Trace
Privacy Policy
Effective 25 September 2026 · Beta
Trace is a private, voice-first symptom journal. You describe how you feel; Trace transcribes it and turns it into simple 0–10 scores so you can see patterns over time. This policy explains, in plain language, what we collect, how we use it, and the choices you have. We built Trace privacy-first: we do not run ads, and we do not sell your data.
What we collect
- Account. You sign in with Sign in with Apple. We receive a user identifier and, if you choose to share it, your name. Apple can relay a private, per-app email address instead of your real one.
- Your entries. The symptom descriptions you record (as text transcribed from your voice, or typed) and the pain, energy, mood, and sleep scores for them, with timestamps.
- App settings. Things like your reminder time.
- Usage & diagnostics. How the app is used (for example, that an entry was recorded, or that scoring failed) and crash/error reports. These are linked to a random account identifier — not your name or email — and never include what you logged: no entry text or scores.
Trace does not record or keep audio. Your voice is turned into text by Apple's speech recognition on your iPhone; depending on your device and settings, Apple may process that audio on its servers to do so.
How we use it
- To provide the app: store what you log, back it up to your account, and show your history and trends.
- To generate scores from your descriptions.
- To write a practitioner brief when you ask for one — from your dates and scores only, never your entry text.
- During the beta, to review what you log so we can improve features and scoring accuracy.
- To find and fix bugs, and understand which features help.
Who processes your data
We use a small number of service providers (“subprocessors”) to run Trace:
- Supabase — hosts our database and stores what you log and your account, with access restricted to your own account.
- Anthropic — processes your descriptions to generate scores, and your dates and scores when you ask for a brief. We request that your content is not used to train models.
- Cloudflare — runs the service that forwards your descriptions to Anthropic. It passes them through without storing them.
- Apple — provides Sign in with Apple and speech recognition.
- PostHog — product analytics (no logged content).
- Sentry — crash and error diagnostics (no logged content).
We do not share your data with advertisers, and there are no advertising or third-party tracking SDKs in the app.
Storage & security
Your data is encrypted in transit (HTTPS). What you log is stored with our database provider and scoped to your account, so other users can't read it. No system is perfectly secure, but we limit who and what can access your data and keep that surface small.
Your choices
- Delete an entry at any time from your history.
- Export your data (CSV or JSON) from Settings.
- Sign out. This phone keeps its copy for when you sign back in. If a different account signs in on this phone, your copy is removed from it first (anything already backed up stays in your account).
- Delete your account from Settings — this removes everything you've logged from our servers and wipes the data stored on your device.
Data retention
We keep what you log until you delete it or delete your account. Usage and diagnostics are retained only as long as useful for fixing issues and understanding the product.
Children
Trace is not intended for anyone under 18, and we don't knowingly collect data from children.
Changes
If we make material changes to this policy, we'll update this page and the effective date above.
Contact
Questions or requests about your data? Email hello@tracejournal.life.