RIVACY POLICY
Draft v1 — last updated 2026-08-12. Pending attorney review; not yet a final legal document.
1. Overview
Gnostrace (“we,” “us”) provides institutional-memory incident-intelligence software. This policy describes what data we collect through the hosted Gnostrace platform, how we use it, and the choices available to you. It does not apply to self-hosted or air-gapped deployments — in those deployments Gnostrace never receives your data at all, and your own controls govern.
2. What we collect
Account information (name, work email, authentication data), handled through our identity provider. Incident metadata from your connected tools — alert titles, error signals, affected-service names, resolver identity, timestamps, priority, and similar structured fields.
We do not store full ticket descriptions, comments, or attachments in our matching index — only structured metadata and the embeddings derived from it.
3. How we use it
To match new incidents against your organization’s own history and against patterns from similar organizations. To power the prevention gate, health surface, and AI-generated closing summaries. We never use your data to train the underlying AI models, never build a separate analytics product from it, and never sell it.
4. Sub-processors
| Sub-processor | Role |
|---|---|
| Neon | Primary database (org config, ticket metadata, user records) |
| Qdrant | Vector store (ticket embeddings and metadata) |
| Anthropic | AI generation — 30-day retention, not used for training |
| OpenAI / Azure OpenAI | Embeddings — 30-day retention, not used for training |
| Clerk | Identity and authentication |
| Cloudflare | Network edge, audit-log storage |
| Railway | Application compute |
| Upstash | Ephemeral queue/cache, not persisted beyond TTL |
We give 30 days’ notice before adding a new sub-processor that will process personal data.
5. Data retention & residency
Audit logs are retained 2 years (7 years on Enterprise plans). EU-region storage and inference options are available on request. Self-hosted and air-gapped deployments keep all data on your own infrastructure and fall outside this policy’s processing terms entirely.
6. Your rights
Organization admins can self-serve export or erase their org’s data from Settings. You can also contact us directly to exercise access, correction, or deletion rights — typically fulfilled within 30 days (GDPR jurisdictions) or 45 days (others).
7. Security
Encryption in transit and at rest, tenant isolation enforced at both the application layer and the database layer (row-level security), and append-only audit logging of security-relevant actions.
8. International transfers
Where personal data crosses borders, we rely on Standard Contractual Clauses with our sub-processors, or region-pinned infrastructure where available.
9. Children
Gnostrace is a B2B product not directed at children, and we don’t knowingly collect data from anyone under 16.
10. Changes to this policy
We’ll update the date at the top of this page when this policy changes; material changes will be communicated to organization admins.
11. Contact
privacy@gnostrace.dev