Privacy Policy
At TrailKit, trust is foundational. Our agents act on your behalf across the tools your work already lives in — so we hold ourselves to a high bar on how we collect, use, and protect what you share with us.
Effective Date: May 31, 2026
Our Commitment to Your Privacy
TrailKit ("TrailKit," "we," "us," or "our") is committed to protecting your privacy and ensuring the security of your information. This Privacy Policy describes our practices with respect to Personal Data we collect from or about you when you use our website, applications, and services (collectively, "Services").
This Privacy Policy is referenced by our Terms of Service. By using the Service, you agree to the practices described here.
The Service is currently operated by its founder pending the activation of TrailKit, Inc. This policy will be reassigned to the corporate entity on its activation without material change to your rights.
1. Personal Data We Collect
We collect personal data relating to you ("Personal Data"). As an agent service that acts on your behalf across the tools you already use, our Services are powered by your context and actions, including the content you make available to us via our integrations with your third-party services. Depending on how you use the Services, the data we collect and process on your behalf can include any data you choose to make available to our Services.
We also collect Personal Data directly from you as follows:
Personal Data You Provide: We collect Personal Data from you when you create an account, use the Service, or otherwise communicate with us:
- Account information: When you create an account with us, we collect information associated with your account, including your name, contact information, and (where you authenticate via OAuth) the limited profile fields the identity provider returns.
- User Content: In addition to Personal Data we automatically collect via integrations you choose to set up, we collect Personal Data you directly provide as input to our Services, including your prompts, agent definitions, and other content you upload, such as files, images, and audio, depending on the features you use.
- Payment information: If you use our paid Services, we collect information needed to complete your transactions with us, including name, payment card information, and billing information. This information is processed by our payment service provider(s), which may handle your payment information in accordance with its or their own privacy policy(ies). We do not have access to your full payment card information.
- Communication Information: We may collect information when you contact us with questions or concerns and when you voluntarily respond to questionnaires, surveys, or requests for market research. Providing this information is optional.
- Other Information: We may also collect other information not specifically listed here, for which we will provide disclosure at the time of collection.
Personal Data We Automatically Receive from Your Use of the Services:
- Log Data: Information your browser or device automatically sends when you use our Services, including IP address, browser type and settings, date and time of your request, and how you interact with the Services.
- Usage Data: Information about your use of the Services, such as the features you use, the actions you take, the agents you create and run, your time zone, country, dates and times of access, user agent and version, and type of computer or mobile device.
- Authentication Tokens for Integrated Services: Encrypted OAuth tokens (or, where the vendor doesn't offer OAuth, API keys you paste) for the services you've chosen to integrate with the Service. These are used solely to perform the actions you've directed an agent to take.
- Agent Activity Records: A record of every action your agents take on your behalf — the messages they read, the tools they called, the data they returned — so you can audit their behavior in the dashboard.
- Device Information: Information about the device you use to access the Services, such as device name, operating system, device identifiers, and browser.
- Cookies and Similar Technologies: We use cookies and similar technologies to operate the Site, authenticate your session, gather usage data, and improve your experience. See §10 below.
Information we obtain from other sources:
- Third-party login information: When you link, connect, or log in to our Services with a third-party service (e.g., Google), you may direct the service to send us information controlled by that service or as authorized by you via your privacy settings on that service.
- Social media: When you interact with our pages on social platforms, you or the platforms may provide us with information through the platform, which we treat in accordance with this Privacy Policy.
- Other sources: We may obtain personal information from marketing partners, publicly-available sources, and data providers.
2. How We Use Personal Data
We use Personal Data to:
- Provide, analyze, and maintain the Service, for example to run agents you've set up and respond to messages you send;
- Improve and develop our Services and conduct research, for example to develop new product features;
- Communicate with you, including to send information about our Services and events;
- Prevent fraud, criminal activity, or misuse of our Service, and ensure the security of our IT systems, architecture, and networks; and
- Comply with legal obligations and legal process and to protect our rights, privacy, safety, or property, and/or that of you or other third parties.
Use of User Content for Service Improvement. By default, we do not use your User Content (your prompts, agent conversations, files, or content your agents read from integrated services) to train or refine AI models — ours or anyone else's. If you affirmatively opt in via your account settings, you may grant us permission to use your User Content to improve and develop our Services, including to train and refine our AI models. You can withdraw that opt-in at any time. Content sent to third-party AI model providers (e.g., Anthropic, OpenAI) to generate agent responses is handled under our commercial agreements with those providers, which restrict the providers' independent use of your content.
Aggregated Information. We may aggregate Personal Data and use the aggregated information to analyze the effectiveness of our Service, to improve and add features, and for other similar purposes. We may share aggregated information like general user statistics with prospective business partners.
Marketing. We may contact you to provide information we believe will be of interest to you. You may opt out of marketing emails by following the instructions in each promotional email or by contacting us. We will continue to send service-related emails regardless.
Our use of Personal Data we receive from Google Workspace APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Data from Google Workspace APIs is not used to train AI models regardless of any broader account-level setting.
3. Sharing and Disclosure of Personal Data
In certain circumstances we may share the categories of Personal Data described above with the following categories of third parties without further notice to you, unless required by law:
Vendors and Service Providers: To assist us in meeting business operations needs, we may share Personal Data with vendors and service providers, including providers of hosting and infrastructure services, AI model inference providers, payment processors, email and customer-support providers, and product-analytics services. These parties are bound by strict confidentiality agreements and may access, process, or store Personal Data only in the course of performing their duties to us.
At Your Direction: When you connect a third-party tool or direct an agent to contact one, we transmit the relevant content to that destination as needed to complete the task you've asked for.
Business Transfers: If we are involved in a merger, acquisition, financing due diligence, reorganization, bankruptcy, receivership, sale of all or a portion of our assets, or transition of service to another provider, your Personal Data may be shared in the diligence process and transferred to a successor or affiliate as part of that transaction.
Legal Requirements: If required to do so by law or in the good faith belief that such action is necessary to (i) comply with a legal obligation, including to meet national security or law enforcement requirements, (ii) protect and defend our rights or property, (iii) prevent fraud, (iv) act in urgent circumstances to protect the personal safety of users of the Services, or the public, or (v) protect against legal liability.
We do not sell, rent, or trade your Personal Data to third parties. We do not share phone numbers, SMS opt-in information, or the contents of SMS messages with third parties for marketing or promotional purposes.
4. Data Security
Your privacy and security are top priorities. We implement industry-standard security measures including:
- TLS 1.2 or higher for all data in transit
- AES-256 encryption at rest for stored data
- Envelope encryption of authentication tokens via AWS Key Management Service (KMS)
- Row-level security in our database, enforced at the application role so per-tenant isolation holds at the storage layer
- Least-privilege access controls for engineering staff; production access is audited and time-limited
- Centralized logging of administrative actions
- Regular security reviews of our infrastructure and application code
No system is perfectly secure. If you believe your account has been compromised, contact security@trailkit.ai immediately.
5. Vulnerability Disclosure
We welcome responsible security research. If you believe you've found a vulnerability in TrailKit, please report it to security@trailkit.ai. We acknowledge reports within 72 hours and work the fix on a private timeline before any public disclosure. We will not pursue legal action against researchers acting in good faith under these terms.
6. Data Retention
We keep Personal Data for as long as reasonably necessary for the purposes described in this Privacy Policy, while we have a business need to do so, or as required by law (e.g., for tax, legal, accounting, or other purposes), whichever is longer.
- Authentication tokens are deleted immediately when you disconnect the corresponding integration.
- Account data (conversations, agent definitions, files, activity records) is deleted within 30 days of account closure, except where retention is required by law.
- Billing records are retained for the period required by tax and accounting law (typically 7 years).
- Audit logs are retained up to 1 year for security and abuse investigations.
7. Your Rights
You have control over your Personal Data. Depending on your location and how you interact with our Services, you may request the following:
- Access your Personal Data and information about how we process it
- Delete your Personal Data from our records
- Correct or update inaccurate or incomplete Personal Data
- Export your Personal Data in a portable format
- Restrict or limit how we process your Personal Data
- Object to certain processing of your Personal Data
- Opt in to (or withdraw consent from) use of your User Content for service improvement (off by default; manage in your account settings)
- Withdraw consent where we rely on your consent for processing
- Lodge a complaint with your local data protection authority
How to Exercise Your Rights
To exercise any of these rights, contact us using the information in §13. We may request additional information to verify your identity before processing your request. You may designate an authorized agent to submit requests on your behalf, though we may require written permission and independent identity verification. We will not discriminate against you for exercising any of your privacy rights.
8. Legal Basis for Processing (EEA / UK Users)
If you are an individual in the European Economic Area (EEA), the United Kingdom (UK), or Switzerland, we collect and process information about you only where we have legal bases for doing so under applicable law. The legal bases depend on the services you use and how you use them. This means we collect and use your information only where:
- We need it to provide the Services, including to operate the Services, provide customer support and personalized features, and protect the safety and security of the Services (contract);
- It satisfies a legitimate interest (not overridden by your data protection interests), such as for research and development, to market and promote the Services, and to protect our legal rights and interests;
- You give us consent to do so for a specific purpose (e.g., authorizing a third-party integration); or
- We need to process your data to comply with a legal obligation.
Where required, we use Standard Contractual Clauses or equivalent safeguards to protect cross-border transfers of Personal Data to the United States, where TrailKit and its primary subprocessors operate. EU business users may request a Data Processing Agreement by contacting privacy@trailkit.ai.
9. Children's Privacy
Our Service is not directed to children under 17. TrailKit does not knowingly collect Personal Data from children under 17. If you have reason to believe a child under 17 has provided Personal Data to TrailKit through the Service, please contact us and we will endeavor to delete that information from our databases.
10. Cookies and Tracking
We use cookies and similar technologies to operate and administer the Service:
- Strictly necessary. Authentication and session cookies required for the Service to function. These cannot be disabled.
- Analytics. First-party analytics (PostHog) used to understand how the Service is used and improve it. This data is associated with your account but is not shared with advertisers or used for cross-site tracking.
We honor Global Privacy Control (GPC) signals.
11. Legal Compliance
TrailKit complies with applicable data protection laws and regulations, including the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA / CPRA), and other applicable state and federal privacy laws.
12. Changes to the Privacy Policy
The Service and our business may change from time to time. As a result we may change this Privacy Policy at any time. When we do we will post an updated version on this page and, where appropriate, notify you by in-app notification, email, or update on our website. By continuing to use our Service after we have posted an updated Privacy Policy, you consent to the revised Privacy Policy and practices described in it.
13. Contact Us
Have questions about privacy, security, or compliance? We're happy to talk.
- Privacy requests: privacy@trailkit.ai
- Security disclosures: security@trailkit.ai
- General inquiries: support@trailkit.ai
Mailing address: Available on request to the address above pending TrailKit, Inc. registration.