tracekitby labsolute.devBack to Tracekit

PRIVACY POLICY

Local by default.
Shared by choice.

Effective 17 August 2026 · Tracekit version 1.2.0

Summary

Tracekit records browser testing evidence on your device. Nothing is uploaded while you record, review, copy, or download a report. Data is sent to Tracekit Cloud only when you select Share report, review what will be included, and confirm sharing.

Information Tracekit handles

A recording can contain page URLs with query values redacted, page interaction labels, element selectors, JavaScript error messages, failed network request methods and status codes, browser environment details, timestamps, tester-written expected and actual results, and a visible-tab screenshot.

Tracekit records that a form field changed but does not record the value typed into text fields. Password, email, telephone, and number field values are explicitly excluded. Error messages and screenshots may still contain information displayed by the tested website, so you must review a report before sharing it.

Local recordings

Active and latest sessions, including the team API key you enter, are stored in Chrome local storage on your device. Tracekit does not use those local recordings for advertising, analytics, profiling, or unrelated purposes.

Optional cloud sharing

When you confirm sharing, the Extension sends your API key for authorization and uploads the reviewed report and its screenshot over HTTPS. The API key associates the report with your team; only a one-way hash of that key is stored by Tracekit Cloud. Anyone who receives the resulting unlisted team link can view the report. Shared reports are not intended to be indexed by search engines.

Retention and deletion

Cloud reports and screenshots expire automatically 30 days after creation. The creator also receives a private deletion token stored in the Extension and can use Delete report to remove the report immediately. Deleted and expired report links stop working.

Sharing and limited use

Tracekit does not sell report data, use it for personalized advertising, or share it with third parties for unrelated purposes. Information is processed only to provide the user-facing recording, export, sharing, security, and reliability features described here. Tracekit's use of information complies with the Chrome Web Store User Data Policy, including the Limited Use requirements.

Security

Cloud reports are transmitted using HTTPS, require an active team API key to create, use hard-to-guess identifiers, and require a separate creator-only token for deletion. API keys can expire or be revoked by an administrator. Unlisted links are not a substitute for per-viewer authentication; do not share a link beyond its intended recipients.

Your choices

  • Keep every report local and never use Cloud sharing.
  • Review and edit the report before sharing.
  • Download the Markdown, JSON evidence, and screenshot instead.
  • Delete a shared report before its automatic expiry.

Contact

For privacy questions or deletion assistance, contact support@labsolute.dev.