Legal

Privacy Policy

Last updated August 29, 2026

Draft pending legal review.
This draft describes what the Service actually does with data today, but it has not yet been reviewed by counsel. Bracketed items are placeholders for counsel to complete.

1. Who we are and what this policy covers

The service available at gettrazo.app (the "Service") is operated by midnightslicer LLC ("Trazo", "we"). This policy explains how we handle personal data in two roles. For data about you and your account, we are the controller. For the data that visitors submit through your sites' forms ("Submission Data"), we are a processor acting on behalf and on the instructions of the site operator, our customer.

If you are reading this as someone who submitted a form on a website that uses Trazo, the operator of that website is responsible for your data; this policy describes what we do with it on their behalf (see "Submission Data" below and "Your rights").

2. Data we collect

Account data: your email address, role, and organization, plus your sign-in credentials (passwords are stored as one-way hashes, passkeys as public keys, and TOTP secrets encrypted).

Security logs: authentication and account-security events, with IP address, browser user agent, and timestamps, kept for one year and then purged automatically.

Submission Data: whatever an End User submits through a form (typically a name, email address, message, and any custom fields the site has configured), together with the submitting IP address and browser user agent.

Billing data: payments are handled by Stripe. We store your subscription status and billing identifiers; full card numbers never reach us.

We do not run analytics or advertising trackers. Visits to our marketing pages produce only standard, short-lived server logs.

3. How we use data, and on what legal bases

We use data to operate the Service (authentication, storing submissions and delivering notifications, enforcing plan limits), to secure it (bot verification, rate limiting, spam and abuse screening, security logging), to bill subscriptions, and to communicate with you about the Service. Where the GDPR applies, we rely on performance of a contract (operating the account you asked for), legitimate interests (securing the Service and preventing abuse), and legal obligation (tax and accounting records). We do not sell personal data, do not share it for cross-context behavioral advertising, and do not use Submission Data for marketing.

4. Automated spam screening

The content of each submission (the fields an End User filled in) is sent to AI language models via OpenRouter, our AI gateway subprocessor, to classify it as spam or legitimate. We store the verdict, a confidence score, and the model's brief reasoning alongside the submission. Screening affects only whether and how we notify the site operator by email; every submission is stored and remains reviewable by the site operator, who can override the classification. Neither we nor the model providers we route to use Submission Data to train AI models. We only route requests to providers whose terms prohibit training on the data we send them.

5. Subprocessors and sharing

We share personal data only with the subprocessors that run the Service: Stripe (payments; never receives Submission Data), Resend (sends notification and account emails), OpenRouter (AI spam screening of submission content). The Service and its database run on infrastructure we operate ourselves, and CAPTCHA verification (Cap) is self-hosted as part of the Service, so no hosting or CAPTCHA third party is involved. Beyond these, we disclose personal data only where required by law or to protect the Service, and we will notify you of legal demands where we are allowed to.

6. International transfers

Our subprocessors may process data in the United States and other countries. Where data protected by the GDPR or UK GDPR is transferred to such countries, we rely on the European Commission's Standard Contractual Clauses (with the UK addendum where applicable) or an adequacy decision.

7. Security

Two-factor authentication is required on every account. Passwords are stored as one-way hashes; API keys are stored hashed and cannot be retrieved after creation; TOTP secrets and other sensitive values are encrypted at rest; all traffic is served over HTTPS. Access to production data is limited to what is needed to operate the Service.

8. Retention

Submission Data is kept until you delete it or delete the site that collected it. Security logs are purged after one year. Account data is kept for the life of the account. When an account or organization is closed, we delete its data within 30 days, except where we are required to retain it (for example, billing and tax records). Residual copies may persist in backups for up to 30 additional days.

9. Cookies

We use a single first-party session cookie to keep you signed in (it expires after 8 hours) and to remember preferences such as your language. We use no analytics, advertising, or third-party cookies.

10. Your rights

Depending on where you live, you may have the right to access, correct, export, delete, or restrict the processing of your personal data, to object to processing based on legitimate interests, and to lodge a complaint with your supervisory authority or equivalent regulator. Much of this you can do yourself: account data and Submission Data can be viewed, exported, and deleted directly in the admin panel.

If your data was submitted through a customer's form, the site operator (the controller) is your first point of contact. If you contact us instead, we will forward your request to them or handle it on their instructions. To exercise any right with us, contact us or write to legal@gettrazo.app.

California residents: we do not sell or share personal information as defined by the CCPA/CPRA, and we act as a service provider with respect to Submission Data.

11. Children

The Service is a business tool and is not directed to children. We do not knowingly collect personal data from anyone under 16; if you believe a child's data has been submitted to us, contact us and we will delete it.

12. Changes to this policy

We may update this policy. For material changes we will give notice by email or in the dashboard and update the date above; the current version always applies.

13. Contact

Questions or requests about privacy? Contact us, or write to legal@gettrazo.app.