Private-beta policy centre

Plain rules before fine print.

These drafts explain how the private beta handles information, connected providers, calls, cancellation, and responsible use. They are not final commercial terms and do not open public signup, checkout, or downloads.

Draft status — August 14, 2026

The product behaviour below is the current operating rule. The legal operator is now identified. The accountable Privacy Officer, verified privacy, support and billing contacts, mailing address, support commitment, refund terms, governing-law language, and commercial legal review must still be completed before sales open.

Current identity

One product. One accountable operator.

Product
Trace Intake
Legal operator
William Osborne
Business structure
Unincorporated sole proprietor in Alberta, Canada
Contracting party
William Osborne
Commercial gate
Publish verified privacy, support and billing contacts, a suitable mailing address, tax treatment, and the final reviewed commercial agreement before sales open

Full drafts

The overview below has a full document behind it.

01

Privacy and data handling draft

Collect less. Explain the rest.

Who controls the business records?

The subscribing business controls the submissions, caller information, recordings, transcripts, summaries, documents, inventory, legacy records, client and project records, and storage locations used in its work. The installed Trace Intake program handles that information for the business and writes it to the computer, network folders, and business drives selected during setup.

The business is responsible for having a lawful reason to collect and use information from its own customers, workers, callers, and other individuals; giving any notices and choices its activities require; deciding who on its team can access the delivered records; and maintaining appropriate business backups and retention rules.

What does the Trace Intake owner system keep?

The owner system keeps only information needed to operate the account and paid or sponsored service:

  • business, billing, and verified account-contact name and email;
  • Stripe customer, subscription, purchase, invoice, refund, and transaction references;
  • selected modules, entitlement status, access dates, and renewal or cancellation state;
  • installation, account, grant, and access identifiers or secure hashes;
  • the approved HTTPS connection address used by an installation;
  • expiry, last-connection, usage-limit, spending-limit, and aggregate cost information;
  • OpenAI project and Twilio subaccount or telephone-number references; and
  • release version, service-health timestamps, security events, and technical incident codes.

The owner dashboard is not designed to store form answers, lead contact details, caller recordings, transcripts, attachments, customer documents, inventory line items, legacy files, or business folder paths.

Why is owner-side information used?

Owner-side information is used to authenticate access, provide selected modules, administer private-beta grants, manage subscriptions and refunds, enforce provider limits, secure callbacks and installations, respond to support or privacy requests, investigate technical or security incidents, meet accounting and legal obligations, and understand aggregate service health. It is not sold or used to build advertising profiles.

Marketing site information

The current website has no advertising tracker, analytics service, contact form, public account creation, or checkout. Cloudflare provides HTTPS, delivery, and security and may process ordinary request information such as IP address, browser details, requested page, security signals, and timestamps under its own terms. No application ZIP or business record is served from this marketing site.

Safeguards

Safeguards include separate credentials for approved testers, encrypted local provider credentials, verified Stripe and Twilio callbacks, narrow owner-dashboard fields, spending limits, expiring grants, suspension and revocation controls, least-access provider projects or subaccounts, HTTPS, restrictive website security headers, and tests that block credentials and business records from release packages.

No system can promise absolute security. Suspected unauthorized access, loss, or disclosure must be contained, investigated, documented, and assessed for required customer, individual, provider, insurer, or regulator notice.

02

Connected providers

Some features have to leave the building.

Trace Intake uses enabled providers only for the feature the business chooses. Those providers may process or temporarily retain limited information in Canada, the United States, and other countries where they or their subprocessors operate. Information in another country may be subject to that country's laws and lawful access processes. Provider locations and terms can change, so they must be reviewed again before commercial launch and when a material provider changes. The Third-Party Provider Directory identifies each role and links to the provider's current official policies.

Cloudflare

HTTPS, website delivery, application Tunnel connectivity, traffic protection, and related technical request information.

Cloudflare role and policies

Stripe

Future checkout, subscriptions, invoices, refunds, payment-method handling, fraud prevention, tax, and accounting records. Trace Intake does not store full card details.

Stripe role and policies

Twilio

Telephone-number provisioning, call connection, keypad selections, temporary recording, callback delivery, and provider usage or cost information for Answering Service.

Twilio role and policies

OpenAI

When enabled, transcription, classification, structured summaries, and other bounded AI tasks. API business inputs and outputs are not used for model training by default; provider abuse-monitoring and retention rules still apply.

OpenAI role and policies

Customer-selected storage

Google Drive, OneDrive, Dropbox, or another locally synchronized folder is optional and controlled by the business. That provider's account, region, sharing, backup, and retention settings apply.

Storage roles and policies

Trace Intake must not silently enable a new provider or use operational information for a new purpose. A material new use requires an updated disclosure and, where required, fresh consent or customer approval.

03

Calls and transcription draft

Tell callers what is happening.

The subscribing business decides why it uses Answering Service and is responsible for its caller notice, consent, retention, access, and alternative-contact practices. Before a call is recorded or transcribed, the configured greeting must clearly tell the caller that recording and transcription will occur, explain the business purpose, and provide an appropriate way to decline or use another contact method when required.

Trace Intake uses the call only to operate the answering workflow chosen by the business: play a greeting or menu, collect a message, transcribe it, prepare a structured summary, route the result, and deliver the package to the business-controlled storage locations. The business must not describe one purpose to the caller and later reuse the call for an unrelated purpose such as advertising, profiling, or staff training without the required notice and consent.

After both configured business storage roots confirm delivery, Trace Intake removes the remote Twilio recording. Delivered business copies follow the business's own retention and access rules. A caller's access, correction, or deletion request about a delivered recording must normally be handled by the business that received the call.

Not an emergency service.

Trace Intake Answering Service is inbound business intake. It is not a 911, emergency, dispatch, medical, crisis, or life-safety service and must not be presented or relied on as one.

04

Cancellation, retention and deletion draft

Your files do not become leverage.

Cancelling one module

Other subscribed modules continue. The cancelled module stops accepting new work at the end of its access period, while its setup and records on the business system remain in place for an easier return. Trace Intake does not delete delivered business records because a module is cancelled.

For Answering Service, the customer must separately choose whether to keep the Twilio number and accept the disclosed ongoing number-holding cost, or release the number and stop that provider cost. A released number may not be recoverable.

Fully cancelling Trace Intake

The commercial cancellation flow will provide two choices:

  1. Keep my Trace Intake profile for 90 days. Eligible profile, setup, routing, and provider-reference information is retained until the displayed deletion date. The customer can restore service during that period or choose earlier deletion. Only a separately accepted provider cost, such as holding a telephone number, may continue.
  2. Delete my Trace Intake profile and data. After a second confirmation, eligible owner-side profile, settings, access, and provider resources are scheduled for deletion. Business records already delivered to the customer's computer, network, and drives remain untouched.

Information that may remain

Billing, transaction, tax, accounting, fraud-prevention, security, dispute, consent, and legal-compliance records may be retained for the period reasonably required by law, provider rules, limitation periods, or an active dispute. A deletion receipt must explain what was deleted, what remains, why, and the expected completion date without exposing credentials.

Enabled providers may retain limited information under their own verified retention and legal obligations. Trace Intake cannot delete information that remains only on the customer's own drives; those files stay under the customer's control.

The permanent customer control is not active yet.

The private beta is owner-assisted. Authenticated self-service cancellation, 90-day restoration, provider cleanup, audit receipts, and permanent deletion must pass the documented release gates before public checkout opens.

05

Private-beta use draft

Real testing, controlled limits.

  • Access is limited to owner-approved testers and may expire, be suspended, or be revoked for security, provider-cost, unlawful-use, or material misuse concerns.
  • Testers pay $0 for the private beta. Stripe remains in Sandbox. Owner-funded OpenAI and Twilio use is subject to per-tester limits.
  • The tester computer, Trace Intake service, internet connection, and unique Cloudflare Tunnel must remain reachable for always-online delivery.
  • Testers must use legitimate business workflows and must not submit fabricated information as if it were a real lead, call, inventory event, or client record.
  • Trace Intake must not be used for unlawful surveillance, harassment, spam, emergency dispatch, high-risk automated decisions, credential theft, malware, or content the business is not entitled to collect or process.
  • Health information, payment-card data inside forms or messages, government identity documents, children's information, and other specially regulated or highly sensitive content are not approved for the private beta unless a separate written review explicitly authorizes the use.
  • Businesses must review uncertain routing, test backups and recovery, restrict folder access, and verify that required customer notices are present before using a workflow with the public.

The private beta is provided for feedback and acceptance testing. Commercial warranties, service levels, support response times, limitation-of-liability language, indemnities, refund rules, and governing-law terms are not finalized and are not implied by this draft.

06

Access, correction and concerns

A real person must own the answer.

An individual may ask whether Trace Intake owner systems hold personal information about them and may request access or correction, subject to identity verification and applicable legal exceptions. Requests concerning a lead, recording, transcript, document, inventory record, or other file already delivered to a business should normally be directed to that business because Trace Intake owner systems do not hold the operational copy.

Private-beta testers use the direct owner-assisted channel supplied during onboarding for privacy questions, access or correction requests, cancellation, deletion, and incident reporting. Before commercial sales, William Osborne must designate the accountable Privacy Officer, publish a verified privacy email and mailing address, describe the response and complaint process, and identify any applicable regulator escalation route.

If a concern is not resolved directly, individuals may be able to contact the Office of the Information and Privacy Commissioner of Alberta or the Office of the Privacy Commissioner of Canada, depending on which law and organization apply.

What happens next

Drafts first. Legal promises last.

Tester feedback can improve clarity, but commercial policies will not be labelled final until the missing contact, support, billing, provider-review, and legal decisions are complete.

See the launch gates