1. Controller and scope
The controller of the processing related to the website, accounts, licenses, and billing is Arthur Ferreira Macias, Sole Proprietor, 12 rue du Moulin de Sault, Les Peupliers 456, 64600 Anglet, France, reachable at contact@tramya.com. This policy covers the website, the local companion, the web interface, and the Tramya Cloud service.
2. Data processed locally
The histories of supported agents, conversation imports, projects, memories, search indexes, and local backups are processed on the device. They are not sent to the commercial service by default. The public website has no access to the application's local API.
3. Tramya Cloud option
When the user enables Cloud, the application encrypts a copy of the vault before sending it. The hosted service stores the encrypted blob, the account and device identifiers, the backup dates, and the technical data required for synchronization. Remote commands and their results also travel in encrypted form.
The recovery key is handed to the user and is not sent with the vault. Tramya therefore cannot restore the content without this key in the current architecture. The user must keep it in a password manager. Encryption reduces access to the content but does not make the metadata anonymous and does not remove the application from the scope of the GDPR.
4. Pro remote control
In Pro, the Mac must be powered on and connected. The relay temporarily stores the encrypted commands, their status, the target device, and the encrypted result. Execution and decryption take place on the paired devices. Tramya does not ask for the password of AI accounts.
5. Free account, download, purchase, and license
When creating a Free account, Tramya records the email address, the date and version of the acceptance of this policy, the optional preference regarding product news, the declared acquisition source, and the verification date. When downloading, Tramya records the chosen system, the date, and the number of downloads. This information is used to create and secure the account, deliver the application, measure downloads, and prevent abuse. It includes neither conversations, nor messages, nor project files.
For a paid plan, Stripe processes the payment information. Tramya receives in particular the email address, the Stripe customer, session, and subscription identifiers, the plan, the date of contractual consent, and the payment status. This data is used to perform the contract, deliver or restore the license, provision Cloud, and comply with accounting obligations.
6. Transactional emails
When Brevo is used, the email address and the content of the transactional message are transmitted to it solely to confirm the account, deliver or restore the license. No commercial solicitation is sent without consent or another applicable legal basis.
7. Purposes and legal bases
- Pre-contractual measures and performance of the contract: creation of the requested account, download, license, optional synchronization, remote control, support, and renewal.
- Legal obligation: billing and accounting records.
- Legitimate interest: security, fraud prevention, and proportionate technical diagnostics.
- Consent for product news, when the user separately chooses to receive it.
8. Retention
- Histories, projects, memories, and local backups remain under the user's control on their device, for the duration they choose in the settings.
- The account, the associated downloads, and the data required for the license are kept for the duration of the contractual relationship. A login session expires after ninety days at most. When an account deletion is confirmed, this data is removed from active systems.
- The encrypted Cloud vault, the devices, and the associated commands are kept as long as Cloud access is active. Their removal from active systems occurs upon account deletion or effective revocation of that access.
- The encrypted technical backups are produced daily and limited to the last fourteen versions. Deleted data may therefore persist there for a maximum of fourteen days; these backups serve only for disaster recovery and cannot be used to reactivate a deleted account.
- Invoices and accounting records are kept for ten years from the close of the relevant financial year, in accordance with applicable accounting obligations.
9. Recipients, processors, and transfers
The recipients are the authorized persons of Tramya and the strictly necessary providers: Stripe for payment, Contabo GmbH in Germany for hosting, Brevo for transactional emails, and Google when the user voluntarily chooses Google sign-in. These providers process the data according to their own locations and contractual safeguards. The mechanisms applicable to any transfers outside the European Economic Area are those put in place by each provider in accordance with the GDPR.
10. Security
Tramya applies in particular encryption in transit, device-side vault encryption, account separation, revocable sessions, restrictive local permissions, encrypted backups, and secret rotation. No system is infallible.
11. Your rights
You may request access, rectification, erasure, restriction, or portability of your data and object to the relevant processing at contact@tramya.com. You may also refer the matter to the CNIL. Exclusively local data can be deleted directly from the device; Tramya cannot provide data that it does not receive.
12. Cookies
The current version installs no advertising tool or audience measurement. Stripe may apply its own mechanisms on its payment page in accordance with its policy.