Troof — Privacy Policy
Effective date: August 14, 2026 Version: 1.1 Operated by: Mighty Meat LLC d/b/a Troof, a Tennessee limited liability company
A note on who this covers
Most privacy policies address one group: users. This one addresses two.
- Senders — customers who place an order and agree to our Terms.
- Recipients — people who receive a message. Recipients never signed up for anything. A sender gave us their phone number.
We take the second group's position seriously. Sections 5 and 8 are written specifically for recipients, and recipients have rights here that no paying customer can override.
1. What we collect
From senders
| Category | Examples |
|---|---|
| Account | Email address, password credential |
| Order | Message text, recipient phone number, recipient first name, delivery preferences, recording add-on selection |
| Payment | Handled by Stripe. We receive a transaction ID, last four digits, and status. We never receive or store your full card number. |
| Agreement records | Timestamp and version of the Terms and this Policy you accepted, and the IP address at acceptance |
| Technical | IP address, browser and device type, pages viewed, timestamps |
| Support | Correspondence you send us |
From website visitors
| Category | Examples |
|---|---|
| Updates list | Your email address, if you ask us to tell you when calling starts |
Joining the updates list does not create an account and does not place an order. We use the address for that one announcement and for nothing else. You can ask us to remove it at any time by emailing privacy@troofapp.com.
From and about recipients
| Category | Examples |
|---|---|
| Phone number | Provided by the sender, not by the recipient |
| First name | Provided by the sender, not by the recipient. Used to address the disclosure and reminder messages to you. |
| Abuse-prevention record | A one-way cryptographic fingerprint of your phone number, stored with each order. It lets us enforce limits on how many messages one number receives without keeping a list linking you to the people who messaged you. It cannot be reversed to recover your number. |
| Consent record | Your SMS reply, its timestamp, the number it came from, the disclosure version sent |
| SMS log | Delivery status of the disclosure and reminder messages, and your replies |
| Call record | Date, time, duration, outcome (answered, voicemail, declined), and whether recording and transcript consent was given |
| Recording and transcript | Audio and a written transcript of the call — only where you gave verbal consent on the call |
| Do-not-contact | Your number, if you ask never to be contacted again |
We do not buy, rent, append, or enrich recipient data. We do not look up a recipient's name, address, email, social profiles, or any other information. We know a phone number and what happened on it.
2. How we use information
Senders' information is used to provide the Service, process payment, send transactional email, provide support, prevent fraud and abuse, and comply with law.
Updates-list addresses are used only to send the one announcement you asked for. They are not used for marketing, are not added to any other list, and are not shared.
Recipients' information is used only to:
- Send the disclosure and reminder messages
- Record whether consent was given
- Place the call, if consent was given
- Produce the recording and transcript, if consent was given
- Honor do-not-contact requests
- Maintain records demonstrating that consent existed before the call
- Prevent abuse of the Service — including limiting how many messages any one number receives, and detecting patterns of repeated or coordinated contact
- Comply with law and defend legal claims
We do not use recipient information for marketing. We will never send a recipient a promotional message, add them to a mailing list, or contact them for any purpose other than a specific order or a do-not-contact confirmation.
What we do not do with anyone's information
- We do not sell personal information. We have not and will not.
- We do not share personal information for cross-context behavioral advertising.
- We do not use your message content or call recordings to train AI models, and we contractually require the same of the vendors who process them on our behalf.
3. Message content
Your message is transmitted to the recipient by voice, screened against our content standards, and retained as a record of the order.
Message content is accessible to a limited number of authorized personnel for screening, support, abuse investigation, and legal defense. We do not read messages for any other purpose.
Your message is never sent to the recipient by SMS and is never left on voicemail. It is delivered by voice, to a consenting recipient, on a live call — or not at all.
4. Recordings and transcripts
A recording and transcript exist only where the sender purchased the add-on and the recipient consented verbally on the call. We ask once, for both.
If a recipient declines, we produce neither. We do not deliver a transcript of a call the recipient refused to have recorded. A transcript is the contents of the conversation, and we treat a refusal as covering both forms.
What every order produces
Every order generates a delivery confirmation for the sender: date, time, duration, outcome, and whether the recipient acknowledged the message. This contains no content from the call — it says what happened, not what was said.
Where they live
Both files are transferred to our own encrypted storage (Cloudflare R2) immediately after the call, and the copies held by our telephony and voice vendors are deleted.
How long they live
14 days. Then permanently deleted.
- The sender receives a secure, short-lived download link
- The sender may generate a fresh link at any time during the 14 days
- We send a reminder on day 12
- On day 14 both files are permanently deleted
"Permanently deleted" means what it says. We do not keep versioned copies, archived copies, or backup copies, and no vendor retains a copy. After day 14 neither the audio nor the transcript can be recovered by us, by the sender, or by anyone else — including in response to a subpoena.
What survives is not the content. We retain the record that a call occurred, that consent was given, and the metadata in Section 5. If a recipient later wants to know what was said, we may not be able to tell them after day 14.
5. Retention — how long we keep what
| Data | Retention | Why |
|---|---|---|
| Call recordings and transcripts | 14 days, then permanently deleted | Product deliverable. No reason to hold call content longer. |
| Consent records — SMS replies, timestamps, disclosure version, recipient number | 5 years | Demonstrating that consent existed before a call is our legal defense. This is the record we cannot lose. |
| Call metadata — date, time, duration, outcome | 5 years | Same. This is what delivery confirmation is drawn from. |
| Recipient abuse-prevention fingerprint | 5 years | Enforcing contact limits requires recognising a repeat number after the raw number is deleted. |
| Updates-list address | Until you ask us to remove it, or 90 days after the announcement is sent | — |
| Message content | 2 years | Abuse investigation and defense of claims |
| Sender account | Life of account, then 90 days | — |
| Payment records | 7 years | Tax and accounting law |
| Terms acceptance records | 5 years after last order | Evidence of agreement |
| Do-not-contact list | Indefinitely | Deleting it would mean contacting you again. |
| Web analytics | 14 months | — |
| Support correspondence | 3 years | — |
Call content and the consent record are different things with different lifespans. This is deliberate. The recording and transcript are a product; the consent record is a legal necessity.
6. Who we share information with
We share only with service providers who need it to operate the Service, under contracts limiting their use to our instructions.
| Vendor | Purpose | What they receive |
|---|---|---|
| Stripe | Payment processing | Payment and billing details. Stripe is the controller of card data. |
| Twilio | SMS and telephone calls | Recipient phone number, SMS content, call audio in transit |
| Retell AI | AI voice agent | Message content and call audio during the call |
| Cloudflare | Website hosting, recording storage, DNS | Recordings, technical data |
| Supabase | Database and authentication | Account data, orders, consent records |
| Render | Application hosting | Application data in processing |
| Postmark | Transactional email | Sender email address, message subject and body |
| Google Workspace | Business email | Support correspondence |
We require our AI and telephony vendors to commit to zero data retention and to not train models on our data.
Other disclosures
- Legal process — in response to a subpoena, court order, warrant, or lawful request
- Safety — where we believe in good faith that disclosure is necessary to prevent imminent harm
- Legal defense — to establish or defend legal claims, including in a dispute with a sender or recipient
- Business transfer — in a merger, acquisition, or asset sale. This Policy governs until it is replaced with notice.
We do not disclose a sender's identity to a recipient as part of the Service. We will disclose it in the circumstances above, and senders are told this in the Terms.
7. Security
We use encryption in transit and at rest, access controls limiting personal information to authorized personnel, short-lived signed URLs for recording downloads, automated deletion, and vendors selected for their security posture.
No system is perfectly secure. We cannot guarantee absolute security, and short-lived links protect against exposure but cannot protect a file after a sender downloads it.
8. Your rights
If you are a recipient
You have these rights regardless of where you live and regardless of what any sender wants:
- Never be contacted again. Reply STOP, or contact us. We add your number to a permanent do-not-contact list. No customer can override this.
- Refuse a specific message. Not replying ends the order. Your message is never delivered.
- Refuse recording and transcription while still receiving the call. Declining does not prevent delivery, and we will not produce a transcript instead.
- Know what we hold about you. Contact us and we will tell you.
- Have it deleted. We will delete what we hold, except the do-not-contact entry (deleting it would mean contacting you again) and consent records where we need them to defend a legal claim. We will tell you what we kept and why.
- Know who sent it. We will tell you what our records show, subject to Section 6.
If you are a sender
Depending on your state, you may have the right to access, correct, or delete your information, opt out of sale or targeted advertising (we do neither), and appeal a denied request.
Residents of California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, Tennessee, and other states with comprehensive privacy laws have these rights under those laws. We extend them to all users regardless of residency.
How to exercise them
Email privacy@troofapp.com. We respond within 45 days and may extend once where permitted, with notice. We may need to verify your identity. We will not discriminate against you for exercising a privacy right.
Appeals: If we deny a request, you may appeal by replying with "Appeal" in the subject. We will respond within 45 days with a written explanation. If we deny the appeal, you may contact your state Attorney General.
9. Children
The Service is not for anyone under 18. We do not knowingly collect information from children, and senders are prohibited from using the Service to contact minors.
If we learn a recipient is under 18, we cancel the order and delete their information. If we learn a sender is under 18, we terminate the account.
If you believe we hold a child's information, contact privacy@troofapp.com immediately.
10. Cookies
We use cookies necessary for the site to function — session management, security, and checkout. We use limited analytics to understand site usage.
We do not use advertising cookies, third-party trackers, or cross-site tracking pixels. We do not sell or share information for cross-context behavioral advertising, so no "Do Not Sell or Share" mechanism is required — but we honor Global Privacy Control signals regardless.
11. Changes
We may update this Policy. Material changes will be posted with a new effective date and version number and, where we have your email, sent to you at least 7 days before taking effect.
We will not retroactively reduce the protections applying to information already collected without your consent.
12. Contact
Mighty Meat LLC d/b/a Troof 4145 Outer Drive Nashville, TN 37204
Privacy: privacy@troofapp.com Support: support@troofapp.com
Recipients: you can reach us at the privacy address above. You do not need an account and you will not be asked to create one.
Version 1.1 — Effective August 14, 2026