1. What this policy covers
This Privacy Policy describes how trAIce ("trAIce", "we") collects, uses, and shares information when you use the hosted dashboard and APIs backing the open-source @traice/sdk package.
2. Information we collect
From you, when you sign in:
- GitHub profile (name, email, avatar): via OAuth, the minimum needed to authenticate
- Workspace and API-key metadata you create
From your application, when you stream events:
- Event payloads you choose to send: provider, model, feature, user ID, tenant ID, agent IDs, token counts, cost, latency, status, custom metadata
- If you enable the optional eval-sampling feature: prompt and output text for a sampled fraction of events. Captured samples are deleted after 14 days.
When you use paid features:
- Billing contact email, selected plan, seat quantities, and promo code
- Paddle customer, subscription, transaction, and invoice identifiers and payment status
- Limited payment-method details supplied by Paddle, such as card brand and last four digits
Paddle collects and processes full payment credentials directly. trAIce does not receive or store complete card numbers or security codes.
We do not collect raw LLM prompt/output text unless you explicitly opt in.
When you visit the hosted site:
- Operational logs, error diagnostics, performance traces, and authenticated product-usage milestones. Product events use internal user and workspace IDs and exclude names, emails, prompts, outputs, API keys, and URL query values.
- Microsoft Clarity page-view, interaction, browser, device, and session-replay data. Clarity uses limited no-consent tracking without cookies unless you allow analytics storage. Advertising storage remains disabled.
- Google Analytics page-view and interaction data. GA loads with Google Consent Mode defaulting analytics storage to denied, and sets analytics cookies only after you allow them. Advertising storage, user data, and personalization remain disabled.
3. How we use it
- To operate the dashboard, alerts, and analytics you signed up for
- To meter usage against your plan's monthly event quota
- To fix bugs, prevent abuse, and understand authenticated product adoption
- To understand and improve the hosted site through Microsoft Clarity and Google Analytics usage analytics
- To communicate about your account (welcome, alerts, billing receipts)
- To administer subscriptions, reconcile payments, and prevent payment abuse
We do not sell your data, train models on it, or share it for advertising.
4. Legal bases
Where data-protection law requires a legal basis, we process information to perform our contract with you, to comply with legal obligations, with your consent for optional features, and for legitimate interests such as securing, supporting, and improving the service. You may withdraw consent for optional processing at any time without affecting earlier lawful processing.
5. Service providers and disclosures
We rely on these services to operate trAIce:
- Google Cloud: application hosting, database, storage, secrets, scheduled jobs, and infrastructure
- Sentry: error, performance, and authenticated product-usage monitoring
- Microsoft Clarity: hosted-site usage analytics and session replay
- Google Analytics (Google): hosted-site usage analytics
- Brevo: transactional email
- GitHub and Google: identity providers when you choose those sign-in methods
- Paddle: merchant of record, subscription billing, tax, fraud prevention, receipts, and payment support
- AI model providers selected for replay or evaluation features, only when you enable and use those features
We may also disclose information when required by law, to protect users or the service, or as part of a business transaction subject to appropriate confidentiality and notice where required.
6. Retention
Raw event records are retained for the retention window of your plan (7 days on Free, 14 days on Starter, 30 days on Pro, and 90 days on Team). A daily retention job removes raw events older than that window, while aggregated usage rollups are kept so historical dashboards remain intact. Sampled prompts/outputs (if you opted in) have a 14-day expiration and are removed by the sample-retention job. Account and workspace records are removed according to the account deletion behavior described below, subject to backups and records we must keep for security, abuse prevention, or legal reasons.
Subscription, transaction, and invoice records may be retained for the period required for accounting, tax, fraud prevention, dispute resolution, and other legal obligations. Paddle maintains payment records under its own privacy notice and legal obligations.
7. Your choices and privacy rights
You can export the currently supported account dataset via Settings → Account → Export: your user record, workspace and membership records, API-key metadata (not raw keys or key hashes), budgets, customer revenue rows, and event records. The export does not currently include sessions, OAuth account records, sampled prompt/output records, experiments, or admin audit logs. Workspace owners can schedule a workspace for deletion in Settings. The workspace becomes read-only during a 7-day recovery period, credentials are revoked immediately, and an owner can cancel before the scheduled date. Owners can instead choose immediate permanent deletion after reviewing a data summary; empty workspaces default to this option. Personal-account deletion is a separate, immediate action: it removes solo workspaces you own and removes your membership from shared workspaces; if you are the sole owner of a shared workspace, you must transfer ownership first. For other requests (correction, restriction, portability), contact us.
You can allow or reject Microsoft Clarity and Google Analytics analytics cookies below or in Settings → Privacy. Rejecting a previous grant tells them to stop setting analytics cookies and return to limited no-consent mode.
8. Security
API keys are stored as SHA-256 hashes: the raw key is never persisted. Production data is stored in Google Cloud and protected in transit with TLS and at rest using managed encryption. We use access controls and least-privilege service identities. No security measure is perfect, and we cannot guarantee absolute security.
9. International transfers
Data is processed in the regions where our subprocessors operate (primarily the United States and the EU, depending on the provider).
10. Children
trAIce is a business service and is not directed to children. We do not knowingly collect personal information from children under 16.
11. Changes
We'll post material updates here and update the effective date. Continued use after changes constitutes acceptance.
12. Contact
Privacy questions: privacy@runtraice.com