TraceShot Privacy Policy

Last updated: July 22, 2026

TraceShot is a Chrome extension that captures a region of the page you are viewing, embeds an invisible traceable ID into the saved image, and later lets you decode that image to recover the URL it came from. This policy explains what data TraceShot collects, why, and how it is handled.

What we collect

What we do not collect

How your data is stored and shared

Account and screenshot metadata are stored in a Supabase (PostgreSQL) database and served through infrastructure hosted on Vercel. Your authentication token is stored locally on your device in the extension’s chrome.storage.local and is cleared when you sign out.

We share data only with the service providers that operate TraceShot on our behalf — Google (sign-in), Supabase (database), and Vercel (hosting) — and only as needed to run the service. We do not share your data with any other third parties.

Extension permissions

TraceShot requests only the permissions it needs to capture the current page:

Data retention and deletion

We retain your account and screenshot metadata until you request its deletion. To delete your account or any stored screenshot records, contact us at anshs+traceshot@umich.edu and we will remove it.

Children

TraceShot is not directed to children under 13, and we do not knowingly collect their data.

Changes to this policy

We may update this policy from time to time. Material changes will be reflected by updating the “Last updated” date above.

Contact

Questions about this policy or your data? Email anshs+traceshot@umich.edu.

TraceShot is open source. You can review exactly what it does at github.com/anshah1/TraceShot.