Privacy Policy
Last updated 23 July 2026
What we collect, why we need it, and who else touches it. No tracking for advertising, and we don't sell your data.
What we collect
Your account: email address, name, business name, the kind of work you do, your currency and default rate. If you sign in with Google we receive your email, name and profile picture from Google, not your Google password.
What you log: photos, voice recordings and their transcripts, notes, hours, milestones, materials and costs, project details, and the client name and contact detail you enter.
Payment: if you subscribe, Stripe handles your card. We store the subscription status and plan, never card numbers.
Technical: ordinary server logs, which include an IP address, browser type and the pages requested. We use these to keep the service running and secure.
Why we use it
- To run the product: store your entries, build the client view, and produce invoice records.
- To transcribe voice notes into searchable text.
- To keep your account secure and detect abuse.
- To take payment for Pro and send receipts.
- To send you service email you can't opt out of, such as password resets, and reminders you have switched on yourself.
We do not run advertising, and we do not profile you for advertisers.
Who else processes it
We use a small number of providers to run Tracevane. They act on our instructions and only get what they need:
- Supabase — database, file storage and authentication.
- Vercel — hosting the application and serving it.
- OpenAI — turning voice recordings into transcripts. Audio is sent for transcription and is not used to train their models.
- Stripe — subscription payments, if you upgrade.
Some of these operate outside your country, so your data may be processed elsewhere under standard contractual protections. We will also disclose data if the law genuinely requires it.
Who can see a shared project
A client link is a long, unguessable address. Anyone holding it can read that project’s entries and its running total without an account. Viewers see only what belongs to that project, they cannot change anything, and they do not see costs you have marked as your own. You can revoke a link at any time.
Client names and contact details you type in are personal data about someone else. Only add what you need, and make sure you’re allowed to store it.
How long we keep it
- Account and project data: while your account is open.
- Uploaded photos and audio: kept for the retention period of your plan, which is longer on Pro.
- Deleting your account removes your projects, entries and uploaded files. Backups age out shortly after.
- We keep the minimum billing records that tax rules require, even after an account closes.
Your choices
- See and correct your details in Settings at any time.
- Export any project's log to CSV, which includes entries, hours and costs.
- Delete individual entries, revoke client links, or delete your whole account.
- Ask us for a copy of your data, or for it to be erased, by emailing support.
Security
Traffic is encrypted in transit. Access to your rows is enforced by the database itself, so one account cannot read another’s data. Uploaded files are private and served through short-lived signed links rather than public addresses. Passwords are hashed and we never see them in readable form.
Cookies
We set the cookies needed to keep you logged in and to protect form submissions. There are no advertising or third-party tracking cookies.
Children
Tracevane is for people running or working in a business, and is not intended for anyone under 18.
Changes
If this policy changes in a way that matters, we’ll update the date above and let account holders know in the app or by email.
Contact
Privacy questions or requests: privacy@tracevane.com. See also our Terms of Service.
