Terms & privacy
Two products, one page: Trackshund, the managed private MLflow service, and the Trackshund iPhone app. The app works with any MLflow server, so most of what follows about the service does not apply to it — and where that is true, it says so.
Last updated 8 August 2026.
Part one: terms of service
By creating a Trackshund account, or by using the iPhone app, you agree to these terms. They are between you and Trackshund — "we", "us", "Trackshund" below.
Your account
You are responsible for keeping your sign-in credentials safe and for what happens under your account, including what the people you invite do with it. We do not store your password: sign-in is handled by our identity provider, which holds the credential and any second factor.
You must be able to form a binding contract to open an account, and you must give a real email address — it is the only way we can reach you about your own server.
What you pay
Trackshund is in beta and free. When paid plans begin, the price and what it includes will be on the pricing section of the site before you are charged, and we will tell existing customers at least 30 days before any price change that affects them.
We do not currently take payments. When we do, card details will be handled by a payment processor and we will not see or store full card numbers. This page will be updated in the same change that turns payments on, naming the processor.
Your data is yours
Everything you log to your MLflow server — experiments, runs, metrics, parameters, tags, models and artifacts — belongs to you. We claim no ownership of it and no licence to it beyond what is needed to run the server you asked us to run: storing it, backing it up, and serving it back to you.
It is plain MLflow. You can export it with MLflow's own tools at any time, with no involvement from us, and we would rather you knew that before you signed up than after you wanted to leave.
Cancelling, and what happens then
You can delete your server, or your whole account, from the dashboard. When you do, the server stops immediately and the data becomes inaccessible.
After that there is a 30-day window in which it can be restored if you tell us you deleted it by mistake. At the end of that window the database, the artifact bucket and the credentials are erased, and we cannot get them back for you — that is the point of erasing them.
We may suspend or close an account that is being used for something in the "What you may not do" list below, or where we are required to. Where we can give notice first, we will.
What you may not do
- Break the law with it, or help somebody else do so.
- Try to reach another customer's server, data or credentials. Each customer gets their own container, database and bucket; probing the boundaries between them is not research unless we have agreed in writing that it is.
- Use it to store or distribute malware, or to attack anything from it.
- Resell access, or run somebody else's workloads on your server in a way that makes you a hosting provider using our infrastructure.
- Abuse the people who work on Trackshund.
The service is provided as it is
We work to keep your server running and your data intact, and we take nightly backups kept for seven nights, stored where the server itself cannot reach them. But Trackshund is provided as is. We do not promise any particular level of availability, any restore time, or that the service will be free of faults, and nothing on this site should be read as promising one.
Keep your own copies of anything you cannot afford to lose. That is good advice about any hosted service, including ours.
To the fullest extent the law allows, we are not liable for indirect or consequential loss, lost profits, or lost data, and our total liability to you is limited to what you have paid us in the twelve months before the claim. While Trackshund is free, that figure is zero — which is the honest consequence of a free beta, and a reason to keep your own copies.
Changes to these terms
We will update this page as the product changes. When a change materially affects you, we will email the address on your account before it takes effect. Continuing to use Trackshund after that means you accept the change; if you would rather not, you can delete your account.
Part two: privacy
The short version: we collect what is needed to run a server for you and bill you for it, and nothing else. We do not sell your data, we do not advertise, and there is no analytics or tracking of any kind inside the iPhone app.
What the managed service collects
Your account. Your email address, an identifier from our identity provider, and the date you signed up. Your password and any second factor are held by the identity provider, not by us — we never receive them.
Your server's configuration. The name you chose, which becomes its address; which plan it is on; which machine it runs on; and its current state. Credentials for it are stored encrypted in a secret store and are not readable from the application database.
API tokens. Only a SHA-256 hash of each token, plus the first few characters so you can tell your tokens apart in the dashboard. The token itself is shown once, at creation, and is unrecoverable afterwards — if you lose it, we cannot look it up, you mint a new one.
What you log to MLflow. Your experiments, runs, metrics, parameters, tags, models and artifacts. These live in your server's own database and its own artifact bucket. We do not read them, index them, mine them, or use them to train anything.
Operational logs. Requests to the control plane and events from the provisioning pipeline, so we can tell why something failed. These can include your IP address, the path requested and a timestamp. Values that look like credentials — tokens, keys, passwords, session identifiers, ciphertext — are masked before a log line is written, by a filter that runs on every record rather than at each call site.
Website analytics. Self-hosted Umami, on our own infrastructure. It is cookieless, does not follow you between sites, and collects aggregate page views, referrer and country. It runs on the marketing site and the blog only — never in the dashboard, and never in the app.
Anti-abuse counters. Sign-in, sign-up and password-reset attempts are counted per email address and per client address for fifteen minutes at a time, so that a login form cannot be ground down by guessing. These counters expire on their own.
What the iPhone app collects
Nothing. That is the whole answer, but it is worth spelling out what it means, because "nothing" is a claim people are right to be sceptical of.
- There is no analytics SDK, no crash reporter and no advertising identifier in the app, and there will not be one.
- The app talks to the MLflow server you configure, and to nothing else. There is no Trackshund server behind it. If you point it at your own self-hosted MLflow, no traffic reaches us at all — we do not know you are using it, and we cannot.
- Your server's credential is stored in the iOS keychain on your device.
- Everything you browse is cached on your device so it works offline. That cache is deleted when you disconnect the server. Artifact files are never cached — they are fetched to a scratch area and deleted when you close the viewer.
- Alerts are local notifications, evaluated on your device against that local cache. No alert leaves the phone.
- Where the app summarises a run with AI, it uses Apple's on-device model. Your run data is not sent to us or to any AI provider.
If you use the app against a Trackshund-managed server, then that server is covered by the section above — but that is the service collecting it, not the app.
Who else can see it
We use a small number of infrastructure providers to run the service — a hosting provider for the machines, and object storage for artifacts. They hold your data because they hold the disks it is on; they do not get it for their own purposes.
People who work on Trackshund can access customer data only where it is needed to fix a problem or where the law requires it. We do not sell, rent or trade personal information, and we do not share it for advertising.
If we are ever legally compelled to hand over your data, we will tell you before we do, unless we are prohibited from doing so.
How long we keep it
- Your MLflow data: while your server exists, then 30 days after you delete it, then erased.
- Backups: nightly, kept seven nights, then overwritten.
- Your account record: retained after closure so that billing history and audit events still resolve to a subject, with the account marked closed.
- Operational logs: kept for troubleshooting and rotated; they are not a customer-data archive and are not mined.
Your rights
You can ask us for a copy of the personal information we hold about you, ask us to correct it, or ask us to delete it. Your MLflow data you can export yourself at any time using MLflow's own tools — no request needed.
Deleting your account through the dashboard starts the deletion described above. If you would rather ask a person, write to us.
Security
Traffic to your server and to this site is encrypted in transit. Each customer gets their own container, database and artifact prefix rather than a shared table with a customer column, and credentials live in a secret store rather than in the application database.
No system is perfectly secure, and we are not claiming any certification — we have not been through one. If you find a vulnerability, please tell us rather than anyone else: write to privacy@trackshund.com.
Children
Trackshund is a tool for professional and academic work and is not intended for anyone under 16. We do not knowingly collect information from children.
Changes to this policy
When our practices change, this page changes with them, in the same release. The date at the top is the date it last changed. Where a change materially affects what we do with your information, we will email you.
Getting in touch
Questions about any of this, requests about your own data, or a vulnerability report: privacy@trackshund.com.
Structure and plain-English register adapted from the Basecamp open-source policies, used under CC BY 4.0. The facts are ours, and describe this codebase.