Data Security & AI
Your clients' confidences are your livelihood. Here is exactly how TRYX handles them.
Last updated August 1, 2026
Your data is never used to train AI models
TRYX uses AI for one job: turning rough notes and voice dictation into clean, professional billing entries and suggesting the right UTBMS code. None of that data trains a model — ours or anyone else's.
- On-device first.On iPhones with Apple Intelligence, note formalization runs entirely on your device using Apple's on-device Foundation Models. The note never leaves the phone.
- Dictation audio never reaches TRYX. When you dictate a note, your device's own speech recognition turns it into text and TRYX receives only the words — exactly as if you had typed them. We never receive, store or transmit the recording, and there is no TRYX server in that path.
Where the recognition itself happens is your platform's decision, not ours: Apple, Google and your browser vendor each choose between handling it on the device and handling it on their own servers, depending on the device, the language and your settings. It is the same path as dictating into Notes or any other app. We will not promise you it is local when that is not ours to guarantee — if the audio must never leave the handset, type the note instead. - API-only processing for everything else. When on-device AI isn't available, TRYX sends only the note text to OpenAI through its business API. Under OpenAI's API policy, data submitted via the API is not used to train OpenAI's models. That is contractually different from consumer ChatGPT.
- No prompt warehousing. TRYX does not store AI prompts or responses anywhere except the time entry you choose to save. We keep no separate corpus of your notes, and we never will.
- Minimal context leaves your device. Anything sent to our servers or to OpenAI contains only the note text, the task-code list, and — when your firm has set one — the list of words it has told TRYX to keep out of billing narratives. Never your client list, your rates, or your firm's history. That avoid-words list is free text your firm writes, so treat it as something that leaves the device: put style preferences in it, not client or matter names.
- Matter suggestion stays on your phone. Suggesting which client matter a note belongs to genuinely needs your client and matter names, so TRYX only does it on-device with Apple Intelligence. If on-device AI isn't available, TRYX simply doesn't suggest a matter — that list is never sent anywhere.
- You review before a client is billed. AI never writes an invoice on its own. When a note names the client outright, or reads out the matter ID, TRYX fills the client and matter in and marks it "Filled from your notes", with one tap to undo; anything less certain is only offered as a suggestion you tap to accept. A suggested billing code is filled in and marked "AI suggested — tap to change", so you can see it came from AI and change it before you save. A note that AI has rewritten is labelled as such in the app, with one tap to restore your original wording. Nothing reaches a bill until you save the entry.
Firm-level isolation, enforced by the database
Every table in TRYX is protected by Postgres Row Level Security. Access policies are enforced inside the database itself — not just in application code — so a user can only ever read or write rows belonging to their own firm. Notes on draft entries are private to the lawyer who wrote them until they are submitted for review.
Encryption everywhere
- All traffic is encrypted in transit with TLS.
- All data is encrypted at rest (AES-256) in our database and storage provider, Supabase.
- Expense receipts live in a private storage bucket. They are served only through short-lived, firm-scoped signed URLs — there are no public links.
- Payments are processed by Stripe. Card numbers never touch TRYX servers.
Privacy controls built for law firms
- Firm admins can hide client names app-wide (show matter IDs only) or require Face ID to reveal them — including on widgets and the watch app.
- The iOS app supports biometric app lock (Face ID / Touch ID).
- Sign-in, sign-up, and password-reset endpoints are rate-limited.
You own your data
Export your entries at any time as CSV or LEDES — the same formats your billing systems already speak. If you delete your account, your firm's authentication records and data are deleted with it. We don't hold your hours hostage.
Questions
Security questions, disclosure reports, or due-diligence requests: info@tryxapp.com. We answer these personally.

