Legal

Privacy Policy

Last updated: October 2, 2026

This policy explains what information Trinitis ("Trinitis", "we", "us") collects when you visit trinitis.ai or use the Trinitis service at app.trinitis.ai, what we deliberately do not collect, and how we protect and retain what we hold.

1. The short version

  • Trinitis stores metadata about your data platforms — never the data values inside them.
  • Query history is kept for the audit trail with real data values stripped out.
  • Credentials for your platforms are held in AWS Secrets Manager, encrypted with AWS KMS.
  • Everything is hosted in the United States (AWS us-east-1).
  • Policies already enforced in your platforms keep working if you stop using Trinitis.

2. What we store

When you connect a data platform, Trinitis stores only the metadata it needs to manage access:

  • Schema, table and column names
  • Tags applied to those objects
  • Existing grants and privileges, as read from each platform's native API
  • Policies you draft and approve in Trinitis
  • Group and role membership
  • Query history for the audit trail, with real data values stripped

We also hold account information for people who use Trinitis: name, work email address and the authentication records needed to sign you in.

3. What we do not store

  • Customer data values — the rows and cell contents in your tables are never copied into Trinitis.
  • Column-value samples — Trinitis does not sample column contents today.
  • Literal values from your queries — they are stripped before query history is stored.

4. Access Trinitis needs to your platforms

On Snowflake, Databricks, Redshift and PostgreSQL, discovering column metadata requires the SELECT privilege. These platforms do not offer a metadata-only option, so the grant that reveals column names and types is the same grant that could read rows. Trinitis reads only schema and column metadata and stores no row values — but the credential you give us is capable of reading data, and you should evaluate it on that basis.

BigQuery is the exception: the roles/bigquery.metadataViewer role exposes column metadata while data reads are denied.

The exact privileges for each platform are listed in our connector documentation.

5. Information from our website

If you submit the demo request form, we receive the details you enter (name, work email, company and the information you choose to share) and use them to respond to you. Form submissions are delivered to our inbox by Resend, an email delivery provider.

The marketing site is hosted on Vercel and uses Vercel Web Analytics to count page views in aggregate.

6. How we use information

  • To provide the service: discover your data estate, draft policies, write approved policies into your platforms, and maintain the audit trail.
  • To sign you in and manage your team's access to Trinitis.
  • To respond to demo requests and support questions.
  • To secure and operate the service.

We do not sell personal information.

7. Credentials

Platform credentials are stored in AWS Secrets Manager, encrypted with AWS KMS. A credential is retained while its connection exists, including when a connection is archived — archival keeps the secret so past actions remain attributable in the audit trail. Credentials are removed during account offboarding, subject to AWS's 7-day recovery window.

8. Hosting and encryption

  • Hosting: United States — AWS us-east-1 (N. Virginia). Additional regions are on the roadmap.
  • At rest: encrypted with AES-256 via AWS KMS, including database storage.
  • In transit: TLS 1.2+.

9. Subprocessors

We use the following providers to deliver the Trinitis service:

  • Amazon Web Services — application hosting, database and credential storage
  • Vercel — marketing site hosting
  • Auth0 — authentication
  • Google Workspace — email and calendar/scheduling

10. Retention

  • Configuration and metadata: kept for the life of your account and deleted within 30 days of termination.
  • Audit and access-intelligence events (query metadata, values stripped): kept on a rolling 12-month window from the event date. These are not deleted at termination; they are purged when they reach the end of the window.
  • Credentials: deleted at account offboarding, with AWS's 7-day recovery window.
  • Backups: automated database backups are retained for 7 days. Deleted data ages out of backups within that window; individual records are not edited out of backups.
  • Customer data values: none are stored.

After termination, policies already enforced in your platforms keep working — they live in your platforms' own native controls, not in Trinitis.

11. Your choices and rights

You can ask to access, correct or delete personal information we hold about you by emailing privacy@trinitis.ai. We will respond in line with applicable law.

12. Changes to this policy

We will post changes on this page and update the date above. Material changes will be communicated to account owners before they take effect.

13. Contact

Questions about privacy: privacy@trinitis.ai. See also our Terms of Service and Data Processing Agreement.