← Back to home

Privacy Policy

Version 1.0 · Effective: July 14, 2026 · Entity: AiTrade LLC

Local-first by design. RailCall is architected to minimize data transmission. Your code, API keys, and action receipts stay on your machine. This policy explains what limited data we do collect and why.

What We Collect

1. Account Information

When you create an account: email address, password (hashed), account ID, and billing details if you subscribe to a paid plan.

2. Seat Validation (Paid Plans Only)

To confirm an active paid seat, RailCall sends a blind validation ping:

  • SHA-256 hash of your key + a nonce (no plaintext key)
  • No per-action data — no action names, no counts of what you run
  • No business data — we do not see message content, recipient addresses, or transaction amounts

The free single-seat tier does not validate seats and sends no pings.

3. Hosted Compose (Optional)

If you use server-side compose (instead of BYOK/local model):

  • Your natural-language description is transmitted to our gateway
  • Gateway forwards it to the model provider (zero-retention)
  • We do not log or store your description
  • Alternative: Use BYOK or a local model to avoid this entirely

4. Technical & Diagnostic Data

  • CLI version, OS type (for compatibility)
  • Error logs (if you opt in to crash reporting)
  • Web analytics (page views, no personally identifiable tracking)

5. Support & Communication

If you contact us (Discord, email, GitHub), we retain the content you send for support purposes.

What We Do NOT Collect

Your API keys: Stored locally in a 0600 vault, never transmitted to AiTrade.
Connected-service action content (v1): Flows directly from your machine to the provider you keyed (Slack, Stripe, etc.) — never transits RailCall servers.
MCP session data: Loopback/stdio only. Nothing leaves your machine to reach us.
Receipts: Ed25519-signed and stored locally for offline verification. Not transmitted to AiTrade.
Your codebase or business data: Remains on your machine unless you explicitly choose hosted compose.

How We Use Your Data

  • Billing: Seat validation pings confirm an active paid seat — they count no usage and carry no per-action data
  • Service delivery: Account info enables login, key management, and billing
  • Support: Correspondence retained to resolve issues
  • Product improvement: Aggregate, anonymized usage patterns (no individual action content)
  • Legal compliance: As required by law

Data Sharing & Third Parties

Service Providers

We may use third-party processors for: payment processing (Stripe), hosting (AWS/GCP), analytics (privacy-respecting tools), and email delivery. These processors are bound by confidentiality and data protection terms.

Connected Services (Your Direction)

When you approve an action to a connected service (Slack, GitHub, Stripe, etc.), you are directing that data flow. RailCall v1 architecture means:

  • Data goes directly from your machine to the provider
  • AiTrade is not a processor or sub-processor of that content
  • Each provider is governed by its own terms and privacy policy

Legal Obligations

We may disclose data if required by law, court order, or to protect our rights and safety.

Your Rights (GDPR, CCPA, UK GDPR, LGPD)

  • Access: Request a copy of your data
  • Correction: Update inaccurate information
  • Deletion: Request account and data deletion (subject to legal retention)
  • Portability: Receive your data in a structured format
  • Objection: Object to certain processing activities
  • Withdrawal of consent: Revoke consent for optional data collection

To exercise these rights, contact us at privacy@railcall.ai.

Data Retention

  • Account data: Retained while account is active, plus 90 days after deletion (unless legal hold applies)
  • Billing records: Retained for tax/audit requirements (typically 7 years)
  • Seat validation pings: Carry no usage counts and are not retained; billing is per seat
  • Support correspondence: Retained as long as relevant for service improvement

Security

We employ industry-standard security measures including encryption at rest and in transit, access controls, and regular security audits. However, no system is 100% secure. RailCall's local-first architecture minimizes attack surface by keeping sensitive data on your machine.

Children's Privacy

RailCall is not intended for individuals under 13 (or 16 in the EU). We do not knowingly collect data from children. If you believe a child has provided us with personal information, contact us immediately.

Changes to This Policy

We may update this policy from time to time. Material changes will be announced via email or in-product notification. Continued use after changes constitutes acceptance.

Contact

Data Controller: AiTrade LLC

Email: privacy@railcall.ai

Governing Law: Florida, USA

Entity: AiTrade LLC · Governing law: Florida · Last updated: July 14, 2026
See also: Data Flow Disclosure · Terms of Service