Version 1.0 · Effective: July 14, 2026 · Entity: AiTrade LLC
Local-first by design. RailCall is architected to minimize data transmission. Your code, API keys, and action receipts stay on your machine. This policy explains what limited data we do collect and why.
When you create an account: email address, password (hashed), account ID, and billing details if you subscribe to a paid plan.
To confirm an active paid seat, RailCall sends a blind validation ping:
The free single-seat tier does not validate seats and sends no pings.
If you use server-side compose (instead of BYOK/local model):
If you contact us (Discord, email, GitHub), we retain the content you send for support purposes.
We may use third-party processors for: payment processing (Stripe), hosting (AWS/GCP), analytics (privacy-respecting tools), and email delivery. These processors are bound by confidentiality and data protection terms.
When you approve an action to a connected service (Slack, GitHub, Stripe, etc.), you are directing that data flow. RailCall v1 architecture means:
We may disclose data if required by law, court order, or to protect our rights and safety.
To exercise these rights, contact us at privacy@railcall.ai.
We employ industry-standard security measures including encryption at rest and in transit, access controls, and regular security audits. However, no system is 100% secure. RailCall's local-first architecture minimizes attack surface by keeping sensitive data on your machine.
RailCall is not intended for individuals under 13 (or 16 in the EU). We do not knowingly collect data from children. If you believe a child has provided us with personal information, contact us immediately.
We may update this policy from time to time. Material changes will be announced via email or in-product notification. Continued use after changes constitutes acceptance.
Entity: AiTrade LLC · Governing law: Florida · Last updated: July 14, 2026
See also: Data Flow Disclosure · Terms of Service