Contents

  1. Introduction
  2. 1. Information We Collect
  3. 2. Browser Permissions
  4. 3. Content You Capture From Other Sites
  5. 4. AI Processing
  6. 5. Third-Party Services
  7. 6. Data Security
  8. 7. Data Retention & Your Choices
  9. 8. Changes to This Privacy Policy
  10. Contact Us
  1. Home
  2. Privacy Policy

Legal

Privacy Policy

How TraceUI handles your information across the web app and the browser extension.

Effective Date: 15 September 2026|Last updated: 25 September 2026

Introduction

Welcome to TraceUI! Your privacy matters to us. This Privacy Policy explains how TraceUI ("we", "us", "our") collects, uses and protects information obtained through our browser extension and our web app at traceui.dev. The two are one product: the extension captures a component from a page you are looking at, and the web app generates, stores and lets you edit it and this policy covers both. By using TraceUI, you agree to the terms of this Privacy Policy.

In short: we hold your account details, your billing tier, and the components you choose to capture. We do not track your browsing, we do not read pages you have not explicitly captured, and we never sell your data.

1. Information We Collect

To turn an element you clicked into a component you can reuse, TraceUI collects and processes the following:

A. Personally Identifiable Information (PII)

  • Account credentials: we authenticate you with email and password or Google OAuth, both powered by Supabase. We store your email address, a unique user ID, and — when you sign in with Google — your name and profile avatar URL. Passwords are stored and verified by Supabase; we never see or store yours.
  • Account purpose: this is used to manage your account, identify your subscription tier (free or pro), keep your library in sync between the extension and the web app, and process upgrades.

B. Captures

A capture is created only when you activate the extension and click an element. For each one we store:

  • Source details: the URL, page title and hostname of the page you captured from, the CSS selector that identified the element, and the time of capture.
  • Rendering context: your viewport size, device pixel ratio, colour scheme (light or dark) and the page background colour — what the component was measured against.
  • Transcribed markup: the element's structure, text, class names, inline styles and remaining attributes, with relative URLs made absolute. Scripts, event handlers, on* attributes, nonces and framework bookkeeping are stripped before the capture ever leaves your browser.
  • A screenshot of the visible tab, cropped to the element you selected and scaled so its longest edge is at most 1024 pixels.
  • Your instructions: anything you typed into the extension's prompt box, plus your saved standing prompt if you set one.
  • The generated component, and which provider, model and prompt version produced it.
  • Your edits: the name you give a component and your design token and scale overrides.

C. Interaction & Analytics Data

  • Plausible Analytics: cookieless, aggregate page and event counts on the web app. It stores nothing on your device and collects no personal data.
  • Mixpanel: product analytics on the website and web app. We record the pages you visit, the site or campaign that referred you (including UTM tags), your approximate location (country and city) and key actions such as joining the waitlist, signing up, signing in and exporting a component. A random identifier is stored in your browser's local storage so visits can be linked together; once you sign in, events are linked to your TraceUI user ID and email. We have configured Mixpanel not to store your IP address. We use this only to understand and improve TraceUI, never for advertising.
  • We do not run Google Analytics or any advertising tracker on TraceUI. If that changes we will say so here, and ask for your consent first where consent is required.
  • Server logs from our hosting provider, which include IP address, user agent, timestamp and requested path.
  • Your IP address is also used for rate limiting, to keep the service available. Those counters expire within minutes and are not linked to your captures.

D. Local Data Stored in Your Browser

The following is stored directly in your browser's extension storage (`chrome.storage.local`) and never leaves your device except as part of a capture you make:

  • Your signed-in session (access and refresh tokens), so the popup, the preview tab and the background worker all see the same session.
  • Your standing prompt and generation preferences.

E. Financial & Payment Information

  • All payments and subscription management are processed securely by Dodo Payments. TraceUI does not collect, process or store your card numbers, banking details or billing address on our servers.
  • We store only what tells us which plan you are on: a customer identifier, a subscription identifier, your tier, subscription status, billing cycle and current period end date.

2. Browser Permissions

TraceUI requests specific browser extension permissions to operate core functions. Below is a breakdown of each one:

  • Storage (`storage`): keeps your session and prompt settings locally, shared across the popup, the preview tab and the background worker.
  • Active Tab, Scripting and Tabs (`activeTab`, `scripting`, `tabs`): highlights the element under your cursor during a capture, and photographs the visible tab at the moment you click. Used only while a capture is running, and only on the tab you are capturing.
  • Content script on all sites (`<all_urls>`): so the capture overlay can be started on whatever page you are on, without you having to grant a permission per site. The script sits idle until you start a capture — nothing is read, sent or stored on pages where you never capture.
  • Host permission for traceui.dev: lets the extension upload a capture to your library and receive your session after you sign in. It is scoped to our own domain alone, so the extension cannot send data to any other server.

TraceUI keeps no browsing history, does not read pages in the background, injects nothing into pages you have not captured, and communicates with no server other than our own.

3. Content You Capture From Other Sites

A capture is a copy of part of someone else's page, chosen by you. If the element you select contains personal data — a name, an email address, an avatar, a message, an account balance — then that data is inside your capture, in both the markup and the screenshot. The same holds if you capture from a page you are logged into.

We treat captures as your content. They are stored under your account, we do not browse them, and we never use them to train models. But we cannot tell from the outside whether a capture contains someone else's information, so the choice of what to capture is yours.

Please do not capture elements displaying other people's personal, confidential or regulated information. Capture the design, not the data — where the layout is what you are after, capture an example with placeholder content wherever you can.

You can delete any capture from your library at any time, which removes the stored markup, the generated component and the screenshot.

4. AI Processing

Turning a captured element into a clean component is done by a third-party AI model. When you capture, we send the transcribed markup, the screenshot and any instruction you typed to one of our model providers, and store what comes back alongside the original.

  • We call these providers through their API tiers, on terms under which submitted content is not used to train their models.
  • Which provider handles a given capture depends on our configuration at the time; we support OpenAI, Google Gemini and Anthropic.
  • The call is made server-side by us. The extension never talks to a model provider directly, and no provider ever receives your account identity or email address.
  • We do not use your captures, prompts or generated components to train any model of our own.

5. Third-Party Services

We partner with trusted third-party providers to power essential features. Each processes data according to its own privacy policy:

  • Supabase & Google: Authentication, database and screenshot storage; Sign in with Google. Privacy policy
  • Vercel: Application hosting and delivery, including server logs. Privacy policy
  • Dodo Payments: Checkout and subscription billing processing. Privacy policy
  • OpenAI: AI model inference — receives capture markup, screenshot and your prompt. Privacy policy
  • Google Gemini: AI model inference, when selected as the provider. Privacy policy
  • Anthropic: AI model inference, when selected as the provider. Privacy policy
  • Upstash: Redis, used for short-lived rate-limit counters. Privacy policy
  • Plausible Analytics: Cookieless, aggregate product analytics. Privacy policy
  • Mixpanel: Product analytics: page visits, referral sources and key actions on the website and web app. Privacy policy

6. Data Security

We take the security of your data seriously. All communication between the extension, our servers and third-party APIs uses industry-standard HTTPS/TLS encryption, and data is encrypted at rest by our infrastructure providers.

  • Every row in our database is protected by row-level security, so one account cannot read another's captures.
  • Screenshots live in a private storage bucket that is not publicly readable. Viewing one needs a short-lived signed link, issued only after your ownership of that capture has been verified.
  • Model API keys and other secrets are held server-side and are never included in the extension bundle.

We never sell, rent or trade your personal information to third parties or advertising networks. No system is perfectly secure, and if a breach affects your personal data we will notify you.

7. Data Retention & Your Choices

  • Captures, generated components and screenshots are kept until you delete them, or until you delete your account.
  • Account details are kept for as long as your account exists.
  • Billing records are kept as long as tax and accounting law requires.
  • Rate-limit counters expire within minutes; server logs are kept for a short operational period, measured in days rather than months.

You can view and delete individual captures from your library, and delete your account from settings — which removes your captures, screenshots and profile. Depending on where you live you may also have the right to access, correct, export or restrict the data we hold, and to withdraw consent where processing rests on it. Email us and we will help; there is no charge, and you will not be treated differently for asking.

8. Changes to This Privacy Policy

We may update this Privacy Policy periodically to reflect new features, performance improvements or legal requirements. Any update will be published with a revised "Last updated" date at the top of this policy, and we will tell you by email or in the app before a change that materially affects how we use your data takes effect. We encourage you to review this policy from time to time.

Contact Us

If you have any questions or concerns about this Privacy Policy or TraceUI's privacy practices, please contact us at:

Bhuwan Mahato Mail: support@traceui.dev

Thank you for using TraceUI!

See also our Terms of Service.