Privacy Promise
1. What we collect
From the agent on your Mac:
- File-system events: file name, parent folder path, event type (save, create, delete), and timestamp. We never read or transmit the contents of any file.
- App-switch events: which application was in the foreground and for how long, used to detect context switches. We do not record what you typed or clicked.
- Idle gaps: periods with no keyboard or mouse activity, used to calculate session boundaries.
- A computed "depth score" per minute, derived entirely from the signals above.
From your account:
- Email address (used for authentication and billing emails).
- Display name (shown in the dashboard and on invoices).
- Subscription status and billing history (managed by our payment processor; we do not store card numbers).
Automatically from the dashboard:
- Browser type and OS version (for compatibility debugging).
- Pages visited within the dashboard, session duration.
- Error logs (stack traces, not user data).
2. What we never collect
- File contents — we never open, read, or transmit the contents of any file on your machine.
- Keystrokes or clipboard contents.
- Screenshots or screen recordings.
- Your Git history, commit messages, or code diffs.
- Data from folders you have not explicitly added to Tracewise.
3. How we use your data
- To display your focus sessions, depth scores, and project breakdowns in the dashboard.
- To generate invoices and weekly reports on your behalf.
- To produce AI insights (these run on our servers using your session summaries — never raw file contents).
- To send you transactional emails (magic-link login, invoice ready, billing receipts).
- To improve the product — we analyse aggregate, anonymised patterns across all users. We never analyse individual sessions without consent.
4. Data storage and security
Session data is stored locally in a SQLite database at ~/.tracewise/events.db on your Mac. It is synced to our Supabase-hosted database (EU region, Frankfurt) only when you are signed in and connected to the internet.
All data in transit is encrypted with TLS 1.3. Data at rest is encrypted at the database level. We use row-level security so your data is accessible only to your account.
Cookies and local storage. Tracewise does not use tracking or advertising cookies, and we run no analytics that profile you. The dashboard uses your browser's local storage only for essential functions — keeping you signed in and remembering your light/dark theme preference. Because we set no non-essential cookies, there is no cookie-consent banner to click through.
5. Third-party services
- Supabase — database and authentication (EU region).
- Paddle — payment processing and merchant of record. We never see or store your card details.
- Anthropic Claude API — used to generate AI insights from session summaries. Session summaries contain time and project metadata only — no file contents.
We do not use Google Analytics, Meta Pixel, or any advertising trackers.
6. Your rights
You have the right to:
- Access — export all your data as CSV or JSON from Settings → Data export.
- Delete — delete your account and all cloud-synced data from Settings → Delete account. Local data on your Mac must be removed manually (instructions provided).
- Correct — update your name or email at any time from Settings.
- Portability — your export includes everything we hold about you in machine-readable format.
If you are in the EU, you may also lodge a complaint with your national data-protection authority.
7. Data retention
We retain your cloud-synced data for as long as your account is active. If you cancel and delete your account, all cloud data is deleted within 30 days. Anonymised, aggregated statistics derived from your data (e.g. "average session length across all users") may be retained indefinitely as they cannot be linked back to you.
8. Changes to this policy
If we make a material change to how we handle your data, we will email you at least 14 days before the change takes effect. Minor clarifications may be made without notice but the "Last updated" date at the top will always reflect the latest version.
9. Contact
Privacy questions, data requests, or concerns: privacy@tracewise.app. We aim to respond within 5 business days. For formal data-access requests under GDPR, use the same address and include "GDPR request" in the subject line. Our Terms of Service and Refund Policy explain the related account and billing rules.