Privacy Policy
1. Overview
TrackChanges ("we," "our," "the service") is operated by Gullah Technologies LLC. This policy explains what information we collect when you use TrackChanges, how it's used, and how it's protected.
2. Information We Collect
We collect the minimum needed to operate the service:
- Account information: email address and a bcrypt-hashed password. We never store your password in plain text.
- API keys: shown to you once at creation, then stored only as a one-way SHA-256 hash. We cannot recover a lost key.
- Monitored source data: the URLs you subscribe to and the spec content fetched from them, stored as versioned, hashed artifacts.
- Usage and request logs: method, path, status code, duration, and caller identity for each API request, retained for 90 days for debugging and support purposes.
- Audit log: a permanent record of account actions (subscriptions, key creation, member changes) tied to your account.
3. How We Use Information
Information is used to operate and improve the service: authenticating requests, polling and diffing your subscribed sources, delivering webhook and email notifications, and providing support when you contact us.
4. Third-Party Services
We use a small number of third parties to operate TrackChanges:
- Resend — sends transactional email (verification codes, notifications, invites) on our behalf.
- DigitalOcean — hosts our application and database infrastructure.
We do not sell your data to anyone, and we do not use it for advertising.
5. Data Retention
Account and source data is retained until you delete it. Request logs are automatically deleted after 90 days. You can permanently delete your account and all associated data at any time via DELETE /account or tch delete.
6. Security
Passwords are hashed with bcrypt. API keys are never stored in plain text. All traffic to the API is encrypted via TLS. Access to production infrastructure is limited to the operator of Gullah Technologies LLC.
7. Your Rights
You can access, export (via the API), or permanently delete your account data at any time. If you have a specific request our self-service tools don't cover, contact us directly.
8. Children's Privacy
TrackChanges is a developer tool not directed at children, and we do not knowingly collect information from anyone under 13.
9. Changes to This Policy
If this policy changes materially, we'll update the date at the top of this page and, where appropriate, notify account holders by email.
10. Contact
Questions about this policy: support@trackchanges.io