Privacy

Last updated 2026-07-30 · Plain-English policy, no boilerplate.

Trace AI records introspective self-report data. That is a category of data more sensitive than typical web analytics — a leaked reasoning trace of a real person is more revealing than a leaked chat log. We take this seriously by design, not by policy.

What we don't collect

What the recorder captures — and where it stays

When you use the recorder at /record.html:

Audio (via your microphone), event tags you press, self-report snapshots you fill in, and session metadata (start/end timestamps, browser user-agent string) are all held in your browser's memory only during recording. Nothing is transmitted anywhere by default.

On stop, the recorder gives you a trace JSON and an audio blob as downloads. Those files land on your device, not our servers.

The only field we persist between sessions is an opaque subject_id you optionally provide, stored in localStorage for your own convenience so you don't have to retype it. That value never leaves your browser unless you explicitly submit a trace.

What happens if you submit a trace

The "Submit to Trace AI" button on the completion screen opens an email in your default mail client, pre-filled with the trace JSON in the body. This is a deliberate design choice for v0.1: the submission path goes through your own email software so you can review exactly what you're sending, add or remove context, and attach the audio file yourself. We do not receive any part of a trace unless you actually send that email.

If you do send it, we handle the trace as follows:

If you want a submitted trace removed, email hello@use-trace.ai from the address that sent it and we'll delete it within 7 days.

Waitlist and outbound contact

If you send us a DM on X or write to hello@use-trace.ai, we hold the conversation in the receiving service (X or the email provider). We do not add you to a mailing list. We do not sell, share, or transfer your contact information to any third party.

If we start a paid research partnership or commercial engagement with you, we will describe explicitly what data flows are involved before we ask for anything additional.

Server-side logs

The site runs on Railway. Standard access logs (IP, path, timestamp, user-agent) are kept for a rolling 14-day window for basic operational purposes (debugging, abuse detection). We do not analyze these logs for behavioral insights, and we do not join them with any other data.

Session 7f3b — the founder's own private trace

The reference corpus lists three sessions. One of them, Session 7f3b, is marked private. It contains personally identifying references (companion names, family members, a home address). Even though the subject is the founder himself, we do not display it publicly, because doing so would establish a norm we do not want: the founder's private trace is a special case, and every subject's trace deserves the same protection by default.

Changes to this policy

If we materially change how any of the above works, we will update this page with a new date at the top and, for anyone who has submitted a trace, send an email describing the change before it takes effect for submitted data.

Contact for privacy matters

Email hello@use-trace.ai with subject line beginning "[PRIVACY]" and we'll respond within 3 business days. For deletion requests, include the address you originally sent from.

This policy is intentionally short and specific because the interesting privacy questions in a data-collection company are the ones the boilerplate never mentions. If something you care about isn't addressed here, email us and we'll write about it.