Privacy Policy

Your traces are yours. Full stop.

This policy explains what data TraceMiner collects, why, and what happens to it — across the website (traceminer.dev), the app (app.traceminer.dev), the API (api.traceminer.dev), and the TraceMiner browser extension.

Effective date: July 24, 2026

What we collect

Account information

When you create a TraceMiner account we collect your name and email address, and maintain a session so you stay signed in. We use this to identify your account and associate your projects and captures with it.

Network captures

The product's core data: HAR files you upload and recordings you make with the browser extension. See the next section — this deserves its own explanation.

Billing information

Payments are processed by Dodo Payments. We never see or store your card number. We keep a record of your transactions and credit balance so we can grant and meter the credits you purchase.

Operational data

Standard server logs (timestamps, request paths, status codes) used to keep the service running, debug failures, and prevent abuse.

Network captures & credentials

A network trace of a real application contains everything that application sent and received: URLs, request and response headers, cookies, and request and response bodies. That routinely includes credentials — Authorization headers, session cookies, API keys, and tokens. This is not incidental: those headers are exactly what makes a capture useful for reproducing and documenting an API, and TraceMiner captures them deliberately.

  • Captures are created only when you explicitly start a recording or upload a HAR file yourself. TraceMiner never records in the background.
  • Captured data is transmitted only to your own TraceMiner account, over HTTPS, and is visible only to you.
  • We never sell captured data, never share it with third parties for their own purposes, and never use it for advertising or any purpose other than providing TraceMiner's features back to you.

Treat captures of authenticated applications with the same care you would treat the credentials inside them — and prefer ephemeral retention (below) when a capture contains secrets you don't want stored.

The browser extension

The Trace Miner Chrome extension records the network requests of a single browser tab and uploads the result to your TraceMiner project.

  • Recording is always user-initiated. It starts only when you press Record, applies only to the one tab you chose, and stops when you press Stop or close that tab. In debugger mode, Chrome additionally displays its own "Trace Miner started debugging this browser" banner for the entire session.
  • The extension reads only TraceMiner's own session cookie, on the TraceMiner API domain, so uploads go to the account you're already signed in to. It never reads cookies belonging to any other site, and never writes or modifies any cookie.
  • In-progress recording data is held in session storage, which the browser clears when it restarts. Nothing is written to disk on your machine.
  • No remote code. All extension code ships in the store package; the extension loads no external scripts.

The extension's use of data complies with the Chrome Web Store User Data Policy, including its Limited Use requirements: data collected by the extension is used only to provide TraceMiner's user-facing recording features, is never sold, never used for advertising, and never transferred to third parties except as needed to provide those features (see Sharing & third parties).

How we use data

  • To store your captures and give them back to you — viewing, search, analysis, chat, and export.
  • To authenticate you and keep your account secure.
  • To grant, meter, and account for the credits you purchase.
  • To operate, debug, and protect the service.

We do not use your data for advertising, do not build profiles from your captures, and do not train machine-learning models on your data.

AI processing

TraceMiner's analysis features (capture summaries, chat, extraction, generated outputs) are powered by large language models. When you use these features, the relevant parts of your capture are sent to an AI model provider — OpenAI, or models routed via OpenRouter or Cloudflare AI Gateway — solely to generate the analysis you requested. This happens only when you invoke an AI feature; storing a capture does not by itself send it to a model provider.

Storage, retention & deletion

Your data is stored on Cloudflare infrastructure (object storage and databases) and encrypted in transit via HTTPS. Captures support two retention modes:

  • Standard: the capture is stored until you delete it or delete your account.
  • Ephemeral: the raw capture is automatically and permanently destroyed after a lifetime you choose — from 15 minutes up to 30 days, with a default of 1 hour. The destruction is recorded, and the raw source cannot be retrieved afterwards.

You can delete individual captures and projects from the app at any time. To delete your entire account and its data, contact us (below) and we will complete the deletion.

Sharing & third parties

We share data only with the service providers required to run TraceMiner, and only for that purpose:

  • Cloudflare — hosting, storage, and delivery of the service.
  • OpenAI / OpenRouter / Cloudflare AI Gateway — AI model inference, only when you invoke an AI feature.
  • Dodo Payments — payment processing.

We do not sell personal data or captures, and we do not share them with advertisers or data brokers. We may disclose data if required to by law, and we'll tell you when legally permitted to do so.

Cookies

TraceMiner uses a session cookie to keep you signed in and a local preference for your theme (light/dark). We do not use advertising or cross-site tracking cookies.

Your rights

You can access your captures and account data in the app, delete captures and projects yourself, and request a full export or deletion of your account data by contacting us. Depending on where you live (for example, under the GDPR or CCPA), you may have additional statutory rights to access, correct, delete, or port your data — contact us and we will honor them.

TraceMiner is not directed at children under 16, and we do not knowingly collect their data.

Changes

If this policy changes materially, we will update the effective date above and note the change on this page. Continued use of TraceMiner after a change means the updated policy applies.

Contact

Questions, deletion requests, or anything else about your data: [email protected]