Privacy and data
What TraceLog captures, what it does not, where it lives, and how long it is kept — the page a platform review and your own privacy policy can cite.
TraceLog records the conversion path, not the whole website. This page lists what that means in data, for a platform review or your own privacy policy to cite.
What is captured
Three things, and nothing else.
The session record. One row per visit, carrying its acquisition context: referrer, campaign parameters, the acquisition channel and AI platform where confirmed, device class, country, landing page, and the time it started. Conversion rates are calculated over these sessions.
The conversion path. Each declared conversion with its stable identifier, its optional value and currency, and the declared steps preceding it — each with whatever context you chose to send, and each conversion with the tag requests below.
Requests to GA4, Meta and Google Ads. Beside each conversion the browser reports, TraceLog notes which of those tags the page sent requests to just before and after it. TraceLog keeps the tag's kind, its ID — for Google Ads with its conversion label — and, for Meta, the event the request names. The ID is your site's own account, never a visitor's. Nothing else of the request is kept: not its URL, its other parameters or its body. TraceLog never knows whether the platform received it. Shopify reports none: its pixel runs in a sandbox that cannot see the page's requests.
Errors are captured only inside the conversion path. An error during checkout belongs to the conversion; one on a blog page does not.
What is not captured
- Page views, clicks, scroll depth, mouse movement, keystrokes
- Session replay, or any recording of the screen
- Cross-site or cross-device identity, and any visitor's advertising identifier
- IP addresses in storage — the address is read once at ingestion to resolve a two-letter country code, and never written down
- Special-category data, which the product has no field for
- Any other part of a request the page makes to another service
A conversion carries at most sixteen tag requests.
Cookies and consent
The capture code sets no tracking cookie, and no cookie of any kind. After consent has been granted, a session identifier lives in the browser's own local storage on your site, and nowhere else.
Before a consent decision the capture code creates no identifier, writes
nothing to storage and sends no network request. Capture starts only when your
consent setup allows it: you call TraceLog.consent.grant() from your own
consent platform. A denial is remembered in one key and nothing else, so the
capture code does not ask a visitor who refused again.
Where it lives
In the European Union. Events and account data are stored in an EU region, and the capture code is served from storage in the EU through a CDN.
How long it is kept
| What | How long |
|---|---|
| Raw events | Thirty days |
| Daily totals (rollups) | While the project exists, Free included |
| Account metadata | While the account exists, deleted with it |
Daily totals have no time limit on any plan. Paying does not create that history; it lets you compare it, segment it and follow it over time.
Verification traffic
Events produced while verifying an install are marked. They stay visible in data health for the thirty days raw events are kept, are excluded from every analytical read, and count against neither your quota nor your bill. The conversion record keeps, for good, that the order was verification traffic.
Google Sign-In
Google Sign-In is optional for customer accounts and the only sign-in method for TraceLog operators. When chosen, Google receives the authentication request and returns a stable account identifier, verified email, name and profile image. TraceLog requests no Gmail, Drive, advertising or analytics permission, and no measurement data is sent to Google. Customer and operator OAuth clients and account records are separate.
Where answers are computed
Asking a question in the product sends three things to Anthropic, which runs the model that reads the question and chooses the read: the question as you typed it, the project's tracking plan, and what TraceLog's governed reads returned — aggregate numbers, recorded findings and, when the question needs them, your own notes on actions and changes. Raw events, sessions, identifiers and payloads are never sent — the model cannot reach storage at all, only the governed, read-only reads.
That inference runs on Anthropic's infrastructure in the United States. Storage does not move: every event, rollup and account record stays in the EU. A project that never asks a question sends nothing outside it. Anthropic is listed on the subprocessor page with everything else that processes data on TraceLog's behalf.
Questions and answers are kept
Every question asked in the product, and the answer TraceLog wrote for it, is stored with the project it was asked on and deleted with it.
TraceLog also keeps an index of the questions: the latest wording of each, when it was first and last asked, and whether the project saved it. A question can then be run again without retyping it. Each run asks it again over the current data; the old answer is not reused, shown again or sent to the model.
A project saves at most twenty questions. Saved questions belong to the project, not to a person: anyone who can ask on that project can save one and unsave another's.
Questions and answers are never used to train a model or to suggest anything to another customer. The export includes the questions but not the answers.
Your role and ours
For events captured on your site you are the controller and TraceLog is the processor, under the data processing agreement. You decide what to declare and on what legal basis capture runs.
The full statements are in the privacy policy and the subprocessor list.