← Back to home

Privacy Policy

Version 1.0 · Effective: July 14, 2026 · Entity: AiTrade LLC, a Florida limited liability company

Local-first by design. RailCall is architected to minimize data transmission. Your code, API keys, and action receipts stay on your machine. This policy explains what limited data we do collect and why.

What We Collect

1. Account Information

When you create an account: email address, password (hashed), account ID, and billing details if you subscribe to a paid plan.

2. Entitlement and seat validation (paid plans only)

Where a paid plan requires us to confirm an active entitlement or seat, that check is a blind validation call:

  • SHA-256 hash of your key + a nonce (no plaintext key)
  • No per-action data — no action names, no counts of what you run
  • No business data — we do not see message content, recipient addresses, or transaction amounts

Running the free local protocol involves no account, no entitlement, and no such call.

Counsel — unresolved across four pagesWhether this is a periodic outbound ping is genuinely unsettled in our own material. This page and the Data Flow Disclosure previously described it as recurring — “periodically, while a paid seat is active.” Terms of Service §25 records that the same description was not carried forwardfrom Terms v1.0, on the stated ground that it describes “a periodic outbound call that the trust page says does not happen,” and ToS §5.2 and §11.2 say the local engine has no runtime dependency on any service we operate. The frequency language is removed here rather than replaced with a guess, because for a privacy policy the honest failure mode is under-claiming precision, not inventing it. Resolve against the code and restate the actual trigger and interval on this page, the Data Flow Disclosure, the Security page, and the trust page together. If the call does happen periodically, say so plainly — a disclosed blind ping is defensible; an undisclosed one is not.

3. Hosted Compose (Optional)

If you use server-side compose (instead of BYOK/local model):

  • Your natural-language description is transmitted to our gateway
  • Gateway forwards it to the model provider (zero-retention)
  • We do not log or store your description
  • Alternative: Use BYOK or a local model to avoid this entirely

4. Technical & Diagnostic Data

  • CLI version, OS type (for compatibility)
  • Error logs (if you opt in to crash reporting)
  • Web analytics (page views, no personally identifiable tracking)

5. Support & Communication

If you contact us (Discord, email, GitHub), we retain the content you send for support purposes.

What We Do NOT Collect

Your API keys: Stored locally in a 0600 vault, never transmitted to AiTrade.
Connected-service action content (v1): Flows directly from your machine to the provider you keyed (Slack, Stripe, etc.) — never transits RailCall servers.
MCP session data: Loopback/stdio only. Nothing leaves your machine to reach us.
Receipts: Ed25519-signed and stored locally for offline verification. Not transmitted to AiTrade.
Your codebase or business data: Remains on your machine unless you explicitly choose hosted compose.

How We Use Your Data

  • Billing: entitlement and seat validation confirms an active paid plan — it counts no usage and carries no per-action data
  • Service delivery: Account info enables login, key management, and billing
  • Support: Correspondence retained to resolve issues
  • Product improvement: Aggregate, anonymized usage patterns (no individual action content)
  • Legal compliance: As required by law

Data Sharing & Third Parties

Service Providers

We use third-party processors for payment processing, hosting, authentication, and email delivery. These processors are bound by confidentiality and data protection terms. The current, named list is published at railcall.ai/trust/subprocessors and is the authoritative version — it names Render, WorkOS, Stripe, Resend, GitHub, and Cloudflare. We maintain it there rather than here so that one page changes when a processor changes, instead of three drifting apart.

Counsel — GDPR Art. 13(1)(e) / Art. 28This paragraph previously named “AWS/GCP” as our hosting processor, which does not appear on the published subprocessor list and, as far as this review could determine, is not accurate. Naming processors we do not use — and omitting ones we do — is a disclosure defect, not a copy problem. Vendor names are removed above and the reader is pointed at the single maintained list. Confirm that list is complete, that it names the downstream inference provider used by hosted compose, and that a mechanism exists to notify customers of changes to it.

Connected Services (Your Direction)

When you approve an action to a connected service (Slack, GitHub, Stripe, etc.), you are directing that data flow. RailCall v1 architecture means:

  • Data goes directly from your machine to the provider
  • AiTrade is not a processor or sub-processor of that content
  • Each provider is governed by its own terms and privacy policy

Legal Obligations

We may disclose data if required by law, court order, or to protect our rights and safety.

Your Rights (GDPR, CCPA, UK GDPR, LGPD)

  • Access: Request a copy of your data
  • Correction: Update inaccurate information
  • Deletion: Request account and data deletion (subject to legal retention)
  • Portability: Receive your data in a structured format
  • Objection: Object to certain processing activities
  • Withdrawal of consent: Revoke consent for optional data collection

To exercise these rights, contact us at privacy@railcall.ai.

Data Retention

  • Account data: Retained while account is active, plus 90 days after deletion (unless legal hold applies)
  • Billing records: Retained for tax/audit requirements (typically 7 years)
  • Entitlement and seat validation: carries no usage counts and is not retained
  • Support correspondence: Retained as long as relevant for service improvement

Security

We employ industry-standard security measures including encryption at rest and in transit and role-based access controls. No system is 100% secure. RailCall's local-first architecture minimizes attack surface by keeping sensitive data on your machine. Our security posture is described in full, including what we do not hold, on the Security page.

CounselThis paragraph previously claimed “regular security audits.” No audit or penetration-test artifact is published or listed on the trust page, and the Security page made a parallel claim to annual third-party penetration tests that is withdrawn in the same change. Unbacked assurance language is removed rather than softened. Restore a specific claim only when there is a report behind it, and say who performed it and when.

Children's Privacy

RailCall is not intended for individuals under 13 (or 16 in the EU). We do not knowingly collect data from children. If you believe a child has provided us with personal information, contact us immediately.

Changes to This Policy

We may update this policy. We will publish the updated version with a new version number and effective date, keep the prior version accessible, and give at least 30 days’ notice of a material change — by in-product notice in the dashboard, by email to the address on your account if you have given us one, and by a dated entry on this page. Continued use after the effective date constitutes acceptance.

Why all three, and not just email. Most people who run RailCall have no account and have never given us an email address, so email alone cannot reach them — and a term nobody could have seen is a term that binds nobody. This policy concerns data we actually hold, which means we have a way to reach you; the dated public entry is the backstop for everyone else. Terms of Service §21.2 and §21.3 use the same mechanism.

EU and UK Representatives

AiTrade LLC is established in the United States and offers the Services to individuals in the European Economic Area and the United Kingdom.

Counsel — required, currently absentGDPR Art. 27 requires a designated EU representative, and the UK GDPR requires a UK representative, for a controller established outside those territories that offers services to people inside them. Neither is named on any page today, and Art. 13(1)(a) requires the representative’s identity and contact details to appear in this notice. A DPA is offered at Terms §12.5, so the processor relationship is already contemplated. Appoint both and insert the names and addresses here. Related and also outstanding: the Art. 13 identity block still needs the controller’s registered address. Counsel supplied the state of formation on 2026-08-27 and the Data Controller block below now reads “AiTrade LLC, a Florida limited liability company”; the registered business address was not supplied, no published page carries one, and we have not invented one.

Contact

Data Controller: AiTrade LLC, a Florida limited liability company

Email: privacy@railcall.ai

Governing Law: Florida, USA

Entity: AiTrade LLC, a Florida limited liability company · Governing law: Florida · Last updated: July 14, 2026
See also: Data Flow Disclosure · Terms of Service