TraceDeck · Privacy

Your browser data stays in your browser.

A detailed, plain-language account of what TraceDeck handles, why it needs that access, and the controls available to you.

Plain-language summary

TraceDeck processes browser data only to provide the feature you use, and it does not send that data to us. Your profiles, rules, and preferences stay in your browser. Redirect traces are temporary. Exported files go only to the location you choose.

01

Scope

This Privacy Policy explains how the TraceDeck browser extension (“TraceDeck,” “we,” “us,” or “our”) handles information when you install or use it. It applies to the extension and this policy page. It does not govern websites you visit or browser services supplied by Google, Microsoft, or another browser vendor.

02

Information TraceDeck processes

TraceDeck requires access to browser information to provide its visible, user-facing features. Depending on what you use, it may process:

  • URLs and browsing activity: page and request URLs needed to display a redirect path, identify URLs from the current domain, reload tabs, and determine whether a configured rule applies.
  • Request and response data: HTTP status information, request timing, and headers needed to present a trace or apply header rules.
  • Authentication information: cookies accessible to the active site so you can view, create, edit, delete, encode, or decode cookie values.
  • User configuration: profiles, request and response header rules, cookie overrides, redirect rules, URL conditions, request methods, enabled states, and preferences you create.
  • Technical context: tab identifiers and navigation events required to associate activity with the correct browser tab.
Processed is not collected. This information is handled within the extension on your device. TraceDeck does not transmit it to us or to a third-party analytics or storage service.
03

How information is used

TraceDeck uses browser information only to deliver and maintain the extension features you direct:

  • capture and display redirect and navigation paths;
  • generate a cURL representation of a captured request;
  • show and edit cookies for the active site;
  • show and edit parameters for the current URL or other open URLs on the same domain;
  • match and apply enabled profiles, headers, cookie overrides, and redirects; and
  • save, import, export, and restore configuration when you request those actions.

TraceDeck does not use browser information for advertising, marketing, credit decisions, lending, insurance, surveillance, or any purpose unrelated to its single-purpose developer tooling.

Limited Use commitment. TraceDeck’s use of information received from Google APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements.
04

Storage and retention

TraceDeck has no developer-operated backend and does not use remote storage.

Information stored locally

Your profiles, rules, and preferences are stored in chrome.storage.local. They remain on that browser profile until you modify or delete them, clear the extension’s local data, or uninstall TraceDeck.

Information kept temporarily

Redirect traces live in service-worker memory only. They disappear when you clear the trace, close its tab, or when the service worker or browser session ends, and TraceDeck never builds a persistent history of visited URLs. The URL Parameters view works the same way: it derives same-domain URLs from the current tab, other open tabs, and whatever trace data is already in memory, so there is nothing left to look up later.

Sensitive header values captured in a trace, such as an authorization token or session cookie, are masked by default in the popup's trace detail. Revealing one takes an explicit “Reveal sensitive headers” action in that view, and even then the value never leaves your device.

Website cookies

Cookies you create or modify are stored by your browser for the applicable website according to the cookie’s own attributes and that website’s behavior. They are not copied into a TraceDeck account or server.

05

User-directed imports and exports

TraceDeck can read a configuration file you select and can write configuration backups or redirect reports to a location you select on your device. These are local, user-initiated operations, and TraceDeck never receives a copy of what you export.

Redirect-report exports redact sensitive header values such as authorization credentials, cookies, and recognized API-key headers. Before an import or restore replaces your current configuration, TraceDeck shows you what the file contains so you can decide whether to go ahead. Exported files are under your control from that point on, so review them before sharing and store them appropriately.

06

Browser permissions

Browser stores display broad permission notices because TraceDeck must work on sites where you choose to use it. Access is limited to providing the extension’s stated functions.

PermissionWhy TraceDeck needs it
cookiesView and manage cookies for the site you are working with and apply cookie overrides you enable.
alarmsTurn automatically expiring profiles off at the time you select.
declarativeNetRequestWithHostAccessApply enabled rules only on sites you have approved.
storageKeep your profiles, rules, and preferences locally in the browser.
tabsIdentify the active tab, reload tabs when requested, and find currently open same-domain URLs for the URL Parameters tool.
webNavigationAssociate navigations and redirect events with the correct tab and display their sequence.
webRequestObserve request and response metadata needed to construct redirect traces and cURL output.
Optional <all_urls>Approve only the current site from the popup, or explicitly allow all sites in Settings. TraceDeck uses only the website access you grant.
07

Incognito mode

TraceDeck can operate in incognito windows only if you explicitly allow incognito access in your browser’s extension settings. When allowed, the same local-processing commitments in this policy apply. Your browser controls how extension configuration is shared between regular and incognito windows.

08

Sharing, sale, and advertising

TraceDeck does not sell, rent, license, or disclose your browser data to third parties, and it carries no advertising, analytics, telemetry, or tracking pixels. It does not build a behavioral profile or follow you across websites.

The extension does not load remotely hosted executable code. Its code and assets ship with the installed extension.

The popup includes an optional Buy me a Coffee link. TraceDeck contacts no support or payment service automatically. If you choose that link, your browser opens https://buymeacoffee.com/sutrakara in a new tab with referrer information suppressed. Your visit and any transaction are then governed by Buy Me a Coffee’s own terms and privacy practices. TraceDeck never sends that service your browsing activity, cookies, headers, profiles, rules, or preferences.

09

Your controls and privacy rights

You can enable or disable profiles, edit or delete rules, clear redirect traces, manage cookies, export or restore local configuration, reset profiles and settings to safe defaults without losing your rules, revoke site or incognito access in your browser, or uninstall TraceDeck.

Privacy laws in some jurisdictions give you rights to access, correct, delete, or restrict personal information held by a service provider. Because TraceDeck does not receive or maintain your browser data on its own systems, there is generally no server-side user record for us to retrieve or delete. For help understanding the extension’s local data, contact us below.

10

Security

TraceDeck reduces its exposure by keeping all processing local and avoiding a backend. Sensitive header values are masked in the popup by default, revealing them takes an explicit action, and they are redacted from trace exports and copied cURL commands. The extension ships its executable code directly rather than loading it at runtime. Still, no software or local storage method is risk-free: keep your browser and extension current, protect access to your device, and review rules and exported files before using or sharing them.

11

Children

TraceDeck is a technical browser utility. It is not directed to children under 13 or the minimum age required by applicable law, and we do not knowingly collect personal information from children, or from any user, through a TraceDeck-operated service.

12

International users

Because TraceDeck does not transmit your browser data to us, it does not transfer that data to a TraceDeck server in another country. Your browser vendor, operating system, websites you visit, and any files you independently share may have their own data practices and geographic processing locations.

13

Changes to this policy

We may update this policy when TraceDeck’s features, permissions, or legal obligations change. The effective date at the top will identify the latest version. If a change materially affects how the extension handles browser data, we will provide notice through an appropriate product or distribution channel before the change takes effect where required.

14

Contact

Questions about this policy or TraceDeck’s privacy practices can be sent to:

[email protected]