Legal

Privacy Policy

Effective September 16, 2026

1. Scope and company identity

This Privacy Policy describes how Treto, Inc. (“Treto,” “we,” or “us”) collects, uses, and shares information in connection with our marketing website at treto.ai (the “Site”) and the Treto application at app.treto.ai (the “Service”). It applies to visitors to the Site and to individuals who use the Service on behalf of a client firm.

2. Information submitted through the website and demo form

When you submit the Request a Demo form on the Site, we collect the information you provide: your full name, work email address, firm name, and, if you choose to share them, your role/title and a short note about what you'd like to discuss. We use this information to respond to your request, follow up about a demo, send occasional Treto product updates and marketing emails, and, if you become a customer, set up your account.

3. Account and authentication information

Access to the Service is invitation-based. When you are invited to join a firm's Treto workspace, your account, sign-in, and session are managed by our authentication provider, Clerk. Clerk collects information needed to authenticate you, such as your email address, name (if provided), and authentication events; multi-factor authentication and password reset, where used, are also handled by Clerk. Treto does not itself store your password.

4. Product and customer information processed when using Treto

Once your firm is using the Service, Treto processes the business records, documents, and communications your firm connects to or uploads into the product (for example, deal, company, portfolio, relationship, task, and reporting information) in order to organize that information, surface it back to your firm, and answer questions your firm's users ask about it. This content belongs to and is controlled by your firm, not by the individuals who happen to submit it.

Some of this processing uses third-party AI model providers to generate extractions, summaries, or answers. Where Treto sends content to a model provider for this purpose, it does so under provider terms intended to restrict that provider's use of the content, including to prevent the content from being used to train the provider's own models.

5. Connected-source information

If your firm chooses to connect external systems (such as email, calendar, or file-storage accounts, or a messaging channel like WhatsApp or Telegram) to Treto, we ingest the content those connections make available, consistent with the permissions your firm grants at the time of connection. Some of these connections are brokered through a delegated-authorization provider (Composio) rather than Treto directly; see Section 9 below.

6. Device, browser, log, and analytics information

Like most websites and applications, we automatically collect some technical information when you visit the Site or use the Service - for example, browser type, device type, approximate location derived from IP address, pages or screens viewed, and timestamps. We use this information for analytics, security, and to understand how the Site and Service are used.

7. Cookies and PostHog

The Site and Service use PostHog for product analytics. PostHog sets cookies and/or browser storage to distinguish visitors and sessions. On the Site, analytics is currently limited to page views and a small set of named conversion events (for example, clicking “Sign in” or submitting the demo form); session replay is not enabled on the Site at this time, we do not capture the values you type into form fields, and we do not send your name, email address, firm name, or note to PostHog - only structural, non-identifying event properties. We do not use third-party advertising trackers on the Site.

8. How we use information

We use the information described above to operate, secure, and improve the Site and Service; respond to demo requests and other inquiries; provide customer support; communicate with you about your account or our services; and comply with legal obligations.

9. Service providers and subprocessors

We share information with service providers engaged to help us operate the Site and Service:

  • Clerk - authentication, account, and session management for the Service.
  • PostHog - product and website analytics, hosted in the United States.
  • OpenRouter and the underlying AI model providers it routes to - process product content to generate extractions, summaries, and answers within the Service.
  • Composio - brokers delegated authorization for optional connected sources (for example, Google Workspace accounts) your firm chooses to connect.
  • Resend - stores demo-request contacts and delivers transactional and internal notification emails, including notifying our team of a new demo request.
  • Cloud infrastructure and storage providers (including Google Cloud Storage) - host the Service and store uploaded documents and application data.
  • Cloudflare - hosts and delivers the Site and related edge services.
  • Sanity - stores and delivers public Resources content on the Site.

Demo-request submissions stay outside the Service's customer database. Contact details are stored in Resend, while the full submitted information is delivered to our configured internal demo-request inbox.

10. Marketing communications and opt-out

Submitting the Request a Demo form enrolls a new contact to receive occasional Treto product updates and marketing emails through Resend. Each marketing email includes an unsubscribe option. If a contact has previously unsubscribed, a later demo request keeps that preference in place. Account and service communications may still be sent when required to provide the Service.

11. Data retention

We retain information for as long as needed for the purposes described in this policy - for example, demo-request contact information until you ask us to delete it, and account and product information for as long as your firm has an active relationship with Treto, plus a reasonable period afterward for legal, accounting, or security purposes. Retention periods vary by data type and legal requirement; we do not currently commit to a fixed deletion timeframe beyond what is described here.

12. Security practices

We use administrative, technical, and organizational measures designed to protect information, including encrypting data in transit and enforcing row-level tenant isolation in the Service's database so that one customer firm's data is not accessible to another. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

13. International processing and transfers

Treto is a U.S. company, and information we collect is generally processed in the United States, including by service providers such as PostHog. If you access the Site or Service from outside the United States, your information will be transferred to and processed in the United States and other locations where our service providers operate.

14. Your privacy rights and requests

Depending on where you live, you may have rights to access, correct, or request deletion of personal information we hold about you, or to object to certain processing. To exercise these rights, contact us using the details in Section 18; we will respond consistent with applicable law.

15. Children's privacy

The Site and Service are intended for business use by adults and are not directed to children. We do not knowingly collect personal information from children.

16. Third-party links and services

The Site and Service may link to or integrate with third-party websites and services we do not control, including services your firm chooses to connect (Section 5). This Policy does not apply to those third parties; please review their own privacy policies.

17. Changes to this policy

We may update this Privacy Policy from time to time. We will update the “Effective” date above when we do, and, for material changes, provide additional notice where appropriate.

18. Contact us

Questions about this Privacy Policy or requests regarding your information can be sent to privacy@treto.ai.

19. Effective date

This policy is effective as of September 16, 2026.