Your data and privacy
Summary
- Who’s responsible
- Transica is operated by an individual based in India.
- Contact
- support@transica.dev
- Selling your data
- Never
- Cookies
- Only to sign in and open your reports
- Account deletion
- Within 30 days of your request
- Last updated
- 1 October 2026
| Data | What it is | How long we keep it |
|---|---|---|
| Free page scans | The page address, any phrase or link you ask us to find, a copy of the page’s HTML and text, and the results. | 7 days, or 30 days if you attach the report to a message. Delete it from its page any time. |
| Messages to us | Your name, email address, website and message. | 90 days. Email to support@transica.dev or hello@transica.dev stays in our inbox while we need it to help you. |
| Email sign-ups | Your email address, for a report link or the product updates you asked for. | A report link lasts as long as its report. Unconfirmed update sign-ups: 7 days. Confirmed: 12 months, or until you unsubscribe. |
| Your account | Your email address, your organisation, its members and roles, and a log of who changed what. | While your account exists. |
| Sites and setup | Site addresses, how you verified them, and your saved tasks and settings. | While your account exists. |
| Test results | Tasks, pass or fail, each step the agent took (action, page address, the agent’s notes, timing), costs, trends and comparisons. | While your account exists, or until you delete the report. |
| Step screenshots | A picture of your page at each step of an agent test. | 12 months on paid plans, 90 days on Free. On Free, older screenshots are deleted, including ones taken on a paid plan. |
| Captured API traffic | During a test: which of your site’s endpoints were called and the shape of each request, without values. Plus a few sample bodies. | Sample bodies: 30 days. The endpoint list stays with the test results. |
| Uploaded access logs and edge records | The log file itself only until we’ve read it (minutes), then it’s deleted. From it we keep: request, visit, error and block counts per day and per kind of visitor; which named bots visited and whether their addresses matched the vendor’s published list; the most-requested pages; and up to 200 sample visits (pages in order, status codes, times). Never IP addresses: sample visits carry a code made with a one-time key we throw away. (When a vendor’s DNS confirms an address is its crawler, we keep a hash of that address for 7 days so we don’t look it up again.) Query strings are dropped except a few harmless ones such as page and language, and emails or long codes in page addresses are removed. Records your edge Worker sends (time, page, status, user agent and address of requests from AI agents, crawlers and scripts, never people’s browsing) are read as they arrive and kept the same way. Visits from the edge are linked with a key that exists for one day and is deleted two hours after that day ends. Ingest keys are stored only as a hash. | 90 days from the upload or from the day the records arrived, or until you delete the upload. |
| Test accounts and connector keys | The sign-in details or server token you give us, with passwords and tokens encrypted. | Test accounts: until you remove them. Connector keys: until you replace them or ask us to delete them. |
| Hosted connectors | Your connector’s tools and settings. For each call: the connector version, the tool name, whether it worked and the kind of error, how long it took, public or signed in, which AI app called (Claude, ChatGPT, Cursor, Codex or other), a daily session code that can’t be traced back to a person, address or token once its day ends, and the names of the inputs used, never their values. Call records never hold the tool’s results, sign-in tokens, IP addresses or browser details. Daily call counts for billing. | Settings while hosting is on. Each call: 90 days. Daily totals per tool and AI app, without session codes: 13 months. Call counts with your usage history. |
| Sign-ins to hosted connectors | For each person who connects an AI app: the tokens your site’s login provider gives us for them, encrypted with a key only their AI app’s sign-in can unlock, and a code for their account at your provider. If you created a client for us at your provider, its secret, encrypted on our hosting service and never shown back. | Until they disconnect the AI app, you turn hosting off, or 90 days without use. A client secret: until you replace or remove it. |
| Billing | Your plan, usage, spending limit and what you bought. Never card details. | While your account exists, and longer where tax law requires. |
| Abuse limits and product events | A hashed network identifier to limit repeated requests, and events such as “site added”. | Limits: until their window ends, usually a day. Events: 30 days. |
| Service | What it does | What it sees |
|---|---|---|
| Cloudflare | Hosting, database, file storage, queues, and email forwarding for our inboxes | Everything we store, and the requests your browser and your hosted connector’s callers send us |
| Clerk | Sign-in and organisations | Your name, email address, sign-in details and team membership |
| OpenRouter | Sends our AI agents’ requests to AI providers. We only allow providers that keep no prompts or responses. | Your tasks and what the agent reads on your site during a test |
| Resend | Sends our email | Your email address and the email we send you |
| Dodo Payments | Merchant of record: takes payment, handles tax and invoices | Your billing details and card, which we never see |
| Our Gmail inbox, where support email arrives | Messages you send to our email addresses |
They may process data outside India, including in the United States.
We use your data only to run Transica
We use it to run your scans and tests, show your results, bill you, reply to you and keep the service safe. We don’t sell it, share it for advertising or use it to train AI models. We don’t add you to marketing email unless you tick the box and confirm your address. Every update has an unsubscribe link.
Agent tests run only on sites you verify
An agent test records each step the agent takes on your verified site, with screenshots. Results are private to your organisation. Signed out, a test only reads. With a test account you provide, it can make the changes you allow. We decrypt test-account passwords only to start the test that uses them.
Hosted connectors keep only what sign-in needs
When someone connects an AI app to your hosted connector, they approve it on our consent page, then sign in with your site’s login. We keep the tokens your login provider gives us for them, encrypted, so we can call your site on their behalf. The AI app only ever gets our own token for that one connector. We delete their tokens when they disconnect, when you turn hosting off, or after 90 days without use.
We don’t store the values of the tool’s inputs, its results, or the caller’s IP address. To show you usage, we keep which AI app called, how the call went and a session code made from a secret that changes daily and is then deleted, so after that day it can’t be traced back to anyone. Cloudflare keeps short-lived request logs.
Ask us to see, fix or delete your data
- Delete a free-scan report from its page at any time.
- Delete a finished test or comparison report, with its steps, screenshots and captured traffic, from its details. Members and admins can do this; viewers can’t.
- Remove a test account from the site’s settings.
- For a copy of your data, a correction, or to delete your whole account, email support@transica.dev. We delete accounts within 30 days of the request.
Copies you download stay on your device until you delete them. Don’t submit URLs that contain passwords, access tokens or personal information.
We protect what we store
Everything travels over HTTPS. Test-account passwords and connector keys are encrypted, and never shown back to you or anyone else. Only the operator has admin access, and uses it only to run and support Transica.
Transica is for adults
You must be 18 or older to use Transica. We don’t knowingly collect data from children. If you think we have, email support@transica.dev and we’ll delete it.
We’ll email you about big changes
If we change this policy in a way that matters, we’ll email account holders at least 30 days before it takes effect. A change needed for legal or security reasons may apply sooner. Our terms and refund policy cover the rest.