or to comply with law, and what is required to operate features you are using.

Anthropic's Claude API is used only to operate Gmail and Drive features you enable or invoke (for example, asking Quinn to summarise an email, opening a Drive file, or an enabled private-investment intelligence scan, including scheduled runs). Gmail and Drive content is sent to Anthropic for that work only. It is not used to train Anthropic models, and we do not share it with Anthropic for training.

Truseta does not send email from your Gmail account. Anything Truseta composes for you — a reply Quinn suggests, a K-1 request to a fund manager — is placed in your Gmail drafts. You read it, edit it if you want, and send it yourself.

To be precise about the permission itself: Google has no setting that allows an application to prepare a draft without also allowing it to send. Google describes the permission we hold, gmail.compose, as “manage drafts and send emails”. It is therefore broader than what we do with it. We do not request the dedicated send permission, we do not request the permission that would let us alter your mail, and no code in Truseta calls Gmail's send endpoint. This is the one Google permission where the boundary is enforced by us rather than by Google, and we hold ourselves to it.

Truseta does not request access to Google Calendar. The compliance calendar in the product is Truseta data, not your Google Calendar.

Google user data is used to operate Gmail and Drive features you enable or invoke — including Quinn searches you ask for, Drive folders you point us at, and private-investment intelligence scans when that feature is on (including scheduled cron runs). It is not used for unrelated product features, advertising, or model training.

You can disconnect Google at any time from Settings → Connections. Disconnecting revokes Truseta's access with Google, deletes the stored encrypted tokens, and purges Google-derived email and calendar cache for that mailbox. Sender, subject, date and short excerpts saved on an investment by the intelligence scan (email_signals) stay with that investment until you request account deletion (Settings → Data, or support@truseta.com). You can also revoke Truseta from your Google Account permissions.

When K-1 portal notice detection is enabled, Truseta may read the sender, subject, and date of messages from portal senders you have turned on for your workspace (for example Carta or Goldman Sachs notification addresses). Message bodies are not stored. You can disable detection or individual portals in Settings or on the K-1 Tracker page.

2.6 Communications and AI interactions

When you use Quinn, Truseta's AI assistant, your queries and the context provided (including relevant portfolio data) are transmitted to Anthropic's Claude API to generate responses. Conversations may be stored in your account to provide continuity. We do not use your conversation data to train AI models, and we do not share it with Anthropic for training purposes.

2.7 Usage and technical data

We collect standard technical data including IP address, browser type, operating system, device identifiers, pages visited, and timestamps. This data is used for security, debugging, and service improvement. We do not sell or share this data for advertising.

2.8 Crypto account data (via Coinbase)

If you connect a Coinbase account using OAuth, we receive read-only access to your account balances and holdings. We do not receive the ability to move funds and we do not store your Coinbase credentials.

3How we use your data

We use your data for the following purposes and no others:

  • To operate and deliver the Truseta platform, including aggregating and displaying your financial data
  • To compute analytics, returns, IRR, net worth, and portfolio summaries
  • To power Quinn, the AI assistant, using context from your portfolio and documents
  • To operate Google features you invoke only — Gmail search/read/draft and Drive folder access — using encrypted OAuth tokens, and to store the sender, subject, date and a short excerpt when a feature (such as private-investment intelligence) draws a finding from mail
  • To extract structured data from documents you upload or link
  • To send platform notifications, alerts, and the daily wealth digest (where enabled)
  • To authenticate your identity and maintain session security
  • To detect and prevent fraud, unauthorized access, and abuse
  • To comply with legal obligations
  • To improve the platform based on aggregated, de-identified usage patterns

We do not use your financial data to make or suggest investment decisions, provide financial advice, or generate personalized recommendations of financial products. Truseta is a tracking and organizational tool, not an advisory service.

4Third-party services

Truseta integrates with the following third-party services to deliver its functionality. Each operates under its own privacy policy and terms.

Plaid Technologies, Inc.

Used for connecting and syncing bank, brokerage, and investment accounts. Plaid handles credential entry and financial institution authentication. Plaid's privacy policy is available at plaid.com/legal/privacy-policy.

Anthropic, PBC

Truseta uses Anthropic's Claude API to power Quinn. Queries sent to Quinn, including relevant portfolio context and — when you invoke a Gmail or Drive feature — the Google content needed for that request, are transmitted to Anthropic for processing only. Anthropic does not use that content to train models. Anthropic's privacy policy is available at anthropic.com/legal/privacy.

Supabase, Inc.

Truseta's database, authentication, and storage infrastructure runs on Supabase, hosted on Amazon Web Services. Your data is stored in a dedicated database instance. Supabase's privacy policy is available at supabase.com/privacy.

Vercel, Inc.

Truseta's web application is deployed and served through Vercel's edge network. Vercel's privacy policy is available at vercel.com/legal/privacy-policy.

Google LLC

If you connect Gmail or Google Drive, your use is governed by Google's terms and privacy policy. Truseta stores encrypted OAuth tokens, and stores the source details of any email a feature drew a finding from. We request only the scopes those features need (see Section 2.5). You can disconnect in the product or revoke access from your Google Account.

Coinbase Global, Inc.

If you connect a Coinbase account, your use of the Coinbase OAuth integration is governed by Coinbase's privacy policy. Truseta receives read-only balance and holdings data only.

5Data sharing and disclosure

We do not sell, rent, or trade your personal data. We do not share your data with advertisers or data brokers. We do not use your data to target you with advertisements.

We disclose your data only in the following limited circumstances:

  • To the third-party service providers listed in Section 4, strictly as necessary to operate the platform
  • To advisor or CPA accounts you explicitly authorize through the Truseta advisor portal, limited to the data scopes you grant
  • To comply with a valid legal obligation, court order, or government request, after we have made reasonable efforts to notify you unless prohibited by law
  • To protect the security or integrity of the platform or to prevent imminent harm
  • In connection with a merger, acquisition, or sale of substantially all assets, subject to advance notice and successor privacy protections

6Data security

We operate above baseline standards for a software product handling personal financial data.

  • All data is encrypted at rest using AES-256 encryption
  • All data is encrypted in transit using TLS 1.2 or higher
  • Sensitive fields (Plaid access tokens, tax IDs, account numbers) are encrypted at the column level using per-user derived keys — your encrypted data cannot be decrypted using another user's key
  • Encryption keys are stored in a dedicated secrets vault separate from the application database
  • Multi-factor authentication is required for password accounts and advisor portals; Google and Microsoft sign-ins use the provider's second factor
  • Sessions require re-authentication daily on desktop, and every 7 days on iOS devices
  • Access to production data by Truseta personnel is logged and requires separate authorization
  • Platform access is controlled: only approved accounts can log in

If you believe your account has been compromised, contact us immediately at security@truseta.com.

7Data retention

We retain your account and financial data for as long as your account is active. If you close your account, we will delete your personal data within 30 days, except where retention is required by law or where encrypted backups are still within their rotation cycle (completed within 90 days).

You may request a full export of your data before account closure. Settings → Data produces a complete workspace archive on demand, without needing to contact us.

How to close your account. Deletion is deliberately not a self-serve button — a single click that erased an entire family office is not a control we are willing to ship. Request deletion from Settings → Data and we will confirm the request with you directly before anything is removed, then complete it within the 30 days described above. You may also email support@truseta.com.

If your concern is a connected account rather than the workspace itself, you do not need to wait for us: disconnecting Google in Settings → Connections revokes our access with Google immediately, deletes the stored encrypted tokens, and purges Google-derived email and calendar cache for that mailbox. Investment-intelligence email excerpts are removed on the account-deletion ticket, not on Disconnect.

8Your rights

You have the following rights with respect to your data:

  • Access: request a copy of the personal data we hold about you
  • Correction: request correction of inaccurate data
  • Deletion: request deletion of your data and account
  • Portability: request an export of your data in a machine-readable format
  • Restriction: request that we stop processing your data in certain circumstances
  • Objection: object to processing based on legitimate interests

To exercise any of these rights, email privacy@truseta.com from the address associated with your account. We will respond within 30 days. We may need to verify your identity before processing your request.

9California residents (CCPA / CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA).

In the past 12 months, we have collected the categories of personal information described in Section 2. We have not sold any personal information and do not sell personal information. We have not shared personal information with third parties for cross-context behavioral advertising.

You have the right to know what personal information we collect, disclose, or sell; the right to delete your personal information; the right to correct inaccurate personal information; the right to opt out of sale or sharing (not applicable, as we do not sell or share); and the right not to receive discriminatory treatment for exercising these rights.

To submit a CCPA request, email privacy@truseta.com. We will respond within 45 days.

10Children's privacy

Truseta is not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If you believe a minor has created an account, contact us at privacy@truseta.com and we will delete the account promptly.

11Changes to this policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or through a notice in the platform at least 14 days before the changes take effect. Your continued use of Truseta after the effective date constitutes acceptance of the revised policy.

12Contact us

For privacy questions, data requests, or security concerns:

  • Email: privacy@truseta.com
  • Security issues: security@truseta.com
  • Mailing address: Truseta Corporation, 1900 Glades Rd, STE 340, Boca Raton, FL, 33496
Truseta
Privacy PolicyTerms of ServiceSecurityHome
© 2026 Truseta Corporation.