Legal
Privacy Policy
Last updated: 22 July 2026. Applies to the TRACE service at trace-cloud.aioniq.ai.
Plain summary. For ordinary use TRACE holds nothing about you: your files live only in memory inside a private sandbox that is destroyed when your session ends, we don't log your searches, and your identity is a wallet address, not a name or email. The only place we process real personal data is if you voluntarily apply for the identity-verified persistent tier — described in section 4.
1. Who we are (data controller)
The data controller is Aioniq Corporation ("TRACE", "we"). For any privacy question or to exercise your rights, contact privacy@aioniq.ai.
2. Our privacy-by-design model
- Per-session sandbox. Each session runs in its own isolated container that holds all data in memory-backed storage — never written to disk. When you sign out, go idle, or the session times out, the entire sandbox and its contents are deleted and the resources recycled.
- No query logging. The gateway does not record request paths, search queries, or request/response bodies.
- No third-party identity provider and no tracking. You sign in by connecting a wallet and signing a message; we store no name, email, or profile, and we use no advertising or analytics trackers.
- EU data residency. The managed service runs in Google Cloud's europe-west1 (Belgium) region. Data processed in-session stays in the EU/EEA.
3. What we process for ordinary use, and why
| Data | Purpose | Legal basis (GDPR Art. 6) | Retention |
|---|---|---|---|
| Your uploaded files & searches (in-session) | To index and search your content at your request | Contract (Art. 6(1)(b)) — providing the service you asked for | In memory only; destroyed at session end |
| Wallet address (pseudonymous identity) | To authenticate your session and route it to your sandbox | Contract (Art. 6(1)(b)) | A hash is retained only if you hold the persistent tier; otherwise none |
| Agent payer address (x402) | To meter and authorize pay-per-request API calls | Contract (Art. 6(1)(b)) | Settlement receipts as required; no request content stored |
| Security events (Sentinel) | To detect and review abuse, attacks, or illegal-content signals | Legitimate interests (Art. 6(1)(f)) — securing the service | Encrypted to an offline key; retained only as long as needed for review |
A wallet address is pseudonymous data: on its own it does not identify you, but it may be personal data where it can be linked to you. We treat it accordingly.
4. The persistent (KYC) tier — the one place we process identity data
Durable storage of a library across sessions is optional and requires identity verification, because retaining user content carries legal responsibility. If you apply, we process the information you submit — legal entity name, entity type, formation documents, tax identifier, intended purpose, and data-locale/region.
- Purpose & legal basis: to verify your identity and meet our legal and anti-abuse obligations before granting durable storage — contract (Art. 6(1)(b)) and legal obligation / legitimate interests (Art. 6(1)(c),(f)). Where documents contain special-category or national-ID data, we rely on your explicit provision of them for this purpose.
- Where it lives: your application is encrypted in your browser's request to an operations key and stored only on an isolated review system outside the main cluster — it is never readable by the running service.
- Retention: kept only as long as needed to review and, if approved, to maintain your account and meet record-keeping obligations; deleted on request or when no longer required.
- Human review: a person reviews applications (typically within ~3 business days). You can withdraw an application at any time before approval.
5. Cookies
TRACE uses a single strictly-necessary cookie — a signed session
cookie that keeps you logged in after you connect your wallet. It contains no
personal data beyond a pseudonymous session identifier, is
HttpOnly/Secure/SameSite=Strict, and expires
with your session. We use no analytics, advertising, or tracking
cookies. Because the session cookie is strictly necessary to deliver a service you
requested, it does not require consent under the ePrivacy Directive — so TRACE
shows no cookie-consent banner. See the cookie notice.
6. International transfers
The managed service is hosted in the EU (Google Cloud europe-west1). Our infrastructure provider may process limited operational metadata under standard contractual clauses. In-session content is not transferred outside the EU/EEA by us.
7. Your rights
Under the GDPR you have the right to access, rectify, erase, restrict, port, and object to processing of your personal data, and to lodge a complaint with your supervisory authority. For ordinary use there is usually nothing to act on — in-session data is already ephemeral and we hold no profile. For the persistent tier, email privacy@aioniq.ai and we will respond within one month. Because a wallet is pseudonymous, we may ask you to prove control of the address (a signature) before acting on a request.
8. Security
Sandboxes have no network egress and make no remote calls; traffic is encrypted in transit (TLS 1.2+); at rest, in-session data lives only in encrypted-node memory; self-hosted libraries are sealed with AES-256-GCM. A passive monitor flags security events into an index that even the running service cannot read.
9. Data processing for business customers
If you use TRACE to process personal data of others (e.g. as a persistent-tier customer), we act as your processor for that content. A Data Processing Addendum (DPA) is available on request at privacy@aioniq.ai.
10. Children
TRACE is not directed to children under 16 and we do not knowingly process their personal data.
11. Changes
We will update this policy as the service evolves and revise the date above. Material changes will be surfaced in-product.
This policy describes how the service actually works and is provided in good faith. It is not legal advice; if you rely on TRACE for regulated processing, have your own counsel review it against your obligations.