Legal · Privacy
Privacy Policy
Effective September 6, 2026
01Who We Are
Trace Flow is operated by Zaks.io LLC, a California limited liability company. For privacy inquiries, contact privacy@zaks.io.
02What Data We Collect
When you use the Service, we collect:
- Request and response content
- When recording is enabled, Trace Flow stores the prompt text, system instructions, tool calls, and model completions from LLM API calls routed through the proxy. You can opt out of body storage for a request by setting the
X-Trace-Flow-Omit-Body: trueheader. Usage metadata is still recorded, but the request and response bodies are omitted. - Usage metadata
- Model name, token counts (input/output), latency, estimated cost, provider name, and timestamps.
- Coding-agent analytics
- If you enable collector syncing, the local collector reads supported coding-agent stores and uploads typed facts such as source, model, token usage, tool outcomes, repository fingerprints, and redacted excerpts. The normal analytics path does not upload raw transcripts.
- Account data
- Email address, name, account identifiers, organization membership, subscription state, and authentication metadata managed through Auth0.
- API keys in transit
- Your LLM provider credentials pass through the gateway to authenticate with the upstream provider. Trace Flow does not write those header values to its application database, analytics tables, or stored request and response bodies.
- Website telemetry
- The website sends performance traces, errors, and sampled session replays to Sentry. Replay configuration masks text and form inputs and blocks media. Feature flags are configured in Splitch and evaluated within our Convex backend. Account identity and subscription attributes used for these decisions stay in Convex.
03How We Use Your Data
- Display request analytics and cost breakdowns in dashboards
- Generate usage reports and trend analysis
- Provide trace-level debugging for individual LLM calls
- Provide coding-agent cost, context, tool, repository, and review analytics
- Authenticate your identity and secure your account
We do not use your data for advertising, model training, profiling, or any purpose beyond operating the Service.
04Data Storage and Security
Your data is stored across the following infrastructure providers:
- Cloudflare R2
- Request and response body storage
- Tinybird (ClickHouse)
- Usage analytics and metrics
- Convex Cloud
- Application backend and metadata
- Auth0
- Authentication
- Sentry
- Performance monitoring, error tracking, and masked session replay
All data is scoped to your organization. One organization cannot access another's data. We use HTTPS for all data in transit, and request and response bodies stored in R2 are encrypted at rest with per-organization AES-256-GCM keys. See our Security page for details on encryption, PII redaction, and tenant isolation.
05Data Sharing
We do not sell or rent personal data. We disclose data to the infrastructure and service providers listed here only as needed to operate Trace Flow.
06Data Retention
Model trace access is limited to 7 days on Hobby and 30 days on Pro. Aggregate model usage tables have longer operational retention: hourly rows for 90 days, daily rows for 2 years, and monthly rows for 5 years. Coding-agent facts and aggregates expire after 1 year. An access limit does not guarantee that an underlying encrypted body object has already been physically removed.
Account and control-plane data is retained while an account is active and as needed to operate the Service. You may request access or deletion by contacting us. Requests are handled according to applicable law and may require identity verification.
07Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data
- Export your data in a portable format
- Object to or restrict processing of your data
California residents have additional rights under the CCPA. European residents have additional rights under the GDPR. To exercise any of these rights, contact privacy@zaks.io.
08Cookies and Tracking
The Service uses session cookies for authentication through Auth0. We do not use advertising trackers or sell behavioral data. Sentry collects performance telemetry and sampled, masked session replays. Feature flag decisions are evaluated within our Convex backend using configuration synced from Splitch.
09Sensitive Data
LLM prompts, responses, and coding-agent excerpts may contain personally identifiable information, proprietary code, trade secrets, or other sensitive content. You are responsible for the data you route through the gateway or choose to sync. Trace Flow processes this content to redact persisted copies, extract observability metadata, and provide the Service. We do not use customer content for advertising or model training.
10Third-Party Services
11Changes to This Policy
We may update this policy at any time. Material changes will be noted by updating the effective date above. Continued use of the Service after changes constitutes acceptance.
12Contact
For privacy-related questions or data requests, contact privacy@zaks.io.