Skip to content
TITRACE INTAKEIncoming work, already organized
Straight answersPolicy centrePrivacyTermsAcceptable use

Acceptable use draft

Use it to organize work. Not create harm.

Version dated August 14, 2026. These rules apply to approved private-beta use and will be incorporated into the final service terms after identity and legal review.

Current operator disclosure

Trace Intake is the product. William Osborne is its legal operator and contracting party, carrying on this work as an unincorporated sole proprietor in Alberta, Canada. This draft applies to approved private-beta use and does not make the service publicly available.

On this page1. Authority and consent2. Prohibited activity3. Sensitive information4. Calls and communications5. Security and credentials6. Providers and limits7. Reporting and enforcement

1. Authority, lawful purpose and consent

A business may process only information and connect only systems it is authorized to use. It must identify a reasonable business purpose, provide required notice, obtain required consent, honour withdrawal or objection where applicable, and limit access to people who need it.

Trace Intake must not be used to hide recording, monitoring, collection, or AI processing from a person when law or fair practice requires disclosure.

2. Prohibited activity

  • illegal surveillance, interception, stalking, harassment, threats, discrimination, exploitation, or invasion of privacy;
  • spam, robocalling, deceptive marketing, impersonation, phishing, credential theft, fraud, or manipulation;
  • malware, vulnerability exploitation, denial of service, unauthorized access, or attempts to bypass safeguards and limits;
  • uploading or distributing content the business does not have the right to collect, copy, analyze, or disclose;
  • using the service to make high-impact decisions about employment, credit, housing, insurance, health care, legal rights, or essential services without required human review and legal authorization;
  • reselling access, sharing tester credentials, or provisioning undisclosed customers through one sponsored grant; and
  • using fabricated operational data in a way that could be mistaken for a real customer, call, lead, inventory record, or transaction.

3. Sensitive and regulated information

The private beta is not approved for protected health information, full payment-card data in forms or messages, bank credentials, government identity documents, biometric identification databases, children's information, intimate information, criminal-investigation records, or other specially regulated or highly sensitive content unless a separate written review explicitly authorizes the workflow and required safeguards.

The business must configure forms and greetings to discourage unnecessary sensitive information and must remove accidental collection according to its lawful retention process.

4. Calls, recordings and communications

Before recording or transcribing, the configured greeting must tell the caller what will happen, state the business purpose, and provide an appropriate alternative when required. Proceeding after a clear notice may support implied consent in some circumstances, but the business remains responsible for determining the rule that applies to its call and location.

A recording collected for intake and routing cannot silently be reused for advertising, profiling, biometric identification, discipline, or training. Caller access and correction requests must be handled through the responsible business and applicable privacy process.

Never an emergency service.

Trace Intake must not be advertised, configured, or relied on for 911, emergency dispatch, crisis response, medical triage, alarms, public safety, or any situation where delay or failure could cause injury or serious harm.

5. Security, devices and credentials

  • protect activation codes, passwords, API keys, authentication factors, and business storage access;
  • use supported Windows security controls and restrict folder permissions;
  • do not copy owner credentials or use one tester's provider resources for another;
  • install updates and follow recovery instructions when supplied;
  • do not disable signed-callback verification, spending limits, duplicate protection, review queues, or audit safeguards; and
  • report a suspected compromise, exposed credential, misrouted record, privacy incident, or unusual provider charge promptly through the beta channel.

6. Provider rules and cost limits

Use of Cloudflare, Stripe, Twilio, OpenAI, and customer-selected storage must remain compatible with those providers' applicable terms and acceptable-use rules. Current official links are listed in the Third-Party Provider Directory. Tester projects, subaccounts, numbers, spend limits, usage triggers, and grants may not be circumvented.

A telephone-number preview is read-only. A paid number may be activated only after explicit owner approval and customer selection. A sponsored tester is limited to the approved number and funded limits.

7. Reporting, review and enforcement

Potential violations may be investigated using narrow account, security, provider-reference, and service-health information rather than customer business-file contents. Access may be limited or suspended when reasonably necessary to stop harm, control provider cost, comply with law, protect credentials, or preserve service integrity.

Where safe and lawful, the operator should notify the affected business of the concern and corrective step. Serious illegality, deliberate abuse, credential theft, or immediate harm may require suspension without advance notice and referral to a provider or authority.

Commercial enforcement, appeals, notice periods, and termination remedies must be reviewed and finalized with the Terms of Service.

Official call-recording guidanceOffice of the Privacy Commissioner of CanadaCriminal Code, Part VI
TITRACE INTAKEOperated by William Osborne
Policy centrePrivacyTermsProviders

Private draft. No public sales or downloads.