privacy policy

Privacy.

This is the single privacy policy for Tracelane. It covers both tracelane.dev — the website you are reading — and the hosted product: the gateway, the dashboard, and the audit ledger.

What we collect on the website

What we don't collect on the website

What the product processes

When you send traffic through the Tracelane gateway or ship telemetry to it, we process:

Where your data lives

Hosted Tracelane runs in the European Union. Trace data is not replicated outside your region.

Sub-processors

A deliberately short list. Each one is here because it is load-bearing, not for convenience.

We never send your prompts or completions to a model provider on our own initiative. You bring your own provider keys, and traffic goes to the provider you selected.

How long we keep it

Trace retention has two windows that differ by plan: an indexed window for fast queries (3 days on Free, up to 365+ days on Enterprise) and a longer queryable history (30 days on Free, 730 days on every paid tier) during which older data is still readable from cold storage. See /pricing for the full per-tier figures. Longer retention is never a shortcut around erasure: deletion on request is unaffected.

The tamper-evident audit ledger is retained for the life of the ledger by design: a record you can selectively delete is not a tamper-evident record.

Deletion and your rights

Email support@tracelane.dev and we will remove your tenant's trace data and account metadata. Deletion is handled manually by our team today — there is no self-serve erasure endpoint, and the append-only audit ledger is retained as described above. GDPR data-subject requests and India DPDP rights requests are handled through the same address, as is removal from the website updates list.

Changes

This policy may change. If it changes materially, anyone with an account or on the updates list gets a single email explaining what changed before the change takes effect.

Last updated: July 28, 2026.