Privacy Policy

Last updated: September 18, 2026

1. Introduction

TrailGuide is a marketing orchestration platform. Marketers and their AI coworkers run campaigns through a Model Context Protocol (MCP) server, a command-line interface, and this web application, which provides the orchestration and visualization layer. This Privacy Policy explains what we collect, how we use it, how AI models process your data, and the controls you have, including connecting your own model and minimizing data retention.

2. Information We Collect

  • Account and organization information: your name, email, workspace, and role, used to sign you in and administer your team.
  • Data you connect: to run campaigns you may connect data sources such as a data warehouse, product analytics, or an engagement or messaging platform. We access that data to build audiences, segments, and measurement as you direct.
  • Content you create: campaigns, copy, notes, tasks, skills, and the related prompts and AI output.
  • Usage and log data: actions taken in the app and over MCP, timestamps, and diagnostic logs used to operate and secure the service.
  • Calendar email: if you use the calendar subscription feature, described in the Calendar section below.

3. How We Use Your Information

  • Provide and operate the platform and the automations you configure
  • Generate marketing content and analysis using AI models (see below)
  • Deliver the messages you configure across your connected channels
  • Secure, debug, and improve the service
  • Communicate with you about your account and the service

4. AI Models and How Your Data Is Processed

By default, TrailGuide runs on Anthropic's Claude models to generate copy, analysis, and other content. To perform a task, we send the model provider only the inputs needed for that task, for example your prompt, the relevant campaign context, and the instructions you provide.

We do not sell your data, and we do not use your data to train foundation models. On the default path, model providers act as our subprocessors. When you connect your own model (see below), your data is processed by the provider you choose under your agreement with that provider.

Providers that can power content creation include:

  • Anthropic (Claude), directly or via Amazon Bedrock or Google Vertex AI
  • OpenAI and Azure OpenAI
  • Google Gemini
  • Mistral
  • OpenRouter
  • Any OpenAI-compatible endpoint you configure, including your own gateway or self-hosted model

5. Bring Your Own Model

Owners and admins can connect their organization's own model provider so that all content creation runs on your account and under your provider's terms rather than ours. This is the most complete control over how your prompts and outputs are handled.

  • Supported providers: Anthropic (direct, Amazon Bedrock, or Google Vertex AI), OpenAI, Azure OpenAI, Google Gemini, Mistral, OpenRouter, and any OpenAI-compatible endpoint.
  • Credential handling: the provider keys and secrets you enter are encrypted at rest and are never returned to the browser or exposed through the MCP.

6. Zero-Retention Mode

Owners and admins can turn on zero-retention mode, which minimizes platform-side retention of your prompts and AI output. With it off, TrailGuide may keep prompts and AI output to power logging and product features.

Connecting your own model is the definitive control: on that path, content generation happens under your chosen provider and your data-handling terms. You can change both settings at any time from Bots and Models in the app.

7. Data Sharing and Subprocessors

We do not sell, rent, or trade your personal information. We share data only with the subprocessors that operate the service, and each receives only what it needs for its function:

  • Cloud hosting and database providers that run the platform
  • The AI model providers described above (on the default path)
  • The message-delivery providers you connect, such as email, SMS, push, or chat services

Each organization's data is isolated by tenant.

8. Data Security

Data is encrypted in transit. Connected credentials and secrets are encrypted at rest. Outbound requests you configure are sent through a network layer that blocks internal and cloud-metadata addresses to reduce the risk of misuse. No method of transmission or storage is completely secure, but we work to protect your information.

9. Data Retention

We keep account and content data for as long as your organization uses the service, and we delete or anonymize it on request or within a reasonable period after account closure, subject to our legal obligations. Where zero-retention mode or your own model is in use, platform-side retention of prompts and AI output is minimized as described above.

10. Calendar Subscription Services

TrailGuide also offers calendar subscription features. If you subscribe to a calendar or add one through Google sign-in:

  • We collect your email address to create your calendar feed and send setup instructions if needed
  • We only request the minimum Google permissions needed to add a calendar subscription
  • We use the calendar.calendarlist scope to add the subscription
  • We do not access, read, or store your existing calendar events
  • We do not retain your Google access token after adding the calendar
  • You can remove the calendar subscription at any time from your Google Calendar settings

11. Your Rights and Choices

  • Access, correct, export, or delete your data by contacting us
  • Connect a private model and enable zero-retention mode at any time (owners and admins)
  • Revoke a connected integration from within the app or from the provider
  • Unsubscribe from a calendar at any time via your calendar app

12. Contact Us

If you have any questions about this Privacy Policy, please contact us at support@trailguide.co.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the date above.