Privacy Policy

MyTrace is a privacy product, so we hold ourselves to the standard we recommend: collect little, mask what is sensitive, and delete on request.

Last updated 25 August 2026

What we collect

Account details from your Google sign-in (name, email, avatar), the identity details you choose to provide for an audit, the findings your audits produce, your verdicts on those findings, your risk score, cleanup tasks, and purchase records for paid plans.

What we search

Only publicly accessible sources: indexed web pages, public profiles, public documents and openly published records. We never access private accounts, never attempt authentication, and never use credential or recovery flows.

What we never infer

Political affiliation, religion, race or ethnicity, sexual orientation, medical or mental-health conditions, and criminal history are never inferred, scored or displayed — even when hints appear in public content.

Masking and security

Emails, phone numbers and address references found in public documents are masked before storage. Every table holding audit data is protected by row-level security scoped to your account, and audits are rate limited to prevent abuse.

Cookies and analytics

We use strictly necessary cookies to keep you signed in. Optional analytics and preference cookies are only set if you accept them in the cookie banner, and you can change your choice at any time.

Processors we use

Authentication and database hosting for the application, PayPal for payments, and a third-party public search API to run live audits. We do not sell your data or share it for advertising.

Retention and your rights

Audit data is kept until you delete it. You can erase all audit data from Settings at any time — deletion is immediate and irreversible. You may also request access, correction or erasure by email; we respond within 30 days.

Contact