Privacy Policy
Last Updated: August 5, 2026
1. Introduction
TraceMind ("we", "us", or "our") operates the TraceMind desktop application and website (collectively, the "Service"). This Privacy Policy explains how we collect, use, disclose, and protect your information when you use our AI-powered schematic design software.
TraceMind is operated by TraceMind, a company registered in Canada. By using our Service, you agree to the collection and use of information in accordance with this policy.
Contact Information:
Discord: Join our community
2. Information We Collect
2.1 Account Information
When you create an account, we collect:
- Email address
- Password (encrypted and hashed)
- Display name and profile information (if provided)
- Authentication provider data (if using third-party OAuth)
2.2 Schematic Files and Design Data
When you use TraceMind's AI features:
- Design metadata: Component information, connections, and structural data extracted from your schematic files — including KiCad and Altium file formats — for AI processing (complete schematic files remain on your device)
- Design descriptions: Text descriptions and commands you provide to the AI assistant
- Chat history: Conversations with the AI assistant for context and service improvement
- Project metadata: Project names, file names, timestamps, and version information
2.3 Usage and Technical Data
We automatically collect:
- Error reports: Crash reports, error logs, and diagnostic information
- Device information: Operating system, version, hardware specifications
- Usage analytics: Feature usage patterns, session duration, and interaction data
- IP addresses: For security, authentication, and geographical analytics
- Connection data: Connection status, latency, and performance metrics
- AI usage records:For each request processed, the volume of text processed, the AI model used, the computed cost, and a timestamp. These records measure usage against your plan's included allowance and, if you have enabled pay-as-you-go, determine what you are charged. They record the size and cost of a request, not the content of your prompts or designs.
2.4 Payment Information
If you purchase a paid subscription or feature:
- Payment information is processed by our third-party payment processor
- We do not store full credit card numbers
- We retain transaction IDs, billing addresses, and purchase history
- If you enable pay-as-you-go, we store your budget settings (whether it is enabled and the cap you set) and the charges accrued in the current billing period
- We keep a record of your plan's included allowance over time, including when it changed, so that usage is priced against the allowance that applied when the usage occurred
- To generate your invoice, we send our payment processor the quantity of billable usage attributed to your account, along with the timestamp and an internal record identifier. We do not send your prompts, designs, or design metadata to our payment processor.
3. How We Use Your Information
We use your information for the following purposes:
- Service Delivery: To process your schematic files with AI, generate designs, and provide real-time assistance
- Authentication: To verify your identity and manage your account
- Service Improvement: To analyze usage patterns, fix bugs, and enhance features
- Error Detection: To identify, diagnose, and resolve technical issues
- Communication: To send service-related notifications, updates, and responses to inquiries
- Analytics: To understand user behavior and optimize the application
- Legal Compliance: To comply with legal obligations and protect our rights
- Payment Processing: To process transactions and manage subscriptions
4. Third-Party Services
We use trusted third-party service providers to deliver and improve our Service:
- AI Service Providers: We use multiple Large Language Model (LLM) providers for natural language understanding, schematic analysis, and design generation. Your design metadata and chat messages are processed by these providers according to their privacy policies.
- Cloud Infrastructure: Cloud hosting services for metadata storage, database management, real-time messaging, and AI processing infrastructure.
- Authentication Services: Third-party authentication providers for secure user account management, email verification, and OAuth integration.
- Analytics Services: Website analytics for tracking page views, downloads, and user engagement on our marketing website only (desktop application does not use web analytics).
- Error Tracking Services: Crash reporting and error monitoring services that collect diagnostic information, stack traces, and system context when errors occur.
- Payment Processors: Secure payment processing for subscriptions, usage-based billing, and billing management. For pay-as-you-go, we report billable usage quantities to our payment processor so it can invoice you; see Section 2.4. We do not store complete payment card numbers.
- Real-time Messaging: Services for enabling real-time communication between your desktop application and our AI processing servers.
These service providers are located in various jurisdictions including the United States and Canada. They process your data according to their own privacy policies, and we implement contractual safeguards including data processing agreements and standard contractual clauses where required. All data in transit is encrypted using TLS/SSL, and data at rest is encrypted using industry-standard encryption.
5. Data Retention
We retain your personal data only as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law. Specific retention periods include:
- Design metadata: Transient data processed during active sessions is not permanently stored. Historical metadata may be retained for service improvement purposes.
- Chat history: Retained for service improvement and AI model training, or until you request deletion
- Account information: Retained while your account is active and for a reasonable period after account deletion to prevent fraud and re-registration abuse
- Error logs: Retained for a limited period for debugging and service improvement
- Analytics data:Website analytics data is anonymized and retained according to our analytics provider's retention policies
- Payment records: Retained for the period required by applicable tax and accounting laws
- Usage tracking: AI API usage records (token counts, costs, model types) are retained for billing accuracy, fraud prevention, and service optimization. Records underlying pay-as-you-go charges are retained for the period required by applicable tax and accounting laws, so that invoices remain auditable and billing disputes can be resolved.
You may request deletion of your personal data at any time by contacting us. We will respond to your request in accordance with applicable data protection laws.
6. Data Security
We implement industry-standard security measures to protect your data:
- Encryption: TLS/SSL encryption for data in transit; AES-256 encryption for data at rest
- Access Controls: Role-based access control (RBAC) and least-privilege principles
- Authentication: Secure OAuth 2.0 implementation with JWT tokens
- Monitoring: Continuous security monitoring and logging
- Regular Audits: Periodic security assessments and vulnerability scans
However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.
7. Your Rights and Choices
Depending on your location, you may have the following rights:
7.1 General Rights
- Access: Request a copy of the personal data we hold about you
- Correction: Request correction of inaccurate or incomplete data
- Deletion: Request deletion of your personal data (subject to legal retention requirements)
- Data Portability: Request export of your data in a machine-readable format
- Withdrawal of Consent: Withdraw consent for data processing (may limit service functionality)
7.2 GDPR Rights (EU/EEA Users)
If you are located in the European Union or European Economic Area, you have additional rights under the General Data Protection Regulation (GDPR):
- Right to Restriction: Request restriction of processing in certain circumstances
- Right to Object: Object to processing based on legitimate interests
- Right to Lodge a Complaint: File a complaint with your local data protection authority
7.3 Canadian Privacy Rights (PIPEDA)
As a Canadian company, we comply with the Personal Information Protection and Electronic Documents Act (PIPEDA). You have the right to:
- Know what personal information we collect and how it's used
- Access your personal information
- Challenge the accuracy and completeness of your information
- File a complaint with the Office of the Privacy Commissioner of Canada
7.4 United States Privacy Rights
If you are a resident of certain U.S. states with comprehensive privacy laws (such as California, Virginia, Colorado, Connecticut, or Utah), you may have additional rights including:
- California (CCPA/CPRA): Right to know what personal information is collected, right to deletion, right to opt-out of sale (we do not sell personal information), and right to non-discrimination
- Other States: Similar rights to access, correct, delete, and obtain a copy of your personal information
- Right to opt-out of targeted advertising (contact us to exercise this right)
We do not sell your personal information to third parties. We do not process sensitive personal information as defined under applicable U.S. state privacy laws without your consent.
7.5 How to Exercise Your Rights
To exercise any of these rights:
- Contact us via our Discord community
- We will respond to verified requests within 30 days
8. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence, including:
- Canada (our primary business location)
- United States (cloud infrastructure and AI service providers)
- Other countries where our service providers operate
We ensure appropriate safeguards are in place for international transfers, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Data processing agreements with third-party providers
- Compliance with applicable data protection laws
9. Children's Privacy
TraceMind is not intended for use by individuals under the age of 13 (or 16 in the EU). We do not knowingly collect personal information from children. If we become aware that we have collected personal information from a child without parental consent, we will take steps to delete that information.
10. Cookies and Tracking Technologies
We use cookies and similar tracking technologies on our website and desktop application:
- Essential Cookies: Required for authentication and basic functionality
- Analytics Cookies: For usage tracking and performance monitoring
- Session Storage: To maintain your login session and preferences
You can manage cookie preferences through your browser settings, but disabling certain cookies may limit functionality.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by:
- Posting the new Privacy Policy on this page
- Updating the "Last Updated" date
- Sending an email notification for significant changes
- Displaying an in-app notification
Your continued use of the Service after changes become effective constitutes acceptance of the updated policy.
12. Data Breach Notification
In the event of a data breach that affects your personal information, we will:
- Notify affected users within 72 hours of discovering the breach (as required by GDPR)
- Provide details about the nature of the breach and affected data
- Outline steps we are taking to mitigate harm
- Recommend actions you should take to protect yourself
- Notify relevant regulatory authorities as required by law
13. Third-Party Links
Our Service may contain links to third-party websites, including electronic design documentation, component libraries, and manufacturer datasheets. We are not responsible for the privacy practices of these external sites. We encourage you to review their privacy policies before providing any personal information.
14. Legal Basis for Processing (GDPR)
For users in the EU/EEA, we process your personal data based on the following legal grounds:
- Contractual Necessity:To provide the Service you've subscribed to, including measuring your usage against your plan and billing you for pay-as-you-go usage you have authorized
- Consent:Where you've given explicit consent (e.g., marketing communications)
- Legitimate Interests: For service improvement, fraud prevention, and security
- Legal Obligation: To comply with applicable laws and regulations
15. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
TraceMind
Discord: https://discord.gg/n7NeQVeeSJ
By using TraceMind, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy.
Revision History
A record of substantive changes to this document. Superseded versions are preserved in full for reference.
- August 5, 2026Current
Noted KiCad and Altium file formats in how design data is handled, removed the Bring Your Own Key (BYOK) API-key collection, sharing, and security disclosures, and disclosed the AI usage records and billing data collected for pay-as-you-go.
- December 30, 2025
Initial published Privacy Policy.
View this version