Privacy & data handling
Last updated: May 2026
Summary
TraceForge is a hosted service at app.traceforgehq.io. We store your valve package documents (ITPs, Data Books, BOMs) per project under your account. Some processing uses third-party AI APIs. We do not use your uploads to train our own models.
What we store
- Account data: email address and a bcrypt password hash.
- Project metadata: project name and identifiers linked to your account.
- Project files: uploaded PDFs, search indexes, parse caches, and output logs in isolated project storage on TraceForge infrastructure.
- Usage events: sign-in, project create/delete, uploads, and completed runs (counts and timestamps only — not document contents).
Your files are not shared with other users or projects. Each account can access only its own projects.
How we use AI (and what we send)
TraceForge does not fine-tune or train language models on your documents.
- On our servers: Data Book PDFs are checked for searchable text and indexed using text extracted locally from each page. Full Data Book PDFs are not sent to LlamaParse for indexing.
- LlamaCloud (LlamaParse): ITP and BOM/part-list PDFs (and supported images) when you run parse or organize. Used for table and text extraction only.
- Google Gemini (paid API): text embeddings of Data Book pages for search; ITP row organization and summaries when you run organize or related features. TraceForge uses a paid Google Gemini API key for all production processing — not the free AI Studio tier.
Is my data used to train AI models?
TraceForge: No. We do not use your uploads to train, fine-tune, or build shared models.
Third-party providers process content on our behalf under their terms:
- LlamaCloud (LlamaParse) states that customer data is kept private, used only to return your results, and not used for model training. Parsed jobs may be cached for a short period (typically up to 48 hours) and then deleted from their servers. See LlamaParse FAQ.
- Google Gemini API (paid): TraceForge uses a paid Gemini API key for all AI features on the hosted service. Under Google's Gemini API terms, paid services are not used to improve Google products from your prompts, files, or responses. Google may retain prompts and responses for a limited time for abuse monitoring and legal compliance only.
If your employer or contract requires a data processing agreement (DPA) before uploading vendor MTRs or ITPs, contact us before using the service with production package data.
Retention and deletion
- Project data remains until you delete the project from the Projects screen.
- Deleting a project removes its database record and deletes associated files (Data Book, indexes, caches, and outputs) from our storage.
- Deleting a project does not delete your user account.
We may retain encrypted backups for a limited period for disaster recovery. Backups are access-controlled and are not used for model training. Third-party providers apply their own retention rules to content they process (see above).
Security
- The app and API are served over HTTPS (app.traceforgehq.io, api.traceforgehq.io).
- Passwords are hashed; sessions use signed tokens.
- Project storage is isolated per user account.
- API keys for LlamaCloud and Google are held on our servers, not in your browser.
Your responsibilities
- Use a strong password and do not share your account.
- Upload only documents you are permitted to process under your contract and employer policy.
- Confirm that cloud AI processing is acceptable for your valve package before uploading real vendor data.
Contact
Privacy or security questions: support@traceforgehq.io