Privacy Policy
Last updated: July 15, 2026
Torchlite.ai (“Torchlite,” “we,” “us”) provides an AI-powered search and answer service for construction, contractors, and the service industry. This Privacy Policy describes how we collect, use, and protect information when you use our website and application at torchlite.ai.
Information we collect
- Account information. When you register, we collect your name, email address, and a hashed password. If you enable multi-factor authentication, we store the credentials needed to verify your second factor.
- Connected source data. When your organization connects integrations such as QuickBooks Online or Basecamp, we access and index the records you authorize (for example invoices, customers, project messages, and documents). We store this data to power search and AI answers for your organization only.
- Usage data. We collect information about how you use Torchlite, including search queries, Ask conversations, and actions taken in the product, to operate and improve the service.
- Technical data. We automatically collect standard log data such as IP address, browser type, and request timestamps for security, debugging, and reliability.
How we use information
We use the information above to:
- Provide, maintain, and improve Torchlite
- Authenticate users and enforce per-organization access controls
- Index connected data and generate semantic search results and AI answers
- Send transactional email (for example account verification and password reset)
- Monitor security, prevent abuse, and comply with legal obligations
Third-party services
We use trusted service providers to operate Torchlite. Depending on your configuration, data may be processed by:
- OpenAI — document text and user queries may be sent to OpenAI to generate embeddings and AI answers. Do not use Ask for data you are not permitted to share with a third-party AI provider.
- Intuit (QuickBooks Online) — when you connect QuickBooks, we access accounting data via Intuit’s API using OAuth tokens you authorize.
- 37signals (Basecamp) — when you connect Basecamp, we access project data via Basecamp’s API using OAuth tokens you authorize.
- Google — if you sign in with Google, Google provides basic profile information under their own privacy policy.
- Amazon Web Services — we host Torchlite on AWS (compute, storage, and database services) in the United States.
- Amazon SES — we send transactional email through AWS Simple Email Service.
We do not sell your personal information or your organization’s connected data.
Data isolation and retention
Each customer organization (“tenant”) has its own isolated data. Users can only access data belonging to their organization, subject to permissions in connected sources. We retain account and indexed data for as long as your organization uses Torchlite and as needed to comply with law. You may request deletion of your account by contacting us.
Security
We use industry-standard measures to protect data in transit and at rest, including HTTPS, encrypted storage of integration tokens, and access controls. No method of transmission or storage is completely secure; we cannot guarantee absolute security.
Your choices
- You can disconnect integrations at any time from Settings or from the provider’s app management page.
- You can update account details and security settings in Settings.
- You may contact us to request access to or deletion of personal information associated with your account, subject to legal and contractual limits.
Changes
We may update this Privacy Policy from time to time. We will post the revised policy on this page and update the “Last updated” date above.
Contact
Questions about this Privacy Policy? Email info@torchlite.ai.