Trust and Security
What the connection can and cannot do
Trueness holds a read-only connection to Stripe™:
- Read-only OAuth scopes on Stripe. Trueness never writes to your Stripe account (one narrow exception: it creates the single event destination it reads from — it never modifies or deletes a destination it did not create, and it never writes to a billing object). It reads subscriptions, invoices, customers, payments, credit notes and refunds, and nothing else.
- Registered as a Stripe Extension, not Connect. This keeps Trueness out of PCI scope. Trueness never sees a card number, never sees a CVV, and never sits between you and payment processing.
- Writes nothing to HubSpot today. The free Drift Report is produced by reading your Stripe account and your HubSpot CRM and comparing them — it does not create or change any record in your HubSpot portal. When Trueness later writes anything to HubSpot, it will write only to HubSpot App Objects, never to HubSpot's native invoice, payment or subscription objects, which would make the data inaccessible to your own integrations.
- Deletion, today. Uninstalling removes Trueness's access and, on request, its stored copy of your report and discrepancy data. Erasure by crypto-shredding of a permanent history is planned for when the paid, history-keeping product ships — it is not yet built, so this page does not claim it exists.
Where your data goes
Processing location. Trueness runs on Cloud Run in us-east4 and stores data in Neon aws-us-east-1.
EU data. EU personal data reaching a Brazilian entity requires no SCCs and no transfer mechanism following the EU–Brazil mutual adequacy decision of 27 January 2026.
Sub-processors. Each sub-processor and its data-handling function is listed at /subprocessors.
People
Data protection contact (LGPD encarregado). trueness.lab@gmail.com
GDPR Article 27 representative. Not yet designated. We have no customer established in the European Union yet; a representative is appointed before the first one.
Coverage, in every report
Every Drift Report carries a coverage statement: what was compared, what could not be compared and why, how many objects were examined, and the exact Stripe and HubSpot API versions used to read them. A report without a coverage statement is a screenshot — ours never sends one.
An append-only, hash-chained history of every sync decision ("History: complete, verified, N entries") is planned for the paid product. It has not shipped yet, is not on the free Drift Report, and this page does not claim otherwise.
Retention
Today: the free Drift Report. You get the current report, refreshed daily, exportable as PDF, CSV and JSON at any time.
Paid-tier retention (13 months hot) is planned, not shipped. There is no paid tier yet, so there is nothing to retain under one. This section will describe the real behaviour once a paid tier exists.
The wind-down promise
See About for what happens if Trueness is ever discontinued, and for what that promise does and does not cover today, before any paid account exists.
Security questionnaire
Once paid accounts exist, we will answer one written questionnaire per customer per year, within two business days. We do not do on-site audits or calls.
For details, see the Data Processing Agreement.
Questions? trueness.lab@gmail.com