Skip to content
trismag
ProductPlaygroundDevelopersTrust center
Get started ↗
TRISMAG / OPEN PREVIEW
Trust centerPrivacy policyTerms of use

Privacy policy

Effective September 11, 2026. Operator: Jonathan Hill, an individual operating as Trismag. Trismag is not currently an LLC. Contact: Jonhillnj@gmail.com.

This policy covers trismag.dev, its Trismag Netlify previews and gateways, api.trismag.dev, and trismag-api.fly.dev. It also explains the separate handling of support email. It does not cover unrelated sites operated by the same person.

The short version

The Trismag application processes scan content in memory and is designed not to write raw scan payloads or a history of their verdicts to application storage or logs. We do not use submitted scans to train models, sell them, or use them for advertising. This is not a promise that no data is processed or that no logs exist anywhere. Hosting providers process requests, the API stores account and abuse-control records, and messages you deliberately email us are retained separately.

Do not submit credentials, private keys, passwords, regulated records, or other sensitive content to the public demo. Use synthetic or properly deidentified examples. Submit content only if you have authority to have it processed.

What passes through the service

  • Local examples: selecting a reference example runs in your browser; it does not submit that example for a live scan. Visiting the site still sends ordinary page requests to its host.
  • Anonymous homepage scans: text goes over HTTPS directly to the Trismag API on Fly.io. Visitors sharing a public IP also share the anonymous allowance.
  • Keyed website scans: your content and API key pass through a Netlify function to the API on Fly.io. The gateway does not intentionally persist request bodies or keys and sends scan responses with no-store caching instructions.
  • Direct integrations: requests to api.trismag.dev or trismag-api.fly.dev reach Fly.io. Legacy API routes on trismag.dev pass through Netlify before Fly.io. Findings returned to you can include excerpts of your input; your integration determines how it stores those responses.
  • API key issuance: the supplied email is processed to create a salted hash for account lookup. The account database does not retain the raw email or raw issued key. This does not mean the email was never received in memory or that a hash is anonymous.
  • Optional MCP URL inspection: when you explicitly supply a server URL to the API, the service contacts that public HTTPS server to initialize MCP and request tool metadata. It does not invoke the listed tools or deliberately forward your Trismag key or separate scan content. The named server sees the connection and the requested URL, including any path/query you supplied. Do not embed secrets in URLs. Pasted metadata inspection does not make that outbound request.

Memory processing is not a guarantee of immediate secure erasure from RAM, protection against a compromised host, or absence of every possible infrastructure copy. HTTPS protects transport; Trismag must access plaintext to inspect it.

Stored application data and retention

Data Purpose and form Current retention behavior
Account and key records SHA-256 key hashes; salted email hashes and salts; creation dates, plan/label, balances Retained while the account exists; operator-assisted deletion is available. There is no automatic inactivity deletion.
Daily usage records Pseudonymous client identifiers, date, request category and count Eligible for removal when older than seven days at the next cleanup.
Burst and monthly counters Key-derived identifiers and usage counts Burst rows older than one hour become eligible for cleanup. Current and previous calendar-month counters are retained; older months become eligible for cleanup.
Duplicate-request records Salted request-byte hash, pseudonymous client identifier, timestamp A repeat normally stops qualifying for deduplication after 600 seconds. Expired rows remain until cleanup; ten minutes is a reuse window, not a guaranteed deletion deadline.
Grant records Key hash, reference, amount, source, creation date Retained with the account unless deleted. Manual grants can exist; no public payment checkout is currently available.
Support and privacy requests Your email address, message and any information you choose to provide Retained in the operator’s email account while resolving the request and for legitimate follow-up, security or legal needs. No automatic fixed deletion schedule is currently configured. Ask for deletion when appropriate.

Cleanup currently runs at API startup and on the key-issuance path, not on a periodic deletion timer. Eligible records can therefore remain longer, especially without those events. Deleting SQLite rows does not promise immediate forensic erasure from database pages, write-ahead logs or existing backups. Disabling deduplication stops new dedupe inserts but is not a purge of all stored data.

Hashes and pseudonyms are not anonymous data. A party with the database and salts may test guessed text or email addresses and may reconstruct network addresses. Usage totals reveal activity even though they are not a content or verdict archive.

Backups and infrastructure copies

Operator SQL exports currently remove daily_usage rows but can retain recent_bodies request fingerprints and client pseudonyms, along with accounts, balances, salts and grant records. Fly volume snapshots can contain the full database, including metering and deduplication tables. Existing local exports and snapshots do not have a verified uniform deletion deadline. They are not described as anonymous or free of client identifiers.

An account deletion removes its active account, credit, grant and key-linked usage rows. It does not automatically erase old exports, provider snapshots, unrelated IP-derived records or correspondence. The operator must address identifiable copies separately when handling a valid request. We will explain applicable limitations, preservation requirements and available deletion steps rather than promising immediate deletion everywhere.

Providers and other disclosures

  • Netlify hosts the website and gateway functions and processes traffic to them. Netlify privacy information.
  • Fly.io hosts the API and its volume, and terminates HTTPS on the direct API path. Fly.io privacy information.
  • Cloudflare provides authoritative DNS for the Trismag domain. The current records use DNS-only routing; this does not make Cloudflare an HTTP scan gateway. Cloudflare privacy information.
  • Google/Gmail processes support and legal email sent to the operator’s Gmail address. Emailing us is a separate path from scanning. Do not email raw API keys or sensitive scan samples. Google privacy information.
  • An MCP server you name receives the optional metadata request described above. Its operator has its own practices.

Providers may process IP addresses, request paths, timestamps, status codes and other operational metadata under their service configurations, contracts and policies. Their general privacy pages do not establish exact retention settings for this deployment. Our tests do not audit provider logging or backups. Processing can occur in the United States and other countries where providers operate; the configured API region is US East (iad). We do not promise geographic data residency or claim a certification, data-processing agreement or legal transfer mechanism that has not been established for your use.

We may disclose information we actually hold when legally required, to address abuse or security incidents, or to establish or defend legal claims. We cannot supply a raw scan archive that the application did not retain, but stored metadata, correspondence and provider records are different categories. If operation transfers to a future company, we will update this policy and provide notice where required; an LLC has not already been formed.

Browser storage, tracking and security

The Trismag website code does not add advertising, analytics, session replay or tracking cookies. It does not save playground API keys in cookies, local storage, session storage or URLs. A key stays in the current page’s password field until cleared or the page closes; use Forget to clear it. Browser extensions, autofill and customer integrations can handle information separately. Third-party provider websites have their own practices.

The application suppresses ordinary access logging and avoids raw-payload exception messages. It can log limited operational events such as an endpoint and exception type. Retention regression tests check selected synthetic canaries on exercised code paths and in readable local files, including the test database. They skip inaccessible files and files over the test size limit. They are not proof of every path, provider behavior, or universal zero retention. No security measure can guarantee absolute security.

Your choices and requests

Email Jonhillnj@gmail.com with the subject “Trismag privacy” to ask about access, correction, deletion, restriction, objection or portability where applicable. Use the email associated with the API account and describe the request; do not send your API key. We may need proportionate verification before disclosing or changing account data. We respond within applicable legal deadlines and explain if information cannot be located, verified or deleted. Account deletion makes its key unusable. A scan-content history cannot be exported because the application does not retain one.

Where applicable, you can complain to your local data-protection authority and exercise rights without unlawful discrimination. Rights and exceptions depend on your location and circumstances; this page does not claim that every privacy law applies to Trismag. The service is intended for adults and is not directed to children. Contact us if you believe a child submitted personal information.

Changes

The effective date appears above. We will update this policy when practices change and provide additional notice where required. This revision corrects earlier statements about exact deletion deadlines, backup exclusions and the hosting path; it does not mean new scan-content logging has been introduced. Because account emails are hashed in the API store, a universal email notification mechanism is not available. Current notices will be published on the website and changelog.

trismag

A clearer signal.
Before the next action.

Documentation ↗Security & limitations ↗Changelog ↗API health ↗
© 2026 Trismag · Jonathan HillEarly warning. No guarantee of complete detection or protection.PrivacyTerms