Legal

Privacy Policy

How Trama handles personal data: what we collect, why, who helps us process it, how long we keep it and how you control it. Written to be read; the short version is that we collect what the product needs, we don't sell data, and analytics cookies wait for your yes.

On this page

Who we are

Trama (ontrama.com, formerly Lixta) is run by LOCOLTD Tech Ltda, CNPJ 61.801.879/0001-65, Av. Vicente Machado, 160, Conj. 0023, Centro, CEP 80420-010, Curitiba/PR, Brazil (“Trama”, “we”). We are the controller of the personal data described here.

Our data protection officer (encarregado, under Brazil's LGPD) is reachable at hello@ontrama.com.

This policy covers the website, the Trama app, the API at api.ontrama.com, the MCP server at mcp.ontrama.com, the free invoice generator and the GRUPIM bot. Content a workspace keeps about other people (for example a client's details on an invoice) is the workspace's responsibility: for that data the workspace is the controller and we process it on its behalf, following its instructions and the Terms of Use.

What we collect

DataWhat it is
AccountYour e-mail address, name, username and, if you add them, a phone number and a profile picture; your language. You sign in with a 6-digit code we e-mail you: there are no passwords.
Workspace contentWhat you and your team put in Trama: workspaces, boards, tasks, comments, documents, tags, milestones, files and images you upload, and who did what and when (activity and notifications).
Time and invoicesTime entries (who, which task, when, how long, notes), invoice clients, invoices and their Bill To / Ship To details, and invoice payments recorded.
Subscription paymentsFor card payments, Stripe collects the card in its own checkout: we never see the full number, only the card brand and last four digits. For Pix, the payer's name and CPF or CNPJ. Plan, amounts, dates and payment status.
Getting paidWhen a workspace receives invoice payments: its Pix key, the name and city shown with it, and its Stripe connected account id and status. Stripe collects the identity and bank details for that account directly.
IntegrationsIf you connect them: GitHub or GitLab account names and access tokens (encrypted), repositories, and pull/merge request titles, branches, status and checks linked to tasks (no code or diffs); GRUPIM server, channel and the link between your Trama and GRUPIM accounts.
API and MCPPersonal API keys (the secret is stored as a hash), and the OAuth clients and tokens of apps you connect, such as AI assistants over MCP, with when they were last used.
Technical dataIP address, browser user agent, pages and API paths requested, and timestamps, in our server logs. Text fields such as task descriptions, comments, invoice details, tax ids and Pix keys are filtered out of logs.
AnalyticsPages viewed, clicks (never what you type) and a few product events, such as creating a workspace or starting a checkout. Details under Cookies and analytics.
Error reportsWhen something breaks: the error, the page, your browser and, if you're signed in, your user id. Never cookies, request bodies, e-mails or sign-in codes.

The free invoice generator (/invoice) keeps your invoices in your own browser. To make a PDF, the invoice is sent to our PDF renderer for the length of that one request and is not stored.

Invoice pay pages (/pay/…) and published pages (/share/…) load no analytics. If you pay an invoice by card, you pay in Stripe Checkout on the workspace's own Stripe account.

Why we use it

PurposeLegal basis (LGPD)
Run your account and workspaces, sign you in, sync changes live, send sign-in codes, invitations and the notifications you keep onPerforming our contract with you
Charge for plans, keep billing and tax recordsPerforming the contract; legal obligation
Keep access logs for 6 monthsLegal obligation (Marco Civil da Internet, art. 15)
Keep Trama secure and working: fraud and abuse prevention, error monitoring, performance monitoring, backupsLegitimate interest
Count page views without cookies before you choose, and billing events such as a subscription starting or endingLegitimate interest
Analytics cookies (PostHog, Google Analytics) and the product events tied to themConsent, which you can withdraw any time
Answer you when you write to usLegitimate interest; performing the contract

We don't sell personal data, don't use it for advertising, and don't make automated decisions about you that have legal or similar effects.

Cookies and analytics

A banner asks before any analytics cookie is set. Accept lets PostHog and Google Analytics store their cookies; Decline turns analytics off and removes them. Until you choose, PostHog counts page views in memory only, with no cookie or storage. If your browser sends Do Not Track or Global Privacy Control, we treat it as Decline and don't show the banner. Change your mind any time with Cookie settings in the website footer or the app's account menu.

Google Analytics runs with Consent Mode: advertising storage, ad user data and ad personalisation stay denied, and Google signals is off. In the app, analytics know you by your user id and current workspace, never your e-mail.

NamePurposeKept for
lixta_sessionKeeps you signed in (necessary)30 days
lixta_wsRemembers your current workspace (necessary)1 year
trama_localeRemembers your language1 year
trama_consentRemembers your analytics choice1 year
ph_*PostHog analytics, only after Accept1 year
_gaGoogle Analytics, only after Accept (also _ga_<id>)2 years

The app also keeps a few preferences in your browser's local storage (theme, recent items, open sidebar sections, desktop notifications), and the invoice generator keeps its invoices there. They never leave your device unless you save invoices to a workspace.

Who processes it

We share personal data only with the providers below, to run Trama, under contracts that limit them to that purpose; with services you choose to connect; and when the law or a court requires it.

ProviderWhat forWhere
Our own serversThe app, the API, the database, error monitoring (self-hosted Sentry), PDF rendering (Gotenberg) and image resizing, on servers we operate on rented infrastructureBrazil
Amazon Web ServicesUploaded files and images; database backupsBrazil (files); United States (backups)
CloudflareDNS and network protection in front of our serversGlobal
ResendSending e-mails (sign-in codes, invitations, notifications)United States
StripeCard payments for plans; connected accounts that receive invoice paymentsUnited States, Brazil
MARX and EfíPix and Pix Automático payments for plansBrazil
PostHogProduct analyticsUnited States
GoogleGoogle Analytics, after consentUnited States
New RelicPerformance monitoring of the APIUnited States
DiscordInternal alerts to our team when someone signs up or signs in, or creates a workspace or board (with the account's id and the workspace or board name, never the e-mail)United States
GiphyAn animated image in invitation e-mails; loading it shows Giphy your IP addressUnited States

Services you connect, such as GitHub, GitLab, GRUPIM or an AI assistant over MCP, receive what you or your workspace ask Trama to send them and follow their own privacy policies. So do Stripe and your bank when you pay.

International transfers

Some providers above are outside Brazil, mostly in the United States. We transfer data to them only as the LGPD allows (art. 33): to perform our contract with you, under contractual safeguards such as standard contractual clauses, or with your consent for analytics.

How long we keep it

  • Account and content: while your account exists. Content in a workspace stays while the workspace exists.
  • Billing records (subscriptions, payments, invoices issued by Trama): at least 5 years, as Brazilian tax law requires, even after the account is deleted.
  • Access logs: 6 months, as the Marco Civil da Internet requires; longer only when needed for a security investigation or a legal claim.
  • Backups: daily, each kept for 7 days.
  • Error reports: 90 days. Analytics: up to 2 years.
  • Uploaded files no longer used anywhere are cleaned up after 7 days.

Your rights

Under the LGPD (art. 18), and similar laws such as the GDPR where they apply, you can ask us to confirm whether we process your data and to give you access to it; correct it; anonymise, block or delete data that is unnecessary or processed unlawfully; give you a copy in a portable format; tell you whom we share it with; and delete data processed on consent. You can withdraw consent, object to processing based on legitimate interest, and complain to Brazil's data protection authority, the ANPD, or your local authority.

Most of it you can do yourself: edit your profile in Account settings; export through the API and the invoice backup; change analytics with Cookie settings; turn e-mail notifications off in your notification preferences. For anything else, write to hello@ontrama.com. We answer within 15 days and may ask you to confirm it's you.

Deleting your account

Choose Delete account in Account settings. Deleting it signs you out everywhere, revokes your API keys and connected apps, and removes your personal data. Workspaces where you are the only owner are deleted with it, after you confirm. In workspaces you share with others, the content you created stays for the team and shows as made by “Deleted user”. Billing records we must keep by law stay for the period above, and backups roll over within 7 days.

Security

Traffic is encrypted with HTTPS. Your session lives in a cookie scripts can't read; integration tokens and webhook secrets are encrypted in the database and API secrets are stored as hashes. Access to production is limited to the people who run Trama. No system is perfectly secure: if a breach puts you at risk, we will tell you and the ANPD as the law requires.

Children

Trama is for people 18 and older. We don't knowingly collect data from children or teenagers; if you believe we have, write to us and we'll delete it.

Changes

When we change this policy we update the date at the top. If a change matters, such as a new purpose or a new kind of data, we tell you by e-mail or in the app before it takes effect.

Contact

Privacy questions and requests, including to our encarregado: hello@ontrama.com. Post: LOCOLTD Tech Ltda, Av. Vicente Machado, 160, Conj. 0023, Centro, CEP 80420-010, Curitiba/PR, Brazil.