Privacy Policy
Last updated: August 6, 2026
This policy explains what personal data VolkerVisions LLC ("we", "us") processes when you use TrenchOS, and the rights you have. It applies to all users, including visitors and customers in the European Union / EEA and the UK.
1. Data we process
- Account data: email address, name, password (hashed by our auth provider), workspace role.
- Billing data: handled by Stripe. We store your organization's Stripe customer and subscription IDs and seat count; we never see full card numbers.
- Workspace content: brands, products, styles, prompts, chats, uploaded images/videos and generated media you or your team create. Uploaded and generated media is stored under per-organization paths at our storage provider and served from unguessable URLs that are not listed or indexed; those media URLs are not additionally access-controlled, so anyone you share such a link with can open the file.
- Provider API keys: stored encrypted; used only to run the generations your workspace requests. Only a masked hint is ever shown in the UI.
- Device hash (anti-sharing): at login/use we compute a salted SHA-256 hash of your browser user agent, screen dimensions and timezone, and store it with first/last-seen timestamps. This hash cannot be reversed into the underlying values. We do NOT store raw IP addresses with it, and we do not use canvas or hardware fingerprinting. Purpose: detecting one account being shared by many people, which is prohibited by the Terms.
- Support and feedback: messages you send us, in-app help questions.
- Technical logs: our hosting providers generate standard server logs (including IP addresses) for security and operations, retained short-term.
2. Why we process it (legal bases)
- To provide the service you signed up for - contract performance (Art. 6(1)(b) GDPR): account, workspace content, billing, provider keys.
- To protect the service and enforce seat licensing - legitimate interest (Art. 6(1)(f) GDPR): device hash, security logs, abuse prevention.
- To meet legal obligations (Art. 6(1)(c) GDPR): tax and accounting records.
- Where we ever rely on consent, you can withdraw it at any time.
3. Processors and recipients
We use these processors to run the service:
- Supabase (database, authentication, file storage)
- Vercel (application hosting)
- Stripe (payments and subscription management)
- Resend (transactional email)
- Anthropic (in-app help assistant)
When you run generations, your prompts and reference media are sent to the AI providers connected via YOUR API keys (e.g. Anthropic, kie.ai, fal.ai, Google Gemini) - that processing happens under your direct relationship with those providers. We do not sell personal data and we do not use advertising trackers.
4. International transfers
Our processors operate primarily in the United States. Where data of EU/EEA or UK users is transferred there, the transfer relies on the processors' safeguards such as EU Standard Contractual Clauses and, where applicable, the EU-U.S. Data Privacy Framework.
5. Retention
- Account and workspace data: kept while your subscription exists, including while suspended for failed payment. If you cancel, you can request deletion at any time; otherwise we delete or anonymize workspace data within 90 days of account closure.
- Device hashes: kept while the account exists, reviewed for enforcement purposes on a rolling 24-hour window.
- Billing records: kept as long as tax law requires.
6. Your rights
You can ask us for access to your data, correction, deletion, restriction of processing, data portability, and you can object to processing based on legitimate interest. Write to support@trenchos.ai - we answer within one month. If you are in the EU/EEA or UK you also have the right to lodge a complaint with your local data protection supervisory authority.
7. Cookies
We use only cookies that are strictly necessary to run the service: authentication session cookies and a small setup-state cookie. No advertising or cross-site tracking cookies.
8. Security
Data is encrypted in transit, provider keys are encrypted at rest (AES-256-GCM), database access is denied by default and every API route enforces organization membership server-side. Media files are stored under per-organization paths and reachable only via unguessable URLs.
9. Children
The service is for business use and not directed at children under 16.
10. Changes and contact
We will announce material changes to this policy in the app or by email. Controller: VolkerVisions LLC · support@trenchos.ai
VolkerVisions LLC · support@trenchos.ai

