Legal

Privacy Policy

Your privacy matters. This policy explains what data Trappr collects, why we collect it, and how we protect it.

Effective date: July 1, 2026  ·  Trappr Labs, Inc.

1. Who We Are

Trappr Labs, Inc. ("Trappr," "we," "us," or "our") operates the Trappr platform — a zero-trust AI agent security service. Our registered address is in the State of Delaware, United States. For privacy inquiries, contact us at hello@trappr.io.

This Privacy Policy applies to data collected through trappr.io, the Trappr dashboard, APIs, and all related services (collectively, the "Service").

2. Data We Collect

2.1 Account and Identity Data

When you create an account, we collect your name, email address, and password (stored as a hash). If you sign in via a third-party identity provider (e.g., Google), we receive basic profile information from that provider.

2.2 Workspace and Configuration Data

To provide the Service, we store your workspace configurations, connected platform credentials (encrypted at rest — see Section 8), workflow baseline fingerprints, agent registrations, canary token assignments, DLP rule dictionaries, and alert channel settings.

2.3 LLM Gateway Request Logs

When you route AI traffic through the Trappr gateway, we log request metadata including: timestamps, model provider and model name, token counts, latency, cost estimates, and DLP event flags. We do not store raw LLM responses by default. Prompt content may be logged for DLP analysis purposes only, subject to your DLP configuration.

DLP Masking: When DLP masking is enabled, Trappr intercepts your LLM request, replaces sensitive patterns (PII, custom terms, API keys, etc.) with masked tokens before the request reaches the LLM provider, and unmasks the response before returning it to your application. Trappr processes this data in-flight; masked content is not stored in unmasked form.

2.4 Agent Fingerprints and Execution Data

We store cryptographic fingerprints (hashes) of your registered workflows and agents, used to detect tampering. We also store execution lifecycle records: start/end times, execution token identifiers, heartbeat timestamps, and completion status. Raw workflow content is not stored beyond what is necessary to compute and compare hashes.

2.5 Canary Token Events

When a canary token fires, we log the triggering request metadata including timestamp, source IP address, user-agent string, and the token identifier. This data is used to generate incident records and alerts.

2.6 Usage Metrics

We collect usage metrics including feature usage frequency, API call volumes, error rates, and plan consumption data. These are used for billing, capacity planning, and improving the Service.

2.7 Automatically Collected Data

When you use the Trappr dashboard or website, we automatically collect browser type, operating system, referring URLs, pages visited, and IP addresses. We may use cookies and similar technologies for session management and analytics.

3. How We Use Your Data

We use the data we collect to:

  • Provide, operate, and maintain the Service
  • Detect workflow tampering and generate security incidents
  • Monitor canary token triggers and deliver alerts
  • Apply DLP masking and unmasking in real time
  • Route and log LLM gateway requests
  • Authenticate you and maintain your session
  • Process payments and enforce subscription limits
  • Send transactional communications (incident alerts, billing notices, account updates)
  • Improve detection accuracy and platform performance
  • Respond to support requests
  • Comply with legal obligations

We do not sell your personal data. We do not use your data to train external AI models without your explicit consent.

4. Data Retention

We retain data as follows:

  • Account data: Retained for the duration of your account plus 30 days after deletion, unless legal obligations require longer retention.
  • Gateway request logs: Retained for 90 days by default on free and Business plans. Enterprise plans may configure custom retention periods.
  • Incident records and canary event logs: Retained for 12 months by default.
  • Execution tracking records: Retained for 90 days by default.
  • Workflow fingerprints (hashes): Retained for the lifetime of the registered agent or until manually deleted.
  • Billing records: Retained for 7 years to comply with financial recordkeeping requirements.

You may request earlier deletion of specific data categories subject to our legal obligations. See Section 7 for how to exercise data rights.

5. Third-Party Processors

We share your data with third-party service providers only to the extent necessary to provide the Service. Our primary processors include:

  • Clerk (Identity and Authentication): Clerk processes your login credentials, session tokens, and multi-factor authentication. Clerk acts as a sub-processor subject to its own DPA and privacy policy.
  • Upstash (Rate Limiting and Caching): Upstash Redis stores rate limit counters and ephemeral session data. Data stored in Upstash is transient and expires automatically.
  • PostgreSQL Database Provider: Your workspace data, agent fingerprints, gateway logs, and incidents are persisted in a PostgreSQL database. Data is encrypted at rest on the infrastructure level.
  • Email Providers (Gmail SMTP / Resend): Used to deliver alert notifications and transactional emails. Alert message content is transmitted to these providers.
  • Slack: If you configure Slack alerts, incident notification payloads are transmitted to Slack via their API.
  • LLM Providers (OpenAI, Anthropic, Google, Mistral, etc.): When you route traffic through the Trappr gateway, requests are forwarded to your configured LLM provider. DLP masking, if enabled, is applied before forwarding. Your use of these providers is subject to their respective terms.
  • Payment Processors: Billing and payment data is handled by our payment processor. Trappr does not store raw payment card numbers.

We require all processors to maintain appropriate security and confidentiality obligations and to process data only on our documented instructions.

6. Data Security

We implement technical and organizational security measures appropriate to the sensitivity of your data, including:

  • AES-256-GCM encryption for all stored provider API keys and sensitive credentials
  • Encryption at rest for all database storage
  • TLS/HTTPS for all data in transit
  • API key scoping — agent API keys have limited access by design
  • Rate limiting to prevent credential stuffing and abuse
  • Access controls and role-based permissions within workspaces

Despite these measures, no system is 100% secure. In the event of a data breach that affects your personal information, we will notify you as required by applicable law.

7. Your Rights (GDPR and Applicable Law)

Depending on your jurisdiction, you may have the following rights regarding your personal data:

  • Right of Access: Request a copy of the personal data we hold about you.
  • Right to Rectification: Request correction of inaccurate or incomplete personal data.
  • Right to Erasure ("Right to be Forgotten"): Request deletion of your personal data, subject to legal retention obligations.
  • Right to Data Portability: Request an export of your data in a structured, machine-readable format.
  • Right to Restrict Processing: Request that we limit processing of your data in certain circumstances.
  • Right to Object: Object to processing of your personal data for direct marketing or legitimate interest purposes.
  • Right to Withdraw Consent: Where processing is based on consent, withdraw that consent at any time.

To exercise any of these rights, contact us at hello@trappr.io. We will respond within 30 days. You also have the right to lodge a complaint with your local data protection authority.

8. Encryption of Provider Credentials

Provider API keys (e.g., OpenAI, Anthropic, Google API keys) that you store in Trappr are encrypted at rest using AES-256-GCM. The encryption key is derived from your account's authentication secret and is never stored in plaintext. Keys are decrypted in memory only when needed to forward a gateway request and are not written to logs or external storage in unencrypted form.

9. Cookies and Tracking

We use essential cookies for session management (authentication tokens, CSRF protection). We may use analytics cookies to understand how the Service is used. You can configure cookie preferences in your browser settings. Disabling essential cookies will prevent you from using the authenticated dashboard.

10. International Data Transfers

Trappr Labs, Inc. is based in the United States. If you access the Service from outside the United States, your data may be transferred to and processed in the United States or other countries where our processors operate. We rely on appropriate safeguards (such as Standard Contractual Clauses for EU data subjects) for such transfers where required by applicable law.

11. Children's Privacy

The Service is not directed to individuals under the age of 16. We do not knowingly collect personal data from children under 16. If you believe we have inadvertently collected such data, please contact us immediately.

12. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the effective date and notify you via email or a notice in the dashboard. Continued use of the Service after such notice constitutes your acceptance of the updated policy.

13. Contact

For privacy-related questions, data requests, or to report a concern, contact:

Trappr Labs, Inc.
hello@trappr.io

For security vulnerability disclosures, see our Security page.