Privacy Policy
Effective Date: February 16, 2026
1. Introduction
At VedaTrace, we take your privacy seriously. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our log observability platform (the "Service").
By accessing or using the Service, you agree to this Privacy Policy. If you do not agree with the terms of this Privacy Policy, please do not access the Service.
2. Information We Collect
2.1 Personal Information
We collect the following personal information when you create an account or use the Service:
- Account Information: Name, email address, and profile picture (from OAuth providers)
- Authentication Data: OAuth provider information (Google, GitHub) when you sign in via these methods
- Session Data: IP address and user agent information stored with your session for security purposes
- Payment Information: If you upgrade to a paid tier, billing information is processed by our third-party payment processors (Stripe/Polar). We do not store your credit card or payment details on our servers.
2.2 Log Data
You submit log data to the Service via our API. This log data may contain:
- Application logs, error messages, and stack traces
- Timestamps and service identifiers
- Any information you choose to include in your logs
Important: You are responsible for ensuring that the log data you submit does not contain sensitive personal information unless properly anonymized or encrypted. We automatically redact common patterns of secrets, passwords, and API keys before storage as a security measure.
2.3 Usage Data
We collect usage data to understand how users interact with our Service:
- API usage metrics (number of logs ingested, storage used)
- Feature usage patterns
- Account activity (projects created, API keys generated)
3. How We Use Your Information
We use the information we collect to:
- Provide the Service: Store, process, and display your log data; manage your account and API keys
- Improve the Service: Analyze usage patterns to enhance performance, features, and user experience
- Communicate with You: Send account-related emails, respond to inquiries, and provide support
- Ensure Security: Detect and prevent unauthorized access, fraud, and abuse
- Analytics: We use PostHog for product analytics to understand how users navigate and use the Service, helping us make data-driven improvements
4. Data Sharing and Disclosure
4.1 Third-Party Service Providers
We share data with the following third-party service providers to operate and improve the Service:
- Cloudflare: Provides infrastructure hosting (Workers, D1 database, R2 object storage). Your data is stored on Cloudflare's global network.
- Google: Used for OAuth authentication. When you sign in with Google, we receive your name, email, and profile picture.
- GitHub: Used for OAuth authentication. When you sign in with GitHub, we receive your username, email, and profile picture.
- PostHog: Analytics platform for understanding product usage. Data is anonymized before analysis.
- Stripe/Polar: Payment processing for paid subscriptions. We do not store payment information.
4.2 Legal Requirements
We may disclose your information when required by law, regulation, or legal process, or when necessary to:
- Protect our rights, property, or safety
- Enforce our Terms of Service
- Respond to claims or legal requests
4.3 Business Transfers
In the event of a merger, acquisition, or sale of all or a portion of our assets, your information may be transferred as part of that transaction. We will notify you before such transfer.
5. Data Storage and Security
5.1 Data Storage
Your data is stored on Cloudflare's infrastructure, which operates globally. This means your information may be processed and stored in various countries around the world. By using the Service, you consent to such international transfers.
5.2 Security Measures
We implement industry-standard security measures to protect your data:
- Encryption: Data is transmitted over HTTPS/TLS. Log data at rest is stored with encryption.
- API Key Hashing: API keys are hashed using SHA-256 before storage.
- Automatic Secret Redaction: We automatically detect and redact passwords, secrets, and API keys from logs before they are stored.
- Access Controls: Access to personal data is restricted to authorized personnel only.
5.3 Security Disclaimer
No method of data transmission over the Internet or electronic storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.
6. Data Retention
We retain your information as follows:
- Account Data: Retained while your account is active and for up to 30 days after account deletion
- Log Data: Retained until you delete it or your account is deleted. You can delete individual logs or all logs through your account settings
- Session Data: Retained for the duration of your session and up to 30 days thereafter for security purposes
- Analytics Data: Anonymized analytics data may be retained indefinitely in aggregated form
7. Your Rights and Choices
7.1 GDPR Rights (European Union Users)
If you are located in the EU or UK, you have the following rights under the General Data Protection Regulation (GDPR):
- Right to Access: You can request a copy of the personal data we hold about you
- Right to Rectification: You can request correction of inaccurate personal data
- Right to Erasure: You can request deletion of your personal data ("right to be forgotten")
- Right to Restrict Processing: You can request that we limit how we process your data
- Right to Data Portability: You can request a copy of your data in a structured, machine-readable format
- Right to Object: You can object to processing based on legitimate interests or for direct marketing
- Right to Withdraw Consent: You can withdraw consent at any time for processing based on consent
7.2 CCPA Rights (California Residents)
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA):
- Right to Know: You can request disclosure of the categories and specific pieces of personal information we collect
- Right to Delete: You can request deletion of your personal information
- Right to Opt-Out: You can opt out of the sale of your personal information (we do not sell your data)
- Right to Non-Discrimination: We will not discriminate against you for exercising your rights
7.3 How to Exercise Your Rights
To exercise any of these rights, please contact us at: vedatrace@gmail.com
We will respond to your request within 30 days. You may also delete your account through your account settings, which will delete your personal data as described above.
8. Cookies and Tracking Technologies
We use cookies and similar tracking technologies for the following purposes:
- Essential Cookies: Required for authentication and session management
- Analytics Cookies: PostHog uses anonymized tracking to analyze Service usage
You can control cookies through your browser settings. However, disabling essential cookies may prevent you from using certain features of the Service.
9. Children's Privacy
The Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children under 18. If you become aware that a child has provided us with personal information without parental consent, please contact us. If we discover that we have collected data from a child under 18 without parental consent, we will delete such information promptly.
10. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. These countries may have different data protection laws than your country.
We ensure appropriate safeguards are in place for international transfers, including:
- Standard Contractual Clauses approved by the European Commission
- Data processing agreements with third-party service providers
- Ensuring Cloudflare's compliance with applicable data protection frameworks
11. Third-Party Links
The Service may contain links to third-party websites, services, or applications. We are not responsible for the privacy practices or content of these third parties. We encourage you to review the privacy policies of any third-party sites you visit.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the updated policy on this page and updating the "Effective Date" above.
Your continued use of the Service after such changes constitutes acceptance of the updated Privacy Policy.
13. Contact Information
If you have any questions, concerns, or requests regarding this Privacy Policy, please contact us at:
Email: vedatrace@gmail.com
14. Data Controller
The data controller for your personal information is:
VedaTrace
Accra, Ghana
Email: vedatrace@gmail.com
