Trawline Privacy Policy
Last updated: 24 September 2026
1. Who we are and what this policy covers
This policy covers Trawline, the service at trawline.dev ("Trawline", "we", "us"). We are the controller of the personal data described in this policy. You can contact us about privacy at blairephantom@gmail.com.
Trawline is a data service for businesses and professionals. It obtains publicly available information from third-party platforms and processes it, including with automated and AI-assisted processing, to deliver the results our customers request.
This policy applies to visitors to our website, people who request an invite or who are invited, our customers, people who contact us, and people whose public content passes through the Service. It does not cover what our customers do with the results they obtain — each customer is responsible for that as an independent controller — or the practices of the platforms and of other websites we link to.
2. Our principle
We collect, store and log only what the Service needs to work.
3. Data about our customers, invitees and website visitors
| When | What we process | Why | Legal basis |
|---|---|---|---|
| You visit our website | your IP address and technical browser data, received by our cloud infrastructure provider and by the third-party providers of web fonts, sign-in and security (bot-protection) services that our pages load | to deliver and secure the website | legitimate interests |
| You request an invite (the waitlist) | your e-mail address and when you asked; your IP address is checked once by our bot-protection provider. To stop abuse of the invite form we briefly keep a scrambled form of your connection address for up to one hour after your last request. | to e-mail you when your invite is ready or when we launch, and for nothing else; your address is never shared | consent; legitimate interests for protecting the form |
| You are invited | your e-mail address and when it was added to our invite list — nothing else | to let you create an account while sign-up is by invitation | legitimate interests |
| You create an account | your e-mail address and a securely hashed password (never the password itself), or your account identifier and e-mail address from the third-party sign-in provider you chose; a short-lived verification code | to provide the Service | contract |
| You sign up, log in or reset a password | your IP address, checked by our bot-protection provider and kept briefly to prevent abuse | to protect accounts and the Service | legitimate interests |
| You stay logged in | one strictly necessary session cookie (section 9) | to keep you logged in | contract |
| You use the API | your API keys, stored only in a form that cannot be reversed, with their labels and dates; a record of each charge showing the type of request but not the content or account you asked about; the request identifier of each call | to provide the Service, bill correctly, answer receipt lookups and prevent abuse | contract and legitimate interests |
| You sign up for free credits | a non-reversible record of the identity you signed up with (your e-mail address or sign-in account) | to give the free allowance only once | legitimate interests |
| You contact us | your e-mail address, your message and anything you attach | to answer you and keep a record of the request | legitimate interests, or legal obligation for a rights request |
| You buy credits or a plan (once purchases open) | purchase records; payment details are handled by our payment provider, and we do not receive or store your full card details | to take payment and keep accounting records | contract and legal obligation |
You need an e-mail address, and a password unless you use a third-party sign-in provider, to have an account; without them we cannot provide the Service. Everything else in the table results from your use of the Service.
We keep service statistics about each request, such as its type and cost, that contain no account identifier and no request content. We do not use advertising or analytics cookies, and we do not show you targeted advertising.
4. Data about people whose public content passes through Trawline
Our customers ask Trawline for publicly available content on third-party platforms — for example public profiles, posts, comments, videos and their transcripts. If you publish content publicly, it may pass through the Service. This section explains what that means for you.
- Where it comes from: the public pages of third-party social platforms — information that the platform makes available to anyone.
- What we process: public information such as names, handles, public counts, public posts and comments, and transcripts or AI summaries of public videos. No response we define has an e-mail, phone or postal-address field. Free text is returned as published, so it can contain details you chose to make public; we may choose not to return some free-text fields, such as account bios on some platforms. We do not try to infer sensitive characteristics about anyone.
- Why, and on what legal basis: to deliver the results our customers request. Our legal basis is legitimate interests: ours in providing a data service, and our customers' in using public information for purposes such as research, analysis and content work. We have weighed those interests against yours: we process only public information, keep it for no more than 24 hours, build no profiles or database of people, and our Terms forbid customers to use it against the people it is about.
- Who receives it: the customer who requested it, and our service providers (section 5).
- How long we keep it: results may be kept temporarily for up to 24 hours to deliver the Service and are then deleted automatically. Those temporary copies are not linked to the customer who requested them. We keep no database of people and no per-customer record of what was requested, apart from short-lived technical logs used to run and secure the Service.
- Why we have not contacted you: we cannot contact every person whose public content passes through the Service, and we do not keep the information that would be needed to do so. This published notice is how we inform you.
- Our customers' use: each customer is an independent controller of its own use of the results and is responsible for it. Our Terms prohibit surveillance, stalking, discrimination, contact harvesting and re-identification, and anyone can report misuse to us.
- Your rights: you can ask us what we hold, object, or ask for erasure by writing to blairephantom@gmail.com with the public URL concerned. We answer within one month. Because temporary copies are deleted within 24 hours and we keep no database of people, we usually hold nothing about you, and we are generally unable to tell you which customer requested your content. Our Data Sourcing & Takedown page explains what we can and cannot do.
5. Who receives personal data
We share personal data only as needed to run the Service:
- Our cloud infrastructure provider, Cloudflare, which hosts and runs our website and API and the processing behind them, stores our account data, delivers our e-mails, provides security services and keeps short-lived technical logs. Cloudflare is responsible for the services it delivers and for the data it processes in them on our behalf, which it may process only on our instructions, under its own terms and data-processing commitments.
- Other providers of hosting and infrastructure, security, error-monitoring, sign-in, web-font and e-mail services that help us operate the Service, each processing data only for the service it provides to us.
- Our payment provider, once purchases open, when you buy credits or a plan.
- Professional advisers, authorities or courts, where the law requires it or to protect our rights; we check each request from an authority and disclose only what the law requires.
- A successor, if the Service is transferred; we will tell you before your data becomes subject to a different privacy policy.
We do not sell personal data, and we do not share it for targeted advertising.
International transfers. Some providers may process personal data outside the European Economic Area. Where they do, we rely on appropriate safeguards, such as the European Commission's standard contractual clauses or an adequacy decision. You can ask us for more information about them.
6. How long we keep data
| Data | How long |
|---|---|
| Invite-request (waitlist) e-mail | until we have e-mailed you that your invite is ready or that we have launched, or until you ask us to delete it, whichever comes first |
| Invite-list entry | until sign-up opens to everyone, or until you ask us to remove it, whichever comes first |
| Account data and API-key records | while your account exists |
| Records of charges and payments | while your account exists and afterwards for as long as accounting and legal obligations require, linked only to an anonymised account record |
| IP addresses kept for abuse prevention | a few days at most |
| Verification codes and one-time links | until they expire, shortly after they are sent |
| Temporary copies of results | up to 24 hours |
| Messages you send us | as long as needed to deal with them and any follow-up |
| The non-reversible sign-up identity record | after account deletion, to prevent the free allowance being claimed again |
| Proof of an account deletion | permanently, as the record that the deletion took place |
| Technical logs | for the short periods our providers keep them |
7. Your rights
You have the right to access, correct, delete, restrict or object to the processing of your personal data, to data portability, and to withdraw consent at any time where we rely on it.
Your right to object. Where we rely on legitimate interests, you can object at any time, on grounds relating to your particular situation, and we will stop unless we have compelling legitimate grounds that override your interests or need the data for legal claims.
You can download your account data yourself from your account ("Download my data"). For anything else, contact us at blairephantom@gmail.com. We answer within one month and may ask you to confirm your identity. If we cannot fully act on a request, we tell you why and what else you can do. If you have requested an invite, you can also reply to our e-mail at any time and we will delete your address within 7 days.
You also have the right to complain to a data-protection supervisory authority, in particular in the country where you live or work or where you believe an infringement took place.
8. Deleting your account
- You request deletion in your account by typing DELETE.
- You are logged out everywhere immediately, and deletion is scheduled for 7 days later. To cancel, log in and choose "Cancel deletion" before then; logging in alone does not cancel it.
- After 7 days deletion runs automatically. We delete your API keys and your sign-in details, erase your e-mail address from your account, and e-mail you a Proof of Deletion reference.
- We keep only: the non-reversible sign-up identity record (to prevent repeat free allowances), records of charges and payments linked to an anonymised account record (for accounting), and the proof that the deletion took place.
Credits left on the account are lost when it is deleted, as our Terms of Service explain.
9. Cookies and similar technologies
We set one cookie: a strictly necessary session cookie that keeps you logged in. It is set only when you log in and lasts until you log out, or for up to 7 days. Because it is strictly necessary, it does not need your consent. We use no analytics or advertising cookies, and our own pages store nothing else on your device. When our pages load web fonts, bot protection or third-party sign-in, those providers receive your IP address and browser data under their own policies.
10. AI processing and automated decisions
Some results, such as summaries, are produced with AI-assisted processing and are labelled "AI-generated opinion, not a verified fact." We do not make decisions about anyone based solely on automated processing that have legal or similarly significant effects. We do not use our customers' requests, or the results we deliver, to train AI models.
11. Security
We protect personal data with appropriate technical and organisational measures, including encrypted connections, hashed passwords and API keys, secure session cookies and access controls. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
If a personal-data breach is likely to put you at risk, we will tell you without undue delay, and we notify the competent supervisory authority where the law requires it.
12. Children
Trawline is a business service for people aged 18 or over. It is not directed at children, and we do not knowingly collect their account data; if you believe a child has created an account, tell us and we will delete it. A parent or guardian can also ask about a child's public content that may have passed through the Service, as described on our Data Sourcing & Takedown page.
13. Changes to this policy
We may update this policy. The date at the top shows the current version, and we give earlier versions on request. We announce material changes by e-mail and on the website before they take effect.
14. Contact
For any question about this policy or your personal data, write to blairephantom@gmail.com.