Privacy Policy
MyTrace is a privacy product, so we hold ourselves to the standard we recommend: collect little, mask what is sensitive, and delete on request.
Last updated 25 August 2026
What we collect
Account details from your Google sign-in (name, email, avatar), the identity details you choose to provide for an audit, the findings your audits produce, your verdicts on those findings, your risk score, cleanup tasks, and purchase records for paid plans.
What we search
Only publicly accessible sources: indexed web pages, public profiles, public documents and openly published records. We never access private accounts, never attempt authentication, and never use credential or recovery flows.
What we never infer
Political affiliation, religion, race or ethnicity, sexual orientation, medical or mental-health conditions, and criminal history are never inferred, scored or displayed — even when hints appear in public content.
Masking and security
Emails, phone numbers and address references found in public documents are masked before storage. Every table holding audit data is protected by row-level security scoped to your account, and audits are rate limited to prevent abuse.
Cookies and analytics
We use strictly necessary cookies to keep you signed in. Optional analytics and preference cookies are only set if you accept them in the cookie banner, and you can change your choice at any time.
Processors we use
Authentication and database hosting for the application, PayPal for payments, and a third-party public search API to run live audits. We do not sell your data or share it for advertising.
Retention and your rights
Audit data is kept until you delete it. You can erase all audit data from Settings at any time — deletion is immediate and irreversible. You may also request access, correction or erasure by email; we respond within 30 days.