Terms and conditions
These terms govern use of Trace Commons: the websites, documentation, contributor software, ingest and issuer services, and community surfaces.
Effective 22 August 2026. Using the services, enrolling a device, or submitting a trace means you accept these terms. If you cannot accept them, do not contribute.
Who these terms bind
They bind anyone who visits the sites, installs a client, redeems an invite, submits a trace, or opts into public attribution.
If you act for an organisation or a lab, you confirm you have authority to bind that group to the parts that apply to it.
You must have legal capacity to agree. If you contribute traces, you must have the right to share what you submit.
What this is, and is not
Trace Commons keeps the record of what AI agents did under terms the contributor set. Contributors capture and scrub those records on their own machines. Only the scrubbed envelope leaves, carrying a revocable consent scope that decides what any future query is permitted to do with it.
You can rely on these statements:
- Contributors set the terms of use for their own records, and those terms bind. A record's consent scope decides what any query may do with it. Scopes are revocable.
- Corpus-level analytics stay open to everyone — no invite, no account, no payment.
- A Trace Credit is a signed, on-chain record that a submission was accepted. Credits are non-transferable.
- When buyers pay to query the register, that flows to contributors. Trace Commons is not a platform collecting rent on other people's work. That payment path is a commitment. It is not yet a capability a reader can exercise.
- Submissions pass two gates: whether a record differs meaningfully from what is already held, and whether it is substantive rather than template-shaped.
We do not claim:
- A corpus size or contributor count on this page. Those numbers move. Pull them live from analytics and date them.
- That Trace Commons is an open dataset. Contribution is invite-gated and query access is not yet open. "Open" describes the commitment and the public analytics, not present-day access to the records.
- Partner, customer, or funder names unless that party has said so themselves.
- Anything about individual contributors. The leaderboard shows only people who explicitly opted into public attribution. Absence from it is not information about anyone.
- Safety or accuracy claims about the agents whose work is recorded. The register documents what agents did. It does not certify that any of it was correct.
Websites and documentation
The public sites include this site, docs.tracecommons.ai, and pages published from the landing and community repositories. They are provided as-is, for the purposes described on each page.
Two surfaces are open without an invite or account: corpus analytics and the contributor leaderboard. Profile management, contribution, and query of records are not.
Do not scrape, overload, or probe the sites or APIs beyond ordinary use of published pages and documented routes. Do not attempt to deanonymise contributors, recover suppressed cells, or treat aggregate figures as a statement about any named person. See the privacy notes and the data policy for what published aggregates do and do not protect.
Site content is not licensed for training or fine-tuning AI models. The site's content signals reserve that use.
Contributing traces
The pilot is invite-only. An invite lets an approved client create a local device identity and register its public key. Redeeming an invite does not discover, read, redact, queue, or upload a trace. Choosing what to contribute is a separate action.
Treat a complete invite link as a temporary credential. Do not put it in an issue, shared chat, screenshot, log, or checked-in file. If it is exposed, ask the operator to revoke it.
The rule that applies on every path:
- Raw session files stay on the contributor's machine.
- A client parses and redacts locally, applies the contributor's consent scope, and submits a versioned envelope.
- Recording and sharing are off until you turn them on. You can turn them off again.
- Preview or dry-run before the first upload. Approve only what you intend to send.
- The server treats the client as untrusted. It validates and re-scrubs every envelope before accepting it into the register or holding it for review.
You are responsible for what you submit: that you have the right to share it, that you have reviewed the redacted preview, and that the consent scopes match the uses you want to allow. Do not submit another person's work, private data, or secrets as a way of getting them off your machine. Local redaction is a control, not a licence to be careless.
A successful upload returns a receipt with a stable
submission_id. Keep it. Delivery is not the same as
acceptance, credit, public visibility, or distribution. Statuses such
as accepted, quarantined, and
awaiting_pii_backstop are described in the
docs.
Consent, redaction, withdrawal
Consent travels with every trace. A deployment can impose a narrower ceiling. A client cannot use that ceiling to grant more than you selected. The set returned during enrollment is authoritative for that contributor and deployment.
| Scope | What it permits |
|---|---|
debugging_evaluation | Debugging, evaluation, and permitted aggregate analysis. Default on many paths. |
benchmark_only | Evaluation, bounded benchmark generation, aggregate analytics. |
ranking_training | The above, plus ranker training. |
model_training | The above, plus training-data inclusion. |
public_attribution | A separate profile permission. It links a pseudonym to a public handle. It does not grant any trace-content use on its own. |
Known secret shapes are replaced locally before upload. A fail-closed guard then scans the finished envelope. If secret-shaped content still survives, that session is refused rather than partially uploaded. Reasoning records can quote files and repeat values the model saw; they are redacted, but they remain the least predictable part of a transcript. Exclude them if you do not want them in the envelope.
Public attribution is off by default. A handle appears on the community site only if you opted in. Withdrawing public attribution takes effect in the register immediately and excludes the handle from later snapshots. A handle already in the published snapshot is removed when that snapshot is next recomputed.
Withdrawing a trace deletes Trace Commons' stored content and excludes
it from future use. Copies already distributed cannot be recalled. The
server reports one of three reach tiers:
not_distributed,
commons_not_distributed, or
commons_distributed.
Credit already recorded stays. Logging out, disarming a project,
uninstalling a client, or revoking a device is not withdrawal.
Uninstalling is not withdrawal. Do any withdrawing before you log out.
The privacy notes and data policy are part of these terms for contribution and public surfaces. If they conflict with marketing copy elsewhere, they win on what is stored, shown, and guaranteed.
Trace Credits
A Trace Credit is a receipt for work that cleared the gates — a signed, on-chain record of an accepted submission. It is tied to a particular record. Sending records, on its own, earns nothing. Credits cannot be bought, sold, or handed on. Nobody else can take them off you.
The server, not a client estimate, is authoritative for value and credit. Pending amounts can settle later; later utility events may add a separate ledger adjustment. A quarantined or privacy-held trace is not eligible for normal credit processing while it remains held.
Credits are not wages, equity, a security, or a promise of future payment. They do not create an employment, partnership, or agency relationship.
Query access
Open query access is not yet available. When it is, a record's consent scope will still decide what a query may do with it, and those scopes will still be withdrawable. Do not assume that contributing today grants you, or anyone else, a right to download the corpus.
Acceptable use
Do not:
- Bypass or disable local redaction, preview, or consent.
- Submit traces you do not have the right to share, including other people's private sessions, employer secrets, or exam material you are not allowed to disclose.
- Try to game novelty or substance gates with template-shaped filler, duplicated sessions, or synthetic junk.
- Probe, scrape, or attack the issuer, ingest, scoring, or community surfaces beyond documented use.
- Impersonate Trace Commons, imply an endorsement, or present unpublished partner or funder relationships as fact.
- Use the sites, APIs, or corpus in a way that breaks applicable law.
We may refuse, quarantine, or withdraw access, or revoke invites, if these terms, the data policy, or a published code of conduct is broken.
Name, marks, and press
The name is two words, both capitalised: Trace Commons. Not TraceCommons, not tracecommons. No article. Trace Credit is a defined term. Ironclaw is a separate project, one word, capital I.
Logo files are for referring to Trace Commons. They are not a licence to use them as part of your own logo, product name, or domain, or to imply that Trace Commons endorses, partners with, or has reviewed something it has not. Clear space, minimum sizes, and which file to use are on the brand and press page. Boilerplate on that page may be reproduced and edited; if you edit it, stay inside what you can safely say.
Software and third parties
Contributor clients and related packages may be signed and published by Iqlusion Inc. Check the publisher shown at install time rather than clicking past it. Ironclaw is a separate local capture tool that Trace Commons depends on; its own terms apply to that software.
Trace Credits are recorded on NEAR. NEAR, agent vendors, and model providers are not Trace Commons, and product names used to describe which tool produced a session are those parties' marks.
Optional extra privacy filtering may send already-locally-redacted message text to a configured TEE-hosted filter. Structured tool payloads do not use that path. If the filter is unavailable, the batch is refused rather than uploaded unfiltered.
Disclaimers
The services are a pilot. They are provided as is, without warranties of any kind, including merchantability, fitness for a particular purpose, non-infringement, uninterrupted availability, or that redaction will catch every secret. Residual risk remains with the contributor who chose to submit.
Acceptance into the register is not a judgement that the recorded agent work was correct, safe, original, or useful to you. Credits, scores, and gate outcomes are not advice.
Limitation of liability
To the fullest extent permitted by law, Trace Commons, Iqlusion Inc., and their officers, employees, and contractors are not liable for indirect, incidental, special, consequential, or punitive damages, or for lost profits, data, or goodwill, arising from the services.
Nothing in these terms limits liability that cannot be limited: fraud, or death or personal injury caused by negligence, where that limit would be unlawful.
Changes
We may update these terms. The date at the top is the effective date of the published version. Continued contribution after a change is acceptance of the new terms for traces submitted after the change. Consent scopes already attached to a submitted trace continue to bind that trace until withdrawn.
Contact
Brand and press: zaki@manian.org.
Privacy notes: /about/privacy. Data policy: /about/data-policy. Brand: /about/brand. Contributor docs: docs.tracecommons.ai.