Privacy policy

This policy describes how this deployment processes personal data.

Data we collect

Account data: email address and password hash when you register. Usage: session cookies for authentication, optional analytics identifiers if GA4 is configured, and server logs typical of a web application.

Payments

Payments and subscription management are handled by your configured payment processor. Their privacy policy applies to checkout and billing data. We receive subscription status updates via signed webhooks to update your account tier.

AI features

If AI summarization is enabled, prompts you submit are sent to the configured provider’s API under their terms. Remove the API key to turn this off.

Retention and security

We retain account records while your account exists. Use strong SESSION_SECRET in production, HTTPS, and restrict database access. You may request account deletion by contacting the operator of your deployment.

Contact

For privacy requests, contact the organization that runs the Tracerail instance you use. Legal entity details appear wherever they publish them for that deployment.