Skip to main content

Privacy Policy

Version 2026-08-11.1 · Last updated: August 11, 2026

This policy explains what Trace collects and what we do with it. Trace is operated by Foundry01, LLC, an Indiana limited liability company, and covers the trytrace.net website, the Trace desktop app, and the Trace browser extension.

The short version

  • Trace records only while you have a session running. You start it and you stop it.
  • It captures still screenshots, not video, and it does not record what you type.
  • We never sell your data, advertise to you, or build a marketing profile.
  • Our AI providers never train on your content, on any plan.
  • Neither do we. Trace has no model of its own to train, on any plan.
  • Your content is stored in the United States. Some providers may process it elsewhere — see “Where your data lives”.

What we collect

What you give us. Your email address and password (or a Google or single-sign-on account), your name and avatar if you add them, your organization and team member emails, and your billing details. Payments run through Stripe; we never see or store your card number.

What you capture. During a recording session the desktop app collects still screenshots of your screen, the position of your clicks, the window and application you are in, and Enter-key presses. It does not record the characters you type, and it does not read your clipboard or record video. If you enable the microphone, it records your narration. Your steps, titles, descriptions, and annotations are stored with the guide.

What the browser extension collects. The extension is present on every site you visit — that is what its all-sites permission is for — but it only collects while a recording session is running. During a session it captures screenshots of the visible tab, the page address and title, the element you clicked (its position, tag, accessible name, a few identifying attributes, and up to 200 characters of its visible text), text you type into ordinary fields, keys such as Enter and Tab, and page loads and new tabs you open.

It skips fields marked as passwords, payment cards, Social Security or national ID numbers, and one-time or verification codes. Those keystrokes never leave the page, and those fields are painted over before a screenshot is taken — if part of the page does not confirm the mask in time, the screenshot is skipped rather than taken unmasked. Text that looks like a card number or a Social Security number is stripped even outside a marked field. All of this reads the page's own markup, so it is a safeguard, not a guarantee: a site that collects a card number in a plain text box is invisible to it.

The extension also reads and refreshes your trytrace.net sign-in cookie so you do not have to log in twice. Outside a recording session it captures nothing, though it may still finish uploading a session that was interrupted, refresh your sign-in, and send crash reports.

What we collect automatically. Your device and operating system, app version, IP address and browser, sign-in and security events, error and crash reports, searches you run inside Trace and which results you click, and your acceptance of these policies before recording (recorded with your email, IP address and browser).

Analytics. We use PostHog to understand how Trace is used. Events are keyed to your account identifier or, in the desktop app, to a random install identifier — never to your email address. In the desktop app you can turn analytics off in Settings → Privacy. Crash reports go to Sentry, with emails, tokens, file paths and similar details stripped out before they are sent, and session replay switched off.

What ends up in a capture

Trace records whatever is on your screen. That can include a customer record in another window, a colleague's name in a chat, or an account number in a spreadsheet. We do not automatically detect or redact this.

We do not want sensitive information about you or anyone else — health details, biometric data, government identification numbers, or payment card data. Close what should not be captured before you start, and use our blur tool to obscure anything that slipped through before you share.

If you record audio, it is used to produce a transcript and nothing else. We do not create voiceprints, identify speakers, or separate voices. The audio file is deleted after transcription; the transcript text is kept with your guide until you delete it.

What we use your information for

  • To run Trace: store your guides, generate steps, search, share, and export
  • To sign you in, keep accounts secure, and prevent fraud and abuse
  • To find and fix bugs, and to keep the service stable
  • To answer your support requests
  • To bill you and manage your subscription
  • To meet our legal obligations

Our legal grounds for this are: performing our contract with you, our legitimate interests in security, error monitoring and auditing, your consent for screen and audio recording, and compliance with law.

We do not sell your personal information, use it for advertising, or build marketing profiles. We do not make automated decisions about you that have legal or similarly significant effects.

AI providers and model training

Trace sends content to AI providers so features work. Specifically:

  • OpenAI — your narration audio, to transcribe it and draft step titles and descriptions.
  • Google — your screenshots, which it analyses so they can be searched. It transcribes every piece of text it can see, including the values inside form fields, and writes a short description of what the screenshot shows: the application or screen, charts and which way they trend, and any prominent objects or images in view. Both the transcription and the description are saved with your guide.
  • Voyage AI — your step text, that step transcription and description, and the searches you type, turned into the numerical form that powers search. No images or audio are sent.
  • Anthropic — your step and narration-transcript text, to refine step titles and descriptions, and the text of a document you import as an existing procedure.

None of these providers train their models on your content. Each holds it only briefly for abuse monitoring and then deletes it.

We do not use your content to train or improve any model of our own, on any plan. Foundry01 does not build or fine-tune models. Trace's AI features run inference through the providers above and search over your stored content, and nothing is trained on the result.

On any plan, if you deliberately send us something as feedback — rating a search result, reporting a bad step title — we may use it to improve Trace.

De-identified and aggregated data

We may use information that has been aggregated or stripped of anything that could reasonably identify you or your device — counts, timings, error rates, usage trends — for research, analysis, and reporting. That information is not covered by this policy. We will not attempt to re-identify it, and we will not de-identify the visual contents of your captures in order to use them this way.

Who we share your information with

We share data with the service providers that make Trace work, and with no one else for commercial purposes. Each is bound by a data processing agreement. The current list, with what each one handles, is on our subprocessors page. We will update that page and give 30 days notice before adding or replacing a material provider. We also use PostHog for the product analytics described above.

Your team. Content you share into an organization is visible to the members you share it with. Organization owners and admins can manage members and see organization activity logs.

Our staff. A small number of Foundry01 staff hold administrative access to the systems your content is stored in, which they need in order to run, support, and repair the service. That access is direct. It lets them read your guides, it does not require anyone's approval first, and we do not keep a record of every time it is used. We keep that group as small as the work allows, review it periodically, and every person in it is bound by a confidentiality obligation.

Law enforcement. We do not hand over personal data without valid legal process. When we must, we give the minimum required and tell you unless the law forbids it. We have never received such a request.

Company changes. If Foundry01 is acquired or merges, data may transfer as part of that. We will tell you first.

Sharing links

Nothing you create is visible to anyone else until you share it, and there are two kinds of link. A private link requires the recipient to sign in and only works for people in your organization who already have access — access follows membership and permissions, so there is no token in it and nothing to revoke. A public link carries a token and opens without signing in; it is unlisted, not secret, so it can be forwarded, embedded, or indexed if someone posts it publicly.

You can shut off a public link by deleting the guide, and an organization owner can switch public links off for the whole organization; either takes effect immediately for links already handed out. You can also ask us to disable a particular link at admin@foundry01.com. Screenshots inside Trace are served through links that expire after an hour.

If your organization connects Trace to ServiceNow, publishing a guide sends its title, steps, and screenshots to your organization's own ServiceNow instance.

Where your data lives, and how long we keep it

Your account and content are stored in the United States. Our database, file storage, and backups are all in US regions, and if you use Trace from elsewhere your data comes here.

Processing is a separate question, and we will not overstate it. Some of the providers we use to deliver Trace reserve the right to process data outside the United States — for example while running an AI request, handling a payment, or responding to a support issue. We do not have a contractual guarantee that every provider processes only in the US, so we do not claim one. Where a provider transfers data across a border, that transfer is covered by Standard Contractual Clauses, the EU-US Data Privacy Framework, or both.

Our sub-processor page lists every provider that touches your data and what it is used for.

  • Your content — kept while your account is active. Deleting your account starts a 30-day grace period you can cancel; after that your content, files, and derived search data are deleted from our live systems.
  • Audio recordings — deleted after transcription, and never copied to backup storage.
  • Backups of your images — screenshots, annotated images, avatars, and brand assets are mirrored to Backblaze B2 so they can be recovered after a failure. The mirror does not delete a file the moment you do, so a copy can outlive the deletion in our live systems by up to 8 days before it expires. We do not use it for anything except recovery.
  • Security and audit logs — 13 months in the live database. A copy is written to storage that cannot be altered or deleted by anyone, including us, for 24 months, and is erased at 25. Some entries survive account deletion because we are required to keep them.
  • Database backups — 7 days. Deleted data can persist in a backup until it rolls off; it is not restored except in a genuine disaster recovery.

Your rights and choices

You can access, correct, delete, and export your data. Export and deletion are both self-service in your account settings; anything else, email admin@foundry01.com and we will respond within 30 days. Depending on where you live you may also have the right to object to or restrict processing, withdraw consent, and complain to your data protection authority.

You can turn off desktop analytics in Settings → Privacy, and unsubscribe from any marketing email using the link in it.

Security

Your data is encrypted in transit and at rest, protected by row-level access controls so you only reach your own content and content shared with you, and monitored for security events. This is not end-to-end or zero-knowledge encryption: our infrastructure provider holds the encryption keys, and our staff can access data under the controls described above.

No system is perfectly secure. If a breach affects your personal data we will tell you without undue delay and within 72 hours of confirming it, and notify regulators where the law requires. Report a security problem to admin@foundry01.com.

Foundry01 is implementing SOC 2 Type II controls covering Security and Confidentiality, and expects to complete its initial Type II examination within the next six months. Trace is not certified under HIPAA, PCI-DSS, FERPA, or ISO 27001.

Children

Trace is for people 18 and over. We do not knowingly collect information from anyone younger. If you believe we have, email admin@foundry01.com and we will delete it.

Changes and contact

We will update this policy as Trace changes. Material changes get an email or an in-app notice before they take effect, and the version at the top of this page changes. Foundry01 does not have a dedicated data protection officer; privacy is owned by senior management.

Questions, requests, or complaints: admin@foundry01.com.

Privacy Policy | Trace