TC

Legal

Privacy Policy

Effective Date: July 31, 2026 · Last updated July 31, 2026

What changed in this revision

  • Identity verification is now required before a signature is accepted, not only for elevated tiers (section 3).
  • Section 4 now describes the controls that actually protect a signature, instead of leading with webhook verification.
  • Section 5 states both OpenAI flows exactly: the text you submit goes to the chat API, and your question also goes to the embeddings API so the relevant legislation can be retrieved.
  • Section 2 no longer claims we collect wallet addresses — we do not, and never ask you to connect one.
  • Section 6 was corrected: no analytics product is initialised at all, and "disable JavaScript" was never a real opt-out.

Operated by: Kirillskiy Construction Ltd.

Address: 12705 114a Ave, Surrey, BC, Canada, V3V 3P3

Jurisdiction: British Columbia, Canada

Contact: founder@trustchain.biz

1. Introduction

TrustChain ("we", "us", "our") is a digital agreement registry and trust infrastructure service operated by Kirillskiy Construction Ltd. This Privacy Policy explains how we collect, use, and protect personal information when you use our platform at trustchain.biz.

By using TrustChain, you agree to the practices described in this policy.

2. Information We Collect

We collect the following categories of information:

  • Account data: Email address, display name, profile photo (if provided via Google sign-in)
  • Agreement data: Agreement text, metadata (parties, dates, amounts), cryptographic fingerprints, and audit events
  • Negotiation chat data: Messages exchanged while negotiating an agreement. The message contents are end-to-end encrypted; the keys are held on your own devices and we cannot read them. The metadata around each message is not encrypted and is visible to us: who sent it (their account identifier and email address) and when. Only the body is ciphertext.
  • Identity verification data: Government-issued ID documents, selfies, and personal information collected during KYC verification (processed by Sumsub — see section 5)
  • Blockchain data: Anchoring writes four values to the Polygon public blockchain: the agreement's internal identifier, the cryptographic fingerprint of the signed document, and two address slots which are empty (all-zero) for every agreement in the registry. The title, terms, amounts and party identities are inputs to the fingerprint and never leave our servers — only the 32-byte digest is published. You do not connect a wallet and we do not store one: the transaction is signed and paid for by a wallet TrustChain operates, so you pay no gas and sign nothing on-chain. On-chain records are permanent and publicly visible by nature of the technology.
  • Payment data: Subscription plan, billing history (payment card details are processed by Stripe — we do not store card numbers)
  • Usage data: IP address, browser/device type, pages visited, activity timestamps

3. How We Use Your Information

  • Providing and securing the TrustChain registry service
  • Creating, storing, and verifying digital agreements
  • Identity verification (KYC), which is required before a signature is accepted
  • Processing subscription payments and managing billing
  • Sending transactional notifications (agreement activity, signing invitations)
  • Improving the platform and detecting misuse
  • Complying with legal obligations

4. Data Storage and Security

User data and agreement records are stored in Google Firebase (Firestore and Firebase Authentication), hosted in the United States. Cryptographic proofs are anchored on a public blockchain network. On-chain records are permanent and publicly visible.

Transport is HTTPS/TLS throughout, and incoming payment webhooks are verified by HMAC-SHA256 signature before they are acted on.

Three controls specifically protect the integrity of a signature, which is the thing this registry exists to guarantee:

  • A signature cannot be created by writing to the database directly. Database rules restrict what a party may change on their own agreement to a short whitelist of fields, and the signature fields are not on it — they can only be set by the signing function on our servers.
  • That function checks identity verification status server-side at the moment of signing. A request from an account that has not reached verified status is refused, whatever the interface shows.
  • Requests that change state — signing, anchoring, inviting, minting — reject a session that has been revoked, or that belongs to an account which has since been disabled or deleted, rather than accepting a token that is merely unexpired.

The negotiation chat is end-to-end encrypted. Encryption keys are held on the parties' own devices, not on our servers, so the contents of the negotiation chat are not readable by TrustChain. This is distinct from the agreement record itself, which we store as described above in order to operate the registry.

5. Third-Party Services

We share data with the following third-party providers:

  • Sumsub — Identity verification (KYC/AML). When you complete identity verification, your documents and biometric data are processed by Sumsub under their own privacy policy. Sumsub acts as a data processor on our behalf.
  • Stripe — Payment processing. Stripe collects and processes payment card information directly. We receive only non-sensitive billing metadata (subscription status, customer ID).
  • OpenAI — AI assistance, over two separate flows. First, when you use the AI Advisor or a review, the text you submit is sent to OpenAI's chat API; for an agreement-specific review this includes the agreement's title, amounts, dates, party fields and terms. Second, the question itself is sent to OpenAI's embeddings API (model text-embedding-3-large), which is how the system finds the relevant provisions of the legislation it has indexed. The indexed statute text is public law and is embedded once when we build the index, not per request. Your end-to-end encrypted negotiation chat is never sent to OpenAI. Do not put information you would not want processed by OpenAI into AI-assisted fields.
  • Google Firebase — Authentication, database, and cloud functions infrastructure.

6. Cookies and Analytics

TrustChain does not run an analytics product. Firebase Analytics and Google Analytics are not initialised anywhere in the application, there is no advertising or tracking pixel, and no third-party advertising cookies are set. The Firebase services we do use are authentication, the database and cloud functions.

What is stored in your browser is what signs you in: Firebase Authentication keeps your session in local storage and IndexedDB so you are not asked to log in on every page, and the app keeps a small amount of interface state alongside it. None of it is shared with a third party for advertising.

To be straightforward about what you can and cannot control: clearing your browser storage for this site, or signing out, removes the session data — you will simply be signed out. Disabling JavaScript is not an opt-out, because TrustChain is a JavaScript application and will not run at all without it; the earlier version of this policy suggesting otherwise was wrong. Server request logs, which include IP address and browser type, are produced by our hosting provider for security and reliability and cannot be opted out of while using the site.

7. Data Retention

Account data is retained while your account is active. Agreement records and cryptographic proofs may be retained indefinitely as they form part of the verifiable registry. On-chain records cannot be deleted due to the immutable nature of blockchain technology.

KYC data is retained as required by applicable law and Sumsub's data retention policies. You may request deletion of your off-chain account data by contacting us.

8. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your account and off-chain data
  • Object to certain processing activities
  • Data portability (export of your agreement records)

To exercise these rights, contact us at founder@trustchain.biz.

9. Children

TrustChain is not intended for use by persons under the age of 18. We do not knowingly collect personal information from minors. If you believe a minor has created an account, contact us and we will remove it promptly.

10. Changes to This Policy

We may update this Privacy Policy periodically. Significant changes will be communicated via email or a notice on the platform. Continued use of TrustChain after changes constitutes acceptance of the updated policy.

11. Contact

For any privacy-related questions or requests, contact:

Kirillskiy Construction Ltd.

12705 114a Ave, Surrey, BC, Canada, V3V 3P3

founder@trustchain.biz

TrustChain is operated by Kirillskiy Construction Ltd.