Email is the whole support system. There is no ticket portal and no account to log into, because Retrace has no accounts. Write to retrace@dragonfractal.com and a person reads it.
Retrace talks to servers we cannot see, so the useful details are the ones only you have:
Never send a password, a private key, or the contents of a file you would not publish. We will never ask for any of them.
Hostnames and bucket names are usually fine to redact — the protocol and the message matter far more than the address.
The server rejected every credential Retrace offered. If you are using a
hardware key, check it is actually enrolled on that server: the public half
is on the keys screen, and it has to be in the server's
authorized_keys.
Retrace refuses the connection rather than asking you to accept it, which is deliberate. If you know why it changed — the server was rebuilt, say — forget the pinned key in Settings under Known hosts, then reconnect and check the new fingerprint against the server.
That is the server's answer, not Retrace's. On S3 it usually means the credentials are scoped to a prefix and the destination is outside it — dropping onto a host row targets the bucket root, which scoped credentials often cannot write. Drop onto a folder inside the bucket instead.
Android only lets an app read folders you explicitly pick. Use add a folder on the host list to grant one; the grant persists.
Write to retrace@dragonfractal.com with "security" in the subject and we will reply before doing anything else. Please do not open it publicly until we have had a chance to fix it.
What Retrace stores and what it never sends is in the privacy policy. The short version: it has no backend, so there is nothing for us to look up about you — which is also why the details above have to come from you.