Privacy Policy
Last Updated: December 30, 2025
1. Introduction
TraceMind ("we", "us", or "our") operates the TraceMind desktop application and website (collectively, the "Service"). This Privacy Policy explains how we collect, use, disclose, and protect your information when you use our AI-powered schematic design software.
TraceMind is operated by TraceMind, a company registered in Canada. By using our Service, you agree to the collection and use of information in accordance with this policy.
Contact Information:
Discord: Join our community
2. Information We Collect
2.1 Account Information
When you create an account, we collect:
- Email address
- Password (encrypted and hashed)
- Display name and profile information (if provided)
- Authentication provider data (if using third-party OAuth)
2.2 Schematic Files and Design Data
When you use TraceMind's AI features:
- Design metadata: Component information, connections, and structural data extracted from your schematic files for AI processing (complete schematic files remain on your device)
- Design descriptions: Text descriptions and commands you provide to the AI assistant
- Chat history: Conversations with the AI assistant for context and service improvement
- Project metadata: Project names, file names, timestamps, and version information
2.3 Usage and Technical Data
We automatically collect:
- Error reports: Crash reports, error logs, and diagnostic information
- Device information: Operating system, version, hardware specifications
- Usage analytics: Feature usage patterns, session duration, and interaction data
- IP addresses: For security, authentication, and geographical analytics
- Connection data: Connection status, latency, and performance metrics
2.4 Payment Information
If you purchase a paid subscription or feature:
- Payment information is processed by our third-party payment processor
- We do not store full credit card numbers
- We retain transaction IDs, billing addresses, and purchase history
2.5 User-Provided API Keys (BYOK - Bring Your Own Key)
If you are using a Bring Your Own Key (BYOK) subscription plan, you may provide your own API keys from third-party AI service providers (such as OpenAI, Anthropic, or others). When you provide API keys:
- API Key Collection: We collect and store the API keys you provide for third-party AI service providers
- Encryption: Your API keys are encrypted using industry-standard AES-256 encryption both in transit (via TLS 1.3) and at rest
- Storage: Encrypted API keys are stored on our secure servers to facilitate AI requests on your behalf
- Access Control: API keys are stored separately from other user data with strict role-based access controls
- Usage Purpose: Your API key is used exclusively to authenticate and make AI model requests to your chosen third-party provider on your behalf
- No Sharing: We do not share, sell, or disclose your API keys to any parties other than the specific API provider you designated
Important: You are solely responsible for the security of your API keys. You should immediately revoke and replace any API key that you believe has been compromised.
3. How We Use Your Information
We use your information for the following purposes:
- Service Delivery: To process your schematic files with AI, generate designs, and provide real-time assistance
- Authentication: To verify your identity and manage your account
- Service Improvement: To analyze usage patterns, fix bugs, and enhance features
- Error Detection: To identify, diagnose, and resolve technical issues
- Communication: To send service-related notifications, updates, and responses to inquiries
- Analytics: To understand user behavior and optimize the application
- Legal Compliance: To comply with legal obligations and protect our rights
- Payment Processing: To process transactions and manage subscriptions
4. Third-Party Services
We use trusted third-party service providers to deliver and improve our Service:
- AI Service Providers: We use multiple Large Language Model (LLM) providers for natural language understanding, schematic analysis, and design generation. Your design metadata and chat messages are processed by these providers according to their privacy policies.
- Cloud Infrastructure: Cloud hosting services for metadata storage, database management, real-time messaging, and AI processing infrastructure.
- Authentication Services: Third-party authentication providers for secure user account management, email verification, and OAuth integration.
- Analytics Services: Website analytics for tracking page views, downloads, and user engagement on our marketing website only (desktop application does not use web analytics).
- Error Tracking Services: Crash reporting and error monitoring services that collect diagnostic information, stack traces, and system context when errors occur.
- Payment Processors: Secure payment processing for subscriptions and billing management. We do not store complete payment card numbers.
- Real-time Messaging: Services for enabling real-time communication between your desktop application and our AI processing servers.
These service providers are located in various jurisdictions including the United States and Canada. They process your data according to their own privacy policies, and we implement contractual safeguards including data processing agreements and standard contractual clauses where required. All data in transit is encrypted using TLS/SSL, and data at rest is encrypted using industry-standard encryption.
4.1 BYOK Users - Additional Third-Party Data Sharing
If you are using a Bring Your Own Key (BYOK) plan and have provided your own API key from a third-party AI service provider:
- Direct API Communication: Your schematic metadata, design descriptions, chat messages, and prompts are sent directly to your chosen AI service provider (such as OpenAI, Anthropic, or others) using your API key
- API Key Transmission: Your encrypted API key is transmitted with each request to authenticate with your chosen provider
- Third-Party Privacy Policies: Your data is processed by the AI provider according to their own privacy policies and terms of service. We recommend reviewing:
- OpenAI Privacy Policy: https://openai.com/privacy
- Anthropic Privacy Policy: https://www.anthropic.com/privacy
- Data Processing Location: Your data may be processed in any location where your chosen AI provider operates (typically United States)
- No Control Over Third-Party Practices: TraceMind has no control over how third-party AI providers use, store, or process your data. Your relationship with these providers is governed by your API agreement with them
- Usage Tracking: We track API usage metrics (token counts, request counts, estimated costs) for your benefit, but this data is derived from API responses and not shared with third parties
Your Responsibilities:When using BYOK, you are responsible for ensuring your use complies with your API provider's terms of service and acceptable use policies. You should review these policies to understand how your data is handled.
5. Data Retention
We retain your personal data only as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law. Specific retention periods include:
- Design metadata: Transient data processed during active sessions is not permanently stored. Historical metadata may be retained for service improvement purposes.
- Chat history: Retained for service improvement and AI model training, or until you request deletion
- Account information: Retained while your account is active and for a reasonable period after account deletion to prevent fraud and re-registration abuse
- Error logs: Retained for a limited period for debugging and service improvement
- Analytics data:Website analytics data is anonymized and retained according to our analytics provider's retention policies
- Payment records: Retained for the period required by applicable tax and accounting laws
- Usage tracking: AI API usage records (token counts, costs, model types) are retained for billing accuracy, fraud prevention, and service optimization
You may request deletion of your personal data at any time by contacting us. We will respond to your request in accordance with applicable data protection laws.
6. Data Security
We implement industry-standard security measures to protect your data:
- Encryption: TLS/SSL encryption for data in transit; AES-256 encryption for data at rest
- Access Controls: Role-based access control (RBAC) and least-privilege principles
- Authentication: Secure OAuth 2.0 implementation with JWT tokens
- Monitoring: Continuous security monitoring and logging
- Regular Audits: Periodic security assessments and vulnerability scans
However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.
6.1 BYOK API Key Security Safeguards
For users on Bring Your Own Key (BYOK) plans, we implement additional security measures specifically for API keys:
- Encryption Standards:
- API keys are encrypted in transit using TLS 1.3 protocol
- API keys are encrypted at rest using AES-256 encryption
- Encryption keys are rotated regularly and stored in secure key management systems
- Isolated Storage: API keys are stored separately from other user data in isolated, access-controlled databases
- Access Controls: Only authorized systems and personnel can access encrypted API keys, using role-based access control (RBAC) and principle of least privilege
- Audit Logging: All access to API key storage is logged and monitored for suspicious activity
- No Plaintext Storage: API keys are never stored in plaintext or logged in system logs
6.2 User Obligations for API Key Security
When using BYOK, you must take the following security precautions:
- Keep API Keys Confidential: Never share your API keys with unauthorized individuals or post them in public forums, code repositories, or unsecured locations
- Monitor API Usage:Regularly check your API provider's dashboard for unusual activity or unexpected usage patterns
- Set Spending Limits: Configure usage limits and budget alerts with your API provider to prevent unexpected charges
- Rotate Keys Regularly: Periodically rotate your API keys as a security best practice
- Immediate Action on Compromise: If you suspect your API key has been compromised:
- Immediately revoke the compromised key through your API provider's dashboard
- Generate a new API key and update it in TraceMind
- Review your API usage logs for unauthorized activity
- Contact TraceMind support if you believe the compromise occurred through our Service
- Secure Account Access: Use strong, unique passwords and enable two-factor authentication (2FA) on both your TraceMind account and your API provider account
6.3 API Key Breach Notification
In the event of unauthorized access to encrypted API keys stored by TraceMind:
- Immediate Notification: We will notify affected BYOK users within 24 hours of discovering the breach via email and in-app notification
- Breach Details: We will provide information about:
- The nature and scope of the breach
- Which API providers may be affected
- Steps we are taking to secure the system
- Recommended actions you should take immediately
- Required User Action: Upon notification, you must immediately:
- Revoke the affected API key through your provider's dashboard
- Generate a new API key
- Update your API key in TraceMind
- Monitor your API provider account for unauthorized usage
- Regulatory Compliance: We will notify relevant regulatory authorities as required by applicable data protection laws (GDPR, PIPEDA, state privacy laws)
7. Your Rights and Choices
Depending on your location, you may have the following rights:
7.1 General Rights
- Access: Request a copy of the personal data we hold about you
- Correction: Request correction of inaccurate or incomplete data
- Deletion: Request deletion of your personal data (subject to legal retention requirements)
- Data Portability: Request export of your data in a machine-readable format
- Withdrawal of Consent: Withdraw consent for data processing (may limit service functionality)
7.2 GDPR Rights (EU/EEA Users)
If you are located in the European Union or European Economic Area, you have additional rights under the General Data Protection Regulation (GDPR):
- Right to Restriction: Request restriction of processing in certain circumstances
- Right to Object: Object to processing based on legitimate interests
- Right to Lodge a Complaint: File a complaint with your local data protection authority
7.3 Canadian Privacy Rights (PIPEDA)
As a Canadian company, we comply with the Personal Information Protection and Electronic Documents Act (PIPEDA). You have the right to:
- Know what personal information we collect and how it's used
- Access your personal information
- Challenge the accuracy and completeness of your information
- File a complaint with the Office of the Privacy Commissioner of Canada
7.4 United States Privacy Rights
If you are a resident of certain U.S. states with comprehensive privacy laws (such as California, Virginia, Colorado, Connecticut, or Utah), you may have additional rights including:
- California (CCPA/CPRA): Right to know what personal information is collected, right to deletion, right to opt-out of sale (we do not sell personal information), and right to non-discrimination
- Other States: Similar rights to access, correct, delete, and obtain a copy of your personal information
- Right to opt-out of targeted advertising (contact us to exercise this right)
We do not sell your personal information to third parties. We do not process sensitive personal information as defined under applicable U.S. state privacy laws without your consent.
7.5 How to Exercise Your Rights
To exercise any of these rights:
- Contact us via our Discord community
- We will respond to verified requests within 30 days
8. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence, including:
- Canada (our primary business location)
- United States (cloud infrastructure and AI service providers)
- Other countries where our service providers operate
We ensure appropriate safeguards are in place for international transfers, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Data processing agreements with third-party providers
- Compliance with applicable data protection laws
9. Children's Privacy
TraceMind is not intended for use by individuals under the age of 13 (or 16 in the EU). We do not knowingly collect personal information from children. If we become aware that we have collected personal information from a child without parental consent, we will take steps to delete that information.
10. Cookies and Tracking Technologies
We use cookies and similar tracking technologies on our website and desktop application:
- Essential Cookies: Required for authentication and basic functionality
- Analytics Cookies: For usage tracking and performance monitoring
- Session Storage: To maintain your login session and preferences
You can manage cookie preferences through your browser settings, but disabling certain cookies may limit functionality.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by:
- Posting the new Privacy Policy on this page
- Updating the "Last Updated" date
- Sending an email notification for significant changes
- Displaying an in-app notification
Your continued use of the Service after changes become effective constitutes acceptance of the updated policy.
12. Data Breach Notification
In the event of a data breach that affects your personal information, we will:
- Notify affected users within 72 hours of discovering the breach (as required by GDPR)
- Provide details about the nature of the breach and affected data
- Outline steps we are taking to mitigate harm
- Recommend actions you should take to protect yourself
- Notify relevant regulatory authorities as required by law
13. Third-Party Links
Our Service may contain links to third-party websites, including electronic design documentation, component libraries, and manufacturer datasheets. We are not responsible for the privacy practices of these external sites. We encourage you to review their privacy policies before providing any personal information.
14. Legal Basis for Processing (GDPR)
For users in the EU/EEA, we process your personal data based on the following legal grounds:
- Contractual Necessity:To provide the Service you've subscribed to
- Consent:Where you've given explicit consent (e.g., marketing communications)
- Legitimate Interests: For service improvement, fraud prevention, and security
- Legal Obligation: To comply with applicable laws and regulations
15. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
TraceMind
Discord: https://discord.gg/n7NeQVeeSJ
By using TraceMind, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy.