Your data stays within our controlled environment.

We built our own AI server on-premises so sensitive chats, case data and meeting summaries can be processed within our controlled environment, reducing the need to send sensitive information to external AI services and lowering certain data-exposure risks that could put vulnerable or sensitive communities at risk.

Three commitments, checkable.

Audit our data centre

Come inspect our security against your own safeguarding and charity standards before you commit. We invite verification because it is more persuasive than asserting.

No content logging, in writing

A clause in your contract, not a promise on a webpage. Content is processed and discarded. Usage metadata (timestamps, token counts) is retained for billing and support — nothing else.

Three-month guarantee

Try Trellistry for three months. If it isn't working for you, we'll fix it free — or give you a full refund and a clean export of your data. No lock-in.

What we collect, and what we don't.

Processed, not stored

When you use Trellistry Private AI, your content (chats, documents, meeting recordings) is processed on our on-premises server and discarded after processing. We do not store your content, use it for training, or make it available for retrieval unless you explicitly configure document retrieval (RAG) for your own materials.

Metadata we retain

Timestamps, token counts, user identifiers, feature usage — for billing, support and capacity planning. This is operational metadata, not content.

Your operational data in the platform

People records, rosters, event registrations and follow-through records are stored in your Trellistry account, governed by role-based permissions you configure, exportable at any time, and deletable on request. We do not access your operational data except at your explicit request for support purposes.

Analytics on this website

We use privacy-respecting analytics that set no cookies and do not identify individual visitors. No cross-site tracking, no fingerprinting, no third-party identity enrichment.

Why this matters — documented, not speculative.

Our privacy argument rests on citable public reporting. A summary of the evidence:

  1. Mainstream AI providers may retain inputs for up to 30 days under standard abuse-monitoring, even with no-training commitments.
  2. Provider bugs have exposed user data — OpenAI disclosed a March 2023 incident affecting conversation titles and some subscriber payment information.
  3. Regulators (Dutch DPA) treat entering personal data into AI chatbots as a potential data breach in itself.
  4. The AI supply chain is a demonstrated target — the March 2026 LiteLLM compromise affected 2,500+ organisations (potential exposure, not confirmed compromise).
  5. Model memorisation of training data, including PII, is peer-reviewed and demonstrated at scale.

Full evidence with sources: Private AI evidence section →

What we don't claim.

We reduce and control exposure. We do not abolish it. We will not write:

These would be untrue, and for the audiences we serve, dangerous. What we can say precisely: your content is processed within our controlled environment, not sent to external AI services, with metadata only and no content logging — written into your contract.

Want to inspect our setup before you commit?

Book a consultation and we'll arrange a data-centre visit or a detailed technical walkthrough.

Book a free 30-minute consultation

Or call +65 9696 2902