tracewise — founders · Mactracking freelancers · right now
Legal

Privacy Promise

Effective date: 1 June 2026 · Last updated: 11 September 2026

TL;DR — the short version
We see file names, timestamps, and project folders.
We never see file contents, code, or keystrokes.
Your data is stored locally first, synced only when you sign in.
We never sell your data. Ever.
You can delete your data anytime, and request an export whenever you need one.
We don't use third-party ad trackers on the dashboard.

1. What we collect

From the agent on your Mac:

  • File-system events: file name, parent folder path, event type (save, create, delete), and timestamp. We never read or transmit the contents of any file.
  • App-switch events: which application was in the foreground and for how long, used to detect context switches. We do not record what you typed or clicked.
  • Idle gaps: periods with no keyboard or mouse activity, used to calculate session boundaries.
  • A computed "focus score" per minute, derived entirely from the signals above.

From your account:

  • Email address (used for authentication and billing emails).
  • Display name (shown in the dashboard and on invoices).
  • Subscription status and billing history (managed by our payment processor; we do not store card numbers).

Automatically from the dashboard:

  • Browser type and OS version (for compatibility debugging).
  • Nothing else. The dashboard runs no analytics, no error-reporting service, and no tracking pixels. Your browser only talks to our database and payment provider.

2. What we never collect

  • File contents — we never store or transmit the contents of any file. To tell a real edit from a plain save, the agent computes a checksum of the first 64 KB of a saved file on your Mac; the bytes are discarded immediately and never leave the process.
  • Keystrokes or clipboard contents.
  • Screenshots or screen recordings.
  • Your Git history, commit messages, or code diffs.
  • Data from folders you have not added to tracewise. On first launch we suggest common code folders (such as ~/Projects, ~/Developer, ~/Documents, ~/Desktop) — you confirm the list before tracking starts and can change it any time from the menu bar.

3. How we use your data

  • To display your focus sessions, focus scores, and project breakdowns in the dashboard.
  • To generate invoices and weekly reports on your behalf.
  • To produce AI insights (these run on our servers using your session summaries — never raw file contents).
  • To send you transactional emails (magic-link login, invoice ready, billing receipts).
  • To improve the product — we analyse aggregate, anonymised patterns across all users. We never analyse individual sessions without consent.

4. Data storage and security

Session data is stored locally in a SQLite database at ~/.tracewise/events.db on your Mac. It is synced to our Supabase-hosted database (EU region, Zürich) only when you are signed in and connected to the internet.

All data in transit is encrypted with TLS 1.3. Data at rest is encrypted at the database level. We use row-level security so your data is accessible only to your account.

Cookies and local storage. tracewise does not use tracking or advertising cookies, and we run no analytics that profile you. The dashboard uses your browser's local storage only for essential functions — keeping you signed in and remembering your light/dark theme preference. Because we set no non-essential cookies, there is no cookie-consent banner to click through.

5. Third-party services

  • Supabase — database, authentication and file storage (EU region, Zürich).
  • Paddle — payment processing and merchant of record. We never see or store your card details.
  • Anthropic Claude API — used to generate AI insights on paid plans. The request contains per-project minute totals and session timestamps only — never file names, paths, or contents.
  • Resend — transactional email (founding-program and account emails).
  • Cloudflare Turnstile — bot protection on sign-in forms, when enabled.

We do not use Google Analytics, Meta Pixel, or any advertising trackers.

6. Your rights

You have the right to:

  • Access — export everything we hold about you as a JSON file from Settings → Your data → Export data.
  • Delete — delete your account and all cloud-synced data from Settings → Your data → Delete account. Deletion is immediate. Local data on your Mac lives in ~/.tracewise — delete that folder to remove it.
  • Correct — update your name at any time from Settings, and change your sign-in email from Settings → Sign-in email (we confirm the change at both addresses).
  • Portability — your export includes everything we hold about you in machine-readable format.

If you are in the EU, you may also lodge a complaint with your national data-protection authority.

7. Data retention

We keep your cloud-synced data for as long as your account exists. Cancelling a subscription does not delete anything — it only stops billing. When you delete your account, all cloud data is removed immediately; encrypted database backups that may still contain it expire within 30 days. Anonymised, aggregated statistics derived from your data (e.g. "average session length across all users") may be retained indefinitely as they cannot be linked back to you.

8. Changes to this policy

If we make a material change to how we handle your data, we will email you at least 14 days before the change takes effect. Minor clarifications may be made without notice but the "Last updated" date at the top will always reflect the latest version.

9. Contact

Privacy questions, data requests, or concerns: privacy@tracewise.app. We aim to respond within 5 business days. For formal data-access requests under GDPR, use the same address and include "GDPR request" in the subject line. Our Terms of Service and Refund Policy explain the related account and billing rules.