Privacy Policy
Effective 27 August 2026
We do not use your prompts, conversations, files, images, voice recordings, responses or other content to train our models.
This Policy explains how TREJJ Communications Limited (“TREJJ”, “we”, “us” or “our”) handles personal data when you use TREJJ One on the web, mobile app, Agentic Access, support or the affiliate programme. It should be read with our Terms of Service and Cookie Policy.
1. Who controls your data
TREJJ Communications Limited operates TREJJ One and is responsible for deciding how account and service data is handled. This Policy covers TREJJ One. A website, app, operating system, IDE, app store, payment service or other service you choose to use has its own privacy practices for data it independently receives.
2. Data we collect
Depending on the features you use, we collect:
- Account and identity data: name, email address, timezone, verification state, password hash, Google or Apple account identifier when you choose that sign-in method, two-factor settings, account creation time and current plan.
- Content you choose to send: prompts, relevant conversation context, selected files and images, voice recordings awaiting transcription, support messages, AI-output reports and the instructions, project context and tool results sent through Agentic Access.
- Service and usage data: requested feature, TREJJ One intelligence selection, token or cost-based usage measurements, plan allowance, response status, timestamps, count-only chat activity, Wallet reservations and limited diagnostic or security events.
- Device and session data: secure web session identifiers; mobile session tokens; one-way device or session hashes; app version, platform, locale, timezone and notification preferences; and, only with analytics consent, coarse country and device, browser and operating-system families.
- Transaction data: plan, billing interval, transaction reference, amount, currency, status, payment dates, masked card details and reusable-card authorization data when automatic renewal is enabled. We do not receive or store a card's full number or security code.
- Affiliate data: application and invitation details, public affiliate ID, country, referral attribution, commission and ledger records, validated bank details, withdrawals, messages and programme status.
- Communications: support tickets, replies, email delivery events and information you give us when asking for help.
We ask you not to send passwords, verification codes, private keys, payment credentials, or sensitive information that is not needed for your request.
3. Why we use data
We use personal data to provide the service you request; create and secure accounts; authenticate sessions and Agentic keys; generate responses and files; synchronize chats when enabled; enforce plan and safety limits; process and reconcile payments, renewals, Wallet activity, commissions and withdrawals; provide support and notifications; detect fraud and abuse; diagnose failures; maintain service reliability; comply with legal obligations; and establish or defend legal claims.
Where privacy law requires a legal basis, processing is based as applicable on performing our contract with you, taking steps you request before entering that contract, our legitimate interests in securing and operating TREJJ One, your consent for optional analytics or device permissions, and compliance with legal duties. You may withdraw consent for future consent-based processing without affecting processing already completed.
4. TREJJ One AI requests
When you send a request, TREJJ One processes the prompt and the conversation context, images, documents or tool results needed to deliver the selected TREJJ One capability. TREJJ operates this as the TREJJ One service and maps each public intelligence choice to the appropriate TREJJ One processing capability. Internal service orchestration does not change the identity of the service you are using.
Raw microphone audio follows the separate transcription process below. The resulting transcript becomes part of an AI request only after you review and send it. We do not use your prompts, conversations, files, images, voice recordings or responses to train our models.
5. Chat history, uploads and generated files
Chat history stays in your browser by default. Browser-only chats are controlled through local browser storage and are not included in a server data export. Signed-in users may explicitly enable cross-device sync; when enabled, conversation text is stored with the account until you delete the conversation, clear synced history or delete the account. Archived synced chats remain stored until deleted. Temporary Chat content is not saved as history, although a count-only activity record may still be recorded.
Uploaded images and extracted document text are encrypted and held only to complete the request; temporary upload records expire after two hours and are pruned automatically. Uploaded media is not retained as a chat-history attachment. Generated files and images use private, expiring links and are removed according to the expiry shown by the service, unless you deliberately report an output for support review.
6. Reporting AI output
If you select Report on an AI response, you choose whether to send the output or generated-media link and, optionally, its prompt and your notes to TREJJ support for manual review. For an image report, TREJJ accepts only the user-selected, unexpired TREJJ-generated image belonging to the reporting account, does not fetch arbitrary external media, and may extend that file's expiry to no more than 30 days. Inline image data is not included. The retained image is deleted sooner if the account is deleted; otherwise it expires within 30 days. The support report remains until the ticket or account is deleted, subject to required legal retention. Reports do not create an automatic moderation decision, and we do not silently retain unreported prompt or response text for this purpose.
7. Agentic Access and Wallet
When you use Agentic Access through Codex or a supported IDE, that client sends the instructions, project context and tool results needed for the task to TREJJ One. Depending on permissions you choose, this can include source files, configuration, command output, diffs, images and other local project material. The client may also run commands or change files on your device under its settings and your approvals; TREJJ One does not receive a general-purpose login to your computer.
We retain the hashed Agentic API credential, its label, creation and last-use times, count and cost-based usage records, bounded Wallet reservations, and Wallet and payment ledger entries. The plaintext API key is shown only when created or rotated and is not stored by TREJJ One in recoverable form. We do not intentionally retain Agentic prompts, responses, source files or command output as chat history, and do not use them for model training. Your IDE or terminal software may maintain its own local sessions and history under its settings.
Wallet transaction and payment-verification evidence is retained while the account is active. Account deletion waits until there is no Wallet value or unresolved Wallet activity, then account links are removed from the remaining financial evidence where retention is needed for reconciliation, fraud prevention or law.
8. Voice transcription
Your browser or mobile app records audio only after you grant microphone permission. The recording is sent securely to TREJJ infrastructure and processed by TREJJ's locally hosted speech-to-text service. Audio is held temporarily for transcription and discarded when processing finishes; it is not added to the account, chat history or analytics logs. The transcript returns to the message box for your review and is not submitted as a prompt until you choose to send it.
9. Mobile app and notifications
The mobile app stores an encrypted session token in the operating system's secure storage. For the TREJJ One notification inbox, we retain a one-way device identifier hash, platform, app version, locale, timezone, notification choice, last activity time, and delivery, read or dismissal timestamps. We do not store the app-generated raw device identifier.
Subscription activation, plan, term and expiry notices use short-lived delivery records containing event type, plan name, relevant dates, delivery state and user reference; they do not contain payment credentials. Rating-prompt state records only prompt timing, deferrals and whether the review flow was opened. App stores do not disclose your submitted review or star rating to us.
Where the app asks permission before AI processing, that choice is stored on the device so new requests can be stopped after withdrawal. TREJJ One does not currently keep a server-side copy of that permission setting. Withdrawing it does not undo processing you previously requested.
10. Payments and automatic renewal
Paystack processes card, bank, transfer, USSD and related payment information, and NOWPayments processes cryptocurrency checkout when selected. These payment services receive the information needed to complete and verify your chosen transaction under their own privacy terms. TREJJ retains transaction references, verified amounts, currencies, checkout and reconciliation status, and subscription dates.
When you expressly enroll in automatic card renewal, we also retain Paystack's reusable authorization record, the billing email used for that authorization in encrypted form, Paystack's customer identifier, consent evidence and masked card details. We use those records only to administer the agreed renewal, reconcile charges, respond to disputes and meet financial duties. Cryptocurrency payments remain one-time and do not create a reusable payment method.
11. Affiliate programme
If you apply or are invited as an affiliate, we process your name, email, country, programme status, referral attribution, commission settings, ledger entries, messages, withdrawal records and validated bank-account details. Paystack validates supported bank accounts and processes transfers. The full account number and transfer-recipient identifier are encrypted; interfaces show only the last four digits.
Referral dashboards show the referred user's name, email, signup date, plan and renewal information so commissions can be reconciled. Financial and attribution records may be retained and account identifiers anonymized after closure where needed for fraud prevention, accounting, tax, disputes and legal obligations.
12. Cookies, local storage and analytics
Essential cookies and browser storage support secure sessions, CSRF protection, remembered sign-in, Guest Mode limits, theme and preference choices, mobile browser authentication, affiliate attribution and your consent record. Optional pseudonymous analytics are recorded only after you consent through the cookie banner. Analytics may include a coarse country code supplied by our network edge, device, browser and operating-system families, general product area, first and last activity times, and counts of chats and successful responses.
Analytics does not store raw IP addresses, raw session identifiers, full user-agent strings, page query strings, prompts, responses, audio or transcripts. Rejecting optional analytics does not reduce core service access. You can change your choice at any time using “Cookie choices” in the footer. See the Cookie Policy for a detailed list and browser controls.
13. When data is disclosed
We do not sell personal data or share your content for advertising. Data is disclosed only as needed:
- to payment services you select, including Paystack or NOWPayments, to process, verify, refund or dispute a transaction;
- to Google or Apple when you choose their sign-in or app-store services;
- to infrastructure, email, security and support services working for TREJJ under confidentiality and data-protection obligations;
- to professional advisers, auditors, insurers or financial institutions where necessary;
- to authorities or other parties where required by law, valid legal process, protection of rights and safety, fraud investigation or enforcement of our Terms; or
- as part of a financing, merger, reorganization or sale, subject to appropriate confidentiality and continued protection.
TREJJ One may be accessed internationally, and operational data may be handled where TREJJ or its contracted infrastructure operates. Where required, we use appropriate contractual, organizational and security safeguards for international transfers.
14. Retention
We keep data only as long as needed for the purposes above, then delete or anonymize it unless a longer period is required by law or a dispute. Current operational periods include:
- temporary document and image-upload records: up to two hours;
- reported TREJJ-generated images retained for manual review: no more than 30 days;
- inactive Guest Mode identity and count records: 90 days;
- coarse session analytics, anonymous chat counters and completed subscription-notice delivery records: 90 days;
- security audit records: generally up to 180 days, with identifying fields removed when an account is deleted;
- account-linked count-only chat records and synced conversations: until the account or relevant conversation is deleted; and
- the limited encrypted deletion receipt described below: up to 180 days.
Billing, Wallet, affiliate, tax, dispute, fraud-prevention and accounting evidence may need to remain longer under applicable law. When the account link is no longer necessary, we remove or anonymize it while preserving the financial event required for reconciliation.
15. Security
We use access controls, HTTPS, credential hashing, encryption for designated sensitive fields, scoped tokens, rate limits, secure cookie settings, short-lived verification codes, logging controls and automated pruning. Staff access is limited to operational need. No internet service can guarantee absolute security, so protect your account, use two-factor authentication where available, review connected devices and rotate an exposed Agentic key immediately.
16. Your privacy choices and rights
From Account settings you can update profile information, change security settings, download an account export, manage synchronized chat history, rotate an Agentic key and request deletion. You can control microphone and notification permissions in your browser or operating system, reject optional analytics through Cookie choices, and cancel future automatic renewal without deleting the account.
Depending on where you live, you may have rights to access, correct, delete, restrict or object to processing, receive a portable copy, withdraw consent, or complain to a data-protection authority. To make a request, use Account settings or contact us from the verified email on the account. We may need to verify identity and may retain data that law requires us to keep. We will not discriminate against you for exercising an applicable privacy right.
17. Account deletion
You can permanently delete your account from Account settings or the mobile app. TREJJ One verifies control, revokes active sessions and keys, ends access, stops future scheduled renewal attempts, removes reusable payment authorization material, and deletes account-linked server data. Deletion waits if an already-started payment can still settle or if Wallet value, Wallet activity, affiliate balance or a withdrawal remains unresolved.
A mobile deletion request may use a short-lived, purpose-specific email code. TREJJ One stores a namespaced account reference, one-way code hash, random issue identifier and expiry; the record is consumed after a verification attempt and expired records are pruned.
After deletion, TREJJ One retains a limited administrative receipt containing the originating account name and email in encrypted form, a random receipt identifier, deletion channel, completion time and a purge time 180 days later. It lets authorized administrators identify the originating account for a recent deletion without restoring or authenticating that account. Automated cleanup removes the receipt at expiry. It contains no user ID, authentication credential, TREJJ One intelligence identifier, plan, payment data or content. Financial records that must remain are detached or anonymized as described above.
18. Children
TREJJ One is not directed to children who cannot lawfully consent to an online service in their country. A minor may use the service only with authorization and supervision from a parent or legal guardian where permitted. Contact us if you believe a child provided personal data without the required authorization.
19. Policy changes
We may update this Policy as the service, law or our practices change. We will post the revised Policy with a new effective date and provide reasonable in-product or email notice for a material change where appropriate. Earlier processing remains governed by the Policy in effect at that time unless law requires otherwise.
20. Contact
For privacy questions or requests, visit TREJJ One app support or email support@trejj.net. Contact us from the verified account email where possible. Do not send passwords, verification codes, payment credentials or confidential content by email.