AirOrchestra · a Torspan product
AirOrchestra — The recordLeave on a Tuesday. Take everything.
Software is the only thing on that job nobody who uses it owns. The saw is yours. The truck is yours. The prints are yours. The record of what your crew did all year should be too. This page is where it is kept, how long it lasts, who can open it, what the assistant is allowed to read, and what happens to all of it if Torspan stops.
09 The records are yours and they leave with you. Any day, whole, in files that open without us.
What comes out, and what it opens in
Ask for it and it is built for you — not a support tier, not a favor. It comes as a folder of ordinary files — PDFs, photos, text — and then it is a folder of yours that has nothing to do with this company.
It works on the last day of the account the same way it works on the first.
- Photos, full size, with who took them and when
- Safety plans and every acknowledgment
- Daily reports
- Documents you uploaded, as you uploaded them
- Answers given, with the sheet each one came from
- Every message, in the language it was written in
- People, jobs and assignments
Nothing in it is held back on any plan, and nothing is held back on a canceled account.
Riverbend-Mechanical_export_2026-08-22/ ├── README.txt ├── photos/ │ ├── Riverbend-Bldg-2/2026-08-14/ │ │ ├── IMG_0442.jpg │ │ └── IMG_0442.json ← who, when, which job, his words │ └── ... ├── safety/ │ ├── pre-task-plans/ (PDF, one per plan) │ └── acknowledgments.csv ├── reports/ (PDF, one per job per day) ├── documents/ ← the original files, unchanged ├── answers/ │ └── answers.csv ← question, answer, sheet, revision, date ├── messages/ │ └── messages.csv ← verbatim, original language └── people-and-jobs/
This folder is yours. Nothing in it needs AirOrchestra to open.
- CSV files open in Excel, Numbers, Sheets or LibreOffice.
- PDFs open in anything.
- Photos are ordinary JPEGs. Beside each one is a .json file in plain text that says who took it, when, which job, and what he said about it.
- CSV files are UTF-8 with a header row.
- If a file in here will not open, write admin@torspan.com and it gets fixed.
Invented crew, invented job, invented building. Real records belong to the companies that made them, and those don't go on a website.
Everything you would need to argue about the 14th of August in 2029 is in that folder, and none of it needs this company to read.
What a certificate answers, and what this page answers
You have seen the row: four seals in a line, a shield, an acronym, a year.
A certificate of that kind says an auditor watched a company follow its own written procedures for a period of time and did not find them broken. That is worth something. It is not nothing. But read what it actually answers, and then read what you came here to ask.
It does not say who owns the file. It does not say how long the file lasts. It does not say which people inside that company can open your record, or under what rule, or whether anybody writes it down when they do. It does not say whether your crew's words get used to build something else. And it does not say one word about what happens to any of it if the company stops.
Did they follow their own procedure for a year.
Who owns it. How long it lasts. Who can open it. What the machine may touch. What happens if Torspan stops.
What is here instead is specific, and every line of it is something you can test in an afternoon: ask for the export and see what comes out; open the terms and search them for the word training; write the address at the bottom and see who answers.
A seal does not tell you what was looked at. A scope does, and a date on the scope does.
What's kept, and how long
Two clocks matter and neither of them is ours.
The first is federal. Payroll records have to be preserved three years, and the records the wage was computed from — the time cards, the schedules — two years (U.S. Department of Labor, Fact Sheet #21).
State law adds its own clock, and it is longer. Washington, for example: on public work, the payroll record has to survive three years from the day the awarding agency accepts the job (RCW 39.12.120) — which on a two-year build is five years from the morning the work was described.
The payroll record is not made here; that is your accounting system's job. What is made here is the daily record of who was on the job and what was done, and that is the thing somebody asks for when the payroll record gets questioned. So it is kept against the longer clock, not the shorter one.
| What | Kept | Floor |
|---|---|---|
| The daily report, and the messages it was written from | Until you delete it | 3 years after the pay period, the payroll clock |
| Pre-task plans and the acknowledgments on them | Until you delete it | No period set by rule |
| Photos, full size | Until you delete it Never downsized, never replaced by a thumbnail |
— |
| Documents you uploaded | Until you delete it The original file, byte for byte. The text pulled out of it is stored beside it, never instead of it |
— |
| Answers, with the sheet and revision each one came from | Until you delete it | — |
| Every message, verbatim, in the language it was written in | Until you delete it | — |
| A photo somebody deletes | Gone from the record that second, and out of backup copies within thirty days | — |
| A canceled subscription | Held read-only for twelve months, then erased — and out of backup copies within thirty days after that. Erased sooner on request, by the end of the next business day | — |
"Until you delete it" means for as long as you are a customer, and the twelve months after. Not "until we need the disk space," and not "at our discretion" — there is no our-discretion to write down. The floor column is the law's number, and meeting it is your company's job; what this column says is that nothing here will be the reason you couldn't.
Nothing here is deleted to save room, and nothing is thinned out with age. A five-year-old photo comes back the size it arrived.
What is never collected
The safest data is the kind that was never taken. Most of what a field product knows about a man is optional, and this one does not take it.
No location. Ever. No GPS trail, no geofence, no clock-in radius, no map of anybody, no last-known position. There is no location column in this system to subpoena, leak, or hand to somebody's lawyer, because nothing writes to one.
No image location either. Location data inside a photo file is stripped before the photo is stored. The photo lands on the right job because a man said which job, or because the schedule says so — never because a camera said where he was standing.
No productivity number about a man. No score, no rating, no utilization, no per-man units count, no ranking, no leaderboard. There is no number about a person anywhere in the product, which means there is no number about a person in the export either.
No face recognition. Photos are files with names attached by the person who sent them. Nobody's face is matched to anything.
No background listening. No calls recorded, no site walks transcribed, no microphone open. Every word in the record is something a person chose to write or say into the app.
No app-activity surveillance. Nothing counts how many times he opened it, how fast he replied, how long he read, or what hour he stopped. A quiet day is a quiet day.
No contacts, no photo library, no calendar. The app asks for the camera when you take a picture. It never asks for the microphone — dictation happens in your own phone's keyboard. That is the whole list.
No tracking on this website. No pixel, no session recorder, no ad network, no analytics beyond a server count of page requests. You can verify that one right now, from this page, in ten seconds.
A record that is complete about the work and empty about the man is not an accident. It is what makes the record worth having.
Who can see what
The word "privacy" hides the actual question, which is: who in my company can open what, and can somebody see something about me that I can't see about him.
Start with the part that is usually left vague, because vague is how a crew finds out the hard way:
What you say into the app about the work is a work record. The people running the job can read it. It is not a diary, and it was never sold as one.
What nobody can read — not the foreman, not the owner, not Torspan — is anything about you as a person, because none of it is collected. Where you were. How fast you worked. How you compare to the man beside you. Those are not permissions that happen to be switched off. They are columns that do not exist.
| Role | Photos | Safety plans | Job docs | Every message | Export everything |
|---|---|---|---|---|---|
| Installer | ✓ | ✓ | ✓ | his own | — |
| Foreman | ✓ | ✓ | ✓ | his crew's | — |
| PM | ✓ | ✓ | ✓ | his jobs | — |
| Office / admin | ✓ | ✓ | ✓ | all | ✓ |
| Owner | ✓ | ✓ | ✓ | all | ✓ |
| Viewer (read-only) | if given | if given | if given | — | — |
| A person at Torspan | A plan or a report, and what it was made from, to read it before it counts; a record you reported broken, to fix it. Each opening is written down. Never for any other purpose. | ||||
"Before it counts" means this: the plan is on the crew's phones as soon as it is written. It enters the record — and the daily report goes to the office — after a person at Torspan has read it. The plan's own page in the app says whether it has entered the record yet, and the plan the crew acknowledged is never rewritten: a correction is a second version with a time on it.
One rule in that grid is the one that gets argued about.
Viewer exists so a record can be shown to somebody without handing them the keys
An adjuster, a GC's safety man, an attorney, an inspector. Read-only, scoped to what you point it at, and it cannot change a line or take an export. When you are done, you turn it off.
Export sits with the office and the owner and nowhere else, and that is the only deliberate lock on this page. A whole-company export is the whole company; it belongs with the people who signed for it.
What the assistant can touch, and what it cannot
This is the question underneath every other question on this page, so here is the whole thing.
The assistant reads three things and there is not a fourth: the messages people send it, the documents uploaded to your jobs, and the rows in your own company's record. That is the entire world it can see.
It cannot reach a file on anybody's phone or computer. It cannot reach another company's record. It cannot reach the internet from inside a job. It has no email, no browser, no shell, no keys, and it does not remember one conversation into the next unless the record itself says so.
Here is the part that matters and it is a design decision, not a policy: the assistant does not write anything.
It reads the message and hands back a plan — file this photo under this job, from this sentence. A separate program, which is not a language model and cannot be talked into anything, checks that plan against the message that is actually stored, and then does the writing itself, under the permissions of the person who sent the message.
Three consequences follow from that, and each one closes a door that is otherwise standing open in every product like this:
| The assistant can | The assistant cannot |
|---|---|
| Read the message it was sent | Say who you are — identity comes from your sign-in, never from anything a model produced |
| Read documents uploaded to your jobs | Write a row, edit a row, or delete one. It proposes; the checker writes |
| Read your own company's record | Reach another company's record. The assistant is given your company's record and only yours — on its own encrypted instance — and no query of ours spans two companies |
| Quote a message it was given | Invent a quote. Quotation marks are cut from the stored message by the server, character by character. A model cannot supply the words inside them |
| Answer from a sheet it has read | Answer from a sheet it has not read. It names the sheet and stops |
| Tell you what it wrote | Claim something was saved that wasn't. The confirmation comes from the checker, not from the model |
The reason to build it that way is not caution. It is that a machine that can only propose cannot be persuaded into anything, by anybody — including by a sentence somebody types into it on purpose to see what happens. The worst outcome available to it is a wrong proposal that a person declines.
And one more, because it is the thing a foreman thinks of first: it never writes in a man's name and never signs as him. There is no message anywhere in this system that looks like it came from you and didn't.
Where it runs, and whose computers it passes through
Nobody runs a product like this alone. The honest version of that sentence is a list, with what each company touches and why, on the page you are already reading.
Start with the sentence that decides the rest of this one: your record is kept on Torspan's own service — one encrypted instance that holds your company and nobody else's, in the United States. Your company's record is yours alone: no query of ours spans two companies. There is nothing to install and nothing to buy. Everything you put in is yours to take out, any day, in files that open without us.
Two companies touch a part of it, and there is not a third. The service it runs on — Amazon Web Services, under Torspan's account, in the United States — holds that instance and delivers the notices and the documents you asked to be emailed to you. The model that reads and writes — Anthropic, under Torspan's commercial account — sees the text of a message, the page of a document it is answering from, or a photograph that has to be read, for as long as it takes to answer, and keeps nothing after that unless a law or its own safety review requires it.
One more belongs on the list even though we did not choose it: you, every time you email a closeout packet to a general contractor or upload a report to somebody's portal.
Who at Torspan can open it, and why, is under What is never done with it. It is a short list and every opening is written down.
It is not training anything
The page goes out to be read and the answer comes back. There is no arrangement in which your crew's messages, your drawings or your photos are used to improve anybody's model — not Torspan's, not the provider's, not in aggregate, and not stripped of names. The account is a commercial one, in Torspan's name, under terms that exclude training on what passes through it. Ask in writing and you get the clause that says so. If it ever changes it will change on this page first, with a date on it, and it will be a thing you agree to rather than a thing you are notified of.
It is one company's record
Your company's record is on its own encrypted instance, and no query of ours spans two companies; no screen at Torspan shows a customer's work. It comes out whole on the day you ask.
This list is dated and it changes when it changes. Any addition is posted here before it is switched on, not after.
The record outlives the company
Construction software changes hands. Products are acquired, sunset, renamed, or priced out from under the contractor who standardized on them, and the records go with them.
Torspan's commitments about your record are written down, and they are in the contract.
-
01
Export is never a favor and never a wind-down step. Ask, any day, and it is built for you — paid, canceled, or thirty days late — with no fee, as ordinary files that open without us.
-
02
If Torspan stops, every account is told ninety days before anything changes — by email, to every address on the account, not a banner somebody has to notice.
-
03
Every account gets a full export built for it, whether or not anybody asks. Delivered as a link, and on request on physical media mailed to the address on file — so nobody has to be paying attention on the right week to keep his own records.
-
04
The record stays readable for twelve months after that. Read-only, no new writing, sign-in works, export works. A wage claim or a safety inquiry does not arrive on a schedule that suits a software company's shutdown.
-
05
A written instruction, kept with the company's records, says exactly this and names who carries it out, in what order and with what access. It is dated.
-
06
Nothing on this page can be quietly walked back. These terms are in the contract, not only on this page, and they can be changed for a new customer but not for an existing one.
No company is permanent, and no promise about the future is worth much on its own. What these six do is make your file independent of what happens to us.
The right way to evaluate a software vendor is not to ask whether it will last. It is to ask what you are holding on the day it doesn't.
What is never done with it
Four things.
It is never sold
Not to anybody, in any form, at any price. Not raw, not aggregated, not de-identified, not "market insights," not as a dataset described some other way in a document you did not read. The only money Torspan makes on your account is the subscription on the pricing page.
It is never used to train a model
Not Torspan's, not anybody else's. Search the terms for the word training and see what is there. That is a genuine instruction — read them, they are short, and the shortness is the point.
It is never shown outside your company
Except to the services named in the block above, each doing only the job named beside it. Not to a partner, not to an insurer, not to a marketing case study, not to an investor's diligence folder, not to another contractor who asked what a normal week looks like.
It is never opened without a reason, and the reason is written down
Every vendor can technically read your database. Almost none of them will tell you that, so: Torspan can. A record is opened for three reasons and there is not a fourth: a person at Torspan reads a plan or a report before it counts; something you reported gets fixed; the system gets kept running. Each time it happens it is written down — the date, the person and the reason — and you can ask for that record and get it. Nobody at Torspan writes in anybody's name, and nothing of yours trains anything.
If any of the four is ever broken, the honest response is not an apology email. It is telling every affected account what was taken, when, and by whom, within 72 hours of knowing — including when the answer is embarrassing, and including when nobody outside would ever have found out.
Written in legal language, once, for the people who need it that way → Terms · Privacy
If those pages ever contradict this one, this one is the bug report.
The part you can check right now
Everything above is a promise about something you cannot see from here. Here is one you can.
Open the developer tools in this browser, click Network, and reload this page. Count the companies.
There are none. This website loads no tracking pixel, no session recorder, no ad network tag, no marketing automation script, no chat widget, no font from somebody else's server, and no analytics that follows you anywhere. Nothing on this page has been loaded from a company you did not come here to read about.
It is a small thing and it takes ten seconds, and that is exactly why it is worth doing: a company that will not run a tracking script on its own marketing site is telling you something checkable about how it treats a record it cannot see you check.
Also: no cookie banner, because there is nothing to consent to. No email address is asked for anywhere on this site. There is one to write to, at the bottom of every page.
See it work.
If something on this page is not what you need it to be, say so before you buy.
One price per jobsite, and the reason it is flat is on this page too.
Write with a question about any line above. It is answered in writing by the end of the next business day.
AirOrchestra