Back

Privacy Policy

Effective: October 4, 2026 · Version 2.2

1. Who We Are

TraptureIQ is operated by Techtrapture Private Limited, a company incorporated under the Companies Act, 2013 and registered in India. This Privacy Policy explains what personal information we collect, why we collect it, and how you can control it when you use the TraptureIQ platform, website, and APIs (the “Service”).

Techtrapture Private Limited is responsible for the personal data processed through the Service and is committed to handling it in accordance with applicable privacy laws. If you do not agree to this policy, do not use the Service.

Techtrapture Private Limited

S. No. 18/11/1 & 18/11/4, S-202, Spot 18 Mall, Kalewadi,

Pune City, Maharashtra, India – 411017

Email: legal@techtrapture.com

2. Information We Collect

We collect information in three ways:

  • You provide it: your email address and display name via Google sign-in; prompts, parameters and configuration you save in the Service; messages to our support team.
  • Your agents send it: the Service receives OpenTelemetry traces, logs and metrics from AI agents you operate. See section 4. This is the most sensitive category and you control how much of it we receive.
  • Automatically, on our website: the pages you visit, the site that referred you, campaign tags in the link you followed, your browser’s user-agent string, and the country our load balancer places the request in. We do not store your IP address for website analytics, the country is derived at the network edge and the address is discarded.
  • Automatically, in server logs: ordinary operational logs of requests to our servers, which do include the originating IP address. These are used to run and secure the Service.
  • Third parties: Google provides your verified email and display name on sign-in and, with your permission, temporary read-only access to your Google Cloud resources (see section 3). Razorpay provides payment and subscription status. We never receive or store card numbers or bank details.

We use secure identity tokens for session management. We do not use cookies for analytics, and we do not use advertising pixels or cross-site tracking. Our website stores two random identifiers in your browser’s local storage to distinguish one visit from another; they are generated on your device, are not derived from any device or browser characteristic, cannot identify you, and are not shared with anyone. Clearing your browser storage removes them.

3. Google User Data

You sign in to TraptureIQ with your Google account. At sign-in we ask Google for the following permissions (OAuth scopes), and Google shows you this list before you agree:

  • Your email address and basic profile (openid, email, profile): your verified email address and display name. We use them to create your account, identify you, show who is a member of a tenant, and send you the transactional email described in section 5.
  • Read-only access to Google Cloud (https://www.googleapis.com/auth/cloud-platform.read-only): used only to help you find and connect AI agents you already run on Google Cloud. This permission cannot create, change or delete anything in your Google Cloud account.

What we access with the Google Cloud permission, and why.

We call Google Cloud APIs on your behalf only when you use a feature that needs them, and we can only see resources your own Google account already has access to:

  • Your Google Cloud projects (Cloud Resource Manager): the list of projects you can access, so you can choose one in the agent picker.
  • Your deployed agents (Cloud Run and Vertex AI Agent Engine): the services and agents in the project and region you choose, so you can register one to monitor, evaluate or load-test.
  • Your agents’ logs (Cloud Logging): log entries for the agent you are viewing, so they can be shown next to its traces.

How we store it.

The access token Google issues for this permission is kept only in your browser’s session storage. It is sent to our servers with the requests that need it, used for that call to Google, and then discarded. We do not save it in our database or write it to our logs. Google limits it to about one hour, and closing the browser tab removes it.

Project lists, agent lists and log entries we fetch from Google are shown to you and are not stored. The only Google Cloud information we keep is what you choose to save: when you register an agent, we store its name, project, region and endpoint in your tenant so the Service can reach it.

How we share it.

We do not sell Google user data. We do not use it for advertising, and we do not share it with any third party except where required by law. We do not use it to develop, improve or train artificial intelligence or machine-learning models, including generalised models. TraptureIQ staff do not read it.

How to remove our access.

You can withdraw TraptureIQ’s access to your Google account at any time at myaccount.google.com/permissions. Features that need Google Cloud access will then ask you to sign in with Google again. To delete your TraptureIQ account and the data linked to it, see section 8.

TraptureIQ’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

4. Agent Telemetry, Prompts and Responses

Read this section before pointing an agent at the Service. Depending on how you configure your agent’s OpenTelemetry exporter, we may receive the full text of prompts sent to models and the responses returned, including any personal data, credentials or confidential information contained in them.

Agent frameworks decide what to put on a span. Google ADK, for example, attaches request and response bodies to spans unless content capture is switched off. When those bodies reach us we store them so you can inspect a trace, and they are visible to anyone you have added to that tenant.

You control this. To send telemetry without prompt or response bodies:

  • Set ADK_CAPTURE_MESSAGE_CONTENT_IN_SPANS=false in your agent’s environment. Costs, token counts, latency, errors and the trace structure still arrive; the message bodies do not. (adk deploy cloud_run sets this to false by default.)
  • Leave OTEL_INSTRUMENTATION_GENAI_CAPTURE_MESSAGE_CONTENT unset, which is its default. This is a separate switch from the one above and both need to be off.
  • Check that your own agent code does not override them. ADK allows content capture to be set per request, and a per-request setting takes precedence over both environment variables above.
  • Redact or omit sensitive values before they reach the model, which is good practice regardless of observability.

We do not read your telemetry except where you have explicitly granted a named TraptureIQ support engineer access to your tenant, which appears in your own member list and can be revoked by you at any time. We never use your prompts, responses or any other content to train models.

5. How We Use Your Information

We use your information solely to operate and improve the Service: signing you in, managing access, computing costs, storing traces, processing billing, and sending transactional emails such as tenant invitations and billing notices.

We may also email you about the Service itself (product updates, availability notices and launch announcements) at the address on your account or on a waitlist entry you submitted. We do not send third-party advertising and we never pass your address to anyone else for their own marketing. To stop receiving these, email legal@techtrapture.com and we will remove you.

We do not sell, rent, or trade your personal information. We do not use it for advertising. Operating the Service requires a small set of trusted infrastructure and payment providers. These are not data-sharing partners. They act only on our instructions:

  • Google Cloud Platform: cloud infrastructure, hosting and storage
  • Google: sign-in, and read-only Google Cloud access you grant at sign-in (you authenticate directly with Google; what we receive and how we use it is set out in section 3)
  • Razorpay: payment processing; we never see your card or bank details. Governed by Razorpay’s Privacy Policy
  • Google Vertex AI: used only when you run an evaluation that scores results with an LLM judge. In that case the outputs being evaluated, and the expected outputs you supplied, are sent to Google’s Gemini models for scoring. This is the one feature that sends your content outside our own systems, and it runs only when you start an evaluation. Cost analytics, traces, logs and the prompt library never do
  • Our email provider: Google Workspace or Microsoft 365, used to deliver transactional and service email. Your email address and the contents of those messages pass through it
  • Members of your tenant: anyone a Tenant Admin has added can see that tenant’s telemetry, including prompt and response bodies where captured

6. How We Protect Information

We use administrative and technical safeguards including:

  • Encryption in transit: all data is encrypted using TLS 1.2+ between your systems and our servers
  • Encryption at rest: all stored data is encrypted using AES-256
  • Tenant isolation: each tenant’s telemetry is stored in its own dedicated database, not a shared table filtered by an identifier. Another tenant’s data is not reachable from your connection
  • Authentication: every request is verified against a secure identity token or a hashed API key; key plaintext is shown once at creation and never stored
  • Access control: Tenant Admin and Tenant User roles determine what each member may do. TraptureIQ staff have no standing access to tenant data through the Service. There is no administrator view of your telemetry and no internal override. Support access is granted by you, appears in your own member list, and is revocable by you at any time. A small number of authorised engineers necessarily hold administrative credentials to the underlying database infrastructure in order to operate it; they do not use them to read customer content
  • Sensitive data protection: platform credentials and stored secrets are protected using managed secret vaults and envelope encryption, and are never stored in plain text

Physical infrastructure security is managed by Google Cloud Platform (ISO 27001, SOC 2 certified). Security is a shared responsibility between you and us. No system is 100% secure, and we cannot guarantee absolute security. In the event of a data breach affecting your personal data, we will notify you without undue delay and as soon as reasonably practicable after becoming aware, in accordance with applicable law.

7. Data Storage & Cross-Border Transfer

Techtrapture Private Limited is incorporated in India. To deliver the Service globally, your data may be stored and processed outside India, including in the United States, using reputable cloud infrastructure providers. By using the Service, you consent to this transfer.

We ensure that any such transfer is subject to appropriate safeguards consistent with applicable law.

8. Data Retention & Deletion

Deleting a tenant in the Service does not erase its data. It deactivates the tenant and removes it from your console, while its stored telemetry is retained. This is deliberate: a tenant holds your traces and prompt bodies, and an accidental deletion must not be unrecoverable. If you want the data actually erased, ask us, as described below.

While your tenant exists, we retain the telemetry it has received (traces, logs, costs, evaluations, prompts and parameters) for as long as the tenant exists. We do not currently expire it on a schedule. If we introduce a retention period we will tell you before it applies to data you have already sent.

Permanent erasure on request. Email legal@techtrapture.com from the address on your account. Once we have verified the request, we will permanently erase your tenant databases and your account record within 30 days, and record that we have done so.

Backups. We take point-in-time backups of the database server as a whole, not of individual customers, so a single tenant cannot be surgically removed from a backup that has already been taken. Those backups are encrypted, are used only to restore the Service after a failure, and age out on their own schedule, after which no copy of your erased data remains.

What we keep after erasure. Billing and financial records, as required by law. A minimal audit record (your registered email address and the identifier of the tenant) retained to verify free-trial eligibility and for security auditing. This is never shared with third parties, never used for marketing, and is reachable only by authorised platform administrators.

9. Third-Party Service Providers

We work with a limited set of trusted third-party providers to operate the Service. Google provides our cloud infrastructure and hosting, sign-in, and (only when you run an LLM-judged evaluation) the Gemini models that perform the scoring. Razorpay handles payment processing. Google Workspace or Microsoft 365 delivers our email. These providers are bound by their own privacy policies and process data only as necessary to deliver their services. Section 5 sets out what each one receives.

10. Your Rights

You have the following rights in respect of your personal data:

  • Access: request a summary of the personal data we hold about you and how it is being processed
  • Correction: request correction of inaccurate or incomplete personal data
  • Deletion: request erasure of your personal data, subject to our legal retention obligations
  • Portability: request a copy of your personal data in a structured, machine-readable format
  • Withdrawal of consent: withdraw consent at any time, without affecting the lawfulness of prior processing
  • Grievance redressal: raise a complaint with our contact below if you believe your data rights have been violated

To exercise any of the above rights, email legal@techtrapture.com. We will respond within a reasonable time and in accordance with applicable law.

The Service is not directed at individuals under 18 years of age. We do not knowingly collect personal data from minors. If you believe a minor’s data has been submitted, contact us immediately for deletion.

11. Changes to This Policy

We may update this policy from time to time. When we make material changes, we will notify you within the Service or by email. The date at the top indicates the last revision. Continued use after changes constitutes acceptance.

12. Grievance Officer & Contact

For any concerns or complaints regarding the handling of your personal data, you may contact our designated point of contact:

Vishal Bulbule

Founder & Director, Techtrapture Private Limited

S. No. 18/11/1 & 18/11/4, S-202, Spot 18 Mall, Kalewadi,

Pune City, Maharashtra, India – 411017

Email: legal@techtrapture.com

We will make reasonable efforts to address grievances in a timely manner.

If you are not satisfied with our resolution, you may approach the Data Protection Board of India once constituted under the DPDPA, 2023.

Terms of Service · Privacy Policy