Privacy Policy
Last updated August 1, 2026
Who we are
TRYX, Inc. ("TRYX", "we", "us") provides billable-hours tracking software for lawyers and law firms through our web application, mobile apps, and related services (together, the "Service"). This policy describes what personal information we collect, how we use it, and the choices you have. For a plain-English overview of how we secure data and use AI, see our Data Security & AI page.
Information we collect
- Account information — name, email address, role, hourly rate, and firm details you or your firm admin provide.
- Work product you create — time entries, notes, voice transcripts, task codes, client and matter records, expenses, and receipt images.
- Billing information — subscription and payment details, processed by Stripe. We never receive or store full card numbers.
- Technical data — log and device information needed to operate the Service securely, such as IP addresses used for rate limiting and abuse prevention.
How we use information
- To provide the Service: tracking time, syncing across devices, generating exports and invoices.
- To process optional AI features (note formalization and billing-code suggestions) at your request. Dictation is handled by your platform's speech recognition; TRYX never receives the recording.
- To manage subscriptions, seats, and billing.
- To secure the Service: authentication, rate limiting, and abuse prevention.
- To respond to support requests.
We do not sell personal information, we do not use your data for advertising, and we do not use your data to train AI models.
AI processing
AI features are initiated by you (or by settings you enable). Where available, processing happens on your device via Apple Intelligence and your content never leaves the device. What happens when on-device AI is not available depends on the feature. For note formalization and billing-code suggestions, the note text is processed through OpenAI's API, which does not use API data to train its models. Two small extras go with it: for a code suggestion, the list of task codes, and for formalization, the list of words your firm has configured TRYX to keep out of billing narratives, if it has set one. Matter suggestion has no such fallback: it needs your client and matter names, so if on-device AI is unavailable TRYX simply does not suggest a matter, and that list is never sent anywhere. Dictation is handled by your device's own speech recognition and TRYX receives only the resulting text — we never receive, store or transmit the recording. Whether that recognition happens on the device or on your platform vendor's servers is decided by Apple, Google or your browser, not by TRYX, and varies with the device, language and settings. TRYX stores only the result you choose to save to a time entry.
Service providers
We share data only with the providers needed to run the Service:
- Supabase — database, authentication, and file storage.
- Vercel — application hosting.
- Stripe — payment processing.
- OpenAI — optional AI note formalization and billing-code suggestions, using the note text, the task-code list, and your firm's avoid-words list where it has set one (API only, no training).
- Apple / Google — app distribution and on-device services on their platforms.
- Resend— email delivery. When your firm emails an invoice from TRYX, Resend receives the recipient's address and the invoice itself, which includes the entry descriptions your firm chose to bill.
- Cloudflare — bot protection on the sign-up form, when enabled. Its challenge runs in your browser and Cloudflare receives your IP address and basic browser signals in order to tell a person from a script. It sees nothing else, and it is not used anywhere else in TRYX.
- Have I Been Pwned — checks a new password against known breaches. Only the first five characters of a one-way hash are sent, never the password, your email, or anything identifying you.
- Upstash — rate limiting and abuse prevention. It receives only a rate-limit counter and its key (an account identifier or an IP address) — never entry content, notes, or client records.
If your firm connects an integration (for example, Clio), we exchange the data needed to provide that integration with that provider at your firm's direction.
Retention and deletion
We retain your data for as long as your firm's account is active. Because time entries are your firm's billing records, they are treated as firm data: when an individual lawyer leaves a firm, their account is deactivated and their entries, expenses, and receipts are retained for the firm. A team member who has no billing records is deleted entirely. For the same reason, changes to time entries are recorded in an audit log so your firm can demonstrate the integrity of its bills.
To delete a firm account and its data, contact us and we will remove it from our production systems; residual copies age out of encrypted backups within the backup retention window. You can export your firm's entries as CSV at any time before deletion.
Your rights
Depending on where you live, you may have rights to access, correct, export, or delete your personal information. Firm admins can manage most of this directly in the app; for anything else, contact us and we will help.
Changes and contact
If we make material changes to this policy, we will update this page and the date above. Questions: info@tryxapp.com.

