Privacy & Compliance Architecture
Mathematical privacy guarantees via 24-hour rotating salt SHA-256 IP hashing, zero terminal storage, and strict GDPR / ePrivacy compliance.
Zero Terminal Storage Architecture
Under European Union ePrivacy Directive (Directive 2002/58/EC, Article 5(3)), consent is required when information is stored on, or retrieved from, a user’s terminal equipment (e.g. cookies, local storage tokens, IndexedDB, canvas hardware fingerprints).
Tracium does not emit Set-Cookie headers, access window.localStorage, or inspect hardware canvas/audio contexts. Every transaction is stateless and processed purely in volatile RAM during transit.
Cryptographic IP Hashing & Salt Rotation
Raw client IP addresses are immediately stripped at the edge. Tracium computes an irreversible one-way cryptographic hash:
The Daily_Salt_Secret is generated from a cryptographically secure pseudo-random number generator (CSPRNG) at 00:00:00 UTC and purged at 23:59:59 UTC. Because earlier salts are destroyed from memory, hashes cannot be pre-computed via rainbow tables or reversed to reveal real client IP addresses.
Regulatory Compliance (GDPR, PECR, CCPA)
| Statute / Framework | Jurisdiction | Legal Status | Implementation Mechanism |
|---|---|---|---|
| EU GDPR (Regulation 2016/679) | European Union | COMPLIANT | Zero PII storage; immediate cryptographic pseudonymization. |
| ePrivacy Directive (PECR) | EU / UK | EXEMPT | No terminal cookies written; cookie consent banner not required. |
| CCPA / CPRA | California, US | COMPLIANT | Zero data monetization or cross-context behavioral ad sales. |
Data Retention & Automated Purge Lifecycle
Ingested telemetry events are governed by database-level TTL (Time-To-Live) indexes on the created_at timestamp. Records exceeding your configured retention period (e.g., 30 days, 90 days, or 365 days) are automatically deleted by the database engine without residual backups.