Skip to main content
Back To Terminal

Privacy Policy

This Privacy Policy explains how TracerTerminal LLC, a Nevada limited liability company ("Tracer," "we," "us"), collects, uses, shares, and protects personal information when you use Tracer Terminal (the "Service"). It is incorporated into and part of our Terms of Service. Capitalized terms not defined here have the meaning given in the Terms.

1. Information We Collect

Information you provide.

  • Account and identity. When you register, we collect your email address and, if you set them, a display name and profile details (avatar, bio, website, location, username). If you sign in with Google, we receive basic profile information (such as email and name) from Google. If you sign in with a Web3 wallet (Ethereum or Solana), we collect your public wallet address. We never receive or store your wallet's private keys or seed phrase.
  • Authentication and security. If you enable multi-factor authentication, we store a hashed form of your recovery codes (we do not store the raw codes). Your password is handled and hashed by our authentication provider; we do not store your raw password.
  • Payment information. When you purchase a subscription, API plan, or AI Credits, our payment processor (Stripe) processes your payment. We receive and store billing identifiers such as your Stripe customer and subscription IDs. We do not receive or store your full payment-card number, which is handled by Stripe.
  • Your content. We store the content you create in the Service, including workspace and chart layouts, watchlists, drawings, saved indicators (including any code and compiled modules), published community content, and your TracerAI prompts and chat history.

Information we collect automatically.

  • Usage and device data. We collect information about how you use the Service, including pages and features used, and technical information such as your IP address, browser/user-agent, and request metadata, which we use for operation, security, and analytics.
  • Cookies and local storage. See Section 3.

Information from third parties. We receive profile information from your sign-in provider (Google) if you use it, and billing and payment-status information from Stripe.

Sensitive information.

The only sensitive personal information we collect is account-authentication information (such as your login credentials and hashed multi-factor recovery codes). We use it solely to authenticate you and secure your account, and not for any purpose that would require an opt-out or a right to limit its use.

Categories of personal information (for California residents).

We collect these statutory categories: identifiers (email, wallet address, IP address); commercial information (subscription, API, and AI-Credit records); internet or network activity (usage and request logs, page views); financial information (billing identifiers held with our payment processor); account-authentication information (as above); and your own content (prompts, layouts, indicators). We collect these from you, your device, and your sign-in and payment providers, for the purposes in Section 2, and disclose them only to the subprocessors in Section 4. We do not sell or share any of these categories.

2. How We Use Information

We use personal information to:

  • provide, operate, maintain, and improve the Service;
  • create and authenticate your account and secure it (including MFA and bot detection);
  • process payments, subscriptions, and AI Credit purchases, and manage billing;
  • provide TracerAI features, including generating indicator code and analysis from your prompts (see Section 5);
  • personalize and persist your layouts, watchlists, and preferences;
  • monitor, prevent, and investigate fraud, abuse, security incidents, and violations of our Terms, and to enforce rate limits;
  • send you service, security, transactional, and administrative communications; and
  • comply with legal obligations and exercise or defend legal claims.

Where the GDPR applies, our legal bases are: performance of our contract with you (to create your account and provide the Service, billing, and TracerAI features); our legitimate interests in operating, improving, and securing the Service and preventing fraud and abuse (including logging, rate limiting, and bot protection); compliance with legal obligations (such as tax and accounting retention); and, where we specifically ask for it, your consent.

3. Cookies and Local Storage

We use a small number of cookies and browser local storage, and we do not use third-party advertising or analytics trackers.

  • Essential cookies (cannot be disabled). An authentication/session cookie set by our authentication provider to keep you signed in, and a security token used to protect certain requests against cross-site request forgery. These are required for the Service to function.
  • Preference storage. Browser local storage keeps non-sensitive preferences such as your theme, chart intervals, layout, and interface state. The Service works without it, and it holds no passwords, keys, or tokens.
  • First-party analytics. We keep first-party usage records (such as page views and request logs) to operate, secure, and improve the Service. These are our own records; we do not share them with third-party ad networks, and they are deleted on the schedule in Section 6.

4. How We Share Information

We do not sell your personal information, and we do not share it for cross-context behavioral advertising or rent or license it to third parties for their own marketing.

We share personal information only as follows:

  • Service providers (subprocessors) who process data on our behalf, under contract and confidentiality obligations. The subprocessors we currently use are:
    • Supabase — authentication and primary database (account, identities, and the data described in Section 1);
    • Stripe — payment processing and billing (billing identifiers and payment events; Stripe handles your card data directly);
    • OpenRouter — the AI gateway that relays your TracerAI prompts and related content to the underlying model providers (see Section 5);
    • Anthropic (Claude), DeepSeek, and Google (Gemini) — the AI model providers that, via OpenRouter, generate TracerAI code, chat, and research responses from your prompts; the research feature also uses a web-search service to retrieve current information;
    • Upstash (Redis) — rate limiting and caching (transient identifiers such as IP- and user-derived keys, held briefly and expired automatically);
    • Cloudflare (Turnstile) — bot/CAPTCHA protection on authentication flows;
    • Google — sign-in, if you choose Google authentication;
    • Application hosting — self-operated. The application servers that process and store the data described in this Policy are operated by Tracer rather than by a third-party hosting platform;
    • Sentry — error and performance monitoring (diagnostic data with personal data scrubbed).
  • Legal and safety. We may disclose information if required by law, subpoena, or legal process, or where we believe in good faith it is necessary to comply with law, enforce our Terms, or protect the rights, safety, or property of Tracer, our users, or the public.
  • Business transfers. If we are involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction, subject to this Policy.

Market-data providers and archives (such as the exchanges whose data we display, and our market-data storage systems) receive market data, not your personal information.

5. TracerAI and Your Inputs

TracerAI generates indicator code, chat responses, and research from the prompts and content you submit. To provide these features, your prompts and related content are sent to our AI gateway (OpenRouter), which routes them to third-party model providers including Anthropic (Claude), DeepSeek, and Google (Gemini) for processing. The research feature performs live web search and may transmit your query and any URLs you ask it to read to a search service to retrieve current information. Your prompts, messages, and generated outputs are stored in your account so your chat history and saved indicators persist. You can delete chats and saved indicators, which removes them and their versions from your account.

Your use of TracerAI is also governed by the AI provisions of our Terms of Service. We do not use the content of paying customers' TracerAI inputs or outputs to train foundation models except as disclosed here or with your consent, and we direct our providers to handle your content in accordance with their applicable enterprise/API terms.

6. Data Retention and Deletion

Retention. We keep personal information for as long as your account is active or as needed to provide the Service, and then for as long as necessary for the purposes described here or as required by law. Specific practices include:

  • operational logs are deleted automatically on a rolling basis (for example, request and error logs after about 30 days, page-view records after about 90 days, and certain aggregate metrics after about 365 days);
  • used multi-factor recovery codes are purged after about 90 days;
  • your content (workspaces, saved indicators, and TracerAI prompts and chats) is retained indefinitely while your account exists, so your history and saved work persist, until you delete it or delete your account; and
  • billing and financial records (such as subscription history and the AI Credit ledger) are retained after account deletion for the period required by applicable accounting, tax, and audit law.

Account deletion. You can delete your account from your account settings, which requires you to re-authenticate. Deleting your account removes your profile, settings, workspaces, saved indicators, API keys, and TracerAI chats and their versions. Please note:

  • if you have an active paid API subscription, you must cancel it before you can delete your account through settings, and a prior (ended) subscription record can also prevent self-service deletion. If you cannot complete self-service deletion for this reason, email privacy@tracerterminal.com and we will erase your non-financial personal information while retaining the financial records below; and
  • we retain the billing and financial records described above after deletion.

Access and portability requests. We do not currently offer a self-service data export. You may request a copy of the personal information we hold about you by emailing privacy@tracerterminal.com, and we will provide it in a portable, machine-readable format (such as JSON) for the information you provided to us, subject only to the exemptions allowed by law.

7. Data Security

We use reasonable technical and organizational measures to protect personal information, including encryption in transit (TLS), hashed credentials and hashed API keys, optional multi-factor authentication, access controls, and bot protection on authentication flows. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

8. Your Privacy Rights

Depending on where you live, you have rights over your personal information. We honor these rights and will not discriminate against you for exercising them.

How to exercise. Email privacy@tracerterminal.com, or contact us at support@tracerterminal.com, and tell us which right you wish to exercise. We will acknowledge your request within 10 business days and respond within 45 days (extendable by a further 45 days with notice) for U.S. state-law requests, and within one month (extendable to three months) for GDPR/UK GDPR requests. Verification: to protect your account, we verify your identity before acting, generally by confirming control of your account email or wallet and, for sensitive actions such as account deletion, by requiring you to re-authenticate. Authorized agents may submit a request on your behalf with your signed written permission (or a valid power of attorney); we may still require you to verify your own identity and confirm the authorization.

If you are in the EEA or UK (GDPR/UK GDPR), you have the right to access, correct, delete, restrict, or object to processing of your personal data, to data portability, and to withdraw consent where processing is based on consent. Our legal bases are described in Section 2. You may lodge a complaint with your supervisory authority (in the UK, the Information Commissioner's Office).

If you are a California resident (CCPA/CPRA), you have the right to know and access, correct, and delete your personal information, and to opt out of the "sale" or "sharing" of personal information and to limit the use of sensitive personal information. We do not sell or share personal information as those terms are defined under California law, and we use the limited sensitive personal information we collect (see Section 1) only for the permitted purposes of providing and securing the Service, so the right to limit its use is not triggered.

If you are in another U.S. state with a comprehensive privacy law (such as Virginia, Colorado, Connecticut, or Texas), you have similar rights, including the right to appeal a denied request. To appeal, reply to our decision or email privacy@tracerterminal.com with "Appeal" in the subject line; if we deny your appeal, you may contact your state attorney general.

Some information may be retained after a deletion request where an exception applies (for example, to complete a transaction, for security, or to comply with a legal obligation), including the billing and financial records described in Section 6.

9. International Data Transfers

We are based in the United States and process personal information there and in other countries where our subprocessors operate. If you access the Service from outside the United States, you understand that your information will be transferred to and processed in the United States. Where we transfer the personal data of individuals in the EEA or UK, we will put in place the appropriate safeguards required by law (such as the European Commission's Standard Contractual Clauses and the UK International Data Transfer Agreement).

10. Wallet Authentication

If you sign in with a Web3 wallet, we use your public wallet address to authenticate you and associate your account. Wallet addresses and on-chain activity are public by nature. We never receive, request, or store your private keys or seed phrase, and we cannot move your assets. For wallet-only accounts, we may ask you to sign a message with your wallet to confirm sensitive actions such as account deletion.

11. Children's Privacy

The Service is intended only for adults 18 years or older, and by using it you represent that you meet that requirement. We do not knowingly collect personal information from anyone under 18, and we do not knowingly collect personal information from children under 13 (as defined by the U.S. Children's Online Privacy Protection Act). If we learn that we have collected such information, we will delete it.

12. Do Not Track and Global Privacy Control

Because we do not use third-party advertising or cross-site tracking, we do not track you across other websites over time. We also do not sell or share your personal information, so there is no sale or sharing for an opt-out preference signal to affect. If that ever changes, we will honor recognized browser opt-out signals, such as Global Privacy Control (GPC), as required by law.

13. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will post the updated Policy here, update the "Last updated" date, and, where appropriate, provide additional notice. Your continued use of the Service after the effective date means you accept the updated Policy.

14. Contact

For privacy questions or to exercise your rights, contact:

TracerTerminal LLC
Privacy: privacy@tracerterminal.com
General: support@tracerterminal.com