Torspan
Torspan · Privacy

Privacy.

What's collected, what never is, whose computers it passes through, how long it lasts, and what you can take back.

There is no second version of this written in lawyer language. That matters more than it sounds like it does: when a company gives you a friendly summary and a real agreement, the friendly one is decoration and the real one is what a court reads. This page is the real one. If a sentence here is unclear, that is a defect in our writing, not a gap the fine print fills in.

This is one half of the agreement. The terms are the other half — same voice, same page rules, no change of register in between.

In effect since August 22, 2026
Last changed September 4, 2026. See What changed
Length 4,512 words. All of the privacy half. There is no summary version of it
Covers torspan.com, the AirOrchestra app, and everything your crew puts into it
Write to admin@torspan.com — answered in writing, next business day

Two rules, before anything else.

One. If this page and Your records ever disagree, the reading that's better for you is the one that holds — and the disagreement is a defect we fix, not a trap we sprung. Nobody should have to read two pages of ours and figure out which one we meant. When we find one, we fix it and it shows up in What changed with the date.

Two. Anything on this page that's better for you can be improved for everybody. Anything that's worse for you applies only to accounts opened after the change, never to yours. Terms that got worse after you signed are the oldest trick in software, and the fix is one sentence long, so here it is.

Everything from here to the bottom is written to be read by the person it affects: the man who wrote the sentence, the foreman who checked it, the office that pulls the file, and the owner who signs. If any of them needs a lawyer to understand a paragraph, that paragraph is wrong and we want to hear about it at admin@torspan.com.

A plain-English summary that a legal document overrules is not plain English. It's a courtesy. This is not a summary.

Three parties, and only one of them is the customer.

Most privacy policies are written as though there are two parties: a company and a user. There are three here, and the middle one is the reason this page is different.

The contractor is the customer

He signs, he pays, and the records belong to his company. His crew's messages, his jobsite photos, his safety documents, his drawings.

The crew are the people in the record

They write the sentences. They are not the customer and they never signed anything with Torspan. They are the reason the record exists and they are the ones with the most to lose if it is handled badly.

Torspan is the keeper

We hold the file, on a service we run, in the United States — one encrypted instance that holds your company and nobody else's. We hand it back on demand, and we have no business that runs on anything else in it.

That middle row is where every privacy failure in field software comes from. A vendor sells to the man who signs, so the vendor writes its policy for the man who signs, and the man who wrote the sentence at 6:41 in the morning finds out later what was done with it.

The man who writes the sentence is not the one who signs, and he is the reason the record exists. So he gets his own clauses on this page, and they are not buried.

What the app collects.

All of it, in one table. If something is not on this list, it is not collected — that is not a figure of speech, it is the point of putting the list in one place.

WhatWhy it exists
His name and how to reach himSo a record has an author. Added by his employer when the account is set up.
What he writes into the appThis is the record. Kept verbatim, in the language he wrote it in, with the time.
Photos he takes or sendsFiled under a job with a date and his name.
Documents your company uploadsDrawings, cut sheets, submittals, dispatch. The original file, byte for byte, plus the text pulled out of it.
The rows the system writes from all of the abovePre-task plans, daily reports, answers. Each one carries the sentence it came from.
Whether an email we sent arrived or bouncedA delivery result from the mail service. Not whether he opened it, because that is not measured.
Billing contact and payment status for the companyThe name and address on the invoice, and whether it was paid.

Location data inside a photo file is stripped before the photo is stored. The photo lands on the right job because a man said which job, or because the schedule says so — never because a camera said where he was standing.

What is never collected.

  • No location. Ever. No GPS trail, no geofence, no clock-in radius, no map of anybody, no last-known position. There is no location column in this system, so there is nothing to hand over, leak, or subpoena.
  • No number about a man. No score, no rating, no ranking, no utilization, no hours-versus-units. Nothing in the export either, because there is nothing to export.
  • No background listening. No calls recorded, no site walks transcribed, no microphone open. Every word in the record is something a person chose to write and send.
  • No face recognition, and no biometric of any kind reaches us. There is nothing about a face or a fingerprint anywhere in this system, and there is no column for one. Washington regulates commercial enrollment of biometric identifiers at chapter 19.375 RCW; we are outside it because we never enroll one.
  • No app-activity surveillance. Nothing counts how many times he opened it, how fast he replied, how long he read, or what hour he stopped.
  • No contacts, no photo library, no calendar. The app asks for the camera when you take a picture. That is the whole list of permissions — it never asks for the microphone, because dictation happens in your own phone's keyboard.

The long version, with what each absence actually costs somebody who wanted it →

The five things it's used for.

There is no sixth.

  1. To make the records your crew asked for — the pre-task plans, the daily reports, the photos on the right job, the answers off the documents.
  2. To answer questions off the documents uploaded to your own jobs, and to say so when it has not read the document the question is about.
  3. To keep the thing running and fix it when it breaks — which sometimes means somebody here opens a record, under the rule in What is never done with it below.
  4. To read a plan or a report before it counts — a person at Torspan reads it against what the crew said and what the drawings and cut sheets say, under the same rule.
  5. To bill your company.

Not to build a picture of what a normal week looks like across contractors. Not to improve a model. Not to sell you something else.

Torspan sells software, and the only money it makes on your account is the subscription on the pricing page.

The word you came here to search for.

If you hit ⌘F and typed training, this is the sentence you were looking for.

Nothing your crew writes, photographs or uploads is used to train a model. Not ours. Not a vendor's. Not in aggregate. Not stripped of names. Not "to improve the Services."

That last phrase is the one to watch for in somebody else's agreement, because that is the phrase that carries it. The ordinary shape of this clause in field software grants the vendor a worldwide, royalty-free license to use your data to develop new products and to train the vendor's own models, and then narrows it with aggregated and de-identified — a qualifier that makes the sentence acceptable to read and impossible for you to check. We do not have that clause because we do not have that use.

If it ever changes: it changes on this page first, with a date on it, and it is a thing your company agrees to in writing, not a thing your company is notified of. No account is ever opted in by an update. That is Rule Two from the top of the page, applied to the single clause where it matters most.

Three ways to check this instead of believing it
  1. This paragraph is the contract, not a marketing page. There is no second document where a broader license lives.
  2. Whose computers it passes through lists every outside company that touches anything, and what each one touches.
  3. Ask, in writing, and get a written answer at admin@torspan.com.

What is never done with it.

Four things, each one short, because a paragraph of reassurance wrapped around a promise is how you can tell the promise is doing work it cannot do.

It is never sold.

Not raw, not aggregated, not de-identified, not as "market insights," not as a dataset described some other way in a document you did not read.

It is never used to train a model.

The clause is one section up, and it is the one to read twice.

It is never shown outside your company.

Except to the services in Whose computers it passes through, each doing only the job named beside it. Not to a partner, not to an insurer, not to a case study, not to an investor's diligence folder, not to another contractor who asked what a normal week looks like.

It is never opened without a reason, and the reason is written down.

Every vendor can technically read your database and almost none of them will say so, so: Torspan can. A record is opened for three reasons and there is not a fourth: a person at Torspan reads a plan or a report before it counts; something you reported gets fixed; the system gets kept running. Each time it happens it is written down — the date, the person and the reason — and you can ask for that record and get it. Nobody at Torspan writes in anybody's name, and nothing of yours trains anything. That last clause is what makes the rest of the paragraph mean anything.

Whose computers it passes through.

Nobody runs a product like this alone. The honest version of that sentence is a list, with what each company touches, on the page you are already reading — not in an appendix, and not behind a form that asks for your company name before it will show you.

Start with the sentence that decides the rest of this one: Torspan holds your record, on its own service, in the United States — one encrypted instance that holds your company and nobody else's — and no query of ours spans two companies. Everything below is who else touches any part of it, and which part.

Each row is one company and one job, and there is not a row you were not told about.

WhoWhat it touchesWhose account · where
HostingThe database, the documents and the photographsAmazon Web Services, under Torspan's account · United States (Oregon)
The model that reads and writesThe text of a message, the page of a document it is answering from, or a photograph that has to be read — for as long as it takes to answer. The provider keeps nothing after that unless a law or its own safety review requires itAnthropic, under Torspan's commercial account · United States
Email deliveryNotices, sign-in links, and the documents you asked to be emailed to youAmazon Web Services, under Torspan's account · United States (Oregon)
BillingYour company's billing contact and the monthly invoiceOurs · United States
YouEvery closeout packet you email a general contractor and every report you upload to somebody's portalYours

The last row is on the list because an honest boundary does not stop at the boundary that flatters us. The same list, in the product's own words: where it runs, and whose computers it passes through.

Two things about the first two rows, because they are the rows people mean when they ask this question.

It is not training anything. The page goes out to be read and the answer comes back. That is the clause above. The account is a commercial one, in Torspan's name, under terms that exclude training on what passes through it. Ask in writing and you get the clause that says so.

It is one company's record. Your company's record is on its own encrypted instance, and no query of ours spans two companies; no screen at Torspan shows a customer's work. It comes out whole on the day you ask.

Any addition to this list is posted here BEFORE it is switched on, with the date. Not published after. Not published on a page you have to subscribe to. Here, first, and your company can leave over it without paying for the rest of the term.

That paragraph is a binding sentence, not a note.

How long it's kept.

Two clocks matter and neither of them is ours.

The first is federal: payroll records preserved three years, and the records the wage was computed from — the time cards, the schedules — two years (U.S. Department of Labor, Fact Sheet #21).

State law adds its own clock, and it is longer. Washington, for example: on public work the payroll record has to survive three years from the day the awarding agency accepts the job (RCW 39.12.120) — which on a two-year build is five years from the morning the work was described.

WhatKeptFloor
The daily report, and the messages it was written fromUntil you delete it3 years after the pay period, the payroll clock
Pre-task plans and the acknowledgments on themUntil you delete itNo period set by rule
Photos, full sizeUntil you delete it. Never downsized, never replaced by a thumbnail—
Documents you uploadedUntil you delete it. The original file, byte for byte—
Answers, with the sheet and revision each one came fromUntil you delete it—
Every message, verbatim, in the language it was written inUntil you delete it—
A photo somebody deletesGone from the record that second, and out of backup copies within thirty days—
A canceled subscriptionHeld read-only for twelve months, then erased — and out of backup copies within thirty days after that. Erased sooner on request, by the end of the next business day—

"Until you delete it" means for as long as you are a customer, and the twelve months after. Nothing in this product deletes a record to save room, and there is no clause anywhere granting us discretion over how long yours lasts. The floor column is the law's number, and meeting it is your company's obligation, not something software confers.

Nothing here is deleted to save room, and nothing is thinned out with age. A five-year-old photo comes back the size it arrived.

The same table, with the reasons under it →

What you can ask for — and what you don't have to ask for.

Washington has no general consumer privacy law. The legislature has not passed one; what exists is narrow — consumer health data at chapter 19.373 RCW and biometric identifiers at chapter 19.375 RCW, and neither one reaches a jobsite record. California's statute applies to companies over $25 million in revenue, or handling 100,000 residents, or making half their money selling personal information (California Attorney General).

So nothing below is a law making us do it. It is a term of the contract, which means you can enforce it against us.

The company

Export everything, any day. Ask in writing and it is built for you — not a plan tier, not a wind-down step, not a fee. It works on a paid account, on a canceled account, and on an account that is thirty days late. What comes out: photos as files with their attribution beside them, documents as the original documents, safety plans and reports as PDFs, the conversation as text. Files that open without us. Delivered within five business days of your asking.

Ask what we have. Write to admin@torspan.com and get a written answer within ten business days, in plain English.

Ask who opened it. The record from What is never done with it — with dates, people and reasons.

The person

This is the clause no state law gives him, and he gets it anyway.

A man can ask for his own copy and get it — his messages, his photos, the safety documents with his acknowledgment on them. Without going through his employer. Without a reason.

The whole-company export belongs to the company, because the whole company is the company's. His own words belong to him too, and he does not have to go through anybody to hold a copy of them.

He can correct anything he wrote. Corrections append. Nothing he authored is silently rewritten, and the original stays attached to the correction, because a record that changes quietly is not a record.

He can delete a photo he took, and it is gone from the record that second, then out of backup copies within thirty days.

A record a man can't see isn't a record he'll feed. That is not sentiment. It is the reason this product has anything in it.

Deleting an account, and what stays.

Ask in writing and the account is deleted by the end of the next business day.

Deleting the account removes the person. It does not remove the work record he authored, and it must not. What he reported on the fourteenth is his employer's record of that day, and it is subject to the clocks in How long it's kept. The acknowledgment on a pre-task plan is what makes that document his. If a man could erase those on his way out the door, the record would have a hole in it exactly where somebody later needs it, and the man beside him would be the one arguing about a missing Tuesday.

Access and authorship are two different things, and confusing them is how records get holes in them. He loses the first. The second is not ours to erase and it is not his employer's to erase either — it is what happened.

Deleted
  • Sign-in and access. Immediately.
  • His name and contact details from the directory.
  • Anything he chooses to delete before he goes — his photos, and he can delete them one at a time.
Kept
  • Photos he took, under his name.
  • Safety documents he acknowledged, with the acknowledgment intact.
  • Messages that are the source of a record — with his authorship, because an unattributed record is worse than no record.

When the subscription ends, the account is held read-only for twelve months — sign-in works, export works, nothing new is written — and then it is erased. Sooner on request, by the end of the next business day. Backup copies follow within thirty days. There is no fee to get anything out.

Nobody at Torspan can tell you your password, because nobody at Torspan has it.

This website.

No cookies. No pixel, no session recorder, no ad network tag, no marketing automation script, no chat widget, no font loaded from somebody else's server, no analytics that follows you anywhere. The server counts requests so we know a page is being read; that count has no person in it and never has.

No cookie banner, because there is nothing to consent to. That is what a banner is for and we do not have the thing it is for.

No email field exists on this site. No form, no list, no sequence, no address collected anywhere. Mail sent to admin@torspan.com gets a written reply, and it is never sold, never put into a marketing tool, never used to retarget anybody, and never handed to a third party.

And this one you can check right now, from this page, in ten seconds: open the developer tools, click Network, reload. Count the companies. There are none.

If something leaks.

Washington gives a company thirty days to tell you (RCW 19.255.010(8), which requires notice "in the most expedient time possible, without unreasonable delay, and no more than thirty calendar days after the breach was discovered").

Seventy-two hours from knowing, and we are not waiting for certainty.

Then the part that decides how much that promise is worth: what we hold. Which company is a customer, your billing contact, the addresses on the account — and the records themselves: your crew's messages, the photographs, the documents, and everything the software made from them. That is the honest list, and it is why the notice below is written the way it is.

The notice still goes to every affected account, by email, to every address on it, and it says what was taken, when, how it happened, and what we have done since. Including when the answer is embarrassing. Including when nobody outside would ever have found out. If the first notice is incomplete, a second one follows when we know more, rather than the first one waiting until the story is tidy.

A company that would rather look composed than tell you early is a company you find out about late.

What changed.

Every version of this page stays readable at its own address. This is the list.

September 4, 2026

This page described a product that ran on a computer your company owned. It runs on a service Torspan operates. What moved, in order:

  • "Torspan is the keeper" is back, because it is true again. The records are on a service we run, in the United States, and your company's record is yours alone.
  • "Whose computers it passes through" lists hosting and the model provider under Torspan's account again. The off-site backup and the operating-system rows are gone with the computer they described.
  • The access clause was rewritten. A person at Torspan opens a record to read a plan or a report before it counts, to fix something you reported, or to keep the system running — and each opening is written down.
  • A canceled account is held read-only for twelve months and then erased, as the first version of this page said.
  • "If something leaks" now says plainly that the records are on our side of the line.
  • Two numbers are printed that were not before: an export is delivered within five business days of your asking, and backup copies clear within thirty days.

The version this replaced is at its own address, unchanged.

August 25, 2026

This page described a product that held your records on servers we rent. It does not hold them at all. What moved, in order:

  • "Whose computers it passes through" no longer lists a hosting company or a file-storage company, because there are none. It is now a list of doors — the outside reading on your own account, mail delivery, your own off-site backup target, the payment processor, Apple at the operating system, and you.
  • "Torspan is the keeper. We hold the file" is gone, and the retention column changed from life of the account to until you delete it for the same reason. The row that said a closed account is held read-only for twelve months and then erased now says nothing is erased.
  • The access clause was rewritten in the other direction. It used to say we can read your database and log it when we do. It now says we cannot, unless somebody in your office opens a session, and that the log of it is on your own disk.
  • "If something leaks" now prints the short list of what we actually hold that could leak, none of which is a record your crew made.
  • Two of these are worse to read, and they are the reason this row is not a press release. A backup you own is a backup we cannot restore for you if it was never running, which is why the restore is now rehearsed with you rather than assumed. And the per-open face or fingerprint lock is labelled as on our year rather than described as though it were running, because it is not.

The version this replaced is at its own address, unchanged.

August 22, 2026

First version. Still readable at its own address.

Software's one attempt at a terms of service you could read the edit history of was a public policy repository kept by the makers of Basecamp. It was archived on 26 December 2023 and is now read-only (github.com/basecamp/policies). That is the whole field. The bar is on the ground and we are stepping over it with a table.

The other half of the same agreement.

Privacy answers what happens to the record. The terms answer what happens between your company and ours: what it costs and how it ends, who owns the record, how you leave, what happens if Torspan stops, what we promise about it working and what we don't promise, what an acknowledgment in an app actually consists of, and what happens if we disagree.

Same voice, same two rules, no fine print underneath either half.

One agreement. Two halves. No third document in lawyer language.

Read the terms →

The same commitments in plain sight, with the reasons under them →

If a sentence here isn't what you need it to be, say so before you buy.

A term is easier to change before a signature than after one, and this is the page where that is literally true.

admin@torspan.com — read the business day it arrives, answered in writing by the end of the next business day.

The same commitments in plain sight, with the reasons under them — Your records.
Everything this product refuses to do, said without a "yet" on the end — What it won't do.