Torspan
AirOrchestra — The record

Leave on a Tuesday. Take everything.

Software is the only thing on that job nobody who uses it owns. The saw is yours. The truck is yours. The prints are yours. The record of what your crew did all year sits on somebody else's computer with a renewal date on it. This page is what's kept, how long it lasts, who can open it, what the assistant is allowed to read, and what happens to all of it if Torspan stops.

What comes out, and what it opens in

There is one button and it is not in a support ticket. It makes a folder of ordinary files — spreadsheets, PDFs, photos, text — and then it is a folder on your computer that has nothing to do with this company.

Nobody has to approve it. It works on the last day of the account the same way it works on the first.

Export everything
RangeAll of it ▾  (Jan 1 2026 – today)
JobsAll jobs
Included
  • Hours, with the sentence each entry came from
  • Photos, full size, with who took them and when
  • Safety plans and every acknowledgement
  • Daily reports
  • Documents you uploaded, as you uploaded them
  • Answers given, with the sheet each one came from
  • Every message, in the language it was written in
  • People, jobs and assignments
Estimated size14.2 GB
Estimated timeabout 20 minutes

Build the export

Nothing here is greyed out on any plan, and nothing here is greyed out on a cancelled account.

The folder that comes back
README.txt

This folder is yours. Nothing in it needs AirOrchestra to open.

  • Spreadsheets open in Excel, Numbers, Sheets or LibreOffice.
  • PDFs open in anything.
  • Photos are ordinary JPEGs. Beside each one is a .json file in plain text that says who took it, when, which job, and what he said about it.
  • CSV files are UTF-8 with a header row. Column order is listed below and it does not change between exports.
  • If a file in here will not open, write [email protected] and it gets fixed.

Invented crew, invented job. The panel and the folder are what the product produces.

Everything you would need to argue about the 14th of August in 2029 is in that folder, and none of it needs this company to read.

Why there's no badge on this page

You have seen the row: four seals in a line, a shield, an acronym, a year.

A certificate of that kind says an auditor watched a company follow its own written procedures for a period of time and did not find them broken. That is worth something. It is not nothing. But read what it actually answers, and then read what you came here to ask.

It does not say who owns the file. It does not say how long the file lasts. It does not say which people inside that company can open your record, or under what rule, or whether anybody writes it down when they do. It does not say whether your crew's words get used to build something else. And it does not say one word about what happens to any of it if the company stops.

What a badge answers

Did they follow their own procedure for a year.

What this page answers

Who owns it. How long it lasts. Who can open it. What the machine may touch. What happens if Torspan stops.

Torspan is two people and holds no certification of any kind. That sentence is on this page instead of off it, because the alternative is letting you find out later, and a company whose whole argument is that the record is honest cannot open with a decoration.

What is here instead is specific, and every line of it is something you can test in an afternoon: press the button and see what comes out; open the terms and search them for the word training; write the address at the bottom and see who answers.

The day an audit is actually done, the date it was done goes here and the scope goes with it. Not the seal — the scope, because the scope is the part that tells you what was looked at.

What's kept, and how long

Two clocks matter and neither of them is ours.

The first is federal. Payroll records have to be preserved three years, and the records the wage was computed from — the time cards, the schedules — two years (U.S. Department of Labor, Fact Sheet #21).

The second is this state, and it is longer. On public work, the payroll record has to survive three years from the day the awarding agency accepts the job (RCW 39.12.120) — which on a two-year build is five years from the morning the hours were spoken.

The payroll record is not made here; that is your accounting system's job. What is made here is the hour record it was keyed from, and that is the thing somebody asks for when the payroll record gets questioned. So it is kept against the longer clock, not the shorter one.

Safety is its own clock: records of the weekly walk-around inspection are kept until the job is complete (WAC 296-155-110). In practice a claim arrives after that, so they are kept past it.

What Kept Floor
Hours, and the sentence each one came from Life of the account 3 years after the pay period
Weekly time record (PDF per man) Life of the account 3 years
Pre-task plans and the signatures on them Life of the account Until the job is complete
Walk-around inspection record Life of the account Until the job is complete
Photos, full size Life of the account
Never downsized, never replaced by a thumbnail
Documents you uploaded Life of the account
The original file, byte for byte. The text pulled out of it is stored beside it, never instead of it
Answers, with the sheet and revision each one came from Life of the account
Every message, verbatim, in the language it was written in Life of the account
A photo somebody deletes Gone from the app that second. Out of the backups within 35 days
A closed account Held read-only 12 months, then erased. Erased sooner on request, same day

"Life of the account" means as long as you are a customer, plus the twelve months after. Not "until we need the disk space," and not "at our discretion." The floor column is the law's number. The kept column is what actually happens, and it is longer.

Nothing here is deleted to save room, and nothing is thinned out with age. A five-year-old photo comes back the size it was shot.

What is never collected

The safest data is the kind that was never taken. Most of what a field product knows about a man is optional, and this one does not take it.

No location. Ever. No GPS trail, no geofence, no clock-in radius, no map of anybody, no last-known position. There is no location column in this system to subpoena, leak, or hand to somebody's lawyer, because nothing writes to one.

No image location either. Location data inside a photo file is stripped before the photo is stored. The photo lands on the right job because a man said which job, or because the schedule says so — never because a camera said where he was standing.

No productivity number about a man. No score, no rating, no utilization, no per-man hours-versus-units, no ranking, no leaderboard. There is no number about a person anywhere in the product, which means there is no number about a person in the export either.

No face recognition. Photos are files with names attached by the person who sent them. Nobody's face is matched to anything.

No background listening. No calls recorded, no site walks transcribed, no microphone open. Every word in the record is something a person chose to write or say into the app.

No app-activity surveillance. Nothing counts how many times he opened it, how fast he replied, how long he read, or what hour he stopped. A quiet day is a quiet day.

No contacts, no photo library, no calendar. The app asks for the camera when you take a picture and for the microphone when you talk. That is the whole list.

No tracking on this website. No pixel, no session recorder, no ad network, no analytics beyond a server count of page requests. You can verify that one right now, from this page, in ten seconds.

A record that is complete about the work and empty about the man is not an accident. It is the reason the crew feeds it.

Who can see what

The word "privacy" hides the actual question, which is: who in my company can open what, and can somebody see something about me that I can't see about him.

Start with the part most vendors leave vague, because leaving it vague is how a crew finds out the hard way:

What you say into the app about the work is a work record. The people running the job can read it. It is not a diary, and it was never sold as one.

What nobody can read — not the foreman, not the owner, not Torspan — is anything about you as a person, because none of it is collected. Where you were. How fast you worked. How you compare to the man beside you. Those are not permissions that happen to be switched off. They are columns that do not exist.

Role His own hours The crew's hours Photos Safety plans Job docs Every message Export everything
Installerhis own
Foremanhis crewhis crew's
PMhis jobshis jobs
Office / adminallall
Ownerallall
Viewer (read-only)if givenif givenif givenif given

Two rules in that grid are worth saying out loud, because they are the ones that get argued about.

A man sees his own hours and nobody else's next to them

His totals screen shows his week and his month. There is no version of it with the crew ranked underneath. The foreman sees his crew's week because he is the one who has to notice that Tuesday is missing — and what he sees is missing, not a filled-in eight.

Viewer exists so a record can be shown to somebody without handing them the keys

An adjuster, a GC's safety man, an attorney, an inspector. Read-only, scoped to what you point it at, and it cannot change a line or take an export. When you are done, you turn it off.

Export sits with the office and the owner and nowhere else, and that is the only deliberate lock on this page. A whole-company export is the whole company; it belongs with the people who signed for it.

What the assistant can touch, and what it cannot

This is the question underneath every other question on this page, and almost nobody answers it in public, so here is the whole thing.

The assistant reads three things and there is not a fourth: the messages people send it, the documents uploaded to your jobs, and the rows in your own company's record. That is the entire world it can see.

It cannot reach a file on anybody's phone or computer. It cannot reach another company's record. It cannot reach the internet from inside a job. It has no email, no browser, no shell, no keys, and it does not remember one conversation into the next unless the record itself says so.

The mechanism, said once, in plain words

Here is the part that matters and it is a design decision, not a policy: the assistant does not write anything.

It reads the message and hands back a plan — file eight hours for these four men on this job, from this sentence. A separate program, which is not a language model and cannot be talked into anything, checks that plan against the message that is actually stored, and then does the writing itself, under the permissions of the person who sent the message.

Three consequences follow from that, and each one closes a door that is otherwise standing open in every product like this:

The assistant can The assistant cannot
Read the message it was sentSay who you are — identity comes from your sign-in, never from anything a model produced
Read documents uploaded to your jobsWrite a row, edit a row, or delete one. It proposes; the checker writes
Read your own company's recordReach another company's record. Every query is scoped before the model is ever called
Quote a message it was givenInvent a quote. Quotation marks are cut from the stored message by the server, character by character. A model cannot supply the words inside them
Answer from a sheet it has readAnswer from a sheet it has not read. It names the sheet and stops
Propose a change of statusApprove hours, sign a safety plan, send a purchase order, or put a unit on hold. A person confirms
Tell you what it wroteClaim something was saved that wasn't. The confirmation comes from the checker, not from the model

The reason to build it that way is not caution. It is that a machine that can only propose cannot be persuaded into anything, by anybody — including by a sentence somebody types into it on purpose to see what happens. The worst outcome available to it is a wrong proposal that a person declines.

And one more, because it is the thing a foreman thinks of first: it never writes in a man's name and never signs as him. When it carries a question from one man to another, it says who asked, in its own voice. There is no message anywhere in this system that looks like it came from you and didn't.

More on what it refuses to answer, and how it says so →

Whose computers it passes through

Nobody runs a product like this alone. The honest version of that sentence is a list, with what each company touches and why, on the page you are already reading — not in an appendix, and not behind a form that asks for your company name before it will show you.

Four kinds of company are involved and there is not a fifth: the one that hosts the database and the app; the one that stores the photos and the documents you upload; the one whose model reads the text of a message, and the page of a document it is answering from, for as long as it takes to answer; and the one that delivers email — notices, and files you asked to be mailed.

Each of the four gets named here — the company, the region, and one clause of what it touches — by September 30, 2026. A table with a placeholder where a company name belongs is worse than this paragraph, because it advertises a disclosure and then does not make one. So it is this paragraph until the names are real, and then it is the table.

It is not training anything

The words go out to be read and the answer comes back. There is no arrangement in which your crew's messages, your drawings or your photos are used to improve anybody's model — not Torspan's, not the provider's, not in aggregate, and not stripped of names. If that ever changes it will change on this page first, with a date on it, and it will be a thing you agree to rather than a thing you are notified of.

It is not everything

A message goes out when it needs to be understood. Your photo archive does not sit on somebody else's model. Your hour record does not. The four above are the whole set of doors, and each one is one row wide.

This list is dated and it changes when it changes. Any addition is posted here before it is switched on, not after.

Signing in, and a phone left on a gang box

Phones get dropped in a mechanical room, left on a gang box, and lost in a parking lot at 4:30. That is the real threat to this record — not a hacker, a Tuesday.

So the app locks behind the phone's own face or fingerprint check every time it is opened, not once a month. Somebody who picks up an unlocked phone still does not get in.

A lost phone costs you a phone.

  • A foreman can cut a man's access from his own screen, in one tap, without calling anybody and without waiting for an office to open. He does not need a password reset, a support ticket, or a person in another state.
  • Every device that is signed in is listed, with the last time it was used, and any of them can be signed out from any other one.
  • Cutting somebody's access takes nothing away from the record. The hours he reported stay. The photos he took stay under his name. The pre-task plan he signed still has his signature on it. Access and authorship are two different things, and confusing them is how records get holes in them.
  • There is no shared login. Not one for the crew, not one for the trailer, not one taped inside a gang box. A record whose author is "the iPad" is not a record.
  • Nobody at Torspan can tell you your password, because nobody at Torspan has it.

If Torspan stops

This is the question a two-person company has to answer in writing, and answering it with "we're not going anywhere" is how you find out a company was going somewhere.

You would be handing two people the file you get sued over. That is not a small thing to ask, and it should not be answered with confidence. It should be answered with a procedure.

  1. 01

    Export is never a favor and never a wind-down step. It is a button in the product on an ordinary day. It is not behind a plan tier, a support request, an account manager, or a paid-up balance. A cancelled account can still export. An account thirty days late can still export. If the button ever requires a human being at Torspan to press something, that is a defect and it gets fixed.

  2. 02

    If Torspan stops, every account is told ninety days before anything changes — by email, to every address on the account, not a banner somebody has to notice.

  3. 03

    Every account gets a full export built for it, whether or not anybody asks. Delivered as a link and, on request, on physical media mailed to the address on file. Nobody has to be paying attention on the right week to keep his own records.

  4. 04

    The record then stays readable for twelve months. Read-only, no new writing, sign-in still works, export still works. Twelve months is chosen because a wage claim or a safety inquiry does not arrive on a schedule that suits a software company's shutdown.

  5. 05

    There is a written instruction, held with the company's records, that says exactly this and names who carries it out if neither owner can. It is not a promise that depends on two people being reachable. Two people being unreachable is precisely the case it exists for.

  6. 06

    Nothing on this page can be quietly walked back. These terms are in the contract, not only on this page, and they can be changed for a new customer but not for an existing one.

None of that makes Torspan permanent. Nothing makes a company permanent. What it does is make your file independent of this company's luck, which is the only version of the promise that is worth anything.

The right way to evaluate a small vendor is not to ask whether it will last. It is to ask what you are holding on the day it doesn't.

What is never done with it

Four things. Each is short on purpose, because a paragraph of reassurance around a promise is how you tell it is doing work it cannot do.

It is never sold

Not to anybody, in any form, at any price. Not raw, not aggregated, not de-identified, not "market insights," not as a dataset described some other way in a document you did not read. There is no revenue line here except the one on the pricing page.

It is never used to train a model

Not Torspan's, not anybody else's. Search the terms for the word training and see what is there. That is a genuine instruction — read them, they are short, and the shortness is the point.

It is never shown outside your company

Except to the services named in the block above, each doing only the job named beside it. Not to a partner, not to an insurer, not to a marketing case study, not to an investor's diligence folder, not to another contractor who asked what a normal week looks like.

It is never opened by a founder without a reason, and the reason is written down

Every vendor can technically read your database. Almost none of them will tell you that, so: two people can. Here is the rule they work under. A record is opened only to fix something you reported or to keep the system running. Each time it happens it is logged with the date, the person and the reason, and you can ask for that log and get it. That last clause is what makes the rest of the paragraph mean anything.

If any of the four is ever broken, the honest response is not an apology email. It is telling every affected account what was taken, when, and by whom, within 72 hours of knowing — including when the answer is embarrassing, and including when nobody outside would ever have found out.

Written in legal language, once, for the people who need it that way → Terms · Privacy
If those pages ever contradict this one, this one is the bug report.

The part you can check right now

Everything above is a promise about something you cannot see from here. Here is one you can.

Open the developer tools in this browser, click Network, and reload this page. Count the companies.

There are none. This website loads no tracking pixel, no session recorder, no ad network tag, no marketing automation script, no chat widget, no font from somebody else's server, and no analytics that follows you anywhere. Nothing on this page has been loaded from a company you did not come here to read about.

It is a small thing and it takes ten seconds, and that is exactly why it is worth doing: a company that will not run a tracking script on its own marketing site is telling you something checkable about how it treats a record it cannot see you check.

Also: no cookie banner, because there is nothing to consent to. No email is asked for anywhere on this site except one field on two pages, and that one gets a reply from a person.

See it work.

If something on this page is not what you need it to be, say so before you buy, not after — it is easier to change a policy early than late.

One price for the whole crew, and the reason it is flat is on this page too.
Write with a question about any line above. A founder answers it, usually the same day.