Privacy policy
Last updated September 5, 2026. Trace is a read-only payment-state service: it inspects the state of supported stablecoin payments and never moves funds, signs transactions, or holds assets.
What Trace processes
Payment identifiers you submit — transaction hashes, provider payment IDs, and wallet addresses — are used to fetch payment state from public blockchain RPCs (Base, Solana) and, where you have connected credentials, from Bridge or Circle. Traces you generate are stored so they can be re-opened and shared; anonymous traces are held in ephemeral server memory unless a database is configured, and you can delete workspace traces at any time.
Account data — signing in is done exclusively with Google (OAuth, identity scopes only: openid, email, profile). We store the Google account identifier, email address, and display name to identify your workspace. Trace never sees or stores a password, and requests no access to your Google data beyond basic identity.
Credentials — API keys you create are stored only as cryptographic hashes; the secret is shown once and never stored or logged. Provider credentials (Bridge/Circle API keys) you connect are encrypted at rest, used solely to fetch payment state on your behalf, never returned to any client, and can be deleted at any time in settings. Trace never collects payment card numbers, bank account numbers, government IDs, health data, private keys, or seed phrases.
Usage telemetry
To understand product usage, Trace records aggregate, category-level telemetry: which surface was used (web, API, MCP), a coarse client hint (e.g. "claude", "chatgpt"), input type (e.g. "base_tx_hash"), result and diagnosis codes, latency, and — for unsupported inputs — a format category (e.g. "looks like a Tron address"). Telemetry never includes the identifiers themselves, wallet addresses, transaction hashes, prompts or conversation content, or credentials.
Sharing
Trace does not sell data and does not share data with third parties, with these operational exceptions: identifiers you submit are necessarily sent to the relevant data sources to answer your request (public blockchain RPC endpoints; Bridge or Circle when you have connected them), and the service is hosted on Vercel, whose infrastructure processes requests in transit. A trace is visible to others only if you explicitly create a public share link; share links are unguessable and contain no workspace metadata, and can be effectively revoked by deleting the trace.
Retention and control
Workspace traces, provider connections, and API keys persist in a managed Postgres database until you delete them (settings provide deletion for all three). Aggregate telemetry contains no identifiers and is retained in operational logs. To request deletion of an account and all its data, contact us at the address below.
Contact
Questions or requests: soren@iverson.inc. See also the documentation for exactly what each endpoint does.