Skip to content
Start free
Menu
Privacy and data

Privacy and data

What TraceLog captures, what it does not, where it lives, and how long it is kept — the page a platform review and your own privacy policy can cite.

TraceLog records the conversion path, not the whole website. This page lists what that means in data, for a platform review or your own privacy policy to cite.

What is captured

Three things, and nothing else.

The session record. One row per visit, carrying its acquisition context: referrer, campaign parameters, the acquisition channel and AI platform where confirmed, device class, country, landing page, and the time it started. Conversion rates are calculated over these sessions.

The conversion path. Each declared conversion with its stable identifier, its optional value and currency, and the declared steps preceding it — each with whatever context you chose to send, and each conversion with the tag requests below.

Requests to GA4, Meta and Google Ads. Beside each conversion the browser reports, TraceLog notes which of those tags the page sent requests to just before and after it. TraceLog keeps the tag's kind, its ID — for Google Ads with its conversion label — and, for Meta, the event the request names. The ID is your site's own account, never a visitor's. Nothing else of the request is kept: not its URL, its other parameters or its body. TraceLog never knows whether the platform received it. Shopify reports none: its pixel runs in a sandbox that cannot see the page's requests.

Errors are captured only inside the conversion path. An error during checkout belongs to the conversion; one on a blog page does not.

What is not captured

  • Page views, clicks, scroll depth, mouse movement, keystrokes
  • Session replay, or any recording of the screen
  • Cross-site or cross-device identity, and any visitor's advertising identifier
  • IP addresses in storage — the address is read once at ingestion to resolve a two-letter country code, and never written down
  • Special-category data, which the product has no field for
  • Any other part of a request the page makes to another service

A conversion carries at most sixteen tag requests.

The capture code sets no tracking cookie, and no cookie of any kind. After consent has been granted, a session identifier lives in the browser's own local storage on your site, and nowhere else.

Before a consent decision the capture code creates no identifier, writes nothing to storage and sends no network request. Capture starts only when your consent setup allows it: you call TraceLog.consent.grant() from your own consent platform. A denial is remembered in one key and nothing else, so the capture code does not ask a visitor who refused again.

Where it lives

In the European Union. Events and account data are stored in an EU region, and the capture code is served from storage in the EU through a CDN.

How long it is kept

WhatHow long
Raw eventsThirty days
Daily totals (rollups)While the project exists, Free included
Account metadataWhile the account exists, deleted with it

Daily totals have no time limit on any plan. Paying does not create that history; it lets you compare it, segment it and follow it over time.

Verification traffic

Events produced while verifying an install are marked. They stay visible in data health for the thirty days raw events are kept, are excluded from every analytical read, and count against neither your quota nor your bill. The conversion record keeps, for good, that the order was verification traffic.

Google Sign-In

Google Sign-In is optional for customer accounts and the only sign-in method for TraceLog operators. When chosen, Google receives the authentication request and returns a stable account identifier, verified email, name and profile image. TraceLog requests no Gmail, Drive, advertising or analytics permission, and no measurement data is sent to Google. Customer and operator OAuth clients and account records are separate.

Where answers are computed

Asking a question in the product sends three things to Anthropic, which runs the model that reads the question and chooses the read: the question as you typed it, the project's tracking plan, and what TraceLog's governed reads returned — aggregate numbers, recorded findings and, when the question needs them, your own notes on actions and changes. Raw events, sessions, identifiers and payloads are never sent — the model cannot reach storage at all, only the governed, read-only reads.

That inference runs on Anthropic's infrastructure in the United States. Storage does not move: every event, rollup and account record stays in the EU. A project that never asks a question sends nothing outside it. Anthropic is listed on the subprocessor page with everything else that processes data on TraceLog's behalf.

Questions and answers are kept

Every question asked in the product, and the answer TraceLog wrote for it, is stored with the project it was asked on and deleted with it.

TraceLog also keeps an index of the questions: the latest wording of each, when it was first and last asked, and whether the project saved it. A question can then be run again without retyping it. Each run asks it again over the current data; the old answer is not reused, shown again or sent to the model.

A project saves at most twenty questions. Saved questions belong to the project, not to a person: anyone who can ask on that project can save one and unsave another's.

Questions and answers are never used to train a model or to suggest anything to another customer. The export includes the questions but not the answers.

Your role and ours

For events captured on your site you are the controller and TraceLog is the processor, under the data processing agreement. You decide what to declare and on what legal basis capture runs.

The full statements are in the privacy policy and the subprocessor list.