Trails is a business service operated by Third Arc Inc. This Policy covers the Trails websites, web application, browser extension, desktop applications, AI Features, support, and related services.
1. Scope and our role
This Privacy Policy explains how Third Arc Inc., a Delaware corporation doing business as Trails (“Trails,” “we,” “us,” or “our”), collects, uses, discloses, and retains personal data. “Personal data” includes information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked with an individual or household.
Trails acts as a controller or businesswhen we determine why and how personal data is processed, such as for account administration, billing, security, support, product analytics, and marketing. When a business customer submits or captures personal data in its workspace and instructs us to process it, the customer is generally the controller or business and Trails is its processor or service provider. Our Data Processing Addendumgoverns that processing.
A Trails customer controls its Customer Content, workspace membership, access settings, and published guides. If your data appears in Customer Content, including a screenshot, recording, transcript, shared guide, or knowledge base, direct your request to the customer that created or published it. We will assist that customer as required by law and our contract. This Policy does not govern a customer's independent privacy practices or websites.
2. Personal data we collect
2.1 Account, identity, and organization data
We collect names, business email addresses, passwords in hashed form, organization and job information, user and workspace identifiers, roles, permissions, invitations, authentication and confirmation data, single sign-on details, Google authentication identifiers, and account preferences.
Account and billing fields identified as required are necessary to create or administer an account, enter the customer relationship, or provide a requested Service. If you do not provide them, we may be unable to create the account or provide the applicable Service. Other information is optional unless a feature requires it.
2.2 Customer Content and product inputs
Depending on how a customer uses Trails, we process screenshots, screen and application recordings, uploaded videos, audio and microphone recordings, voice samples and synthetic voice profiles, transcripts, guide and page text, prompts, instructions, URLs, page titles, favicons, click and interaction information, annotations, redactions, translations, generated narration and video, files, branding, style guides, custom code, and other material a user captures, uploads, creates, or generates. This content may incidentally contain personal data about employees, customers, or other individuals visible or audible in a workflow.
Voice samples and recordings may be considered biometric or sensitive data in some jurisdictions. Trails uses them to provide transcription, narration, and customer-requested voice features—not to identify or authenticate a person by biometric matching. Customers must have all required rights and consent before recording or uploading a person's voice or likeness.
2.3 Sharing, collaboration, and viewing data
We collect workspace memberships, invitations, roles, access levels, sharing and embed settings, public or password-protected status, custom-domain settings, access attempts, and information about views and interactions with guides, pages, videos, embeds, and knowledge bases. If a viewer is logged in, we may associate activity with the viewer's account for security, access control, and product analytics. Trails does not currently provide guide owners with named-viewer analytics. We may provide aggregate or non-identifying engagement information.
2.4 Billing and transaction data
Stripe processes payment-card and bank details. Trails receives limited billing information such as billing contact, customer and subscription identifiers, plan, seat and usage quantities, transaction status, invoice information, payment method type, and last four digits. We do not receive full payment-card numbers.
2.5 Communications and relationship data
We collect information provided in sales inquiries, demos, forms, customer-support requests, live chat, email, surveys, calls, events, and other communications. This may include contact details, organization, message content, attachments, support diagnostics, and preferences. We also keep records of marketing subscriptions and opt-outs.
2.6 Device, usage, and diagnostic data
We and our providers collect IP address, approximate location derived from IP, browser and device type, operating system, language and time zone, referring and exit pages, URLs, page views, clicks, feature use, event timestamps, session and user identifiers, cookie and advertising identifiers, attribution parameters, crash reports, exception data, log data, and performance and security events. PostHog and Google Analytics help us measure website and product use. We do not use precise geolocation unless we provide separate notice and obtain any consent required by law.
2.7 Inferences
We may infer likely business interests, product preferences, account health, marketing attribution, or feature affinity from the information above. We do not use sensitive personal data to infer characteristics about an individual.
3. Sources of personal data
We collect personal data:
- directly from you when you create an account or communicate with us;
- from your organization, workspace administrators, collaborators, and customers that invite you or provide Customer Content;
- automatically from browsers, devices, the Trails extension and desktop applications, cookies, logs, pixels, SDKs, and similar technologies;
- from integrations and service providers, including Google, Stripe, analytics, advertising, authentication, support, and referral partners; and
- from public sources and information you direct us to retrieve or process.
4. How and why we use personal data
| Purpose | Examples | EEA/UK legal basis |
|---|---|---|
| Provide and administer the Services | Create accounts and workspaces; authenticate users; capture, generate, host, translate, narrate, publish, share, and export content; process payments; provide support. | Contract; legitimate interests; legal obligations |
| AI and automation | Generate step text and metadata; transcribe audio; analyze uploaded video; translate content; create narration, synthetic voice, and training videos. | Contract; legitimate interests; consent where required |
| Secure and protect Trails | Detect fraud, abuse, unauthorized access, malware, and policy violations; maintain logs; investigate incidents; enforce terms. | Legitimate interests; legal obligations |
| Analyze and improve | Measure use and reliability; debug errors; develop features; conduct de-identified and aggregate analytics; evaluate AI quality and cost. | Legitimate interests; consent for non-essential cookies |
| Communicate | Send transactional, security, support, billing, product, and policy notices; respond to requests; invite collaborators. | Contract; legitimate interests; legal obligations |
| Market and advertise | Send marketing where permitted; measure campaigns; attribute visits; personalize audiences; limit repeated ads. | Consent where required; legitimate interests |
| Legal and corporate purposes | Comply with law and valid requests; exercise or defend claims; complete audits, financing, or corporate transactions. | Legal obligations; legitimate interests |
Where we rely on legitimate interests, those interests include operating a secure and useful B2B service, understanding and improving our products, communicating with business users, preventing abuse, and growing our business. We balance those interests against the rights and reasonable expectations of affected individuals.
5. AI processing
Trails uses OpenAI, Google Gemini or Vertex AI, and ElevenLabs to provide certain AI Features. Depending on the feature, we may send guide text, prompts, screenshots or image references, uploaded video, audio, transcripts, language selections, voice samples, and related instructions to these providers. Providers process the information to return requested results under their business or API terms.
We do not use Customer Content to train Trails' or a third party's general-purpose AI models unless the customer explicitly opts in. Our personnel do not routinely review Customer Content submitted to AI Features. Authorized personnel may access it when reasonably necessary for customer-requested support, security and abuse investigations, legal compliance, or service reliability, subject to access and confidentiality controls.
For AI observability, cost analysis, and troubleshooting, Trails uses PostHog to record provider and model, latency, token usage, errors, and other generation metadata. These events may also include truncated AI Inputs and Outputs of up to approximately 2,000 characters. Images and files are represented by placeholders in this telemetry. Customers should not include personal or sensitive information in prompts unless necessary and authorized for the requested feature.
AI Outputs may be inaccurate and require human review. Trails does not use AI Features to make legal or similarly significant decisions about individuals on our own behalf. Customers are responsible for their use of Outputs and for any required transparency, consent, labeling, and human oversight.
6. How we disclose personal data
We may disclose personal data to:
- Customer organizations and recipients. Workspace administrators and members may access account information and Customer Content based on permissions. Material published publicly, embedded, or shared by link is available to the intended audience and may be redistributed by recipients.
- Service providers and subprocessors. Hosting, storage, content delivery, AI, analytics, search, authentication, payment, email, communications, support, security, and professional service providers process data for the purposes described here. See our Subprocessor List.
- Advertising and analytics partners. Google Analytics, Google Ads, PostHog, and technologies deployed through Google Tag Manager may receive device, activity, cookie, attribution, and advertising information subject to consent and opt-out choices.
- Authorities and other parties for legal reasons. We may disclose data when we reasonably believe disclosure is required by law or legal process; needed to protect rights, safety, property, or the Services; or necessary to investigate fraud, security, or policy violations.
- Corporate transaction participants. We may disclose data to actual or prospective investors, lenders, buyers, sellers, advisers, and transaction counterparties in connection with due diligence, financing, reorganization, merger, acquisition, bankruptcy, or sale of assets, subject to appropriate safeguards.
- At your direction or with consent. We disclose data when you enable an integration, request a disclosure, or otherwise consent.
7. Advertising, sale, and sharing
Trails does not sell personal data for money. We use Google Ads and related technology to measure advertising and may disclose identifiers, device information, internet or network activity, and related inferences to advertising partners for targeted or cross-context behavioral advertising. Some U.S. state laws define that disclosure as “sale,” “sharing,” or “targeted advertising” even when no money changes hands.
You may opt out by selecting Cookie Settings in our footer or on the Cookie Policyand disabling advertising cookies. Where required, we also treat a recognized Global Privacy Control signal as a request to opt out of sale or sharing for the browser or device that sends it. We do not knowingly sell or share personal data of anyone under 18.
8. Cookies and similar technology
Trails and our providers use cookies, pixels, local storage, SDKs, and similar technologies for authentication, security, preferences, support, analytics, attribution, and advertising. Where law requires, we obtain consent before enabling non-essential technology. You can withdraw or change consent at any time without affecting processing that occurred before withdrawal. See the Cookie Policy for categories, providers, durations, and controls.
9. Retention
We retain data for the shortest period reasonably necessary for the purposes described here, taking account of the customer relationship, user choices, legal requirements, security, dispute resolution, and technical constraints. Our general schedule is:
| Data | General retention approach |
|---|---|
| Active account and Customer Content | For the account or subscription term and as needed to provide the Services. |
| Deleted or terminated account content | Deleted or de-identified from active systems within 30 days after a verified account-deletion request or applicable termination, subject to legal holds and permitted exceptions. |
| Backups | Isolated backup copies are overwritten or rendered inaccessible within up to 90 additional days and are not restored except for disaster recovery, security, or legal requirements. |
| Security and operational logs | Generally up to 12 months, with shorter or longer periods where appropriate for security investigations or legal claims. |
| Billing, tax, and transaction records | Generally seven years or the period required by law. |
| Marketing records | Until opt-out or no longer needed, while retaining a minimal suppression record to honor the opt-out. |
De-identified and aggregate information that cannot reasonably identify an individual may be retained for longer. Content a user marks deleted in the product may remain in a recoverable or logically deleted state until the applicable account-deletion or retention process completes.
10. Security
Trails maintains administrative, technical, and physical safeguards designed to protect personal data, including encryption in transit and at rest, access controls, logging and monitoring, secure development practices, vendor review, incident response, and business continuity measures. Trails maintains a SOC 2 Type 2 program, and eligible customers may request available security materials through the Trails Trust Center. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
If you believe your account or data is at risk, contact [email protected] immediately. Do not send passwords, private keys, or full payment-card information by email or support chat.
11. International transfers
Trails is based in the United States, and personal data may be processed in the United States and other countries where Trails and its providers operate. Those countries may have different data protection laws than your country.
For restricted transfers from the EEA, we use the European Commission's Standard Contractual Clauses where required. For UK restricted transfers, we use the UK International Data Transfer Addendum. We may also rely on adequacy decisions or another lawful mechanism. The Data Processing Addendumcontains the applicable transfer terms. Trails does not claim certification under the EU-U.S. Data Privacy Framework, UK Extension, or Swiss-U.S. Data Privacy Framework.
Australian personal information may be disclosed to recipients in the United States and in other countries identified by our subprocessors. See the Subprocessor List for more information.
12. Privacy rights and choices
Depending on where you live, you may have rights to access, know, correct, delete, or obtain a portable copy of personal data; restrict or object to processing; withdraw consent; opt out of targeted advertising, sale, sharing, or certain profiling; limit certain uses of sensitive personal data; and appeal a denied request. You may also have the right not to receive discriminatory treatment for exercising a privacy right.
Submit a request to [email protected] and describe the right you wish to exercise. You may also use the Cookie Settings control for cookies and targeted advertising. We may verify your identity and authority, including by confirming access to your email or account, and may deny or limit a request where permitted by law. An authorized agent may submit a request if the agent provides proof of authority and we can verify the consumer. We will respond within the period required by applicable law.
To stop marketing email, use the unsubscribe link in the message. Transactional and security communications may continue while you have an account. If Trails processes the data only for a customer, we may direct you to that customer.
13. California notice
This section supplements the rest of the Policy for California residents. The table describes categories of personal information we collected in the preceding 12 months, business purposes, and categories of recipients. We may not collect every example from every person.
| CCPA category and examples | Purposes | Recipient categories |
|---|---|---|
| Identifiers: name, email, account, device, cookie, IP, and online identifiers | All purposes described in Section 4 | Customer organizations; infrastructure, authentication, support, analytics, advertising, email, and security providers |
| California customer-record information: name, business contact, account, and limited payment information | Accounts, billing, support, security, and legal compliance | Customer organizations; Stripe; support and professional providers |
| Commercial information: plan, subscription, transaction, product usage, and purchasing history | Provide Services, billing, analytics, and marketing | Stripe; analytics, support, and business providers |
| Internet or network activity: pages, clicks, feature use, interactions, device, logs, and advertising activity | Provide, secure, analyze, improve, and advertise Trails | Customer organizations in limited contexts; infrastructure, analytics, security, and advertising providers |
| Audio, electronic, and visual information: recordings, screenshots, videos, audio, voice samples, transcripts, and chat | Provide Customer-requested Services, AI, support, and security | Customer-selected recipients; hosting, AI, communications, and support providers |
| Professional or employment information: organization, role, title, and business relationship | Accounts, authorization, support, sales, and marketing | Customer organizations; CRM, email, support, and business providers |
| Inferences: likely business interests, preferences, attribution, and feature affinity | Analytics, product improvement, and marketing | Analytics and advertising providers |
| Sensitive personal information: account credentials and, when customers choose to submit it, certain voice or Customer Content | Authentication, security, and providing the specific requested feature | Customer-selected recipients and providers necessary for the requested feature |
We do not use or disclose sensitive personal information for purposes that require a right to limit under California law. We do not sell personal information for money. In the preceding 12 months, we may have “shared” identifiers, internet or network activity, and related inferences with advertising and analytics partners for cross-context behavioral advertising. Use Do Not Sell or Share My Personal Information or a recognized Global Privacy Control signal to opt out.
California residents may exercise the rights described in Section 12. California's “Shine the Light” law may also permit residents to request information about disclosures for third parties' direct marketing. We do not disclose personal information to third parties for their own direct marketing without the choices described in this Policy.
14. EEA and UK information
Individuals in the EEA and UK have the rights described in Section 12, including the rights to object to processing based on legitimate interests and to object to direct marketing at any time. When we ask for consent, you may withdraw it at any time. Withdrawal does not affect prior lawful processing.
You may complain to the data protection authority where you live or work or where you believe an infringement occurred. We encourage you to contact [email protected] first so we can try to resolve the concern. Trails does not make decisions based solely on automated processing that produce legal or similarly significant effects about individuals for its own purposes.
15. Australia information
Where the Australian Privacy Act 1988 and Australian Privacy Principles apply, you may request access to or correction of personal information and complain about our handling of it by contacting [email protected]. Please provide enough detail for us to investigate. We will acknowledge and respond within a reasonable period. If you are dissatisfied, you may contact the Office of the Australian Information Commissioner.
16. Children
Trails is a B2B service and is not directed to minors. Individuals under 18 may not create accounts or use the Services. We do not knowingly collect personal data directly from minors. If you believe a minor has created an account or submitted data to Trails, contact [email protected]. This does not prevent a business customer from lawfully including limited information about a minor in Customer Content where the customer has all required authority and safeguards; the customer remains responsible for that processing.
17. Changes
We may update this Policy as our Services, vendors, and legal obligations change. We will post the updated version and revise the effective date. If a change materially affects how we use previously collected personal data, we will provide additional notice and obtain consent where required. We encourage you to review this page periodically.
18. Contact us
Send privacy questions, requests, and complaints to:
Third Arc Inc. dba Trails
Attn: Privacy
2501 30th Ave.
San Francisco, CA 94116
United States
Email: [email protected]