PRIVACY NOTICE
How TraceFi handles data.
This notice describes the data used to operate accounts, learning progress, Labs, Community, and security controls.
Last updated: July 21, 2026
Data TraceFi processes
- Account and authentication: email address, email-verification state, account identity, password credential records, and authenticated sessions. Passwords are not stored in plain text.
- Profile and access: username, selected avatar, profile visibility, role, permissions, and account or moderation status.
- Learning activity: Learn and Lab progress, attempts, completion records, points, and server-authoritative verification state.
- Saved work: notes, whiteboard or canvas data, and other learner state where a feature currently persists it.
- Community: posts, replies, edits, votes, reports, moderation actions, roles, badges, notifications, and reputation records.
- Runner operations: execution identifiers, status, timing, verifier version, result evidence, output digests, and limited operational metadata needed to run and verify Labs.
- Security and operations: request, rate-limit, authentication, authorization, administrative audit, protected-verifier, and service health records created to investigate abuse and operate TraceFi.
- Transactional email: email address and delivery metadata sent through Resend for messages such as verification and account-security email.
Why the data is used
TraceFi uses this information to authenticate users, preserve learning progress, verify Lab completion, operate Community features, deliver transactional email, enforce roles and moderation, prevent abuse, diagnose faults, and protect the service.
Sale, advertising, and analytics
TraceFi does not sell personal data. It does not currently build advertising profiles or use a third-party analytics product. Operational logs used for reliability and security are not advertising analytics.
Protection and retention
Access controls, server-side authorization, credential hashing, and operational logging reduce risk, but no online system is perfectly secure. Protected verifiers and other security controls may create logs when they evaluate a request.
Data is kept for as long as reasonably needed for the feature, account, security, moderation, integrity, backup, or legal purpose involved. TraceFi does not promise a fixed deletion schedule that the product does not yet enforce.
Correction and deletion requests
You may request correction or deletion through a configured channel on the Contact page. Some records may need to be retained or de-identified for legitimate security, fraud prevention, Community moderation, content integrity, backup, or legal needs.
Changes to this notice
This notice may be updated as TraceFi evolves. A revised stable “Last updated” date will identify material content changes; the date is not generated from your visit time.