Datenschutzerklärung für Daily Trace
Daily Trace von leonides
Datenschutzerklärung für Daily Trace
Daily Trace is a private journal of your own attention. The short version: your data is yours, it is encrypted at rest, and it is never sold, shared, or used for anything except showing your journal back to you.
Full policy: https://dailytrace.vinnyminhas.com/privacy.html
WHAT WE STORE
- Your email address — used only to identify your account.
- Day summaries — short texts describing what you worked on, generated from browsing activity the extension sends only when you have installed it and signed in. Raw browsing history stays on your device; the server receives clustered session snippets used to write the summary.
- Notes you write — kept until you delete them.
- Kept tabs and planned items you explicitly add, plus calendar event titles if you connect Google Calendar in the web app.
- Your settings, including any LLM API key you configure. API keys are write-only: they are never shown back, even to you.
YOUR OPEN TABS, WHEN YOU OPEN THE EXTENSION POPUP
The popup groups your open tabs by what they were for rather than by which site they came from, so you can close a whole line of work at once. Naming those groups needs a model, so this is the one thing the extension sends without you pressing anything — it happens when the popup opens.
- What is sent: each open tab's page title and hostname. Not the full URL, not page content, and never more than 60 tabs. Pinned tabs and non-web tabs are excluded.
- Where it goes: your Daily Trace server, which passes it to the LLM provider you configured in Settings and gets back a list of group names. The server does not store the list.
- How often: once per set of open tabs. The names are cached in your browser for as long as that exact set stays open, so opening the popup again sends nothing.
- If it fails — offline, no provider configured, anything — the popup falls back to grouping by site, worked out on your own machine, and nothing is transmitted at all.
Nothing is saved to your journal and no tab is closed unless you press "keep & close".
HOW IT IS PROTECTED
All journal content and settings are encrypted at rest (AES-256-GCM). Session tokens are stored hashed; a database leak cannot impersonate you. Everything travels over HTTPS.
SIGN IN WITH GOOGLE
When you sign in with Google, we receive only your email address to create or find your account. Signing in requests nothing else — no contacts, no calendar, no files.
GOOGLE CALENDAR (OPTIONAL, WEB APP ONLY — NOT PART OF THE EXTENSION)
You can separately connect Google Calendar in the web app so your journal can show what you planned beside what you actually did. It is off unless you turn it on, and you can disconnect at any time. We request calendar.events; Daily Trace creates an event when you book a task into a free slot, and changes or deletes one when you edit it from the app. It never touches an event you did not act on. Connecting stores a Google refresh token on our server, encrypted at rest under your account's own key. Events themselves are read by your browser talking to Google directly. Only the event title and start time are stored. Guests, locations, descriptions, attachments and conference links are never stored or transmitted. Disconnecting deletes the token and revokes it with Google immediately.
Daily Trace's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is never used for advertising, never sold, and is never used to train generalized AI models.
RETENTION AND DELETION
Day summaries and kept tabs are held for 30 days, then deleted automatically. Notes you write, and screenshots you dump — both the picture and the text read out of it — are kept until you delete them. Deleting an entry deletes it immediately.
You can take everything with you, or remove all of it, without asking us. Settings has both: an export of your whole account as JSON or Markdown, and a one-click delete of the account and everything under it. The delete is immediate, covers every table we hold, revokes your calendar grant with Google on the way out, and cannot be undone.
NO THIRD PARTIES
No analytics, no trackers, no advertising. If you configure your own LLM provider, your summaries are generated through that provider under your own key and their terms. Two kinds of data reach it and nothing else does: the day's activity when a summary is written, and the open-tab titles described above when the extension popup names your threads.
CONTACT
Questions or deletion requests: harminderminhas@outlook.com