Torspan
AirOrchestra · Privacy

Privacy.

What's collected, what never is, whose computers it passes through, how long it lasts, and what you can take back.

There is no second version of this written in lawyer language. That matters more than it sounds like it does: when a company gives you a friendly summary and a real agreement, the friendly one is decoration and the real one is what a court reads. This page is the real one. If a sentence here is unclear, that is a defect in our writing, not a gap the fine print fills in.

This is one half of the agreement. The terms are the other half — same voice, same page rules, no change of register in between.

In effect since August 22, 2026
Last changed Nothing yet — this is the first version. See What changed
Length 4,398 words. All of the privacy half. There is no summary version of it
Covers torspan.com, the AirOrchestra app, and everything your crew puts into it
Write to [email protected] — one of the two owners reads it

Two rules, before anything else.

One. If this page and Your records ever disagree, the reading that's better for you is the one that holds — and the disagreement is a defect we fix, not a trap we sprung. Nobody should have to read two pages of ours and figure out which one we meant. When we find one, we fix it and it shows up in What changed with the date.

Two. Anything on this page that's better for you can be improved for everybody. Anything that's worse for you can be changed for the next customer, not for you. Terms that got worse after you signed are the oldest trick in software, and the fix is one sentence long, so here it is.

Everything from here to the bottom is written to be read by the person it affects: the man who wrote the sentence, the foreman who checked it, the office that pulls the file, and the owner who signs. If any of them needs a lawyer to understand a paragraph, that paragraph is wrong and we want to hear about it at [email protected].

A plain-English summary that a legal document overrules is not plain English. It's a courtesy. This is not a summary.

Three parties, and only one of them is the customer.

Most privacy policies are written as though there are two parties: a company and a user. There are three here, and the middle one is the reason this page is different.

The contractor is the customer

He signs, he pays, and the records belong to his company. His crew's hours, his jobsite photos, his safety documents, his drawings.

The crew are the people in the record

They write the sentences. They are not our customers and they never signed anything with us. They are the reason the record exists and they are the ones with the most to lose if it is handled badly.

Torspan is the keeper

We hold the file, we hand it back on demand, and we do not have a business that runs on anything else in it.

That middle row is where every privacy failure in field software comes from. A vendor sells to the man who signs, so the vendor writes its policy for the man who signs, and the man who wrote the sentence at 6:41 in the morning finds out later what was done with it.

The man who writes the sentence is not our customer, and he is the reason the record exists. So he gets his own clauses on this page, and they are not buried.

What the app collects.

All of it, in one table. If something is not on this list, it is not collected — that is not a figure of speech, it is the point of putting the list in one place.

WhatWhy it exists
His name and how to reach himSo a record has an author. Added by his employer when the account is set up.
What he writes or says into the appThis is the record. Kept verbatim, in the language he wrote it in, with the time.
The audio of a voice messageSo a disputed line can be checked against what he actually said. Kept with the message, deleted with the message.
Photos he takes or sendsFiled under a job with a date and his name.
Documents your company uploadsDrawings, cut sheets, submittals, dispatch. The original file, byte for byte, plus the text pulled out of it.
The rows the system writes from all of the aboveHours, safety plans, answers, reports. Each one carries the sentence it came from.
Which device he signed in on, and when it was last usedSo a lost phone can be signed out from another one.
Whether an email we sent arrived or bouncedA delivery result from the mail service. Not whether he opened it, because that is not measured.
Billing contact and payment status for the companyHandled by the payment processor. Card numbers never reach us and are never stored by us.

Location data inside a photo file is stripped before the photo is stored. The photo lands on the right job because a man said which job, or because the schedule says so — never because a camera said where he was standing.

What is never collected.

  • No location. Ever. No GPS trail, no geofence, no clock-in radius, no map of anybody, no last-known position. There is no location column in this system, so there is nothing to hand over, leak, or subpoena.
  • No number about a man. No score, no rating, no ranking, no utilization, no hours-versus-units. Nothing in the export either, because there is nothing to export.
  • No background listening. No calls recorded, no site walks transcribed, no microphone open. Every word in the record is something a person chose to write or say into the app.
  • No face recognition, and no biometric of any kind reaches us. The app unlocks with the phone's own face or fingerprint check. That check happens on the phone. We never receive the face or the fingerprint, and there is nothing about either of them in this system. Washington regulates commercial enrollment of biometric identifiers at chapter 19.375 RCW; we are outside it because we never enroll one.
  • No app-activity surveillance. Nothing counts how many times he opened it, how fast he replied, how long he read, or what hour he stopped.
  • No contacts, no photo library, no calendar. The app asks for the camera when you take a picture and the microphone when you talk. That is the whole list of permissions.

The long version, with what each absence actually costs somebody who wanted it →

The four things it's used for.

There is no fifth.

  1. To make the records your crew asked for — the hours, the photos on the right job, the safety documents, the reports.
  2. To answer questions off the documents uploaded to your own jobs, and to say so when it has not read the document the question is about.
  3. To keep the thing running and fix it when it breaks — which sometimes means an owner opens a record, under the rule in What is never done with it below.
  4. To bill your company.

Not to build a picture of what a normal week looks like across contractors. Not to improve a model. Not to sell you something else — there is nothing else to sell you.

Torspan makes one product and the only revenue line in this company is the one on the pricing page.

The word you came here to search for.

If you hit ⌘F and typed training, this is the sentence you were looking for.

Nothing your crew writes, says, photographs or uploads is used to train a model. Not ours. Not a vendor's. Not in aggregate. Not stripped of names. Not "to improve the Services."

That last phrase is the one to watch for in somebody else's agreement, because that is the phrase that carries it. The ordinary shape of this clause in field software grants the vendor a worldwide, royalty-free license to use your data to develop new products and to train the vendor's own models, and then narrows it with aggregated and de-identified — a qualifier that makes the sentence acceptable to read and impossible for you to check. We do not have that clause because we do not have that use.

If it ever changes: it changes on this page first, with a date on it, and it is a thing your company agrees to in writing, not a thing your company is notified of. An existing customer is never opted in by an update. That is Rule Two from the top of the page, applied to the single clause where it matters most.

Three ways to check this instead of believing it
  1. This paragraph is the contract, not a marketing page. There is no second document where a broader license lives.
  2. Whose computers it passes through lists every outside company that touches anything, and what each one touches.
  3. Ask, in writing, and get a written answer at [email protected].

What is never done with it.

Four things, each one short, because a paragraph of reassurance wrapped around a promise is how you can tell the promise is doing work it cannot do.

It is never sold.

Not raw, not aggregated, not de-identified, not as "market insights," not as a dataset described some other way in a document you did not read.

It is never used to train a model.

The clause is one section up, and it is the one to read twice.

It is never shown outside your company.

Except to the services in Whose computers it passes through, each doing only the job named beside it. Not to a partner, not to an insurer, not to a case study, not to an investor's diligence folder, not to another contractor who asked what a normal week looks like.

It is never opened by an owner without a reason, and the reason is written down.

Every vendor can technically read your database and almost none of them will say so, so: two people can. A record is opened only to fix something you reported or to keep the system running. Each time it happens it is logged with the date, the person and the reason — and you can ask for that log and get it. That last clause is what makes the rest of the paragraph mean anything.

Whose computers it passes through.

Nobody runs a product like this alone. The honest version of that sentence is a list, with what each company touches, on the page you are already reading — not in an appendix, and not behind a form that asks for your company name before it will show you.

The jobWhat it touchesWhere
HostingThe database and the appUnited States
File storagePhotos and uploaded documentsUnited States
The model that reads textThe text of a message, and the page of a document it is answering from — for as long as it takes to answerUnited States
Email deliveryNotices, and files you asked to be mailedUnited States
PaymentsYour company's billing contact and card. Card numbers never reach usUnited States

Two things about the model row, because it is the row people mean when they ask this question.

It is not training anything. The words go out to be read and the answer comes back. That is the clause above.

It is not everything. A message goes out when it needs to be understood. Your photo archive does not sit on somebody else's model. Your hour record does not. Each row above is one door, one door wide.

The companies are not named on this page yet, and that is a gap, not a policy. Each row above is a job, not a company. The names go into that table before an outside company's records are in the system, and a table with the names left out is worth less than a table with them in. We are not going to paper over that by writing something vague in the column.

Any addition to this list is posted here BEFORE it is switched on, with the date. Not published after. Not published on a page you have to subscribe to. Here, first, and your company can leave over it without paying for the rest of the term.

That paragraph is a binding sentence, not a note.

How long it's kept.

Two clocks matter and neither of them is ours.

The first is federal: payroll records preserved three years, and the records the wage was computed from — the time cards, the schedules — two years (U.S. Department of Labor, Fact Sheet #21).

The second is this state, and it is longer. On public work the payroll record has to survive three years from the day the awarding agency accepts the job (RCW 39.12.120) — which on a two-year build is five years from the morning the hours were spoken. Safety has its own: records of the weekly walk-around inspection are kept until the job is complete (WAC 296-155-110).

WhatKeptFloor
Hours, and the sentence each one came fromLife of the account3 years after the pay period
Weekly time record, one PDF per manLife of the account3 years
Pre-task plans and the signatures on themLife of the accountUntil the job is complete
Walk-around inspection recordLife of the accountUntil the job is complete
Photos, full sizeLife of the account. Never downsized, never replaced by a thumbnail
Documents you uploadedLife of the account. The original file, byte for byte
Answers, with the sheet and revision each one came fromLife of the account
Every message, verbatim, in the language it was written inLife of the account
A photo somebody deletesGone from the app that second. Out of the backups within 35 days
A closed accountHeld read-only 12 months, then erased. Erased sooner on request, same day

"Life of the account" means as long as you are a customer, plus the twelve months after. Not "as long as necessary for our legitimate business interests." Not "at our discretion." The floor column is the law's number. The kept column is what actually happens, and it is longer.

Nothing here is deleted to save room, and nothing is thinned out with age. A five-year-old photo comes back the size it was shot.

The same table, with the reasons under it →

What you can ask for — and what you don't have to ask for.

Start with the honest part. Washington has no general consumer privacy law. The legislature has not passed one; what exists is narrow — consumer health data at chapter 19.373 RCW and biometric identifiers at chapter 19.375 RCW, and neither one reaches an hour record. California's statute applies to companies over $25 million in revenue, or handling 100,000 residents, or making half their money selling personal information (California Attorney General). Torspan is a two-person company and is none of those things.

So nothing below is a law making us do it. It is a term of the contract, which means you can enforce it against us.

The company

Export everything, any day. A button in the app. Not a support request, not a wind-down step, not a plan tier, not a fee. It works on a paid account, on a cancelled account, and on an account that is thirty days late. What comes out: photos as files with their attribution beside them, documents as the original documents, hours as CSV and XLSX, safety plans and reports as PDFs, the conversation as text. Files that open without us. If that button ever requires a human being at Torspan to press something, that is a defect and it gets fixed.

Ask what we have. Write to [email protected] and get a written answer within ten business days, from one of the two owners, in plain English.

Ask who opened it. The log from What is never done with it — with dates, people and reasons.

The person

This is the clause no law in this state gives him, and he gets it anyway.

A man can get his own copy from his own screen — his hours and the sentence each one came from, his messages, his photos, the safety documents with his signature on them. Without asking his employer. Without asking us. Without a reason.

The whole-company export belongs to the company, because the whole company is the company's. His own words belong to him too, and he does not have to go through anybody to hold a copy of them.

He can correct anything he wrote. Corrections append. Nothing he authored is silently rewritten, and the original stays attached to the correction, because a record that changes quietly is not a record.

He can delete a photo he took, and it is gone from the app that second and out of the backups within thirty-five days.

Settings · My record
My hours142 entries
My messages1,308
My photos96
Documents I signed31
Get my own copy

Goes to the address on your account. Nobody is told you asked.

Invented demo account — Tomas R. on RIVERBEND Building 2. The counts are made up, and so is the crew.

A record a man can't see isn't a record he'll feed. That is not sentiment. It is the reason this product has anything in it.

Deleting an account, and what stays.

Apple requires that an app which lets you make an account also lets you delete it, from inside the app, without calling anybody (App Store Review Guidelines 5.1.1(v)). Good rule. It is in the app: Settings → My account → Delete my account, two taps and a confirmation.

Now the part the rule doesn't cover, which needs an honest answer instead of a tidy one.

Deleting the account removes the person. It does not remove the work record he authored, and it must not. The eight hours he reported on the fourteenth are his employer's payroll record, and they are subject to the clocks in How long it's kept. The signature on a pre-task plan is what makes that document a signed document. If a man could erase those on his way out the door, the record would have a hole in it exactly where somebody later needs it, and the man beside him would be the one arguing about a missing Tuesday.

Access and authorship are two different things, and confusing them is how records get holes in them. He loses the first. The second is not ours to erase and it is not his employer's to erase either — it is what happened.

Settings · My account

Delete my account

Your sign-in and your devices go now. The hours you reported and the documents you signed stay with your company's record, under your name. You can take your own copy first.

Get my copy first Delete my account

Invented demo account. This is the confirmation sheet, not the button. The copy button is first because that is the sequence a person actually wants, and every other app makes him think of it himself.

Deleted
  • Sign-in and access. Immediately.
  • His name and contact details from the directory, and every device session.
  • Anything he chooses to delete before he goes — his photos, and he can delete them one at a time.
Kept
  • Hours he reported, and the sentence each came from — against the clock in How long it's kept.
  • Photos he took, under his name.
  • Safety documents he signed, with the signature intact.
  • Messages that are the source of a record — with his authorship, because an unattributed record is worse than no record.

When the whole company account closes, everything goes. Twelve months read-only, then erased. Sooner on request — same day, for a company that asks.

Nobody at Torspan can tell you your password, because nobody at Torspan has it.

This website.

No cookies. No pixel, no session recorder, no ad network tag, no marketing automation script, no chat widget, no font loaded from somebody else's server, no analytics that follows you anywhere. The server counts requests so we know a page is being read; that count has no person in it and never has.

No cookie banner, because there is nothing to consent to. That is what a banner is for and we do not have the thing it is for.

One email field exists on this site, on What it costs and Contact. The address goes into a list two people can read, it gets a reply from one of them, and it is never sold, never put into a marketing tool, never used to retarget anybody, and never handed to a third party. Ask to be taken off and you are off the same day.

And this one you can check right now, from this page, in ten seconds: open the developer tools, click Network, reload. Count the companies. There are none.

If something leaks.

Washington gives a company thirty days to tell you (RCW 19.255.010(8), which requires notice "in the most expedient time possible, without unreasonable delay, and no more than thirty calendar days after the breach was discovered").

Seventy-two hours from knowing, and we are not waiting for certainty.

The notice goes to every affected account, by email, to every address on it, and it says what was taken, when, how it happened, and what we have done since. Including when the answer is embarrassing. Including when nobody outside would ever have found out. If the first notice is incomplete, a second one follows when we know more, rather than the first one waiting until the story is tidy.

We will also tell you the things a breach notice usually leaves out: whether the messages were included, whether the photos were included, and whether we can tell which accounts were reached and which were not — including when the honest answer is that we cannot tell.

A company that would rather look composed than tell you early is a company you find out about late.

The app's privacy label, published early.

Apple makes every app declare what it collects and puts the answer on its store page (App privacy details). That declaration usually shows up on the day a listing goes live, which is the day a buyer has already decided. Here it is now. The categories below are Apple's own, in Apple's order.

Data used to track you
None. Nothing in this app is linked with data from anybody else's app or site, and nothing goes to a data broker.
Contact info
Name, work email, work phone. Linked to you. Put there by your employer so a record has an author.
Health & fitness
None.
Financial info
None from the crew. Company billing only, and the card never reaches us.
Location
None. Not precise, not coarse, not once.
Sensitive info
None.
Contacts
None. The app never reads a phone's contacts.
User content
Messages, photos, voice messages, uploaded documents. Linked to you. This is the record — it is the product.
Browsing history
None.
Search history
None.
Identifiers
A user ID inside your company's account. No device advertising identifier, ever.
Purchases
None.
Usage data
None. No product-interaction analytics, no advertising data.
Diagnostics
Crash reports, not linked to you.
Surroundings
None.
Body
None.

Face ID and Touch ID are not on that list and here is why. The phone checks the face or the fingerprint and tells the app yes or no. The face never leaves the phone and never reaches us. There is no biometric in this system to lose.

The label above is what will be filed with Apple. If a row on the listing ever differs from a row here, this page is wrong and we want to be told — and What changed will carry the correction with a date on it.

The listing is not live yet. When it is, this table and the listing will say the same thing, and the link goes here.

What changed.

Every version of this page stays readable at its own address. This is the list.

August 22, 2026

Nothing has changed yet. This is the first version. When something changes, the old version stays at its own address and the change is described here in one sentence — including the changes that were in our favor.

Software's one attempt at a terms of service you could read the edit history of was a public policy repository kept by the makers of Basecamp. It was archived on 26 December 2023 and is now read-only (github.com/basecamp/policies). That is the whole field. The bar is on the ground and we are stepping over it with a table.

The other half of the same agreement.

Privacy answers what happens to the record. The terms answer what happens between your company and ours: what it costs and how it ends, who owns the record, how you leave, what happens if Torspan stops, what we promise about it working and what we don't promise, what a signature in an app actually consists of, and what happens if we disagree.

Same voice, same two rules, no fine print underneath either half.

One agreement. Two halves. No third document in lawyer language.

Read the terms →

The same commitments in plain sight, with the reasons under them →

If a sentence here isn't what you need it to be, say so before you buy.

A term on this page is easier to change now than it will ever be again, and this is the page where that is literally true.

[email protected]. One of the two owners reads it.

The same commitments in plain sight, with the reasons under them — Your records.
Everything this product refuses to do, said without a "yet" on the end — What it won't do.