Privacy policyWhat we collect, why, and how long we keep it.

Last updated 26 September 2026

Who we are

IndraTrace is operated by Indrasol LLC ("Indrasol", "we", "us"), Frisco, Texas, United States. This policy covers our website and the IndraTrace service (the "Service"). For anything in it, write to privacy@indrasol.com.

Two roles matter throughout. For the account and billing information you give us, we decide how it is processed (we are the controller). For the telemetry your systems send us, you decide what is sent and we process it on your behalf and on your instructions (we are the processor).

What we collect

Account data

Your email address; the sign-in method you use (passwordless email code, GitHub, Google or your organisation's SAML single sign-on) and the identifier that provider gives us; your organisation's name; your role in it (owner or member); whether multi-factor authentication is on; and the invitations you send.

Billing data

Payments are handled by Stripe. Your card number never reaches our servers. We keep the billing profile Stripe returns to us - business name, country, postal code and the last digits of a tax id - together with your monthly usage in gigabytes, which is what the invoice is made from.

Telemetry you send

Traces, logs, metrics, session data and AI-call data that your applications emit through the SDK or any OpenTelemetry exporter using your key. It carries whatever your code puts in it. Three defaults protect you here:

  • Prompt and completion text is never captured unless you turn it on. The SDK records token counts and model names always, but the text of prompts and completions only when you set capture_content explicitly.
  • Cost is computed on our side from token counts. The wire never carries a price.
  • You choose what your instrumentation sends. We ask that you do not send data you are not permitted to share, and that you use the SDK's controls to keep personal data out of span attributes.

Connector data

If you connect a tool, we process what that connection needs: findings from GitHub, GitLab, Snyk or SonarQube that you route to us; the channel details needed to notify Slack, Microsoft Teams, PagerDuty or a webhook; and the destination you give us for streaming your audit trail to a SIEM. Connector secrets are stored encrypted.

Audit trail

Every significant action in your organisation - a key minted, a role changed, an incident acknowledged - is written to an audit trail with who did it and when. Secrets are scrubbed before the entry is written. The trail is yours: you can read it, stream it, or pull it through the audit log API.

Technical data

Server logs record the IP address, time and route of requests to the Service. We use them for security, rate limiting and to diagnose problems. Our website sets no advertising or analytics trackers; the only cookies are the session cookies that keep you signed in, and your theme and layout preferences live in your own browser's storage.

How we use it

  • To provide the Service: store your telemetry, evaluate your alert rules, open and route incidents, and show you your data.
  • To run your account: sign you in, enforce roles and multi-factor authentication, send you the emails you have asked for (sign-in codes, invitations, alert notifications).
  • To bill you: meter usage, produce the invoice and collect payment through Stripe.
  • To keep the Service safe: rate limiting, abuse prevention, and investigation of security events.
  • To support you when you write to us.

We do not sell your data, use it for advertising, or use your telemetry to train models. Our lawful bases, where the GDPR or a similar law applies, are performance of our contract with you, our legitimate interest in running a secure service, and your consent where you have turned a feature on.

Who we share it with

We use a small number of providers to run the Service. Each processes data only to provide its part of it, under its own security commitments.

ProviderWhat it doesWhere
Microsoft AzureRuns the API, the ingest gateway and the telemetry databaseUnited States (East US 2)
SupabaseAuthentication and the account databaseUnited States
NetlifyServes the web applicationGlobal edge, United States origin
StripePayments, invoices and sales taxUnited States
Amazon Web Services (SES)Sends alert and notification emailUnited States

Beyond these, data leaves the Service only where you send it: to the Slack, Teams, PagerDuty, webhook or SIEM destinations you configure. We will disclose data if the law requires it, and we will tell you when we are allowed to.

How long we keep it

  • Telemetry is kept for your organisation's retention window. Thirty days are included; you can set it longer or shorter, and each day's data is priced at the window in force that day. The audit trail follows the same window.
  • Account and billing data is kept while your account exists, and afterwards only as long as tax and accounting law requires.
  • Server logs are kept for a short, rolling period for security purposes.

Deletion

You can delete a product, an organisation or your own account from inside the Service. Deletion happens in two steps and we say so plainly: access ends immediately, then the data is physically erased across every store within the grace window - seven days for a product, thirty days for an organisation - during which an owner can restore it. The Service shows the erasure's progress and reserves the word "deleted" for when it is complete. You can export your data at any time before that.

How we protect it

  • Encrypted in transit (TLS on every hop, including between our own services) and at rest.
  • Every organisation's data is isolated at the query level; every read and write is scoped to your organisation, and that isolation has been reviewed end to end with tests that run on every change.
  • Passwordless sign-in, SAML single sign-on, multi-factor authentication with no bypass, and owner and member roles.
  • Prompt and completion capture off by default; secrets scrubbed from the audit trail; connector secrets encrypted with a rotated key.
  • Nobody holds standing write access to production; changes arrive through a reviewed deployment.
  • A SOC 2 examination is in progress. We do not yet claim certification.

If you find a security problem, write to security@indrasol.com.

Where it is stored

The Service runs in the United States. If you use it from elsewhere, your data is transferred to and processed in the United States. We do not currently offer regional hosting.

Your rights

Depending on where you live you may have the right to access, correct, export or delete personal data we hold about you, to object to or restrict some processing, and to complain to a supervisory authority. Most of this you can do yourself inside the Service; for anything else, write to privacy@indrasol.com and we will respond within the time the law allows. If you are a user of one of our customers, we will point you to that customer, who controls the data.

Children

The Service is for businesses and is not directed at children under 16. We do not knowingly collect their data.

Changes to this policy

When we change this policy we update the date at the top. If a change materially affects how we handle your data, we will tell account owners by email before it takes effect.