This Privacy Policy explains how [Legal entity name, state of incorporation] (“Ground Truth”, “we”, “us”) handles personal information when you visit our website or use the Ground Truth service (the “Service”). Terms not defined here have the meaning given in our Terms of Service.
1. Our role
Ground Truth is used by businesses. When an organisation (our customer) enters project data into the Service, including information about its crews and project contacts, we process it on that organisation’s behalf and under its instructions. The organisation decides what is collected and how it is used, and is responsible for its own privacy notices to its people. For account, billing, website and usage information, we decide how it is used, as described here.
2. Information we collect
Information you give us
- Account information: email address, password (stored only as a secure hash by our authentication provider), name and phone number if you add them, and your organisation memberships and roles.
- Organisation and invitation information: organisation name, and the email addresses of people you invite.
- Project data: specifications, plans, pile schedules, rules, pile records, driving logs, coordinates and elevations, QC decisions, comments, reports, and messages you send to the in-app assistant. Records show which user created or changed them and when.
- Billing information: billing contact and subscription details. Card details are collected and stored by our payment provider, Stripe; we never see or store full card numbers.
- Communications: what you send us when you contact us for support or otherwise.
Information collected automatically
- Usage and diagnostics: pages viewed, product actions (such as a pile being recorded or a report being generated), errors, and device, browser and approximate location derived from IP address. Usage events are tied to an internal user id and organisation id, not to your email address or name.
- Session replay: we may record how the interface is used to diagnose problems. Replays are configured to mask all text and form inputs and to block images and maps, so they show the layout and interactions, not the content.
- Logs: our hosting and database providers keep server logs, including IP addresses and request details, for security and reliability.
We honour the Do Not Track browser signal for product analytics.
3. How we use information
- to provide, operate and secure the Service, including signing you in and syncing offline records;
- to run features you use, including rule checks, reports and AI features;
- to process payments and manage subscriptions;
- to send service messages, such as sign-in links, invitations, billing notices and important changes;
- to provide support and respond to requests;
- to understand usage, fix bugs and improve the Service, using aggregated or de-identified data where we can;
- to detect and prevent fraud, abuse and security incidents; and
- to comply with law and enforce our Terms.
We do not sell or rent personal information, share it for cross-context behavioural advertising, or use project data to train AI models.
4. AI features
When you use an AI feature, the relevant content (for example, a specification you upload or a question to the assistant, with the project records needed to answer it) is sent to an AI model provider through our AI routing provider to generate a response. We configure this routing to use only model providers that do not retain prompts for training. AI usage is counted per organisation to enforce limits.
5. Who we share information with
We share personal information only as follows:
- Within your organisation: other members can see project data and the names or emails of people who created records, according to their roles.
- Service providers who process data for us under contract, currently: Supabase (database, authentication, file storage and sign-in emails), Vercel (hosting), PostHog (product analytics, error tracking and session replay), OpenRouter and the model providers it routes to (AI features), and Stripe (payments). Each receives only what it needs for its function.
- Legal and safety: when we believe in good faith it is required by law or legal process, or needed to protect the rights, safety or property of our users, the public or us.
- Business transfers: in a merger, acquisition, financing or sale of assets, subject to this policy.
- With your direction: for example, when you export or share a report.
6. Cookies and device storage
- Essential: cookies that keep you signed in, and browser storage that keeps your theme setting and lets the app work offline (cached pages and records waiting to sync). The Service does not work without these.
- Analytics: a cookie or local storage entry from PostHog that recognises your browser between visits. Analytics data is sent through our own domain.
We do not use advertising cookies. You can clear cookies and site data in your browser settings; doing so will sign you out and remove any offline records that have not yet synced.
7. Retention
We keep account information while your account is active. We keep project data for as long as the owning organisation keeps its subscription, and for 30 days after it ends so it can be exported, unless the organisation asks us to delete it sooner or we must keep it by law. Deleted data may remain in backups until they expire on their normal schedule. Data entered in the public demo is erased at each demo reset. Analytics data is kept according to our analytics provider’s retention settings.
8. Security
We use measures designed to protect personal information, including encryption in transit, row-level access controls that keep each organisation’s data separate, role-based permissions, and limited staff access. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
9. Your choices and rights
You can update your name and phone number in your account settings. Depending on where you live, you may have the right to access, correct, delete or receive a copy of your personal information, to object to or restrict certain processing, and to withdraw consent. Residents of some US states, including California, have rights to know, delete and correct personal information and not to be discriminated against for using them. We do not sell or share personal information as those laws define it.
To make a request, email [legal@yourdomain.com]. We will verify your request and respond within the time the law requires. If your information is part of an organisation’s project data, we may refer your request to that organisation, since it controls that data. You may also complain to your local data protection authority.
10. Where data is processed
Ground Truth is operated from the United States, and our providers process data primarily in the United States. If you use the Service from elsewhere, your information will be transferred to and processed in the United States, where data protection law may differ from your own.
11. Children
The Service is for business use and is not directed to children under 16. We do not knowingly collect their personal information. If you believe a child has given us personal information, contact us and we will delete it.
12. Changes to this policy
We may update this policy. We will post the new version here with a new effective date, and if a change is material we will notify account holders by email or in the Service before it takes effect.
13. Contact
Questions or requests: [legal@yourdomain.com], or [Legal entity name, state of incorporation], [Mailing address].