Who We Are
Trame ("Trame", "we", "our", "us") is a business operating system for creative freelancers and studios, developed and operated by Peakgram Studio, based in Ibadan, Nigeria. Trame is accessible via usetrame.com and related subdomains.
This Privacy Policy explains how we collect, use, store, and protect your personal information when you use the Trame platform — including the web application, waitlist, email communications, integrations, community features, booking pages, and any other services we provide.
By using Trame, you agree to the practices described in this policy. If you do not agree, please do not use our services.
Data We Collect
Account Information
When you sign up, we collect:
- Your name and email address (via Google OAuth)
- Your profile photo from your Google account (optional)
- Your studio or workspace name
- Your creative category, experience level, and country
- Your subscription plan and billing status
Work and Project Data
When you use Trame to manage client work, we store:
- Project names, descriptions, deadlines, and status
- Client names, email addresses, and communication records
- Brief questions and client-submitted answers
- Design files, review annotations, and feedback threads
- Revision requests, scope flags, and change order records
- Invoices, payment records, and payout histories
- Studio Notes, mood boards, and brainstorm documents
- Call recordings, transcripts, and AI-generated meeting summaries (only when transcription is explicitly enabled by the creative)
Client Data (Collected on Your Behalf)
When your clients interact with Trame — submitting a brief, leaving review feedback, booking a session, or making a payment — we collect their name, email address, and the content of their interactions. This data is collected on your behalf as part of your workflow. Your clients are informed about Trame's involvement through the review links and booking pages you share with them.
Payment Information
We do not store raw payment card numbers or full bank account details. Payment processing is handled by Paystack and Stellar. We store transaction references, payment status, amounts, payout records, and masked account identifiers (e.g. last 4 digits).
Technical and Usage Data
- IP address, browser type, operating system, and device type
- Pages visited, features used, and time spent on the platform
- Error logs and performance diagnostics
- Referral source and UTM parameters on waitlist signups
- Session tokens and authentication data
Communication Data
- Emails you send or receive through Trame's notification system
- Support ticket content and live chat transcripts
- Community threads, replies, and reactions in The Guild
Integration Data
If you connect third-party services — Figma, Google Calendar, Canva, Notion, or Adobe — we store encrypted OAuth access tokens and the data necessary to operate the integration.
How We Use Your Data
To Operate the Platform
- Authenticate your account and maintain your session
- Store and display your projects, briefs, files, and client records
- Process invoice payments and route payouts to your bank account
- Generate change orders, scope flags, and revision tracking
- Enable real-time collaboration and team workspace features
- Run scheduled calls and session bookings with Jitsi integration
To Power AI Features
Your brief content, client answers, revision requests, and review feedback are processed through our AI systems (powered by Anthropic's Claude API) to provide Brief Intelligence, Scope Drift Detection, Feedback Translation, Change Order Generation, and the Trame AI assistant.
To Communicate With You
- Send transactional emails (invoice receipts, call reminders, brief notifications)
- Send platform notifications (scope flags, feedback received, payment settled)
- Respond to support tickets and live chat messages
To Improve the Product
We use aggregated and anonymised data for product analysis. We do not use your specific project content or client data for product analytics beyond what is necessary to operate features.
To Ensure Security
- Detect and prevent fraud, spam, and abuse
- Monitor for suspicious payment activity
- Enforce our Terms of Service
- Maintain our security audit trail
Data Sharing
Service Providers (Sub-processors)
We share data with trusted third parties only to the extent necessary to operate Trame. All sub-processors are contractually bound to protect your data.
- Supabase — database, authentication, file storage, real-time features
- Anthropic — AI language model processing (Claude API)
- Resend — transactional and notification email delivery
- Paystack — payment processing and bank account verification
- Stellar Development Foundation — blockchain payment rails (USDC/XLM)
- 8x8 / JaaS — video and audio calls via Jitsi infrastructure
- AssemblyAI — real-time call transcription (only when enabled)
- Google — OAuth authentication and Google Calendar sync (when connected)
Your Clients
When you share a review link, brief link, or booking page with a client, the content of that interaction is visible to them as intended. We do not share your internal notes, revenue data, or account information with your clients.
Team Members
If you invite team members to a workspace, they gain access to the projects, tasks, and communications within that workspace according to their assigned role. Workspace owners control who has access.
Legal Requirements
We may disclose your data if required by law, regulation, court order, or government request — only to the minimum extent required, and we will notify you unless prohibited by law.
Business Transfer
In the event of a merger, acquisition, or sale of Trame, your data may be transferred to the acquiring entity. We will notify you before your data is transferred and subject to a different privacy policy.
Payments and Financial Data
What We Store
- Invoice amounts, due dates, and payment status
- Transaction references from Paystack and Stellar
- Payout records showing amounts settled to your account
- Masked bank account details (bank name, last 4 digits)
- Paystack subaccount identifiers for direct settlement
- Stellar wallet public keys
What We Never Store
- Full payment card numbers
- Card CVV or expiry dates
- Full bank account numbers
- Stellar private keys in readable form
- Cryptocurrency seed phrases or wallet passwords
Platform Fee
Trame charges a platform fee on payments processed through the platform. This fee is deducted automatically at the point of transaction via Paystack's split payment system. Your net payout amount is always displayed transparently before and after each transaction.
Stellar / Blockchain Payments
Blockchain transactions are public by nature of the Stellar network. Transaction hashes can be verified independently on the Stellar blockchain explorer. Trame-generated wallet secret keys are encrypted using AES-256-GCM before storage.
AI Features and Your Data
What AI Processes
Trame uses Anthropic's Claude API to power: Brief Intelligence, Scope Drift Detection, Feedback Translation, Change Order Generation, the Trame AI Assistant, Call Transcription Summaries, and Community AI Insights.
How We Send Data to Anthropic
When you use an AI feature, the relevant context is sent to Anthropic's API. We do not send more data than necessary for the specific feature. Anthropic does not use API-submitted data to train their models under standard API usage terms.
Call Transcription
Call transcription is opt-in and must be explicitly enabled during an active call. Both parties are notified when transcription is active. Audio is streamed to AssemblyAI in real time and is not permanently stored by AssemblyAI after processing. Trame stores the resulting text transcript and AI-generated summary.
AI Data Retention
AI-generated content is stored in your Trame account as part of your project record. You can delete these records at any time from within the platform.
Third-Party Integrations
Figma
We use a Figma Personal Access Token (encrypted) to import design frames. We download frames as PNG images and store them in Trame's private storage. We only access files you explicitly import.
Google Calendar
When connected, we read your calendar events to block availability and write new events for calls, sessions, and deadlines. We store OAuth tokens encrypted. We access only: calendar read/write and your email address. We do not access Gmail, Drive, or other Google services.
Notion
We push approved briefs, project wraps, and change orders to Notion pages and databases you explicitly select. We do not read all of your Notion content.
Canva
We list and export Canva designs you explicitly select for import. We do not access your entire Canva account.
Adobe
File uploads for Adobe-format files are supported. The Adobe Express Embed SDK operates under Adobe's own privacy terms.
Token Security
All OAuth tokens for integrations are encrypted using AES-256-GCM before storage. They are never exposed in API responses, client-side code, or logs.
Data Retention
Active Accounts
Data is retained for as long as your account is active.
Deleted Accounts
Deletion begins within 30 days. Backups are purged within 90 days. Financial records are retained for up to 7 years to comply with Nigerian and applicable tax regulations.
Community Content
Guild content may remain in anonymised form after account deletion unless removed on request before deletion.
Waitlist Data
Retained until you request removal or convert to a Trame account. Email support@trame.app to remove.
Call Transcripts
Stored as part of your project record. Delete individually from the call detail page at any time.
Your Rights
Rights include:
- Access — request a copy of your data
- Correction — request correction of inaccurate data
- Deletion — request deletion of your personal data
- Portability — request data in machine-readable format
- Restriction — request restricted processing
- Objection — object to certain processing types
- Withdraw consent — where processing is consent-based
Contact privacy@trame.app to exercise any right. 30-day response time. Identity verification may be required.
Nigeria (NDPR / NDPA 2023)
Rights under the Nigeria Data Protection Regulation and the Nigeria Data Protection Act 2023. Complaints to the Nigeria Data Protection Commission (NDPC).
European Users (GDPR)
Rights under the General Data Protection Regulation. Lawful bases: contract performance and legitimate interests. Where consent is relied upon, you may withdraw at any time.
Security
Security measures include:
- TLS 1.2+ encryption in transit
- AES-256-GCM encryption at rest for sensitive credentials
- Row-Level Security (RLS) at the database level
- Immutable admin audit trail
- PKCE OAuth authentication flow
- HTTP-only, Secure, SameSite-protected session cookies
- Rate limiting on all sensitive API endpoints
- Server-side file type validation on all uploads
- Input validation and sanitisation to prevent injection attacks
- Real-time security event monitoring
Report vulnerabilities to security@trame.app.
Children's Privacy
Trame is not directed at children under 16. We do not knowingly collect data from children under 16. Contact privacy@trame.app if you believe we have inadvertently collected such data.
International Data Transfers
Trame is based in Nigeria. Infrastructure (Supabase) may process data in the United States and other jurisdictions. By using Trame you acknowledge cross-border data transfer. We use Standard Contractual Clauses where required under GDPR and select sub-processors maintaining adequate data protection levels.
Changes to This Policy
Material changes notified by email and dashboard banner at least 14 days before taking effect. Continued use after the effective date constitutes acceptance. You may close your account before the effective date if you disagree with changes.