Privacy Policy
Effective: June 2026
1. Scope and our role
This policy explains how TitleTrace, Inc. (“TitleTrace,” “we”) handles personal information. Our role depends on the data:
- Account & contact data (the information you give us to create and run an account) — we are the controller.
- The documents and data you upload for examination — we act as a processor on behalf of your firm, handling that content only on your instructions and under your customer agreement (and Data Processing Addendum, where applicable).
2. Information we collect
Account information — name, email address, organization name, role, and billing information when you create an account.
Uploaded content — the documents and data you submit for processing, and the findings and work product generated from them.
Usage data — logs and minimal analytics needed to operate, secure, and improve the service.
3. How we use information
4. Your document data
5. Connected cloud accounts (Google Drive and Microsoft OneDrive)
A workspace administrator may connect a Google Drive or Microsoft OneDrive account so that documents in folders they choose are kept in sync with their firm’s knowledge base. When an account is connected:
- What we access. We request read-only access to files (Google:
drive.readonly; Microsoft:Files.Read) and basic profile information (email address) used only to label the connection. We list and download files only from the folders the administrator explicitly connects. - What we do with it.Copies of those files are stored in the firm’s own isolated knowledge base and processed as described in Section 4. Synchronization is one-way: we never create, modify, or delete anything in the connected account.
- Credentials. Access tokens are encrypted at rest in a credential vault, are never exposed to the browser, and are deleted when the connection is removed (for Google, we also revoke the grant with Google). Access can additionally be revoked at any time from your Google security settings or Microsoft account portal.
- Limited Use.TitleTrace’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Data obtained through Google APIs is not used for advertising, is not sold, is not read by humans except with your permission or as necessary for security, support, or legal compliance, and is not used to develop, improve, or train generalized AI or machine-learning models.
6. Cookies and analytics
7. How we share information
We do not sell, rent, or trade your personal information or document data. We share data only with the sub-processors listed below (under data processing agreements), when required by law, or in connection with a merger or acquisition (subject to this policy).
8. Sub-processors
We rely on a small set of vetted infrastructure providers to operate the service. Each is bound by a data processing agreement; the current list is:
- Supabase — database, document storage, authentication (US).
- Vercel — application hosting and AI request routing (US).
- Railway — background processing and document-processing workers (US).
- Anthropic — AI model provider for reading, extraction, and cited analysis; does not train on data submitted through its commercial API (US).
- Resend — transactional and notification email (US).
We’ll provide notice of material changes to this list on request.
9. International data transfers
10. Data retention
11. Security
12. Your rights
Depending on where you live, you may have rights to access, correct, delete, export, or object to the processing of your personal information, and (under U.S. state laws such as the CCPA) to know what we collect and to opt out of any “sale” — which we do not do.
For account data, contact privacy@titletrace.io. For uploaded documents, requests are directed through the firm whose account holds them, since we process that content on the firm’s behalf.