Data Retention Policy

TrueNorth Intell LLC · New Richmond, Wisconsin · Effective August 18, 2026

TrueNorth holds as little client business information as the work allows, for as short a time as the work allows. Where a period below could reasonably be shorter or longer, it's short.

Two things are treated differently, and this document says so out loud rather than burying it: a client's business data, which gets minimized, and TrueNorth's own records of work performed, which are kept because they protect both sides if anyone ever disagrees about what was delivered.

1. What this covers

TrueNorth Intell LLC builds and supports AI operating systems for businesses. This policy covers business information belonging to clients ("Client Data") that TrueNorth accesses, processes, or holds while delivering those services.

The TrueNorth Intell app for Clover has its own published policy at truenorthintell.com/privacy.html. This document governs the service relationship; that one governs the Clover integration.

2. Where a client's system actually lives

Retention depends on the delivery shape, so the shapes come first.

Client-owned (the default). The AIOS runs on the client's own machine, or on a server the client owns and pays for under their own account. Their business context, records, and outputs live in plain files in a folder they control. TrueNorth holds no copy. Support happens in sessions the client authorizes, and nothing persists on TrueNorth systems afterward.

TrueNorth-hosted (an option at entry tier). The client's web door runs on TrueNorth's server, so a copy of their workspace lives there while it's hosted. TrueNorth does hold Client Data in this shape, and says so at signing rather than leaving it in a document. A hosted client can move to infrastructure they own at any time, and TrueNorth does the move at no charge.

3. Client business data

WhatHow long
Hosted workspace: context files, generated briefs, door transcriptsWhile hosting is active. Deleted within 30 days of termination or a move to client-owned infrastructure, usually the same week.
Door access logs and lane events30 days
Discovery recordings (audio)Deleted once transcribed. Never held beyond 90 days regardless.
Discovery transcripts and working notesLife of the engagement, then deleted within 90 days
Build notes and delivery documentation containing client operational detailLife of the engagement, then deleted within 90 days
Correspondence containing client business informationLife of the engagement, then deleted within 90 days
Integration credentials and OAuth tokensDeleted when the integration is disconnected or the engagement ends, whichever comes first

On a client-owned system, most of the above simply never exists on a TrueNorth machine to begin with.

4. TrueNorth's own records

These are TrueNorth's business records about work performed, not a client's operational data. They're kept longer, and deliberately: if a question ever arises about what was agreed, what was built, or what was paid, both parties need the answer to exist.

WhatHow long
Signed agreements and schedules7 years (legal)
Invoices and payment records7 years (tax)
A record of what was built and delivered, and when7 years, stripped of client operational data

That last line is the boundary. TrueNorth keeps the fact that an inventory forecast was built and delivered on a given date. It does not keep the inventory.

5. Deletion on request

A client may ask in writing for the return or deletion of their data at any time, whether or not the engagement is active, and TrueNorth completes the request within 30 days. Most of it is already gone under §3.

Three things survive a deletion request, matching the carve-outs in the service agreement:

Nothing identifiable is used for case studies, marketing, or anything public without the client's written consent, whatever any retention period says.

6. AI providers

Running an AIOS means sending prompts and business context to AI providers (currently Anthropic, with Google as the standing backup and OpenAI where a client has authorized it). Two facts a client should have straight.

No training. Model training is switched off on the client's account at setup. On the API, traffic is never used for training. On a consumer subscription, TrueNorth opts the client out during onboarding and shows them the setting.

A limited provider-side window. Even with training off, the provider retains prompts and responses for a limited period, currently around 30 days at Anthropic, for abuse monitoring and legal compliance, then deletes them. During that window provider personnel may access data only for safety review. This window is governed by the provider's own current policies, not by TrueNorth, and it's comparable to any professional cloud service a business already uses.

TrueNorth does not represent that any provider offers zero retention. Where a client's obligations genuinely can't tolerate that window, see §7.

7. Regulated data

If a business handles protected health information, regulated financial data, or information under a confidentiality obligation that a roughly 30-day provider retention window would breach, the standard setup is not appropriate as delivered. That's a separate arrangement, scoped and priced before any build. TrueNorth says so before taking the work rather than after.

8. Changes and contact

The current version always lives at this address. Material changes are communicated to active clients with notice, per the service agreement.

Questions or deletion requests: logan@truenorthintell.com · TrueNorth Intell LLC, New Richmond, Wisconsin.