Trust and deployment
Privacy, security, and self-hosting.
ReasonTrail is currently built as a private self-hosted application for project memory. This page describes the current approach and the missing launch disclosures without making unsupported compliance claims.
Legal notice
ReasonTrail is in private development. The operator identity, business address, registration details, VAT details, and final public contact address must be completed before a public EU launch.
Current contact placeholder: hello@reasontrail.local. Do not treat this placeholder as a final legal notice.
Controller and scope
For a self-hosted installation, the person or organization running the deployment controls the project data stored in that deployment.
For the private beta request form on this site, the operator of this website controls the contact details submitted through the form.
Data collected
The early-access form may collect name, email, role, active project count, current AI tools, hosting preference, and optional message content.
A self-hosted ReasonTrail deployment may store projects, conversations, tasks, decisions, resources, review items, usage records, local account details, and configuration settings.
AI provider boundary
AI features are optional. If enabled, selected project context may be sent to the configured AI provider or local model runtime to answer a request.
The self-hosted database remains local to the deployment, but provider requests are governed by the provider configured by the operator.
EU data rights
EU users may have rights to access, correction, deletion, restriction, portability, objection, and complaint to a supervisory authority, depending on the final operator and processing context.
Before public launch, the final privacy notice must identify the contact point for these requests and the retention period for private beta submissions.
Self-hosting
- Docker deployment for the app and PostgreSQL database.
- Local PostgreSQL storage with backups and JSON/Markdown exports.
- Configurable AI provider; AI features are optional.
- No external analytics by default on the public pages.
Security approach
- Local email/password authentication with server-side sessions.
- PostgreSQL storage controlled by the deployment operator.
- Backups and JSON/Markdown exports for portability.
- Explicit review before important project changes are accepted.
- Private network deployment recommended until public exposure hardening is complete.
- No claim is currently made for SOC 2, ISO 27001, HIPAA, or hosted GDPR certification.