← Back

Privacy Policy

Effective date: September 30, 2026

What We Collect

TraceWaves collects only what's needed to provide the service:

  • Account identity: the name, email and account ID your sign-in method gives us: Sign in with Apple (which may be a private relay address), Google, Microsoft or GitHub, or the email address you use for an email sign-in link. We never see or store passwords. If you add a passkey, we store only its public key and a device label; the private key never leaves your device.
  • Data you sync: when you're signed in, sync keeps your data the same on all your devices. By default that includes journal entries, scan sessions (networks observed, their security settings and grades), baselines, findings and your triage of them, alert rules, and your app settings (such as theme and notification preferences). Forensic cases sync only when you turn sync on for that case. You can turn sync off for any type in Settings → Sync.
  • Opt-in only: GPS coordinates, Bluetooth device identifiers and local-network device identifiers are not uploaded unless you turn them on. Location recording must be enabled separately on each device.
  • Contact form: if you contact us, we receive your name, email address, topic and message, and a one-way hash of your IP address used only to limit abuse.
  • Security logs: for sign-ins and changes to your data we record the time, the action, your IP address and your browser's user agent, to detect abuse and protect your account.

What Stays on Your Device

  • Anything you haven't signed in to sync, and any type you've turned off, stays on the device where you captured it.
  • The optional local scan agent runs on your computer, listens only on 127.0.0.1, and sends scan results only to the TraceWaves page open in your browser.
  • On-device data is protected by your device's own security (disk encryption, screen lock, app sandbox); TraceWaves doesn't add a separate encryption layer. On a shared computer, remove local data when you sign out, or use Clear All Local Data in Settings.

What We Don't Do

  • We don't track your location in the background. GPS is read only when you capture something and have turned location tagging on.
  • We don't sell, share or monetize your data, and we don't use advertising or analytics trackers.
  • We don't write the contents of your journal, cases or scans to server logs.

Storage & Security

  • All traffic is encrypted in transit with TLS 1.2 or later.
  • Sessions use httpOnly, secure cookies in the web app and the OS keychain in native apps, never script-readable storage. Access tokens expire after 15 minutes, and refresh tokens rotate on every use.
  • Each user can reach only their own data. The server checks ownership on every request.
  • Forensic case evidence is append-only and hash-chained, so any later change is detectable.
  • TraceWaves administrators can see account information needed to run the service (such as your email address, sign-in method, sign-up and last-activity dates, app versions, and how many items you have synced) but cannot view the content you sync, such as journal entries, case evidence or scan results. Every administrative action is recorded in an audit log.

Retention & Deletion

  • Delete any item at any time. Deletions sync to your other devices, and deleted items are permanently removed from our servers after 30 days. A minimal deletion marker (no content) is kept for up to 90 days so your other devices learn about the deletion.
  • Delete Account in Settings (web, Mac, iPhone, iPad and Android) immediately and permanently deletes your account and all data synced to our servers, and revokes Sign in with Apple if you used it. Security log records are kept for abuse prevention but are unlinked from your account.
  • Data on your device is always under your control and isn't affected by account deletion. Clear it separately in Settings.
  • Contact form messages are kept only as long as needed to answer you.

Service Providers & Data Sources

  • Apple, Google, Microsoft and GitHub handle sign-in only.
  • Cloudflare carries traffic to tracewaves.app as our network provider.
  • Our email provider delivers sign-in links, security alerts and replies to contact messages.
  • NIST NVD, CISA and IEEE: our server downloads public vulnerability and hardware-vendor data from them. No user data is sent.

Your Rights

You can delete your account and all synced data yourself in Settings at any time, and remove data stored on your device the same way. Both take effect immediately.

For any other privacy question or request, contact us and choose the topic Privacy. We'll reply by email.

Changes

We'll update the effective date above whenever this policy changes.