This Privacy Policy explains how Traceformer, Inc. ("Traceformer," "we," "us," and "our") collects, uses, and discloses information in connection with the Traceformer.io website, platform, and related services (the "Service").
This Privacy Policy is intended for free users and self-serve paid users. Enterprise customers typically use the Service under a separate agreement and (if applicable) a data processing agreement ("DPA"), which may include additional privacy and security terms.
1. Key definitions
"Customer Content" means any files, data, text, images, netlists, schematics, datasheets, design files, chat inputs, or other materials uploaded or submitted by you.
"Outputs" means analyses, checks, summaries, recommendations, or responses generated by the Service based on Customer Content.
"Derived Data" means technical artifacts generated solely to operate the Service, such as parsed text, indexes, embeddings, summaries, or extracted metadata.
"Content" refers collectively to Customer Content, Outputs, and Derived Data.
"Personal Data" (or "personal information") means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with an individual, as defined under applicable law.
2. Roles: controller vs. processor (business customers)
Traceformer is the controller for Personal Data associated with operating the Service for users and prospective customers (for example account data, billing metadata, and website analytics).
If you upload Personal Data within Customer Content on behalf of a business, you may be the controller of that Personal Data and Traceformer may process it as a service provider/processor. Where required, we will make a DPA available upon request.
3. Information we collect
We collect only the information reasonably necessary to operate the Service.
3.1 Account information
- Name, email address, and organization (optional)
- Authentication identifiers (for example password hashes, session tokens, and account IDs)
- Subscription and plan metadata
3.2 Billing information
- Payments are processed by Stripe, a PCI-compliant third-party processor.
- Traceformer receives billing status and subscription metadata (for example plan name, renewal date, and payment status).
- We do not store payment card details.
3.3 Customer Content
- Engineering files (for example netlists, schematics, datasheets, and images)
- Chat inputs and related context
- Design rules and configuration preferences
3.4 Usage and operational data
Usage and performance telemetry (for example request timestamps, feature usage, response times, error rates, and billing/usage measurements). This data is generally operational in nature and is designed not to include the substance of your Customer Content, except as described in Section 6.3 (Support diagnostics).
3.5 Cookies and analytics preferences
- We use cookies and similar technologies needed for core site operations and security.
- We store an analytics preference cookie that records whether analytics tracking is granted or denied.
- When analytics is granted, we may collect site and product usage and performance telemetry through providers such as Vercel Analytics and Speed Insights.
3.6 Contact and enterprise inquiry data
- Contact and profile details submitted through contact or enterprise inquiry forms (for example name, email, business type, and capacity needs)
- Interest signals (for example request for a demo, free review evaluation, or higher-limit self-serve access)
- Inquiry notes and follow-up communications related to your request
4. How we use information
We use Personal Data and Content to:
- Provide, operate, and maintain the Service
- Perform AI-assisted engineering analysis
- Enforce usage limits and prevent abuse
- Diagnose errors and improve reliability
- Respond to support requests
- Investigate support requests and Issue Reports and, where you explicitly opt in, use those submissions and the related context to evaluate, test, debug, monitor, develop, and improve the Service
- Send service-related communications, including onboarding, feedback requests, product updates, and security notices
- Review and respond to contact or enterprise inquiries, including demo requests and plan-fit conversations
- Comply with legal obligations and enforce our Terms
5. AI model training and service improvement
5.1 No training on Customer Content for foundation models
Traceformer treats all Customer Content as confidential and does not use it to train, fine-tune, or improve any general-purpose or foundation AI models. Your content remains isolated to your account and is not shared across customers or included in public datasets.
5.2 Aggregated and de-identified service improvement
To improve and operate the Service, we rely primarily on aggregated or otherwise de-identified usage metrics (for example error rates and feature usage) that are not reasonably capable of being traced back to you.
6. How we share information
We do not sell Personal Data.
We may disclose information in the following circumstances:
6.1 Subprocessors and service providers
We use subprocessors and service providers to host and operate the Service (for example hosting, storage, authentication, billing, observability, and database providers). We may share Personal Data and Content with these providers only as necessary to provide the Service.
6.2 AI model providers
To generate Outputs, relevant portions of Customer Content are transmitted to AI model providers acting as subprocessors. Providers may include services such as OpenAI, Anthropic, Google, or similar AI platforms.
These providers process Content to generate responses. Their data handling, retention, and caching practices are governed by their respective terms and our configuration.
6.3 Support and troubleshooting diagnostics
When needed for reliability, security, abuse prevention, or support troubleshooting, we may process account-linked technical diagnostics (for example request IDs, timestamps, stack traces, provider error payloads, and limited excerpts of inputs or outputs associated with a failing request).
If you submit a support request, submit an Issue Report, or otherwise ask us to investigate an issue with the Service, we may access and review the Customer Content, Outputs, and related Derived Data reasonably necessary to investigate, reproduce, resolve, remediate, and prevent recurrence of that issue. This may include the affected project, review results, uploaded files or excerpts, citations, configuration context, and associated diagnostics.
If, through the applicable in-product support or feedback flow, you explicitly opt in to broader improvement use, we may also use the submitted materials and the reasonably necessary related project/review context to evaluate, test, debug, monitor, support, secure, operate, develop, and improve the Service and related features, systems, and workflows, including for the benefit of other users. This may include quality evaluation, failure analysis, prompt and retrieval improvements, ranking or classification improvements, validation logic, reliability engineering, abuse prevention, and other product-quality, safety, and operational improvements.
We limit this access and use to authorized personnel and permitted service-related purposes. We do not use this content to train, fine-tune, or improve any general-purpose or foundation AI model unless you separately and expressly opt in to that use.
Outside of those circumstances, we do not access or review the substance of your Customer Content except: (a) at your request, (b) to investigate security issues or incidents, (c) if legally compelled, or (d) with your explicit consent.
6.4 Legal and safety
We may disclose information to comply with applicable law, lawful requests, and legal process; to protect the rights, property, and safety of Traceformer, our users, and others; and to enforce our agreements and policies.
6.5 Business transfers
If Traceformer is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, information may be transferred as part of that transaction, subject to standard confidentiality protections.
7. Cookies and analytics controls
You can control analytics cookies through the in-product or site controls (where available) and through your browser settings. If you deny analytics cookies, we will not run optional analytics tracking, but essential cookies may still be required for core functionality and security.
8. Data retention and deletion
8.1 User-controlled deletion
You may delete uploaded files, chats, and review history from within the Service (where available) and you may request closure of your account.
8.2 Retention periods
Active accounts. We retain Customer Content and Outputs for as long as your account remains active, unless you delete them earlier.
Account closure. When you close your account (or we close it at your request), we will delete Customer Content and Outputs associated with your account within 30 days, except where retention is required by law or for legitimate business purposes described below.
Backups. Residual metadata or encrypted backups may persist for a limited period (generally up to 90 days) for security, integrity, and disaster-recovery purposes.
Operational artifacts. We may retain limited technical artifacts (for example hashed identifiers, aggregated statistics, and anonymized error metadata) for security, abuse prevention, system integrity, and service improvement. These artifacts are not intended to and are not reasonably capable of reconstructing your original designs.
Support and improvement records. If you submit a support request or an Issue Report, we may retain the support record, related investigation notes, and the limited associated project/review context needed to document, resolve, and prevent recurrence of the issue. If you explicitly opt in to broader improvement use, we may also retain the submitted materials and related analyses for the service-improvement purposes described in this Policy, subject to the same confidentiality and deletion framework described in this Policy.
Billing and accounting. We retain billing records and aggregated usage statistics as required by law and for legitimate business purposes (for example taxes, accounting, and audit).
9. Security
We use commercially reasonable administrative, technical, and organizational safeguards designed to protect information, including encryption in transit (TLS) and at rest, per-user access isolation, secure credential management, and monitoring. No system is perfectly secure.
10. International data transfers
By default, the Service is hosted in the United States. If you access the Service from outside the United States, information may be transferred to, stored in, and processed in the United States and other countries where we or our subprocessors operate. Where required, we will use appropriate safeguards for international transfers (for example contractual protections in a DPA).
11. Your rights and choices
11.1 GDPR/UK GDPR
Depending on your jurisdiction, you may have rights to access, correct, delete, restrict, object to processing, and port your Personal Data. You may also have the right to withdraw consent where processing is based on consent.
11.2 California (CCPA/CPRA)
If you are a California resident, you may have rights to know, access, delete, correct, and opt out of the "sale" or "sharing" of Personal Data, and to limit the use of "sensitive personal information," as those terms are defined under California law. Traceformer does not sell Personal Data. We do not share Personal Data for cross-context behavioral advertising.
11.3 How to exercise rights
Privacy requests (data access, deletion, correction): dev@traceformer.io
For faster handling, use subject line: "Privacy Request (Access/Deletion/Correction)".
We will respond to verified privacy requests within applicable legal timelines (typically within 30 days for GDPR requests).
12. Children
The Service is not directed to children, and we do not knowingly collect Personal Data from children under 13 (or under the age threshold applicable in your jurisdiction).
13. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will provide reasonable notice by email or by posting a notice on the Service before the changes take effect. The updated policy will be effective as of the "Last updated" date unless otherwise stated.
14. Contact
Questions about this Privacy Policy: dev@traceformer.io