Trace Flow

Legal · Privacy

Privacy Policy

Effective September 6, 2026

01Who We Are

Trace Flow is operated by Zaks.io LLC, a California limited liability company. For privacy inquiries, contact privacy@zaks.io.

02What Data We Collect

When you use the Service, we collect:

Request and response content
When recording is enabled, Trace Flow stores the prompt text, system instructions, tool calls, and model completions from LLM API calls routed through the proxy. You can opt out of body storage for a request by setting the X-Trace-Flow-Omit-Body: true header. Usage metadata is still recorded, but the request and response bodies are omitted.
Usage metadata
Model name, token counts (input/output), latency, estimated cost, provider name, and timestamps.
Coding-agent analytics
If you enable collector syncing, the local collector reads supported coding-agent stores and uploads typed facts such as source, model, token usage, tool outcomes, repository fingerprints, and redacted excerpts. The normal analytics path does not upload raw transcripts.
Account data
Email address, name, account identifiers, organization membership, subscription state, and authentication metadata managed through Auth0.
API keys in transit
Your LLM provider credentials pass through the gateway to authenticate with the upstream provider. Trace Flow does not write those header values to its application database, analytics tables, or stored request and response bodies.
Website telemetry
The website sends performance traces, errors, and sampled session replays to Sentry. Replay configuration masks text and form inputs and blocks media. Feature flags are configured in Splitch and evaluated within our Convex backend. Account identity and subscription attributes used for these decisions stay in Convex.

03How We Use Your Data

  • Display request analytics and cost breakdowns in dashboards
  • Generate usage reports and trend analysis
  • Provide trace-level debugging for individual LLM calls
  • Provide coding-agent cost, context, tool, repository, and review analytics
  • Authenticate your identity and secure your account

We do not use your data for advertising, model training, profiling, or any purpose beyond operating the Service.

04Data Storage and Security

Your data is stored across the following infrastructure providers:

Cloudflare R2
Request and response body storage
Tinybird (ClickHouse)
Usage analytics and metrics
Convex Cloud
Application backend and metadata
Auth0
Authentication
Sentry
Performance monitoring, error tracking, and masked session replay

All data is scoped to your organization. One organization cannot access another's data. We use HTTPS for all data in transit, and request and response bodies stored in R2 are encrypted at rest with per-organization AES-256-GCM keys. See our Security page for details on encryption, PII redaction, and tenant isolation.

05Data Sharing

We do not sell or rent personal data. We disclose data to the infrastructure and service providers listed here only as needed to operate Trace Flow.

06Data Retention

Model trace access is limited to 7 days on Hobby and 30 days on Pro. Aggregate model usage tables have longer operational retention: hourly rows for 90 days, daily rows for 2 years, and monthly rows for 5 years. Coding-agent facts and aggregates expire after 1 year. An access limit does not guarantee that an underlying encrypted body object has already been physically removed.

Account and control-plane data is retained while an account is active and as needed to operate the Service. You may request access or deletion by contacting us. Requests are handled according to applicable law and may require identity verification.

07Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your data
  • Export your data in a portable format
  • Object to or restrict processing of your data

California residents have additional rights under the CCPA. European residents have additional rights under the GDPR. To exercise any of these rights, contact privacy@zaks.io.

08Cookies and Tracking

The Service uses session cookies for authentication through Auth0. We do not use advertising trackers or sell behavioral data. Sentry collects performance telemetry and sampled, masked session replays. Feature flag decisions are evaluated within our Convex backend using configuration synced from Splitch.

09Sensitive Data

LLM prompts, responses, and coding-agent excerpts may contain personally identifiable information, proprietary code, trade secrets, or other sensitive content. You are responsible for the data you route through the gateway or choose to sync. Trace Flow processes this content to redact persisted copies, extract observability metadata, and provide the Service. We do not use customer content for advertising or model training.

10Third-Party Services

  • Auth0 (Okta)—Authentication.Policy
  • Convex—Database and backend.Policy
  • Cloudflare—Edge network and storage.Policy
  • Tinybird—Analytics.Policy
  • Sentry—Performance monitoring, error tracking, and masked session replay.Policy

11Changes to This Policy

We may update this policy at any time. Material changes will be noted by updating the effective date above. Continued use of the Service after changes constitutes acceptance.

12Contact

For privacy-related questions or data requests, contact privacy@zaks.io.