LEGAL / PRIVACY
Privacy Notice
This notice explains the personal information Trunchbull processes when you visit the site, create an account, connect services, run benchmarks, or purchase a subscription.
Effective August 9, 2026
1. Information we collect
We collect the following categories of information:
- Account information: your name, email address, profile image, account identifiers, authentication records, and session information received through GitHub or provided by you.
- Connected-service information: identifiers, authorization grants, and credentials needed for integrations you choose, including GitHub and OpenRouter. Sensitive credentials are restricted and protected in storage.
- Content and run data: benchmark definitions, prompts, tools, repository references, uploads, model inputs and outputs, evaluation results, tool calls, sandbox activity, and related telemetry.
- Billing information: plan, subscription, customer, transaction, and entitlement identifiers received from Paddle. We do not directly receive or store complete payment-card details.
- Usage and device information: pages viewed, product events, browser and device information, IP-derived information, timestamps, diagnostic logs, and security events.
- Communications: messages and support information you send to us.
2. How we use information
We use information to:
- provide, authenticate, operate, and maintain Trunchbull;
- execute benchmarks, model requests, tool calls, and isolated sandbox workloads you request;
- process subscriptions and apply plan entitlements;
- secure the service, prevent abuse, enforce limits, troubleshoot failures, and preserve audit evidence;
- understand product usage and improve features, reliability, and user experience;
- communicate with you about the service and support requests; and
- comply with legal obligations and protect legal rights.
3. Legal bases
Where applicable law requires a legal basis, we process information as needed to perform our contract with you, based on our legitimate interests in operating and securing the service, with your consent where requested, and to comply with legal obligations. You may withdraw consent at any time, without affecting earlier processing.
4. How information is shared
We share information only as needed to operate the service, honor your instructions, or meet legal obligations. Recipients may include:
- Cloudflare for application hosting, networking, security, storage, and isolated compute;
- GitHub for authentication and repository features you choose;
- OpenRouter and model providers for model requests you initiate;
- Paddle as merchant of record for checkout, payments, taxes, subscriptions, and buyer support;
- PostHog for limited product analytics; and
- professional advisers, authorities, or transaction counterparties where reasonably necessary for legal compliance, safety, or a corporate transaction.
Content you deliberately publish to the public registry is public and may be indexed, copied, or redistributed by others. We do not sell personal information for money.
5. Cookies and local storage
Trunchbull uses cookies and similar browser storage for account sessions, security, interface preferences such as theme, and product analytics. PostHog analytics is configured without session recording or automatic interaction capture, but it may process page views, selected product events, and identified account attributes.
You can limit cookies through your browser settings, although disabling essential storage may prevent sign-in or other service features from working.
6. Retention
We retain information for as long as reasonably needed to provide the service, maintain benchmark provenance and audit records, secure the platform, resolve disputes, and meet legal, tax, and accounting obligations. Retention depends on the type of record and whether your Content was published publicly.
Disposable sandbox infrastructure is designed to be destroyed after use, while run records, results, telemetry, billing records, and published benchmark provenance may be retained for a longer period. Backup copies may persist for a limited time after deletion.
7. Security and international processing
We use technical and organizational safeguards intended to protect information, including access controls, credential protection, isolated execution, network restrictions, and audit records. No system is completely secure, and we cannot guarantee absolute security.
Trunchbull and its providers may process information in countries other than where you live. Where required, we rely on recognized transfer mechanisms and provider safeguards for international data transfers.
8. Your choices and rights
Depending on where you live, you may have rights to access, correct, delete, restrict, or object to processing of personal information, or to receive a portable copy. You may also have the right to complain to your local data-protection authority.
You can disconnect integrations and manage subscription information from your account. To request account deletion or exercise a privacy right, emailsupport@trunchbull.dev. We may need to verify your identity. Some records may be retained where legally required or where deletion would compromise public provenance, security, or the rights of others.
9. Children
Trunchbull is not directed to children under 18, and we do not knowingly collect their personal information. Contact us if you believe a child has provided personal information through the service.
10. Changes and contact
We may update this notice to reflect changes in the service or law. We will post the updated notice and revise its effective date, and provide additional notice when required.
Questions or requests about privacy may be sent tosupport@trunchbull.dev. For payment information handled by Paddle, see ourRefund Policy and Paddle's notices presented during checkout.