Privacy
Daily Trace is a private journal of your own attention. The short version: your data is yours, it is encrypted at rest, and it is never sold, shared, or used for anything except showing your journal back to you.
What we store
- Your email address — used only to identify your account.
- Day summaries — short texts describing what you worked on, generated from browsing activity the browser extension sends only when you have installed it and signed in. Raw browsing history stays on your device; the server receives clustered session snippets used to write the summary.
- Notes you write — your own knowledge base, kept until you delete it. This is the one thing here you author rather than receive.
- Kept tabs and planned items you explicitly add, plus calendar event titles if you connect Google Calendar (see below).
- Your settings, including any LLM API key you configure. API keys are write-only: they are never shown back, even to you.
Your open tabs, when you open the extension popup
The popup groups your open tabs by what they were for rather than by which site they came from, so you can close a whole line of work at once. Naming those groups needs a model, so this is the one thing the extension sends without you pressing anything — it happens when the popup opens.
- What is sent: each open tab's page title and hostname. Not the full URL, not page content, and never more than 60 tabs. Pinned tabs and non-web tabs are excluded.
- Where it goes: your Daily Trace server, which passes it to the LLM provider you configured in Settings and gets back a list of group names. The server does not store the list.
- How often: once per set of open tabs. The names are cached in your browser for as long as that exact set stays open, so opening the popup again sends nothing.
- If it fails — offline, no provider configured, anything — the popup falls back to grouping by site, worked out on your own machine, and nothing is transmitted at all.
Nothing is saved to your journal and no tab is closed unless you press “keep & close”.
How it's protected
- All journal content and settings are encrypted at rest (AES-256-GCM).
- Session tokens are stored hashed; a database leak cannot impersonate you.
- Everything travels over HTTPS.
Sign in with Google
When you sign in with Google, we receive only your email address to create or find your account. Signing in requests nothing else — no contacts, no calendar, no files.
Google Calendar (optional)
You can separately connect Google Calendar so your journal can show what you planned beside what you actually did. This is off unless you turn it on in Settings, and you can disconnect at any time.
- We can read and change events. We request
calendar.events, across the calendars you have showing in Google — not only your primary one. Daily Trace creates an event when you book a task into a free slot, and changes or deletes one when you edit it from the app. It never touches an event you did not act on. - We hold a token for your calendar until you disconnect. Connecting stores a Google refresh token on our server, encrypted at rest under your account's own key. It is what lets the calendar keep working instead of lapsing every hour. Your events themselves are still read by your browser talking to Google directly — they do not pass through our server.
- Only the event title and start time are stored, alongside your journal and encrypted the same way. Guests, locations, descriptions, attachments, and conference links are never stored or transmitted.
- Events you have declined are ignored.
- Disconnecting deletes the token and revokes it with Google immediately. A grant you revoke from your Google account permissions is dropped here too, the next time we try to use it.
To tell you whether a planned item actually happened, the event title is sent — with that day's summary — to the LLM provider you configured in Settings, under your own API key and their terms. That is the only place calendar-derived data goes. If you would rather it went nowhere, leave the calendar disconnected.
Daily Trace's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is never used for advertising, never sold, and is never used to train generalized AI models.
Retention and deletion
Day summaries and kept tabs are held for 30 days, then deleted automatically. Notes you write, and the text read out of a screenshot you dumped, are kept until you delete them — a reference that expires is not one; the picture itself is still dropped after 30 days. Deleting an entry deletes it immediately.
You can take everything with you, or remove all of it, without asking us. Settings has both: an export of your whole account as JSON or Markdown — every day, note and screenshot's text, in a form that outlives this app — and a one-click delete of the account and everything under it. The delete is immediate, covers every table we hold, revokes your calendar grant with Google on the way out, and cannot be undone. Neither the export nor anything we store contains your password.
No third parties
No analytics, no trackers, no advertising. If you configure your own LLM provider, your summaries are generated through that provider under your own key and their terms. Two kinds of data reach it and nothing else does: the day's activity when a summary is written, and the open-tab titles described above when the extension popup names your threads.
Contact
Questions or deletion requests: [email protected]