TRUST+ Privacy Policy

Last Updated: April 24, 2026

TYCS, Inc. ("Trust+," "TrustYouCanSee.com," "we," "us," or "our") provides the TRUST+ Pro iOS app for service technicians and the TRUST+ Home iOS app for homeowners, together with the related cloud services that support those apps (collectively, the "Services").

This Privacy Policy explains what information we collect, how we use it, when we share it, how long we keep it, and what choices you have.

This Policy applies only to the Services. It does not govern the privacy practices of independent contractor partners, identity providers, or other third parties that may receive information through the Services and operate under their own privacy notices and terms.

California residents: see Section 7.D for a notice at collection, a categorized summary of the personal information we collect, and your California privacy rights and how to exercise them.

1. Information We Collect

A. Account and Authentication Information

When you create, access, or manage an account, we collect the information needed to authenticate you and manage access, including your name, email address, and — for password-based accounts — a password you choose.

We do not store passwords in plaintext. Passwords are transmitted over encrypted (TLS) connections and are stored by our authentication provider, Amazon Cognito, in a salted, hashed form designed to resist offline attack. After you sign in, the Services issue short-lived authentication tokens, which are stored in the iOS Keychain on your device and used in place of your password for subsequent requests.

If your device supports Face ID or Touch ID and you enable it for the app, the biometric match happens on-device through Apple's Secure Enclave. We never receive or store your biometric data; we only receive a signal from iOS that an enrolled biometric successfully matched.

TRUST+ Pro. Technician accounts are created and provisioned by an authorized administrator at the contractor or partner organization. We collect the technician's name, email address, role, and the partner organization they belong to.

TRUST+ Home. You may create an account with your name, email address, and a password, or sign in using Apple or Google. If you sign in through Apple or Google, we receive the name and email address associated with that account, and we do not receive or store a password for you.

B. Phone Number and One-Time Passcodes

If you choose phone verification, we collect your phone number solely to deliver a one-time passcode by SMS or voice call. The passcode is stored only as a one-way (SHA-256) hash, expires within five minutes, is limited to a maximum of five verification attempts, and is rate-limited (maximum three passcodes per hour per number). We do not use phone numbers for marketing.

C. Project, Service, and Quote Information

We collect information you create, submit, or upload through the Services, including project details, service addresses, notes, quote request details, invoices, work orders, and service history.

D. Photos, Videos, and Audio

TRUST+ Pro allows technicians to capture photos and videos for service work projects. TRUST+ Home allows homeowners to upload photos and videos for quote requests. This media may be stored on your device and synced to our cloud systems.

If a recorded video includes audio, that audio may be processed to support transcription and other video-processing features described in Section 1.F.

E. Location Information

With your permission, the Services may use your device's precise GPS location to help convert your current location into a project or service address. We use precise location for this purpose only. We do not use it for continuous or background tracking, and we do not share it for advertising. Precise geolocation is treated as sensitive personal information under California law; see Section 7.D.

F. Speech, Video Processing, and AI-Enabled Features

To provide certain features, we may process audio, video, and text using third-party tools and services. Depending on the feature being used, this may include:

Voice-to-text used inside text fields may also be processed on-device through Apple's speech recognition tools.

Consumer quote-request media submitted through TRUST+ Home is not sent to OpenAI.

How AI vendors handle your data. The table below summarizes what each vendor does with content we send them on your behalf. No vendor listed here trains a model on your content.

Vendor / Service Purpose Trained on our content? Retention by vendor Terms
OpenAI (Whisper via API) Transcribing technician-captured video audio No (default under OpenAI Business / API terms) Abuse-monitoring logs up to 30 days by default, then deleted, except where longer retention is required by law OpenAI Business Terms + API Data Processing Addendum
AWS Bedrock (Anthropic Claude models) Generating description and quote summaries No. Bedrock does not store or log prompts/completions, does not use them to train base models, and does not share them with the underlying model provider None (Bedrock does not persist prompts or completions) AWS Service Terms + AWS DPA
AWS Transcribe Video audio transcription No. We maintain an AWS Organizations AI-services opt-out policy that directs AWS not to use processed content to improve AWS AI services Only as needed to return the transcription result; not retained by AWS for service improvement under the opt-out policy AWS Service Terms
AWS Rekognition Detecting regions for address / license-plate blurring No. Same AWS Organizations AI-services opt-out policy applies Only as needed to return the detection result; not retained by AWS for service improvement under the opt-out policy AWS Service Terms
Apple on-device speech recognition Voice-to-text inside text fields No (processing happens on your device; content does not leave the device for this feature) None by us or Apple for this feature Apple Privacy Policy

G. Bluetooth Information

TRUST+ Pro uses Bluetooth to discover and connect to GoPro cameras. We do not collect personal information from the Bluetooth connection itself.

H. Device and Diagnostic Information

We collect limited technical information needed to operate, secure, and improve the Services, such as device model, iOS version, app version, crash information, and diagnostic data.

2. How We Use Information

We use personal information to:

3. How We Share Information

We do not sell, rent, or trade your personal information. We do not share personal information for cross-context behavioral advertising.

We may share information in the following circumstances:

A. Within a Partner Organization

For TRUST+ Pro, project data may be shared with authorized users within the same contractor or partner organization based on role-based permissions. In this arrangement, the contractor or partner organization acts as the controller of those work records, and Trust+ acts as a processor that stores and processes the records on their behalf in order to deliver the Services. Requests relating to work records created by a partner — including access, correction, export, or deletion — are directed to that partner.

B. Between Homeowners and Contractors

If you submit a quote request through TRUST+ Home, the information you submit, including photos and videos, may be shared with the contractor partner assigned to that request. Once that information is forwarded to the contractor, the contractor may independently retain and use those records for its own business, legal, operational, and recordkeeping purposes under its own privacy practices.

C. With Service Providers

We use third-party vendors to host, store, process, secure, and support the Services. These providers may process information on our behalf in order to deliver infrastructure, storage, transcription, image and video processing, AI summary features, and one-time-passcode delivery.

D. With Partner-Enabled Integrations

If a contractor partner enables an integration, we may share relevant project data with that integration. Depending on partner configuration, this may include ServiceTitan, JobNimbus, YouTube, and partner-configured webhook endpoints.

E. For Legal, Safety, and Security Reasons

We may disclose information when we believe disclosure is reasonably necessary to comply with law, respond to legal process, protect users or the public, investigate fraud or abuse, or protect our rights, property, and security.

4. Third-Party Services Used by the Services

Depending on the features used and the configuration selected by a contractor partner, the Services may use third-party services such as:

Those third parties operate under their own terms and privacy notices. We encourage users and partners to review those notices before using those services.

5. Storage and Security

We store data on Amazon Web Services infrastructure located in the United States. Media files are stored in Amazon S3. Project and application metadata may be stored in services such as DynamoDB.

We use safeguards designed to protect personal information, including:

No system is completely secure, and we cannot guarantee absolute security.

6. Data Retention

We keep personal information for as long as needed to provide the Services, maintain customer relationships, comply with legal obligations, resolve disputes, and enforce our agreements. The table below lists the retention period (or the criteria we use to determine the retention period) for each category of personal information we control. Records created, retained, or required by a contractor partner (the controller of work records) are subject to that partner's own retention practices and are not listed here.

Category Retention period / criteria
Account identifiers (name, email, role, partner) — TRUST+ Pro Retained while the partner organization keeps the account provisioned. Removed or de-provisioned at the partner's request.
Account identifiers — TRUST+ Home Retained while your account is active. On account deletion, soft-deleted for 30 days (restoration window), then permanently removed.
Password hashes (Cognito) Same lifecycle as the account. Removed when the account is deleted.
Authentication tokens (iOS Keychain, device-local) Short-lived (minutes to hours). Refreshed and rotated automatically; cleared on logout or app uninstall.
Phone number (for OTP) Retained while linked to a consumer account; removed when that account is deleted.
One-time passcode (SMS / voice) Stored only as a one-way hash. Expires within five minutes; purged after verification or expiry.
Project and quote data (addresses, notes, statuses) Retained while the relevant partner or Home account is active. On delete, soft-deleted up to 90 days, then permanently removed from systems we control.
Photos and videos captured by technicians (TRUST+ Pro) On device: default retention 90 days (partner-configurable). In cloud: retained while the project is active; on delete, soft-deleted up to 90 days, then permanently removed.
Photos and videos uploaded by homeowners (TRUST+ Home) Retained while the TRUST+ Home account is active. On account deletion, soft-deleted for 30 days, then permanently removed.
Precise GPS location used to populate a service address Retained as part of the associated project record, subject to the project retention row above. Not retained separately.
Processed media artifacts (transcripts, redaction masks, processing metadata) Retained with the parent video. Subject to the same soft-delete / 90-day permanent removal.
Device and diagnostic information (crash reports, app version, iOS version) Retained for up to 90 days for operational and security purposes, then aggregated or deleted.
Server logs and audit records Retained for up to 90 days for security and abuse-prevention purposes, or longer where required by law.
Backups Rolling point-in-time snapshots are retained for up to 35 days. Cognito export snapshots are retained for up to 30 days, then deleted.

Note: records created, retained, or required by contractor partners — including projects, invoices, work orders, quote records, and service history — may continue to be kept by those businesses under their own retention and recordkeeping practices even after a TRUST+ Home account is deleted.

7. Your Privacy Choices and Rights

A. Device and App Controls

You may revoke permission for location, camera, microphone, photos, speech recognition, or Bluetooth access through your iOS settings. The Services will continue to operate without those permissions, though some features may not be available.

B. Access, Correction, Export, and Deletion

You may:

C. Partner-Controlled Records

For TRUST+ Pro, some accounts and records are administered by a contractor, employer, or partner organization. In those cases, that organization acts as the controller of the work records and may control certain access, deletion, retention, and export decisions for business records associated with your work account. Requests directed to Trust+ for records controlled by a partner will be forwarded or directed to the relevant partner.

D. Notice to California Residents

This section applies to California residents and is provided as a matter of policy. It summarizes the categories of personal information we collect, the purposes for which we use it, our disclosures, and the privacy rights available under California law. Even if Trust+ is not required to provide all of the following, we commit to the practices described below.

We do not sell or share personal information. We do not sell personal information as that term is defined under the California Consumer Privacy Act ("CCPA"), and we do not share personal information for cross-context behavioral advertising. We have not sold or shared personal information in the preceding twelve (12) months, and we do not anticipate doing so.

Notice at Collection — Categories of Personal Information Collected in the Preceding 12 Months

Category of personal information (Cal. Civ. Code § 1798.140) Examples we collect Sources Business purposes Disclosed to (categories of recipients) Sold / shared? Retention
Identifiers Name, email, account ID, IP address, device identifiers Directly from you; from your identity provider (Apple / Google); from your partner organization Create and manage accounts; authenticate; secure the Services; deliver support AWS (Cognito, hosting), Apple / Google (when used for sign-in), partner organization No See Section 6
Customer records / signed contract info (Cal. Civ. Code § 1798.80(e)) Phone number, mailing / service address Directly from you Phone verification; populate service address; communicate about service AWS (SMS / voice delivery); partner organization (service address) No See Section 6
Commercial information Project and service records, quote requests, invoices, work orders Directly from you; from your partner organization Deliver the Services; fulfill requested work Partner organization (controller of work records); integrations enabled by the partner (e.g., ServiceTitan, JobNimbus) No See Section 6
Internet or other network activity Log data, app usage, crash reports, diagnostic data From your device while using the Services Operate, secure, and improve the Services; detect abuse; diagnose bugs AWS; crash-reporting infrastructure No See Section 6
Geolocation data Precise GPS location (only when you grant permission and only to populate a project / service address) From your device, with your permission Convert current location to a project / service address None beyond our service providers (AWS) No See Section 6
Audio, electronic, visual, or similar information Photos, videos, and video audio you capture or upload; derived transcripts and redaction data Directly from you; generated by processing your content Document service work; support quote requests; provide transcription, redaction, and summary features AWS (storage + AI processing); OpenAI (technician-video transcription); partner organization; integrations enabled by the partner No See Section 6
Professional or employment-related information Technician role and employer (partner organization) for TRUST+ Pro From the partner organization that provisions the account Apply role-based permissions; scope access to partner data Partner organization No See Section 6
Inferences None. We do not draw inferences to create a profile reflecting preferences, characteristics, behavior, or attitudes. No
Sensitive personal information (see below) Account log-in credentials (for authentication); precise geolocation (when you grant permission) Directly from you; from your device with permission Authenticate; secure accounts; populate service address. Not used to infer characteristics. AWS (Cognito for credentials; storage for GPS-derived address) No See Section 6

Categories we do not collect through the Services: characteristics of protected classifications (CCPA category D), biometric information (category E — Face ID / Touch ID matches happen on-device via Apple's Secure Enclave and are never sent to us), non-public education information (category J), and profiling / inferences (category K).

Sensitive Personal Information

We use sensitive personal information — specifically, account log-in credentials and precise geolocation — only as reasonably necessary to provide the Services you request, to maintain the quality and security of the Services, and to prevent fraud and abuse, as permitted by Cal. Code Regs. tit. 11 § 7027(m). We do not use sensitive personal information to infer characteristics about you. Because we limit our use of sensitive personal information to these permitted purposes, the right to limit use of sensitive personal information is generally not applicable; you may still submit a request under that right and we will evaluate it in good faith.

Your California Privacy Rights

Subject to the exceptions and verification steps described below, California residents have the following rights:

How to Exercise Your California Privacy Rights

Request method. Submit a privacy-rights request at https://support.trustyoucansee.com/submit/, selecting the privacy-rights category. We acknowledge requests within ten (10) business days and respond substantively within forty-five (45) days. We may extend that period once by up to forty-five (45) days where reasonably necessary, and we will notify you within the first forty-five-day window if we do.

Verification. To protect your information, we verify a requester's identity before responding. Verification is based on matching the request to identifiers already associated with the account — typically the email address tied to the account, and for higher-risk requests (e.g., deletion) a confirmation via a secondary channel such as the account's verified phone number. We will not require a government-issued ID for routine requests. If we cannot verify a request, we will tell you why and offer a path to re-submit.

Authorized agents. You may designate an authorized agent to submit a request on your behalf. The agent must provide (i) your written, signed permission authorizing them to act on your behalf, and (ii) verification of their own identity. We may also contact you directly to confirm the agent's authority before processing the request. A valid power of attorney under California Probate Code §§ 4000-4465 will be accepted in place of a separate signed permission.

Opt-out preference signals. Trust+ does not engage in the "sale" or "sharing" of personal information, so there is no sale/share activity for an opt-out preference signal (such as Global Privacy Control) to stop. We nonetheless recognize GPC signals that reach our public-facing web properties and treat them as a request not to sell or share personal information.

Records of requests. We keep a record of privacy-rights requests as required by Cal. Code Regs. tit. 11 § 7101 for a minimum of twenty-four (24) months.

Other Rights

Depending on where you live, you may have additional privacy rights under applicable law, similar in substance to the California rights above. Residents of jurisdictions with such laws may use the same support request channel to exercise those rights; we will honor them to the extent required by applicable law.

8. Children's Privacy

The Services are not intended for children under 18, and we do not knowingly collect personal information from children.

9. Changes to This Policy

We may update this Privacy Policy from time to time. If we make a material change, we may notify you through the Services, by email, or by updating the "Last Updated" date at the top of this page. We encourage you to review this page periodically.

10. Contact Us

If you have questions about this Privacy Policy or would like to exercise your privacy rights, submit a request through our support site:

https://support.trustyoucansee.com/submit/

TYCS, Inc.
All privacy-rights requests should be submitted through the support site above so they can be tracked, verified, and responded to within the timeframes described in Section 7.D.


© 2026 TYCS, Inc. All rights reserved.