Privacy Policy

Last Updated: March 12, 2026

  • 1.

    IntroductionWelcome to Truman. Truman is a financial technology company, not an FDIC-insured bank. We provide an all-in-one business account and management platform tailored for freelancers and businesses. We are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our services.

    By accessing or using Truman, you agree to the terms of this Privacy Policy. If you do not agree with our policies and practices, please do not use our services.

  • 2.Information We Collect

    2.1 Information You Provide

    • Account Information: Name, email, authentication credentials
    • Profile Data: Full name, avatar, preferences
    • Identity and Business Data (KYC/KYB): Government-issued identification, business registration details (e.g., SIRET, VAT number), and compliance information collected via our partner, Didit.
    • Financial Information: Invoices, accounting categories, tax data

    2.2 Automatically Collected Information

    • Location Data:IP addresses and geolocation data are strictly collected to verify eligibility, prevent fraudulent use of our services, and comply with international sanctions (e.g., OFAC).
    • Blockchain Data: Public blockchain transaction data from connected wallets and smart accounts.
    • Usage & Analytics: Log data, device information, browser type, and interaction metrics via analytics tools.
    • Cookies: Session cookies and authentication tokens for service functionality and performance tracking.
  • How We Use Your Information

    We use the information we collect to:

    • Provide, maintain, and improve our all-in-one business management services.
    • Verify your identity and business for compliance purposes (KYC/KYB).
    • Process and track transactions securely.
    • Authenticate users and maintain account security.
    • Facilitate cross-chain USDC transfers via Circle Bridge Kit.
    • Generate invoices and financial reports.
    • Comply with legal obligations and prevent fraud.
    • Analyze usage patterns to improve user experience.
  • 4.Data Sharing and Disclosure

    We do not sell your personal information. We may share your information in the following circumstances:

    • Service Providers: Third-party services processing data on our behalf, such as secure cloud database providers, Didit (KYC/KYB), Alchemy (blockchain infrastructure), and Circle (USDC transfers).
    • Payment and Invoice Disputes: In the event of a dispute regarding an invoice or a payment routed through our infrastructure, we may be required to share relevant transaction or contact data with the involved client or payment processor to facilitate resolution.
    • Blockchain Networks: Transaction data is inherently and publicly recorded on blockchain networks.
    • Legal Requirements: When required by law, court order, or government request.
    • Business Transfers: In connection with a merger, acquisition, or sale of assets.
  • 5. Third-Party Services and External Links

    Our platform integrates with several third-party services:

    • Cloud Database & Authentication Providers: Secure database management and user authentication services.
    • Alchemy Account Kit: Smart account creation and blockchain data infrastructure.
    • Circle Bridge Kit: Cross-chain USDC transaction routing.
    • Didit: Identity verification, KYB, and KYC compliance processing.
    • Google OAuth: Third-party authentication option.
    • Analytics Providers: Tools used to monitor and analyze web traffic and platform usage.

    Third-Party Links: Our platform may contain hyperlinks to external websites or locations that we do not control. This Privacy Policy does not apply to those third-party websites, and we make no representations regarding their privacy practices. We encourage you to review their respective policies.

  • 6. Data Security and Non-Custodial Architecture We implement industry-standard security measures to protect your information:

    • Multi-Party Computation (MPC): Truman utilizes MPC technology via Alchemy Account Kit. This ensures a non-custodial architecture where your private keys are fragmented. Truman never holds, stores, or has access to your private keys or your funds.
    • Data Encryption: Encryption of data in transit and at rest.
    • Secure Authentication: Managed via industry-standard authentication providers and Passkeys/OAuth.
    • Row-Level Security (RLS): Strict data access policies on our database tables.

    However, no method of transmission over the internet is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.

  • 7. Your Rights, Choices, and Tracking You have the following rights regarding your personal information:

    • Access & Correction: Request access to, or correct inaccurate personal data.
    • Deletion: Request deletion of your account and associated data.
    • Data Portability: Export your transaction and account data.
    • Withdraw Consent: Revoke consent for data processing where applicable.

    Location Data Management: Because location data and IP addresses are legally required for our KYC/KYB and anti-fraud compliance (via Didit), restricting access to this data will prevent you from using Truman's core services. Do Not Track Signals: Some web browsers transmit "Do Not Track" (DNT) signals. Currently, our platform does not alter its data collection or use practices based upon detection of a DNT signal.

    To exercise your rights, please contact us at the information provided below.

  • 8. Data Retention We retain your personal information for as long as necessary to provide our services and comply with legal obligations. Financial, KYC/KYB, and transaction data may be retained for longer periods as strictly required by anti-money laundering (AML) laws, tax authorities, and accounting regulations.
  • 9. Children's Privacy Our professional services are strictly not intended for individuals under the age of 18. We do not knowingly collect personal information from children.
  • 10. International Data Transfers : Truman is based in the European Union, and our primary databases are hosted in the EU. However, some of our third-party infrastructure providers may process or store your information on servers located outside the European Economic Area (EEA), including the United States. We ensure that such transfers are protected by appropriate safeguards, such as Standard Contractual Clauses (SCCs).
  • 11. Changes to This Privacy Policy We may update this Privacy Policy from time to time. We will notify you of significant changes by posting the revised version and updating the "Last Updated" date. Your continued use of our services constitutes acceptance of the amended Policy.
  • 12. Contact Us If you have questions or concerns about this Privacy Policy or our data practices, please contact the Data Controller:
    • Company: Truman
    • Address: 60 Rue François Ier, 75008 Paris, France
    • Email: support@gettruman.com
    • Website: https://gettruman.com
  • 13. Additional Rights (GDPR & CCPA) If you are a resident of the European Union or California, you have additional rights:

    GDPR (EU Residents)

    • Right to be informed
    • Right to restrict processing
    • Right to object
    • Right to lodge a complaint

    CCPA (California Residents)

    • Right to know what personal information is collected.
    • Right to know if personal information is sold or disclosed.
    • Right to opt-out of the sale of personal information.
    • Right to non-discrimination for exercising CCPA rights.

© 2026 Truman. All rights reserved.