We use cookies

Cookies keep Tryall working, remember preferences, and — only when you consent — help us measure usage and ad performance. choices anytime or review the cookie policy.

Effective: April 25, 2026

Updated: July 18, 2026

Privacy Policy

This Privacy Policy explains how Tryall collects, uses, stores, and shares personal data when you use our website, web application, and related services.

1. Introduction

Welcome to Tryall ("Tryall," "we," "us," or "our"). Tryall is a multi-model AI workspace available at tryall.ai that lets users access, compare, and work with AI models from multiple providers in one product.

This policy applies to our website, product interfaces, authenticated workspace, billing flows, and related support and operational services (together, the "Services"). It explains what personal data we process, why we process it, who receives it, and what rights you may have under applicable law.

2. Who We Are

Tryall is a product operated by Print Sales Ltd, a Bulgarian limited liability company, company registration number (EIK/UIC) 207984059, with a registered address at 26 Elemag Street, Sofia 1113, Bulgaria.

For users in the EEA and the United Kingdom, Print Sales Ltd is the controller of the personal data described in this policy, unless a different role is stated for a specific processing activity.

3. How Tryall Works

Tryall is not a single-model system. When you submit a prompt, compare request, or model-powered action:

  • your request is received by Tryall;
  • the request may be routed through third-party model gateways and processed by one or more third-party AI providers needed to deliver the feature you selected;
  • the provider returns a response through Tryall; and
  • we may receive limited usage and service metadata related to that request.

This means that prompts, messages, and supported attachments may leave our infrastructure and be processed by model gateways and third-party AI providers. Their terms, privacy practices, retention rules, training controls, content policies, and availability constraints may apply and may vary by provider, model, route, and plan. Where privacy-protective controls are available to us, we aim to configure our routing to use them, but we cannot guarantee identical behavior across every provider involved in processing.

We do not control every downstream retention, logging, or training setting used by third-party AI providers, except where those controls are available to us and configured by us.

4. Personal Data We Process

The categories of personal data we process depend on how you use the Services.

4.1 Data you provide directly

  • Account information such as your name, email address, and avatar.
  • Age-gate confirmation data for manual registration, such as whether you meet our minimum age requirement. For this purpose, we do not intentionally store the exact age entered in the sign-up form.
  • Workspace content such as prompts, conversation messages, compare inputs, model selections, saved comparison snapshots, and feedback you choose to submit.
  • Supported attachments such as images, PDFs, documents, and other files that you upload for processing.
  • Feedback signals you choose to submit, such as thumbs up/down feedback, issue categories, and related message identifiers.
  • Billing and checkout information you provide in connection with a subscription or paid plan.
  • Support or contact information you send us directly.

We do not intentionally store full payment card numbers. Payment details are handled by our payment processor.

4.2 Data we collect automatically

  • Usage and operational metadata such as timestamps, request identifiers, model identifiers, token counts, response latency, provider route details, billing or quota metadata, and reviewed feature usage events.
  • AI observability metadata such as trace identifiers, model/function names, route status, timing, token or cost-style metadata, and feedback scores when AI observability is enabled.
  • Technical information such as IP address, browser, operating system, device characteristics, referrer, and session state.
  • Security and anti-abuse data such as rate-limit events, authentication state, and fraud-prevention signals.
  • Diagnostics and error information such as runtime errors, operational telemetry, sanitized request context, and stack traces, which may sometimes include limited route or account context needed to investigate issues.
  • Browser-side preference data such as theme choice, guest session state, and locally stored workspace state.

4.3 Data from third parties

  • Authentication providers may provide identity, session, and account profile data.
  • Payment processors may provide payment status, customer identifiers, checkout results, and subscription events.
  • Model gateways and AI providers may provide limited request metadata, usage records, provider route details, safety signals, and service diagnostics.
  • AI observability providers may provide trace, score, and diagnostic metadata used to debug model behavior and service quality.

Important distinction: we may process prompt and attachment content to provide the service even where we do not persist the full content long-term. Some guest experience data may also be stored locally on your device depending on the feature you use.

5. How We Use Personal Data

We use personal data for purposes such as:

  • creating and operating your account and workspace;
  • authenticating users and maintaining secure sessions;
  • routing requests through model gateways and AI providers, fulfilling AI responses, and displaying compare results;
  • recording AI observability metadata and feedback scores to monitor model quality, reliability, and incidents when the observability feature is enabled;
  • processing payments, managing subscriptions, and enforcing plan limits;
  • monitoring reliability, diagnosing incidents, and improving service quality;
  • detecting fraud, abuse, misuse, and security threats;
  • complying with legal obligations and responding to valid legal requests;
  • communicating with you about service, billing, security, and support matters; and
  • sending product or marketing updates only where permitted by law and, where required, with your consent.

Where applicable, our legal bases include contract performance, legitimate interests, compliance with legal obligations, and consent. For example, we rely on contract performance to provide the Services and manage subscriptions, legitimate interests to secure, debug, and operate the Services, legal obligations for tax and compliance records, and consent where required for optional analytics, marketing, or non-essential cookies.

Tryall does not train its own foundation AI models on your conversation content. Third-party model gateways and AI providers may apply their own retention, logging, training-control, and abuse-prevention settings depending on the provider, model, route, and plan used for a request.

Human review of conversation content is limited to cases where it is necessary for support, safety, security, legal compliance, troubleshooting, or service operation. Service quality review may include investigating bugs, failed requests, abuse reports, safety incidents, and reliability issues.

6. Cookies, Local Storage, and Similar Technologies

We use cookies, local storage, and similar technologies for purposes such as:

  • strictly necessary cookies and session mechanisms for authentication, security, and checkout flows;
  • preference storage for theme, interface state, and guest-session continuity;
  • limited operational telemetry used to keep the app stable and secure; and
  • third-party storage used as part of authentication and billing flows.

Product analytics is optional. PostHog initializes only after analytics consent, uses explicit reviewed events only, and does not use autocapture, heatmaps, pageview capture, pageleave capture, or session replay in the MVP. PostHog identify is minimized and does not include email or name in the MVP.

With your analytics consent, we also use Google Analytics to measure visits, traffic sources, and funnel steps, and your analytics choice is signaled to the Google tag (Google Consent Mode analytics storage). Without that consent, Google receives only cookieless, consent-flagged measurement pings without account identifiers and sets no analytics cookies; withdrawing analytics consent also expires Google Analytics cookies already on your device.

Sentry is treated as operational and security telemetry, not product analytics. We configure Sentry with default PII collection disabled and scrub request-error context so raw cookies, authorization headers, forwarded IP headers, query strings, prompts, generated content, filenames, and secrets are not intentionally sent.

Langfuse, when enabled for AI observability, is treated as model quality and reliability telemetry. By default, Tryall sends metadata such as model/function names, trace identifiers, status, timing, token or cost-style metadata, and feedback scores. We do not send prompt or response text to Langfuse by default. Detector text is not sent to Langfuse by default. Full prompt/response capture requires a separate product and privacy control before it is used for public users.

You can change or withdraw optional cookie choices from . Details are available in our Cookie Policy.

You can manage browser cookies and site data through your browser settings. Blocking strictly necessary cookies or clearing local storage may break sign-in, checkout, and other product features.

With your marketing consent, we use Google Ads conversion measurement cookies to understand whether our ad campaigns lead to sign-ups and purchases. Without that consent, the Google tag operates in cookieless consent mode, sets no advertising cookies, and conversion events carry no account or checkout identifiers. Withdrawing marketing consent also expires the Google advertising cookies already on your device. We do not use session replay or heatmaps, and we do not sell personal data.

7. How We Share Personal Data

7.1 AI routing and model providers

When you use model-powered features, your prompts, messages, and supported attachments may be shared with third-party model gateways and AI providers involved in processing the request.

7.2 AI observability providers

When enabled, AI observability providers may receive model-call metadata, trace identifiers, status, timing, token or cost-style metadata, and feedback scores so we can debug reliability and quality.

7.3 Service providers

We also use service providers in the following categories to help operate the Services:

Authentication and identity: Account login, session management, and identity verification.

Payment processing: Checkout, billing events, subscription processing, and payment administration.

AI routing and model access: Routing AI requests through model gateways and AI providers, returning responses, and providing completion-related metadata.

Hosting and application delivery: Running the application, serving content, and handling request-level infrastructure.

Database and managed storage: Storing account, conversation, subscription, and usage records.

Caching and abuse prevention: Rate limiting, caching, and short-lived operational counters when enabled.

Background processing: Event-driven workflows, asynchronous processing, and operational jobs when enabled.

Security and observability: Error monitoring, diagnostics, sanitized request-error context, AI trace metadata, feedback scores, and operational alerts when enabled.

Advertising measurement: Measuring whether our ad campaigns lead to sign-ups and purchases (Google Ads conversion measurement); advertising cookies are used only with your marketing consent.

We may change providers within these categories over time. Where required by law, contract, or a data processing agreement, we can provide more specific processor or subprocessor details through appropriate legal, privacy, or enterprise documentation. We also maintain a Subprocessors and Service Providers page for current vendor transparency.

7.4 Corporate events and legal disclosures

  • We may disclose or transfer data as part of a merger, acquisition, restructuring, financing, or asset sale.
  • We may disclose data where required by law, court order, regulatory process, or where reasonably necessary to protect rights, safety, security, or the integrity of the Services.

8. Data Retention

We retain personal data for as long as necessary to provide the Services, meet legal and accounting obligations, resolve disputes, enforce agreements, protect the platform, and maintain reasonable backup and recovery procedures.

Retention periods vary depending on the type of data, the feature used, account status, legal requirements, security needs, and provider requirements.

  • Account and subscription records are generally kept while your account remains active and for a reasonable period afterward for compliance, auditing, dispute resolution, and fraud prevention.
  • Signed-in conversation history and saved comparison snapshots are generally kept until you delete them, your account is removed, or we no longer need them for the purposes described in this policy.
  • Usage, security, and operational logs may be kept for service integrity, billing reconciliation, abuse prevention, and incident investigation.
  • AI observability trace mappings and metadata may be kept for debugging, quality review, feedback scoring, incident response, privacy request handling, and provider follow-up.
  • Billing and tax records may be retained for the periods required by applicable financial and tax laws.
  • Guest chat state and certain preferences may remain in your browser until you clear them.
  • Backups and disaster-recovery copies may retain residual data for a limited period after active data is deleted.

In some cases we may retain limited data longer where legally required or where needed to establish, exercise, or defend legal claims.

Operational logs are generally retained for a limited period unless needed for security, abuse prevention, billing reconciliation, incident investigation, or legal reasons.

Model gateways and third-party AI providers may apply their own retention rules to prompts, attachments, outputs, and request metadata that they process. Those practices may vary by provider, model, route, and plan.

Langfuse or another AI observability provider may apply separate retention settings to trace metadata and scores. We do not claim that deletion automatically removes data from every downstream AI provider or observability provider unless the specific provider workflow supports it.

9. Data Security

We use technical and organizational measures designed to protect personal data, including:

  • encryption in transit using TLS/HTTPS;
  • encryption at rest where supported by our infrastructure providers;
  • role-based or least-privilege access controls for production systems;
  • managed authentication and session controls;
  • rate limits and operational safeguards to reduce abuse; and
  • monitoring and incident-response tooling to investigate failures and security events.

No system is perfectly secure. You should use strong credentials, protect access to your email account, and enable additional security features such as multi-factor authentication where available.

10. International Data Transfers

Because Tryall relies on service providers, model gateways, and AI providers that may process data in the United States and other countries, personal data may be transferred internationally.

Where required by applicable law, we rely on appropriate transfer mechanisms such as Standard Contractual Clauses, adequacy decisions, or other lawful safeguards.

11. Your Privacy Rights

Depending on where you live, you may have the right to:

  • access the personal data we hold about you;
  • correct inaccurate or incomplete data;
  • request deletion of personal data, subject to legal exceptions;
  • request restriction of certain processing;
  • object to processing based on legitimate interests or to direct marketing;
  • receive portable copies of certain data where applicable;
  • withdraw consent where processing depends on consent; and
  • lodge a complaint with the data protection authority that applies to you.

To exercise a request, contact privacy@tryall.ai. We may need to verify your identity before acting on a request, and we will respond within the timeframe required by applicable law.

You can withdraw optional cookie and analytics consent through Cookie preferences. Consent withdrawal does not affect processing that happened before withdrawal or processing that relies on a different legal basis.

We do not use solely automated decision-making that produces legal or similarly significant effects about you.

You may also have the right to contact the Bulgarian Commission for Personal Data Protection or your local supervisory authority.

12. Region-Specific Notes

If you are in the EEA or UK, GDPR or UK GDPR may apply to our processing. If you are a California resident, you may have rights under the CCPA / CPRA, including rights to know, delete, correct, and opt out of sale or sharing where those concepts apply. We do not sell personal data. Google Ads conversion measurement may qualify as "sharing" for cross-context behavioral advertising under the CPRA; you can opt out at any time by declining or withdrawing the marketing purpose in Cookie preferences. We also honor the Global Privacy Control (GPC) browser signal as an opt-out: with GPC enabled, "Accept all" does not turn the marketing purpose on, though you can still enable it explicitly in Cookie preferences.

If you are located in another jurisdiction with privacy rights that apply to you, contact us and we will assess your request under the laws that govern the processing.

13. Children's Privacy

The Services are not directed to children under 16, or a higher minimum age where required by local law. If you believe a child has provided us with personal data, contact us at privacy@tryall.ai and we will investigate and take appropriate action.

14. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the "Updated" date above and, where legally required, provide additional notice inside the product, by email, or through another appropriate channel.

15. Contact Us

Mail: Print Sales Ltd, 26 Elemag Street, Sofia 1113, Bulgaria