Data Handling and Security

Traket requires access to selected business data to produce margin analysis. This can include customer identifiers, subscription records, payment summaries, vendor transactions, usage events, model names, token units, costs, and sanitized metadata.

Traket never collects or stores prompts, messages, model outputs, files, tool arguments, provider headers, API keys, or full provider request and response bodies. There is no request-capture mode. Input and output token units are numeric counts, not content.

Access is used to provide the service, troubleshoot imports, secure the platform, and support requested workflows. We do not share your data outside those purposes unless required by law or by vendors necessary to operate the platform.

Traket subscription payments use Stripe-hosted Checkout, so card numbers and CVCs do not enter Traket. Trial-abuse controls retain only a server-keyed HMAC of Stripe's card fingerprint; they do not store the raw fingerprint, IP-based identity, or a device fingerprint.

Storage and authentication are handled through third-party providers such as Supabase. Traket will use reasonable security practices, but no hosted system can be guaranteed immune from unauthorized access, compromise, outages, or data loss.

You are responsible for deciding what data to connect and for keeping credentials, SDK write keys, exports, and local environments secure.