Privacy Policy

Trellis is operated by D7OM. The contact address is hello@d7om.dev.

This policy only describes what the product actually stores and how it is used.

Last updated .

What Trellis stores

For each account, Trellis stores your name, your email address, whether that address has been verified, an optional avatar image when your sign-in provider supplies one, when the account was created and last changed, and whether it predates paid plans.

It also stores OAuth account rows from the sign-in provider and session rows for signed-in browsers.

When you use the editor, Trellis stores the schema documents you create, their full version history, and share links with view or edit permission plus an optional expiry.

How Trellis uses that data

That data exists so Trellis can sign you in, keep your schemas and versions, create share links, and send the email that confirms account deletion.

How deletion works

Deleting an account is confirmed through a token sent to the account email address. A signed-in session alone cannot delete the account.

Once confirmed, the account is scheduled for deletion and stops working straight away: you can still sign in, but nothing else, and every share link and embed for your schemas stops resolving. You have 30 days to change your mind and restore it from the account screen.

After 30 days everything is removed for good: the user record, schema documents, version history, share links and embeds all cascade away together. Until then the account still exists, which means its email address cannot be used to register again.

One thing outlives the account, deliberately. Trellis keeps a log of actions taken on it — a schema created, a link shared, an export run — so that operational questions and abuse can be investigated. When the account is finally removed, those records are stripped of anything identifying: the account id, the email address and the IP address are replaced with a random label that cannot be turned back into you. What is left is the date and the kind of action.

Who at Trellis can see what

Trellis is run by one person, who can see account information: your email address, when you signed up, which plan you are on, and how many schemas, share links and embeds you have. That is what running a service requires.

They cannot read the contents of your schemas from the operator tools. There is no screen that shows them, and the tools deliberately deal in counts rather than documents.

Every action an operator takes on an account — changing a plan, signing sessions out, revoking a link — is recorded with who did it, to which account, and a written reason. That record cannot be edited or deleted.

Processors and hosting

Trellis uses Postgres for storage, Resend to send the deletion email, Google and GitHub for sign-in, and Vercel for hosting when the app is deployed there.

Tracking

Trellis does not use analytics, advertising, or third-party scripts, and it does not set cookies beyond the session cookie Better Auth uses.

At this revision, the fonts are self-hosted, so the app makes no cross-origin requests when it loads.

Contact

Questions about privacy or deletion can be sent to hello@d7om.dev.