This policy explains how TaskTrace collects and uses data. This is an initial operational draft, not legal advice.
What do we collect?
- Account data: your name, email, and settings.
- Tracking data: project display name, relative file path, programming language, branch, repository/commit fingerprints, activity timestamps, and optional agent provider/model/session/token counts.
- Billing data: the projects, employers, rates, and invoices you create.
What do we never collect?
- Source code content.
- Absolute file paths that reveal your username or machine structure.
- Raw Git remote URLs, agent prompts or responses, tool arguments/results, or files matching exclusion patterns (node_modules, vendor, .env, …).
How do we protect your data?
- API keys are stored in your OS keychain via SecretStorage in the extension.
- Non-local connections require HTTPS.
- Public invoices use a private link that search engines do not index.
Your rights
You can request correction or deletion of your data by contacting us at the email registered on your account. You can stop tracking by removing the extension or deleting your API key.
Contact
For privacy inquiries: privacy@tasktrace.app