Legal

Privacy Policy.

Effective July 14, 2026

This Privacy Policy explains how SMASHING DIVS processes personal data when you visit Trumpets, use the platform or its API, or use a Trumpets-powered App operated by us. It also explains when we act only on a customer's instructions and what rights you have.

1 · Scope and controller

The controller for the processing described in this Policy is SMASHING DIVS, EU VAT ID PL9930619827, Stanisława Moniuszki 26, 33-100 Tarnów, Poland. In this Policy, "SMASHING DIVS", "Trumpets", "we", and "us" refer to that operator.

This Policy covers trumpets.ai, the Trumpets Dashboard, agent and workflow runtime APIs, and company-operated products that link here, including Trumpets-powered Apps (together, the "Services"). A third-party website, model, connector, or service has its own privacy terms when you use it independently or connect it under your own account.

Questions and data protection requests can be sent to hello@trumpets.ai.

2 · Our data protection roles

We act as a controller when we decide why and how to process account, subscription, billing, security, support, product usage, website, and marketing data. We also normally act as controller for Customer Content that an individual Consumer submits about themselves to receive a Service for personal or household purposes. This Policy describes that processing.

We normally act as a processor when a business, professional, or organization uses the Services to process personal data contained in prompts, files, knowledge sources, workflow inputs, tool results, or generated outputs ("Customer Content"). That customer decides the purpose of the processing and is the controller, or is itself a processor authorized by another controller. Our Data Processing Addendum in the Terms of Service applies to that processing.

If your personal data was submitted by one of our customers, direct your request to that customer first. We will assist the customer as required by data protection law.

3 · Personal data we process

The data depends on the Service and features you use.

  • Account and identity data. Name, email address, authentication identifiers, email verification status, preferred language, organization, role, invitations, and profile settings. If you sign in with Google or another identity provider, we receive the identifiers and profile information that provider makes available for authentication. We also keep append-only evidence of the Terms version you accepted, the acceptance time, method, and locale.
  • Workspace and configuration data. Organizations, projects, agents, system instructions, workflows, schedules, processors, validators, API keys, model choices, tool and MCP connections, and team permissions.
  • Customer Content. Prompts, messages, model responses, documents, images, audio, knowledge sources, training and evaluation assets, embeddings, generated files, feedback, run inputs, tool results, and other material processed at your direction.
  • App-specific content. Depending on the App, this can include legal drafts and matter sources, manuscripts and narration projects, voice samples, resumes, job postings, interview dates, practice answers, research notes, and generated coaching or analysis.
  • Integration data. Connection status, provider account identifiers, access and refresh tokens, selected permissions, and content retrieved from a service you connect. Google Workspace features can access the Google Drive files, Gmail messages, Calendar events, and basic profile data covered by the scopes shown during authorization.
  • Billing and transaction data. Plan, credit or usage-point balances, subscription status, usage, transaction and invoice references, Stripe customer and checkout identifiers, currency, tax status, and payment outcome. For a paid checkout, we record the versioned express request for immediate performance and withdrawal acknowledgement shown before payment. Card details are collected by Stripe, not stored by us in full.
  • Usage, device, and log data. IP address, browser and device information, timestamps, pages and features used, run and step logs, model and token usage, latency, errors, security events, and audit records.
  • Support data. Messages with us and information you choose to include in an issue report. An App issue report may include the current sanitized page URL, recent console messages, technical context, and, only when you choose it, a screenshot.
  • Marketing data. Newsletter email, subscription and unsubscribe status, consent record, signup source, and campaign attribution data. We use double opt-in for the newsletter.

4 · Where data comes from

  • Directly from you when you register, configure, upload, connect, buy, or contact us.
  • From your organization's administrators and colleagues when they invite you, assign a role, share workspace material, or configure an integration.
  • From identity, payment, cloud, analytics, model, and integration providers involved in delivering a feature.
  • From public sources when a feature performs web or company research, including a URL, public page, or Google Search result requested by a user.
  • Automatically from your browser, device, and use of the Services.

5 · Purposes and legal bases

  • Provide the Services and manage accounts. To register users, authenticate access, create workspaces, execute requested agents and workflows, store content, run integrations, provide support, and administer paid plans. The basis is performance of a contract or steps requested before a contract (Article 6(1)(b) GDPR). For users of a business customer, the basis is our legitimate interest in delivering and administering that customer's service (Article 6(1)(f)).
  • Bill and keep required records. To process payments, allocate usage, prevent duplicate or fraudulent transactions, issue records, and meet tax and accounting duties. The bases are contract, legal obligation (Article 6(1)(c)), and our legitimate interest in protecting revenue and resolving disputes.
  • Secure, troubleshoot, and improve reliability. To prevent abuse, investigate incidents, debug failures, measure performance, audit administrator actions, and improve the Services using operational or aggregated metrics. The basis is our legitimate interest in providing a secure and reliable service. We do not use this basis to repurpose Customer Content for unrelated model training.
  • Communicate about the Service. To send verification, invitation, security, billing, support, and material service notices. The bases are contract and our legitimate interest in administering the Services.
  • Newsletter and optional marketing. To send material you requested. The basis is consent (Article 6(1)(a)). You can withdraw consent at any time without affecting earlier lawful processing.
  • Web analytics. To understand visits and conversions where the analytics feature is enabled. Google Analytics code, storage, and measurement requests are activated only after your consent (Article 6(1)(a) GDPR).
  • Legal compliance and claims. To respond to lawful requests, enforce agreements, and establish, exercise, or defend legal claims. The bases are legal obligation and legitimate interests.

Legitimate interests

Where we rely on legitimate interests, we consider whether the processing is necessary and balance our interests against the impact on individuals. You may object as explained in section 12.

6 · Customer Content and AI processing

The Services send the instructions, context, files, tool results, or other content needed for a requested operation to the selected model or tool provider. Depending on the feature, processing can include generation, extraction, classification, embedding, search grounding, document creation, image generation, audio generation, or evaluation.

We do not use Customer Content to train our own general-purpose model. We do not offer provider training on Customer Content as a Trumpets product feature. Model providers can retain content or metadata for limited security and abuse-monitoring purposes, and their treatment varies by provider, selected model, commercial plan, and privacy configuration. The provider can also change when you select a different model. Do not assume that every model or connector has identical retention or data residency.

Google Search grounding and other web research features send the query and necessary context to the search provider. Search processing is not guaranteed to remain in the EEA, even where the rest of an App uses an EU-configured database or cloud region. Customer-selected connectors and MCP tools receive the data needed to perform the requested tool call.

Customer Content may contain personal data about other people, including sensitive data or data about criminal allegations. The customer is responsible for a lawful basis, transparency, minimization, retention, and any required data protection impact assessment. Do not use the Services for biometric identification, medical diagnosis, or solely automated decisions with legal or similarly significant effects unless a separate written agreement and all required safeguards are in place.

7 · Recipients and service providers

We disclose data only where needed for the purposes above, including to:

  • Supabase for authentication, PostgreSQL databases, storage, and related backend services.
  • Google for Google Cloud and Firebase hosting, Gemini model and file processing, embeddings, Google Search grounding, Google Workspace integrations, and Google Analytics where the relevant feature is enabled.
  • OpenRouter and selected model providers for requests to a selected non-Gemini model. Platform requests require zero-data- retention capable processing and disable provider fallback; the selected downstream provider still depends on the model you choose.
  • Stripe for checkout, subscriptions, invoices, tax-related payment information, and fraud prevention.
  • Brevo for transactional email, support notification delivery, newsletter contact lists, and campaign delivery.
  • Customer-selected integrations such as Google Workspace, MCP servers, or other tools you connect. If you connect a provider under your own account, your agreement with that provider also applies.
  • Professional advisers, authorities, and transaction parties when reasonably necessary for legal compliance, claims, audits, financing, or a corporate transaction, subject to appropriate confidentiality and legal safeguards.

We do not sell personal data. We do not disclose Customer Content to data brokers or third-party advertisers.

The current principal provider list, purposes, locations, and transfer safeguards are published in our Subprocessor Register.

8 · International transfers

Some providers, model endpoints, support operations, or search features process data outside Poland or the EEA. The destination can depend on the selected model, feature, customer configuration, and provider routing.

Where GDPR requires a transfer mechanism, we use the mechanism applicable to the recipient and transfer, such as an adequacy decision or European Commission Standard Contractual Clauses, together with supplementary measures where required. You may ask us for information about the mechanism relevant to your data and a copy of applicable safeguards, subject to lawful redactions.

9 · Retention and deletion

We keep personal data only for as long as needed for the purpose for which it was collected, taking account of the account or contract lifecycle, customer instructions, security needs, backup cycles, disputes, and legal duties. The main criteria are:

  • Pending accounts. An unverified pending account is eligible for automated deletion after seven days if it has no active verification token.
  • Account and Customer Content. Kept while the account or customer agreement is active and until content is deleted through an available feature or a verified deletion or closure request is completed, unless law or a dispute requires limited retention. The Dashboard and current company-operated Apps provide portable JSON export and account deletion controls. Shared-organization content is not deleted by one member; ownership must be resolved first. You can also contact us.
  • Short-lived operational records. Expired verification records are removed after 30 days, expired rate-limit counters after one day, expired unconfirmed newsletter signups after 30 days, and completed internal cleanup jobs after 90 days. The retention job runs daily and records its outcome. Product history, support, security, and incident records are kept only for the period required by their documented purpose or an applicable legal hold.
  • Billing, tax, consent, and contract records. Kept for the period required by applicable accounting and tax law and until relevant limitation periods expire. Terms acceptance and paid-checkout evidence is normally removed six years after the evidence was recorded. An affected record may be kept longer only where a mandatory rule or documented active claim requires it.
  • Newsletter records. Kept while subscribed. After unsubscribe, we may keep the minimum suppression and consent record needed to respect the opt-out and demonstrate compliance.
  • Analytics data. Kept according to the configured Google Analytics property retention setting and then aggregated or deleted by Google.

Deletion from active systems may not immediately remove encrypted backup copies. A backup is isolated from ordinary use and expires through the documented backup rotation, currently configured not to exceed 35 days unless a legal hold applies. Restored data is re-subjected to deletion controls. We may retain anonymized data that can no longer identify a person.

10 · Security

We use technical and organizational measures intended to protect personal data in view of the risk. They include TLS in transit, authentication and scoped credentials, role and tenant access controls, database row-level security, restricted administrative access, audit and operational logging, environment-separated secrets, application-layer authenticated encryption for stored Google Workspace tokens and connector credentials, credential key versioning and rotation, backups, dependency and vulnerability review, and incident handling procedures.

No online service is completely secure. Keep passwords, API keys, integration tokens, and devices confidential, use the narrowest integration permissions available, and tell us promptly if you suspect unauthorized access.

11 · Cookies, local storage, and analytics

The Services use storage that is necessary for authentication, security, session continuity, and remembering settings. These functions cannot be switched off where they are required to provide the Service you requested.

Where Google Analytics is enabled, a consent banner lets you accept or decline analytics. We do not load Google Analytics code, create its data layer, set analytics identifiers, or send measurement requests before you accept. Accepting allows Google Analytics to set identifiers such as _ga cookies and measure page views, campaign attribution, approximate region, device and browser information, signups, and checkout events. We sanitize reported page URLs so ordinary query parameters, invitation tokens, newsletter tokens, and prefilled emails are not sent as page locations.

Declining or ignoring the banner means analytics remains off and does not limit product features. Advertising storage, advertising user data, and ad personalization are not enabled by the Service's analytics control.

Your choice is stored in your browser. You can change it through Cookie settings on a landing-page footer or Cookie preferences in an App or Dashboard. Withdrawing consent updates the setting and the Service attempts to expire Google Analytics cookies for that domain. You can also restrict storage in your browser.

12 · Your rights

Subject to the conditions and exceptions in data protection law, you may:

  • ask whether we process your personal data and obtain access and a copy;
  • correct inaccurate or incomplete personal data;
  • request erasure or restriction of processing;
  • receive personal data you provided in a structured, commonly used, machine-readable format and transmit it to another controller where portability applies;
  • object to processing based on legitimate interests, including profiling on that basis, and object at any time to direct marketing;
  • withdraw consent at any time for future processing based on consent; and
  • lodge a complaint with the President of the Personal Data Protection Office (UODO), ul. Stanisława Moniuszki 1A, 00-014 Warszawa, Poland, or another competent supervisory authority. See the UODO information for individuals.

Send a request to hello@trumpets.ai. We may need to verify your identity and clarify the scope. We normally respond within one month. GDPR permits an extension of up to two further months for a complex or numerous request, in which case we will tell you within the first month.

Where available, you can also use Download my data or Delete my account in account settings. Those controls do not replace your broader GDPR rights or your right to contact us, and an export may exclude another person's data or shared content you do not control.

Rights are not absolute. For example, we may retain information required by law or needed to establish, exercise, or defend legal claims. Exercising a right is free unless a request is manifestly unfounded or excessive.

13 · Automated decisions and AI outputs

SMASHING DIVS does not use account, billing, support, or marketing data to make a decision about you based solely on automated processing that produces legal or similarly significant effects. Fraud and security signals may flag activity for restriction or review, but you can contact us to contest a decision.

AI outputs generated at a user's request are probabilistic assistance, not a decision made by SMASHING DIVS about a person. A customer that uses an output in employment, legal, financial, health, or another significant context is responsible for human review and for any transparency, lawful-basis, fairness, and contestability duties.

14 · Children

The Services are intended for adults and are not directed to children. You must be at least 18 years old, or the age of legal majority where you live, to create an account. If you believe a child has provided personal data to us, contact us so we can assess and remove it where required.

15 · Changes to this Policy

We may update this Policy to reflect changes in the Services, providers, or law. We will post the new version here and update the effective date. If a change materially affects how we use personal data, we will provide a more prominent notice where required. An earlier version continues to govern processing that law does not permit us to change retroactively without a new legal basis.

16 · Contact

SMASHING DIVS
EU VAT ID: PL9930619827
Stanisława Moniuszki 26
33-100 Tarnów, Poland
Email: hello@trumpets.ai

Stay in tune.

Product notes, orchestration patterns, and the occasional field report - sent only when there’s something worth playing.

One email a month at most. Unsubscribe anytime.