Skip to content

Privacy

Last updated 27 August 2026

This is a starting template, not legal advice. Have a lawyer review it before you launch.

The short version

TraceScreen records what you point it at, and the technical context a developer needs to reproduce a bug. It does not run in the background, it has no access to sites you are not actively recording, and it does not build a profile of you.

What we collect

Your account

  • Name and email address
  • A hashed password (Argon2id — we never store the password itself)
  • Workspaces you belong to and your role in each

Recordings you make

The video or screenshot itself, its title and description, and any comments left on it. Recordings are stored so you and the people you share with can watch them.

Technical context, captured with a recording

Every field below exists because a developer needs it to reproduce a bug. Nothing is collected because it is merely possible to collect.

FieldWhy
Page URL and titleWhere the problem happened
Browser and versionVersion-specific bugs are the common case
Operating systemPlatform-specific rendering and input bugs
Viewport and screen sizeLayout bugs are size-dependent
Timezone and languageDate, number and locale formatting bugs
Console errorsThe highest-value signal for reproducing a fault

Console errors are collected only while you are recording that tab, and only where the browser permits it. When it does not, the recording says so rather than showing an empty list.

Viewing a shared recording

When someone opens a share link we record that it was opened and how far the video was watched. We do not record an IP address, a user agent, or any device fingerprint. A viewer is represented by a random key their own browser generates and stores, which exists so that one person is not counted as ten. Clearing site data resets it.

What we never collect

  • Passwords, authentication tokens, cookies or session identifiers
  • Payment card details or bank information
  • Private keys or API credentials
  • Values typed into forms on pages you record
  • Network request or response bodies
  • Anything at all from tabs you are not recording

Before any technical context leaves your browser it passes through a redaction step that removes credential-shaped text — JWTs, bearer tokens, provider API keys, card-shaped numbers, credentials embedded in URLs, and sensitive query parameters. It is deliberately over-cautious: it would rather redact something harmless than let a token through.

Redaction reduces risk; it cannot eliminate it. You are recording your own screen, so please do not record a page showing something you would not want the recipient to see.

Who can see your recordings

  • Members of the workspace the recording belongs to
  • Anyone you give a share link to — links are unguessable, but they are links, so treat one like a key
  • Nobody else. Recordings are not public unless you make them so

A share link can carry a passphrase and an expiry date, and can be revoked at any time. Revoking takes effect immediately.

Where it is processed

Recordings are transcoded on our own servers using FFmpeg. When you ask for an AI bug report, the recording’s title, description, browser context and console errors are sent to Anthropic to generate it. The video itself is never sent to any AI provider. If you never request a report, nothing is sent.

How long it is kept

Recordings are kept until you delete them, subject to your plan’s retention period. Deleting a recording revokes its share links immediately and removes the files shortly afterwards.

Your choices

  • Delete any recording at any time
  • Revoke a share link at any time
  • Turn off console collection in the extension’s options
  • Delete your account, which removes your recordings with it

To delete your account or ask what we hold about you, write to support@tracescreen.app.

Cookies

We use a session cookie to keep you signed in, and a cookie to remember that you unlocked a passphrase-protected share link. There are no advertising or cross-site tracking cookies.

Changes

If this policy changes in a way that affects what we collect, we will say so here and update the date at the top.