Privacy Policy
Last updated: July 19, 2026
This policy explains what PEGTrace LLC ('we', 'us') collects when institutions use PEGTrace, how we use it, and how you can control it. Institutional customers should also review the Data Handling document for the current subprocessor list and data-flow disclosure.
1. What we collect
Account data: analyst name, work email, hashed password, institution, role, and plan status.
Case data (institutional analyst input): identifiers you enter — wallet addresses, URLs, hostnames, IP addresses, phone numbers, last-4 bank references — plus notes, attachments, and evidence-ledger entries.
Optional victim data: victim personally identifiable information (PII) is only stored when you elect to attach it to a case. Victim PII is encrypted at rest, segregated from the tamper-evident ledger, and is not included in exported packages by default.
Usage data: pages visited, features used, cases opened, packages exported.
Coach conversations: prompts and responses when you use the AI Coach. The Coach receives only route context and messages you type — not case data.
Device / technical data: IP address, browser, device type, approximate location, cookies and similar technologies.
Payments: handled by our payment processor; we do not store full card numbers.
2. How we use it
• Operate the service (authentication, case storage, evidence ledger, package export).
• Preserve evidence integrity through hash-chaining and package fingerprinting.
• Improve quality (aggregated, de-identified analytics; debugging).
• Communicate about your account, updates, and service notices.
• Enforce our Terms and Acceptable Use Policy, and prevent abuse.
• Comply with law and respond to lawful requests.
3. Legal bases
Depending on your location, we rely on performance of a contract (delivering the service), our legitimate interests (product improvement, security, evidence integrity), your consent (marketing emails and non-essential cookies where required), and legal obligations.
4. Who we share it with
Service providers acting on our behalf, including hosting and database (Supabase, US region), AI provider for the Coach (Anthropic), on-chain data (Bitquery), breach lookup (Have I Been Pwned), IP and device intelligence (IPQS), token and contract analysis (GoPlus, Honeypot.is), edge protection and CAPTCHA (Cloudflare Turnstile), and transactional email (Resend). See the Data Handling document for the current list.
Legal / safety: to comply with a valid legal request, protect our users, or defend our rights.
Business transfer: if we are acquired or merged, your data may transfer subject to this policy.
We do not sell personal information.
5. AI and Coach
Coach prompts are processed by Anthropic to generate replies. The Coach is scoped so that no case data is transmitted to Anthropic — it receives only the page you are on and the messages you type. Do not paste victim PII, credentials, or privileged material into the Coach. Messages may be logged for quality, safety, and abuse prevention.
6. Cookies and analytics
We use cookies for authentication, preferences, and analytics. Where required by law, we ask for your consent for non-essential cookies. You can control cookies through your browser.
7. Retention
Case data and evidence-ledger records are retained for the life of the institutional account and for a reasonable period afterward to preserve the integrity of exported packages and to satisfy legal and audit obligations. Victim PII may be deleted on request following institutional review.
8. Your rights
Depending on your jurisdiction, you may have rights to access, correct, delete, port, or restrict processing of your personal information, and to object or withdraw consent. To exercise these rights, email support@pegtrace.com. We will verify identity before acting. Victim data-subject requests should be routed through the institution that created the case.
9. Children
PEGTrace is not intended for children under 18 and is not marketed to them. Do not use the service if you are under 18.
10. International users
We are based in the United States and our hosting is in the US region. If you use the service from outside the US, information will be transferred to and processed in the US.
11. Security
We use industry-standard controls, including encryption in transit, encryption of victim PII at rest, hashed passwords, role-based access, tamper-evident evidence hash-chaining, package SHA-256 fingerprinting with a public verification portal at /verify, and monitoring. No system is perfectly secure; use unique credentials and enable multi-factor authentication where available.
12. Changes
We may update this policy; material changes will be posted at /privacy with an updated 'Last updated' date.
13. Contact
support@pegtrace.com