Privacy Policy
Last updated: August 31, 2026
1. Overview of Data Protection
The following information provides a simple overview of what happens to your personal data when you visit this website. Personal data is any data that can be used to identify you personally.
Public pages can be viewed without an account. Account, dashboard, API-key, and payment features require the data needed to provide and secure those services. We use necessary session and security cookies and, when you choose a language, a locale preference cookie that can remain for up to one year. We do not use advertising cookies or track you across other websites.
Our systems receive technical connection data needed to deliver and protect the service, including browser type and version, operating system, IP address, and similar request information. We do not load a third-party web analytics runtime.
2. Responsible Party
The responsible party for data processing on this website is:
Trac Systems UG (haftungsbeschränkt)
Rathausplatz 10A
53604 Bad Honnef
Germany
+49 22249814273
info@trac.network
The responsible party is the natural or legal person who alone or jointly with others decides on the purposes and means of processing personal data.
3. Hosting
Trac Systems self-hosts the website, API, and operational data on rented server infrastructure from Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany ("Hetzner"). Hetzner processes technical network and connection data needed to provide and protect that infrastructure.
We administer the application and its databases on this infrastructure. Server logs are processed to operate the service, investigate failures, prevent abuse, and protect accounts and systems.
4. Server Log Files
The hosting provider automatically collects and stores information in server log files transmitted by your browser:
- Browser type and version
- Operating system used
- Referrer URL
- Hostname of the accessing computer
- Time of the server request
- IP address
This data is not merged with other data sources. Processing is based on GDPR Article 6(1)(f). The website operator has a legitimate interest in the technically reliable presentation and optimization of the website.
5. Service Providers and OpenMayhem Core
If you choose Google sign-in, Google provides the account identifier, email address, and profile information needed to authenticate you. We use Resend to deliver transactional account and security emails; Resend processes the recipient address, message content, and delivery metadata.
Stripe processes checkout and payment information. We receive payment identifiers, status, amount, and billing details needed to credit accounts, handle refunds or disputes, and keep financial records. Card details entered in Stripe's checkout are handled by Stripe and are not stored by us.
Inference and workflow requests are sent through our private OpenMayhem Core buyer gateway to eligible independent providers. Providers process the prompt, input, and requested output needed to perform the job. We process session identifiers, usage, agreed prices, status, signed receipts, and returned artifacts or results to deliver the service, meter usage, settle billing, and reconcile failures.
6. Contact Requests
If you contact us by email or telephone, we process your request and the associated personal data to respond to you. We do not pass this data on without a legal basis or your consent.
Processing is based on GDPR Article 6(1)(b) when your request concerns a contract or pre-contractual measures. Otherwise it is based on our legitimate interest in handling requests effectively under Article 6(1)(f), or on consent under Article 6(1)(a). We retain the data until you request deletion, withdraw consent, or the purpose no longer applies, subject to mandatory statutory retention periods.
7. External Links
This website links to external services such as GitHub, Reddit, Telegram, and tracsystems.io. When you follow a link, that provider processes data under its own responsibility and privacy policy. No data is transmitted to those providers merely because you visit this website.
8. Storage Duration
Generated artifacts are kept for the configured artifact-retention period, currently 30 days. Account and session data is kept while needed to operate and secure the account. Signed receipts, credit movements, payment references, and dispute or reconciliation records may be kept longer for billing, fraud prevention, accounting, and statutory retention duties. Deleted data can remain in protected backups until those backups rotate.
9. Your Rights
You may request information about the origin, recipient, and purpose of your stored personal data, as well as its correction or deletion. In certain circumstances, you may request restriction of processing.
Where processing is based on GDPR Article 6(1)(e) or (f), you may object at any time for reasons arising from your particular situation. We will stop processing unless compelling legitimate grounds override your interests, rights, and freedoms, or processing is needed to establish, exercise, or defend legal claims.
You may withdraw consent at any time for the future. This does not affect the lawfulness of processing carried out before withdrawal.
You have the right to receive data processed automatically on the basis of consent or a contract in a commonly used, machine-readable format, or to have it transmitted to another controller where technically feasible.
You may lodge a complaint with a supervisory authority, particularly in the Member State of your habitual residence, place of work, or the alleged violation. This right is without prejudice to other administrative or judicial remedies.
10. Data Security Note
We treat personal data confidentially and in accordance with applicable data-protection law and this policy. Internet transmission, including email, can have security gaps; complete protection against access by third parties is not possible.