Privacy Policy
Last updated: 2026-10-03
Draft notice: this policy was drafted from Trace's actual data-handling practices to satisfy app-store and regulatory disclosure requirements. It has not yet been reviewed by a lawyer. Treat it as a working starting point, not certified legal advice, until it has been.
Who we are
Trace ("we", "us") operates the Trace mobile app. This policy explains what data we collect, why, and how you can control or delete it. Trace is designed to work without collecting your name or email address. We do ask for a phone number to verify your account (see "Data we collect" below), and we keep only a one-way hash of it, never the number itself.
Data we collect
- Device account key. When you first open Trace, the app generates a random key on your device and registers a pseudonymous account with us. We store a one-way hash of this key, never the key itself, so we cannot reverse it back to your device.
- Pseudonym. A randomly assigned display name shown to other users. It is not derived from any personal information. It changes automatically each time you open the app (except while you're broadcasting, so the name stays the same for the whole broadcast), and you can pick a new one at any time.
- Phone number (for verification). To go live and to add friends, you verify a phone number with a one-time code sent by SMS through our verification provider, Twilio. Your number is sent to Twilio so it can deliver and check that code, and while a code is pending (up to 10 minutes) it is held in short-lived cache memory so you only have to type the code. Once verified, we store only a keyed one-way hash of your number and the time you verified, never the number itself. The hash lets us make sure one phone number is linked to only one Trace account. Your phone number is never shown to other users: they only see a "Verified" badge.
- Moving your account to a new device (account recovery). If you verify the same phone number on a new device (for example after reinstalling the app or changing phones), your existing account, including your friends, the nicknames you gave them and the accounts you've blocked, moves to that new device, and the previous device is signed out. The temporary, never-verified account the new device started with is deleted. This means that whoever controls your phone number can take over your Trace account, so keep your number secure (for example with a carrier PIN), and delete your Trace account or contact us before you give up a number.
- Live location (only while a broadcast is active). When you go visible, your device sends your current location so your friends (and anyone you share a trace link with, see "What other people can see" below) can find you. This location is fuzzed (rounded to an approximate area) before anything is shared with other users, is held only in short-lived cache memory (see "Data retention" below), and is never written to our permanent database. While you're moving, your device also sends your direction of travel, which we reduce to one of 8 compass directions before storing it, and drop entirely when you're standing still. While a broadcast is active, this continues even with your screen locked or the app backgrounded (a persistent notification is shown the entire time so it's never silent), and stops automatically when the broadcast ends. Outside of an active broadcast, Trace never accesses your location in the background or while the app is closed.
- Starting area of a delayed broadcast. If you schedule your broadcast to start later, your starting area (fuzzed the same way) is shared as soon as you commit to it, marked as "starting soon", and stays visible to the same people until the broadcast itself starts and ends.
- Meetup point (optional). If you drop a meetup point before going live, it is shown exactly where you placed it, not fuzzed, since it's a spot you chose to share. It's kept in the same short-lived cache memory as your live location, for the same time.
- Description (optional). A short description you add to a broadcast, shown to the same people who can see the broadcast, and kept for the same time.
- Map area you're looking at. When you use the map to see who's live around you (for example after tapping "Go to my region" or entering a city), the app sends that map position to our server, inside the request itself rather than in its web address, to find broadcasts near it. It is used only to answer that request and isn't stored by Trace. Older versions of the app put it in the web address instead, where it can appear in request logs (see "Request logs" below). Using your location this way only happens while the app is open and only after you've given permission. The last area you picked is also remembered, rounded to roughly 1 km, on your device only.
- Social graph. Your friend connections and the accounts you've blocked, all keyed to pseudonymous account IDs. Friends are added directly by scanning a QR code or opening an invite link (there are no pending friend requests), and both people must have verified their phone number. We also record whether you've seen the "added you as a friend" notice, so we don't show it again.
- Nicknames you give your friends. A private name you can set for each friend. It's visible only to you, never to that friend or anyone else.
- Trace-link subscriptions. If you follow someone's trace link to get notified when they start moving or when their trace ends early, we keep that subscription in short-lived cache memory only, and it disappears when their broadcast ends. We also keep a short-lived count of how many trace links you've shared in the last 24 hours.
- Reports you file. If you report another account, we store the reported pseudonym, the broadcast it was about (if any), the reason selected, and any details you add, so we can review it.
- Moderation records. If we suspend an account for breaking our Terms, we record when it was suspended and a short internal note of why. We can also ban a phone number from Trace: we then keep that number's one-way hash (never the number itself) on a ban list, with the date and an internal note, so it can't be used to verify a Trace account again.
- Push notification token. If you enable notifications, we store a token issued by Apple/Google (via Expo) so we can deliver alerts, for example when a friend goes live, when someone adds you as a friend, or when a trace you follow starts moving. The text of those alerts (such as a pseudonym, an activity and a description) passes through Expo and Apple/Google to reach your device.
- Basic timestamps. When your account was created, when it was last active, when you accepted these terms, and when you verified your phone number.
We do not currently collect analytics, advertising identifiers, or marketing data. If that ever changes, we will update this policy and, where required by law (including the EU's GDPR, California's CCPA/CPRA, Quebec's Law 25, and Canada's PIPEDA), ask for your explicit opt-in consent before collecting it.
What other people can see
- Your friends see your broadcast on their map and in their lists: your pseudonym (or the nickname they gave you), your activity and description, and an approximate distance, all based on your fuzzed position. When both of you are verified, they also see which direction you are from them and roughly how far away (rounded, never exact), and, while you're moving, your coarse direction of travel (one of 8 compass directions). Friends are notified when you go live.
- Anyone you share a trace link with ("drop a trace") can see, until your broadcast ends, your approximate (fuzzed) position, your current pseudonym, your description, and your meetup point if you set one (shown exactly as placed). Viewing a link doesn't require an account, and anyone the link is forwarded to can see the same thing. The link stops working the moment your broadcast ends.
- People who follow your trace link. Following a link (to get notified) does require an account. You see how many people follow your link; a follower who is already your friend is shown to you by name (your nickname for them, or their pseudonym). Everyone else is only counted, never named.
- Nobody sees your phone number, your device key, or your exact live position.
Data retention
Live location (including your direction of travel and any meetup point) is never written to our permanent database at all. It exists only in short-lived cache memory (Redis) for the duration of the broadcast you chose to start, which you control and which is capped at 2 hours of active broadcasting per session. If you schedule a delayed start, your fuzzed starting area is held from the moment you commit, so the total can be up to 16 hours of delay plus up to 2 hours of broadcasting (18 hours at most). It is deleted automatically and permanently the moment your broadcast ends or that time limit is reached, whichever comes first. Any trace link and its followers are deleted at the same time.
A phone number waiting for its code is held in short-lived cache memory for at most 10 minutes, then deleted; once you're verified, only the hash described above is kept.
Everything else we collect (listed above) is kept only for as long as your account exists, and is permanently deleted the moment you delete your account (see "Your rights and choices" below). We don't keep a separate backup or archive of it afterward, and this includes any reports you've personally filed against other accounts. There are two exceptions. First, if someone you reported later deletes their own account, the report itself stays on file (with the display name it was filed under preserved, but no longer linked to a live account) so a pattern of abuse remains reviewable even after the reported account is gone. Second, if we've banned a phone number, the one-way hash of that number stays on our ban list even after the account is deleted, for the sole purpose of keeping that number from being used on Trace again, until we lift the ban. We keep nothing else about the deleted account for this.
Request logs
Like most online services, our server keeps request logs: the IP address, the time, the kind of request and whether it succeeded. Before a request is written to these logs, Trace removes anything after the "?" in its web address (such as a map position sent by an older version of the app) and replaces trace-link and invite-link codes with a placeholder. Our hosting and network providers (Railway and Cloudflare) may also keep their own records of requests, including the IP address and the address requested. These logs are kept for a limited period and are used only to operate and secure the service. Separately, to limit abuse, we keep a shortened one-way hash of your IP address in short-lived cache memory for rate limiting, never the IP address itself.
Beta signup list
If you leave your email address on this website to be notified when Trace launches, we store it for that purpose only: to send that one announcement. This is separate from using the app itself (described above) and is never linked to an in-app account or pseudonym. You can ask us to remove your email from this list at any time by emailing support@gotrace.win.
Third parties we rely on
Trace runs on the following infrastructure providers, each of which processes data on our behalf:
- Railway: hosts our backend, database, and short-lived location cache.
- Cloudflare: all traffic between the app (or a trace-link page) and our server passes through Cloudflare's network, which protects it against abuse. Cloudflare also hosts this website.
- Twilio: sends and checks the SMS verification code. It receives your phone number for that purpose only.
- Expo: builds the mobile app and delivers push notifications to your device.
- MapLibre / OpenFreeMap: renders map tiles. Open-source and free to use, no API key or account tied to it. Your device fetches map imagery directly, and no location data is sent to it as part of that (it only ever receives which map tiles are visible on screen, the same as loading images from any other website).
- jsDelivr: a public code-hosting service that the trace-link web page loads its map library from, pinned to one exact version whose contents the browser checks before running it. It receives an ordinary web request from the viewer's browser, never any location data.
We do not sell or share your data with anyone, including for cross-context behavioral advertising. There's nothing to opt out of, because it doesn't happen in the first place.
Your rights and choices
Wherever you are, you can:
- Choose when you're visible and who can see you: your friends, plus anyone you choose to share a trace link with. You can end a broadcast at any time.
- Block or report an account at any time from your friends list, the list of people live nearby, or while viewing someone's trace link in the app. You can also remove a friend, or change or clear the nickname you gave them.
- Delete your account entirely from Settings > Legal & Privacy > Delete my account. This permanently removes your account (including your phone number's hash), friendships, nicknames, blocks, and the reports you've filed, and ends any active broadcast and its trace link. This cannot be undone. A suspension doesn't take this right away: our server still accepts the deletion of a suspended account, and you can also ask us to delete it by emailing support@gotrace.win. If your phone number was banned, only its hash stays on the ban list (see "Data retention").
- Request a copy of the data we hold about your account, or ask us to correct it, by emailingsupport@gotrace.win. Since Trace is designed to collect very little in the first place (see "Data we collect" above), this is usually a short list.
If the EU's GDPR, California's CCPA/CPRA, Quebec's Law 25, or Canada's PIPEDA applies to you, the choices above are how Trace honors your rights to access, correct, delete ("erasure"), and receive a copy of ("portability") your personal data under those laws: in-app self-service or a direct email to us, not a separate formal-request process you have to navigate. We won't deny you service, charge you a different price, or provide a different level of service just because you exercised any of these rights.
If you're not satisfied with how we've handled a request, you can also complain to your local data protection authority: in the EU, your national supervisory authority; in Canada, theOffice of the Privacy Commissioner of Canada; in Quebec specifically, theCommission d'accès à l'information.
Children's privacy
Trace is not directed at children. You must be at least 16 years old to use Trace, above the minimum age set by both the USA's COPPA (13) and Quebec's Law 25 (14), so this one age applies everywhere Trace is used rather than varying by region. We do not knowingly collect data from anyone younger, and we do not collect birthdates or other identifying information that would let us verify age beyond your own confirmation at sign-up. Phone verification is not an age check.
Contact us
Questions about this policy or your data? Email support@gotrace.win.